info-tech-canon/feedback/2026-09-21-net-kingdom-emission-cadence-declaration.md

113 lines
5.1 KiB
Markdown
Raw Normal View History

---
id: feedback/2026-09-21-net-kingdom-emission-cadence-declaration
type: consumer-feedback
status: reviewed
date: "2026-09-21"
consumer: net-kingdom
consumer_domain: infotech
canon_version: "0.7.0"
artifacts:
- standard/emission-cadence
related_demand:
- demand/EmissionActivityScope.md
related_workplan:
- INFO-WP-0029
spawned_demand:
- demand/EmissionActivityScope.md
spawned_workplan: []
---
# Feedback: first source-owned Emission Cadence declaration (local-identity audit log)
**Consumer:** net-kingdom
**Canon version used:** 0.7.0; Emission Cadence document 0.2.0, wire schema 0.1
**Artifacts exercised:** `infospace/schemas/emission-cadence.schema.yaml`,
`standards/emission-cadence/InfoTechCanonEmissionCadenceStandard.md`
**Related demand:** `demand/EmissionActivityScope.md`
Source: net-kingdom's reply to INFO-WP-0029-T02 (State Hub message
`3b2db043-b910-4552-930f-65d87b475f3b`, thread `3432a831`), and the files it
published at net-kingdom commit `116643f`:
`local-identity/emission-cadence.yaml` and
`local-identity/emission-cadence-findings.md`. The consumer's own findings file
is the authoritative account. The sections below summarize it and do not
restate it.
---
## Consumer purpose
Declare the intended cadence of the local-identity audit log (`serve/token`
issuance, `revoke-token`) as load-bearing security evidence, so that an
observer could read silence in that stream.
## Hits
- `heartbeat-or-reconciliation` with a `reconciliation` block. This expressed
a local-count versus observed-count comparison without inventing a heartbeat
the source does not emit.
- `extensions`. These carried NetKingdom's evidence class, the
rate-monitoring prohibition, and `completeness_claimed: false` without
touching the generic contract.
- The schema was sufficient for a valid declaration. The consumer found it
`contract_valid` through its own profile tool.
## Friction
- `emission-review` could not be run by the consumer because
`infospace-bench==0.1.0` is not installable from a package index. This is the
packaging limitation SCOPE.md already records. It now costs an adopter a
validation step.
- `reconciliation` needs an observer that does not exist, so
`compare_observed` is a declared reference with no feed behind it.
## Gaps
- **Session-scoped silence.** The source can emit only while an attended process
runs. `expected-rate` has no meaningful floor (`expected_min: 0` makes
silence meaningless), and a heartbeat outside a session does not exist.
Neither form can say "silent because not running". Filed as
`demand/EmissionActivityScope.md`.
## Drop candidates
None.
## Steward notes
- **Validated canon-side on 2026-09-22.** `info_tech_canon emission-review` on
the declaration at `116643f` returned `ok: true`, `errors: []`,
`operational_truth_assessed: false`.
- **The pin was stale because of our brief, not because of the consumer.** The
consumer pinned `972c0b6701d1693f` and labelled it document 0.2.0, as
`docs/emission-cadence-adoption.md` instructed. That digest is the 0.1.0 draft
bundle. The candidate promotion (`4d0851c`) changed the standard's text after
the digest was taken, and the brief was not updated. The wire schema is
identical in both bundles, so the declaration's validity is unaffected. The
export manifest also hard-coded `status: draft`. It now reads status and
version from the standard. The brief names the corrected candidate digest,
`b08b4d95fc4b0bd3`.
- **What this counts toward.** This is one source-owned declaration from an owner
independent of this repository. It also records an incompatibility, which is
the third element of the stable gate (standard §10). It is not a second
declaration and not an observer result. The standard stays at candidate.
- **Observer evaluation received, and it does not satisfy the gate.**
audit-core replied 2026-09-22 (State Hub message `266abb18-0a85-4d85-9ff2-0745949c9587`,
thread `368e54bf-6401-4184-a1d2-04f133945d40`), against its own AUDIT-WP-0009
implementation (audit-core `01468ff`, read at contract digest
`b08b4d95fc4b0bd3`): structurally, both entries in this declaration
validate. Operationally, audit-core registers no `local-identity` sender and
holds none of its events, so nothing sits behind `compare_observed` — by
audit-core's own account this is "not an observer result on the stream, and
it should not satisfy your section 10 stable gate." A second incompatibility
surfaced: the declaration's heartbeat block names an `event_class`, but
audit-core evaluates one heartbeat class (`audit-core.heartbeat`, carrying
the vouched-for class in `data.class`) driven by a separately registered
`heartbeat_classes` list — the two can drift apart, and neither side has
reconciled that yet. audit-core states a real observer result needs a
source with an expected-rate or reconciliation declaration registered there
and sending traffic — which is not this declaration. INFO-WP-0029-T05
(observer result) stays open on the strength of this reply alone.
- The NetKingdom security profile's rare-heartbeat MUST failure belongs to
NetKingdom's profile. It is not a defect of the generic contract.