Audit the v0.6 review findings against accepted v0.7
Marking the 2026-08-29 review round read on the reasoning that v0.7's acceptance closed it was an inference, not a check. This does the check: fifteen findings and two answered questions from kings-guard, ops-warden, access-engine and audit-core, each traced to v0.7 text or a decision record rather than to the §15 change log. All fifteen are dispositioned. None was silently dropped. The change log deliberately is not the evidence — kings-guard's finding 1 was exactly the case where the change log claimed a rule the body did not contain. One item surfaced, and it is not a v0.6 finding: §17 still says emission-cadence ownership is proposed and unassented, which GH-DEC-2026-004 and the info-tech-canon and net-kingdom acceptances have since made false. Tracked as GH-WP-0003-T07. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 425128@bnt-lap001 Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
This commit is contained in:
parent
e16cd792b3
commit
fcdcb0af9b
2 changed files with 113 additions and 0 deletions
96
docs/conformance/2026-09-06-v06-findings-audit.md
Normal file
96
docs/conformance/2026-09-06-v06-findings-audit.md
Normal file
|
|
@ -0,0 +1,96 @@
|
|||
# Audit — v0.6 review findings against accepted v0.7
|
||||
|
||||
**Repository:** gate-house
|
||||
**Project family:** NetKingdom security layer
|
||||
**Status:** complete
|
||||
**Version:** 1.0
|
||||
**Date:** 2026-09-06
|
||||
|
||||
## Why this exists
|
||||
|
||||
On 2026-09-06 the four v0.6 review messages — `kings-guard`, `ops-warden`,
|
||||
`access-engine` (flex-auth), and `audit-core` — were marked read on the reasoning
|
||||
that v0.7's acceptance closed the round by definition. That is an inference, not a
|
||||
check. A review round is closed when each finding has a disposition someone can
|
||||
point at, not when a later version is accepted over it.
|
||||
|
||||
This document does the check. Fifteen findings and two answered questions were
|
||||
raised across the four reviews. Each is traced to text in
|
||||
`net-kingdom/canon/standards/security-layer-model_v0.7.md` or to a decision record.
|
||||
|
||||
**Result: all fifteen are dispositioned. None was silently dropped.** One
|
||||
consequence of a *later* decision has since made a v0.7 paragraph stale; it is
|
||||
recorded below and tracked, and it is not a v0.6 finding.
|
||||
|
||||
## kings-guard
|
||||
|
||||
| # | Finding | Disposition |
|
||||
| --- | --- | --- |
|
||||
| 1 | §1 and §15 announce a human/agent principal separation that §3.4 never states | **Written.** §3.4 now carries *"Two principals, one layer"* and the four rules binding the agent principal: no standing credential, tool use is a conduit or an Engine API, agent memory is not a state plane, every agent action reconstructable as the caller's. `glas-harness` is demarcated as governing session conduct. |
|
||||
| 2 | §13 attributes the containment surface to `kings-guard`, which §9.2 ruled is not theirs | **Reattributed.** The §13 row now reads declarer `gate-house (estate-wide)`, owner `access-engine + runtime engines`, state `proposed`; §9.2's text says `kings-guard` is not the declarer. |
|
||||
| 3 | §17's emission-cadence declaration is unowned; offer to draft it | **Accepted, then owned.** §17 records `kings-guard` as accepted drafter. Ownership itself was settled later by `GH-DEC-2026-004`. |
|
||||
| nit | §17–§19 are H1 where every other section is H2 | **Fixed.** §17 and §18 are H2; §19 no longer exists (see access-engine 5). |
|
||||
|
||||
The finding kings-guard called substantive was finding 1, and it was the right call:
|
||||
a rule announced in a change log and absent from the body is the §11 defect turned on
|
||||
the standard itself. It is now in the body.
|
||||
|
||||
## ops-warden
|
||||
|
||||
| # | Finding | Disposition |
|
||||
| --- | --- | --- |
|
||||
| 1 | §6.4 obligation 1 forbids what obligation 3 blesses; ops-warden's shipped fail-open stance was made a violation | **Adopted, near-verbatim.** Obligation 1 now reads *"…or its declared §9.3 stance for the applicable scope permits proceeding without one and the application of that stance is recorded in place of the decision."* The text names the second limb as stricter than silence and credits ops-warden as the reference shape. |
|
||||
| 2 | §6.4 mandates a stance-map register §13 does not implement | **Register created.** §13.1 "PEP stance-map register" exists; §6.4's closing paragraph records that v0.6 named a register that did not exist and that its first inventory had one row, "which is itself the finding". |
|
||||
| rec | The published map MUST equal shipped behaviour | **Adopted.** Obligation 3 carries the equality requirement with the SHOULD-be-tested clause and ops-warden's own reasoning: a map free to drift is worse than none. |
|
||||
|
||||
ops-warden's process note — that `assented_by` carries assent forward across five
|
||||
revisions and could be read as assent to current text — is answered in the v0.7
|
||||
header comment: *"records assent to a BOUNDARY, given at the version named. It is not
|
||||
assent to the current text."*
|
||||
|
||||
## access-engine (flex-auth)
|
||||
|
||||
| # | Item | Disposition |
|
||||
| --- | --- | --- |
|
||||
| Q1(a) | §6.4.2 forbids the session-bound allow §9.7.1 permits | **Scoped.** Obligation 2 is now bounded to replay *outside* the decision's stated binding and lifetime, and says v0.6 forbade what §9.7.1 permits. |
