Marking the 2026-08-29 review round read on the reasoning that v0.7's acceptance closed it was an inference, not a check. This does the check: fifteen findings and two answered questions from kings-guard, ops-warden, access-engine and audit-core, each traced to v0.7 text or a decision record rather than to the §15 change log. All fifteen are dispositioned. None was silently dropped. The change log deliberately is not the evidence — kings-guard's finding 1 was exactly the case where the change log claimed a rule the body did not contain. One item surfaced, and it is not a v0.6 finding: §17 still says emission-cadence ownership is proposed and unassented, which GH-DEC-2026-004 and the info-tech-canon and net-kingdom acceptances have since made false. Tracked as GH-WP-0003-T07. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 425128@bnt-lap001 Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
7.7 KiB
Audit — v0.6 review findings against accepted v0.7
Repository: gate-house Project family: NetKingdom security layer Status: complete Version: 1.0 Date: 2026-09-06
Why this exists
On 2026-09-06 the four v0.6 review messages — kings-guard, ops-warden,
access-engine (flex-auth), and audit-core — were marked read on the reasoning
that v0.7's acceptance closed the round by definition. That is an inference, not a
check. A review round is closed when each finding has a disposition someone can
point at, not when a later version is accepted over it.
This document does the check. Fifteen findings and two answered questions were
raised across the four reviews. Each is traced to text in
net-kingdom/canon/standards/security-layer-model_v0.7.md or to a decision record.
Result: all fifteen are dispositioned. None was silently dropped. One consequence of a later decision has since made a v0.7 paragraph stale; it is recorded below and tracked, and it is not a v0.6 finding.
kings-guard
| # | Finding | Disposition |
|---|---|---|
| 1 | §1 and §15 announce a human/agent principal separation that §3.4 never states | Written. §3.4 now carries "Two principals, one layer" and the four rules binding the agent principal: no standing credential, tool use is a conduit or an Engine API, agent memory is not a state plane, every agent action reconstructable as the caller's. glas-harness is demarcated as governing session conduct. |
| 2 | §13 attributes the containment surface to kings-guard, which §9.2 ruled is not theirs |
Reattributed. The §13 row now reads declarer gate-house (estate-wide), owner access-engine + runtime engines, state proposed; §9.2's text says kings-guard is not the declarer. |
| 3 | §17's emission-cadence declaration is unowned; offer to draft it | Accepted, then owned. §17 records kings-guard as accepted drafter. Ownership itself was settled later by GH-DEC-2026-004. |
| nit | §17–§19 are H1 where every other section is H2 | Fixed. §17 and §18 are H2; §19 no longer exists (see access-engine 5). |
The finding kings-guard called substantive was finding 1, and it was the right call: a rule announced in a change log and absent from the body is the §11 defect turned on the standard itself. It is now in the body.
ops-warden
| # | Finding | Disposition |
|---|---|---|
| 1 | §6.4 obligation 1 forbids what obligation 3 blesses; ops-warden's shipped fail-open stance was made a violation | Adopted, near-verbatim. Obligation 1 now reads "…or its declared §9.3 stance for the applicable scope permits proceeding without one and the application of that stance is recorded in place of the decision." The text names the second limb as stricter than silence and credits ops-warden as the reference shape. |
| 2 | §6.4 mandates a stance-map register §13 does not implement | Register created. §13.1 "PEP stance-map register" exists; §6.4's closing paragraph records that v0.6 named a register that did not exist and that its first inventory had one row, "which is itself the finding". |
| rec | The published map MUST equal shipped behaviour | Adopted. Obligation 3 carries the equality requirement with the SHOULD-be-tested clause and ops-warden's own reasoning: a map free to drift is worse than none. |
ops-warden's process note — that assented_by carries assent forward across five
revisions and could be read as assent to current text — is answered in the v0.7
header comment: "records assent to a BOUNDARY, given at the version named. It is not
assent to the current text."
access-engine (flex-auth)
| # | Item | Disposition |
|---|---|---|
| Q1(a) | §6.4.2 forbids the session-bound allow §9.7.1 permits | Scoped. Obligation 2 is now bounded to replay outside the decision's stated binding and lifetime, and says v0.6 forbade what §9.7.1 permits. |
| Q1(b) | "Later request" needs a mechanical test | Adopted as normative. Replay is permitted iff the canonical request digest matches and the lifetime holds. |
| Q1(c) | Deny-caching is outlawed by inference, never ruled on | Ruled explicitly. Negative caching is permitted narrowly: the refusal must be recorded against the request refused, and the cache lifetime declared alongside the stance map. |
| Q2 | A single visibility deadline is the wrong shape for a PDP | Adopted. §9.7.2 requires one deadline at a PEP and a deadline per input class at a PDP, and names the registry-provenance digest and the deadline as one gap seen from two sides. |
| 1 | §6.4's stance-map register does not exist | Same disposition as ops-warden 2. §13.1 exists; §6.4 credits both repositories as raising it independently. |
| 2 | The companion omits where a stance map is published and omits the inventory obligation | Fixed. SECURITY-COMPANION.md step 3 now says "at a path named in your layer declaration, and register it in statute §13.1". |
| 3 | §17 puts the decision-record schema in the wrong layer | Adopted. The row is struck through and moved to access-engine, with a paragraph applying the §2 ownership rule and noting the finding was raised against its own interest. |
| 4 | §17–§19 H1 headings | Fixed (see kings-guard nit). |
| 5 | §19 grades the document it lives in | Removed. There is no §19 in v0.7; the numbering runs §18 → §20. |
audit-core
| # | Finding | Disposition |
|---|---|---|
| 1 | Atomicity closes accidental omission, not the adversarial case §9.6 opens with | Adopted as a decomposition table. §9.6 now separates accidental omission (closed by atomicity) from adversarial omission ("detected, after the fact" by cadence and reconciliation), and states the residual explicitly: nothing in the model prevents adversarial omission at a compromised source. |
| 2 | Cadence is a SHOULD and is the only control on that residual; rate monitoring inverts the priority for rare events | Both halves adopted. Load-bearing sources MUST declare cadence (attributive SHOULD), and for low-volume load-bearing classes the required form is positive reconciliation or a heartbeat rather than rate monitoring, with GH-WP-0002-T04 named as the reference instance. |
| 3 | §3.3's Evidence row states a trade as a property | Adopted. The row reads "a default, not a property; see below", and the following paragraph records that an operation genuinely requiring independent recording before effect is a declared exception raised when needed, not one ruled out by a table cell. |
Finding 1 corrected a remedy audit-core had itself proposed, and finding 2 argued against the control it was defending. Both are in the standard in stronger form than they arrived.
What the audit did surface
Not a v0.6 finding — a v0.7 paragraph made stale by a later decision.
§17 closes with "Ownership is proposed, not assigned… Neither has assented." That
was true when v0.7 was accepted. It is no longer: GH-DEC-2026-004 assigned the
split — info-tech-canon owns the ecosystem-wide EmissionCadenceDeclaration
contract, net-kingdom owns the NetKingdom security profile — and both accepted in
their own voice (ITC-WP-0018 publishing ITC-EMISSION-CADENCE 0.1 in canon 0.7.0;
NK-WP-0035 publishing emission-cadence-security-profile_v0.1.md). A reader of the
accepted statute is currently told the estate has not decided something it has.
Tracked as GH-WP-0003-T07. v0.7 is not patched in place.
Method note
The four review messages were re-read from the State Hub rather than from memory, and each finding was checked against the v0.7 text rather than against the change log. §15's change log is a claim about the body; kings-guard's finding 1 is precisely the case where that claim was false, so it cannot be the evidence.