Commit graph

7 commits

Author SHA1 Message Date
0a1d1d942a Rule INFD-IN-0001: PEP-shaped, presentation claim permitted, view_hash distinct
informed-decision filed three rulings before writing any architecture,
with candidate answers, their costs, the self-dealing objection argued
against itself, and a list of what it was not asking for. That order is
what section 17 exists to produce, and KEY-WP-0013-T02 is blocked today,
so it is answered now rather than queued.

R1 — PEP-shaped, confirmed as proposed, not an Engine. It holds no
state another layer reads at runtime for a verdict, which is the test.
Its layer stays its own to declare; this settles its shape, which is
what was blocking. It should build to v0.8's obligation 3 rather than
v0.7's and inherit GH-DEC-2026-010's attribution gap knowingly rather
than describe its validation as complete.

R2 — yes, and no second catalog row. PEP and PIP are shapes a
repository has; the catalog records layers it occupies. Obligation 5
forbids a PIP republishing the PDP's decision, which is a prohibition
on republishing a decision, not on holding two shapes. Three limits
carry the permission: the claim carries presentation and nothing else,
it must never be an input to the decision it presents for, and its
evidence copy reaches audit-core independently of the emitter. The last
is the one that matters here, because the actor and the source are the
same component.

R3 — candidate (b). The binding digest is authoritative for what the
request is; view_hash only for what was shown; a disagreement between
them is a finding against the presenting surface, never a fact about
the request. (a) is refused doctrinally rather than on the cost given:
merging the two makes one repository the authority on what another
layer computes over a request, which is GH-DEC-2026-008's objection to
translation. (c) is refused because nesting the binding digest inside
view_hash reproduces the hash cycle that made GH-DEC-2026-008
unimplementable — we paid for that lesson once this quarter. The two
link by co-reference instead: the presentation record names the binding
identifier and never recomputes the other layer's digest.

The residual is not closed and the ruling says so, as they asked. A
compromised surface can present X and attest Y. Attestation covers
accident and later tampering, never a compromised source — the same
disposition approval-engine's equivalent takes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012viPor8WJNCbV64ipwewrm

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1754332@bnt-lap001
Assistant-Session: 9c8ac536-ff5e-46a3-8ab1-a548bde25fc0
2026-09-09 22:10:45 +02:00
1a920a5490 Confirm the approval-claim as the step-1 PEP artifact
approval-engine raised APPROVAL-IN-0002: secrets-engine's PEP validator
expects a flex-auth ActionAuthorization but fetches the approval-claim
endpoint that GH-DEC-2026-003 names as step 1. Two objects on one path.

GH-IN-0002 records the intake; GH-DEC-2026-005 resolves it. The claim is
the step-1 artifact and always was — ActionAuthorization is unratified,
has no valid_now field, and cannot be served from a step-1 call. The
addition beyond confirmation is doctrine: a PEP validates each artifact
against the layer that owns its data, and no PIP republishes the PDP's
decision. The provenance.authority == "state-hub" requirement is struck;
State Hub is a read model and holds no runtime approval authority.

docs/contracts/approval-consumption.md carries the amendment at the
sequence itself so implementers find it there.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:29:28 +02:00
repo-manager
be18542cc6 repo.work.create_intake GH-IN-0002
correlation_id: d2369d5a-ffae-4dc5-9f6a-ee4011d50b4c
reason: rmgr CLI
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 01:28:12 +02:00
repo-manager
c638822d17 chore(registrar): assign State Hub identifiers
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:56:51 +02:00
repo-manager
159283663b repo.work.close_intake GH-IN-0001
correlation_id: 7df6a142-2e5c-45ae-8fbd-b74a9df445be
reason: Promoted to GH-WP-0002
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:55:21 +02:00
repo-manager
776fa6893b repo.work.add_intake_note GH-IN-0001
correlation_id: b339a2a6-eafd-4d77-a140-67f037e7a560
reason: Promote GH-IN-0001 to GH-WP-0002
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2564823@bnt-lap001
Assistant-Session: 2a7ed827-4928-4b9f-8613-9135c9cadfe9
2026-08-29 02:55:21 +02:00
repo-manager
d62d48aba2 repo.work.create_intake GH-IN-0001
correlation_id: 8a98310d-7fcf-41c0-9db2-9157d10a62e4
reason: audit-core raises the emission atomicity gap conditioning its AUDIT-IN-0001 assent; requests promotion to a GH-WP workplan
source: repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 4040362@bnt-lap001
Assistant-Session: 4fd0fd24-2ee8-4413-bd67-43bd79ca73f1
2026-08-28 22:50:02 +02:00