|
||||
| Q1(b) | "Later request" needs a mechanical test | **Adopted as normative.** Replay is permitted iff the canonical request digest matches and the lifetime holds. |
|
||||
| Q1(c) | Deny-caching is outlawed by inference, never ruled on | **Ruled explicitly.** Negative caching is permitted narrowly: the refusal must be recorded against the request refused, and the cache lifetime declared alongside the stance map. |
|
||||
| Q2 | A single visibility deadline is the wrong shape for a PDP | **Adopted.** §9.7.2 requires one deadline at a PEP and a deadline per input class at a PDP, and names the registry-provenance digest and the deadline as one gap seen from two sides. |
|
||||
| 1 | §6.4's stance-map register does not exist | **Same disposition as ops-warden 2.** §13.1 exists; §6.4 credits both repositories as raising it independently. |
|
||||
| 2 | The companion omits where a stance map is published and omits the inventory obligation | **Fixed.** `SECURITY-COMPANION.md` step 3 now says *"at a path named in your layer declaration, and register it in statute §13.1"*. |
|
||||
| 3 | §17 puts the decision-record schema in the wrong layer | **Adopted.** The row is struck through and moved to `access-engine`, with a paragraph applying the §2 ownership rule and noting the finding was raised against its own interest. |
|
||||
| 4 | §17–§19 H1 headings | **Fixed** (see kings-guard nit). |
|
||||
| 5 | §19 grades the document it lives in | **Removed.** There is no §19 in v0.7; the numbering runs §18 → §20. |
|
||||
|
||||
## audit-core
|
||||
|
||||
| # | Finding | Disposition |
|
||||
| --- | --- | --- |
|
||||
| 1 | Atomicity closes accidental omission, not the adversarial case §9.6 opens with | **Adopted as a decomposition table.** §9.6 now separates accidental omission (closed by atomicity) from adversarial omission (*"detected, after the fact"* by cadence and reconciliation), and states the residual explicitly: nothing in the model prevents adversarial omission at a compromised source. |
|
||||
| 2 | Cadence is a SHOULD and is the only control on that residual; rate monitoring inverts the priority for rare events | **Both halves adopted.** Load-bearing sources MUST declare cadence (attributive SHOULD), and for low-volume load-bearing classes the required form is positive reconciliation or a heartbeat rather than rate monitoring, with `GH-WP-0002-T04` named as the reference instance. |
|
||||
| 3 | §3.3's Evidence row states a trade as a property | **Adopted.** The row reads *"a default, not a property; see below"*, and the following paragraph records that an operation genuinely requiring independent recording before effect is a declared exception raised when needed, not one ruled out by a table cell. |
|
||||
|
||||
Finding 1 corrected a remedy audit-core had itself proposed, and finding 2 argued
|
||||
against the control it was defending. Both are in the standard in stronger form than
|
||||
they arrived.
|
||||
|
||||
## What the audit did surface
|
||||
|
||||
Not a v0.6 finding — a v0.7 paragraph made stale by a later decision.
|
||||
|
||||
§17 closes with *"Ownership is proposed, not assigned… Neither has assented."* That
|
||||
was true when v0.7 was accepted. It is no longer: `GH-DEC-2026-004` assigned the
|
||||
split — `info-tech-canon` owns the ecosystem-wide `EmissionCadenceDeclaration`
|
||||
contract, `net-kingdom` owns the NetKingdom security profile — and both accepted in
|
||||
their own voice (`ITC-WP-0018` publishing `ITC-EMISSION-CADENCE 0.1` in canon 0.7.0;
|
||||
`NK-WP-0035` publishing `emission-cadence-security-profile_v0.1.md`). A reader of the
|
||||
accepted statute is currently told the estate has not decided something it has.
|
||||
|
||||
Tracked as `GH-WP-0003-T07`. v0.7 is not patched in place.
|
||||
|
||||
## Method note
|
||||
|
||||
The four review messages were re-read from the State Hub rather than from memory, and
|
||||
each finding was checked against the v0.7 text rather than against the change log.
|
||||
§15's change log is a claim about the body; kings-guard's finding 1 is precisely the
|
||||
case where that claim was false, so it cannot be the evidence.
|
||||
|
|
@ -132,3 +132,20 @@ state_hub_task_id: "ecc01a7b-22df-5a9c-a29b-eb7559713ca7"
|
|||
assent as v0.6 and v0.7 were, and hand to `net-kingdom` for publication. Record
|
||||
dispositions of the returned findings. v0.7 stays accepted and unedited until v0.8
|
||||
is accepted in its place.
|
||||
|
||||
```task
|
||||
id: GH-WP-0003-T07
|
||||
status: todo
|
||||
priority: low
|
||||
```
|
||||
|
||||
**§17 — refresh the ownership paragraph.** §17 closes with "Ownership is proposed,
|
||||
not assigned… Neither has assented." `GH-DEC-2026-004` assigned the split and both
|
||||
`info-tech-canon` (`ITC-WP-0018`, `ITC-EMISSION-CADENCE 0.1` in canon 0.7.0) and
|
||||
`net-kingdom` (`NK-WP-0035`, `emission-cadence-security-profile_v0.1.md`) have
|
||||
accepted in their own voice. Replace the paragraph with the settled ownership and
|
||||
cite the decision; keep §17's drafter credit to `kings-guard`.
|
||||
|
||||
Surfaced by `docs/conformance/2026-09-06-v06-findings-audit.md`, which also confirms
|
||||
that all fifteen v0.6 review findings are dispositioned in v0.7 — this is the one
|
||||
paragraph a later decision made stale, not a missed finding.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue