Commit graph

2 commits

Author SHA1 Message Date
e1a6314131 Check import manifests by hash and name together (INFO-WP-0028 T01-T03)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
import-review takes any partner manifest and returns, per concept, whether the
name resolves in the ownership index and to which artifact, and per entry
whether the pinned SHA-256 matches the blob at the declared source commit. Both
run in one pass so neither can be recorded without the other, which is the
failure this workplan exists to prevent. It exits non-zero on a finding, reads
JSON or YAML, needs no partner checkout, and carries its own limit: resolution
proves a name exists and names one owner, nothing more.

Accepted manifests are registered under infospace/interfaces/manifests/ as
provenance-preserving copies owned by the partner, with the partner revision and
retrieval date recorded. Editing a copy to make a check pass is forbidden in the
file itself. Validation re-resolves them and reports drift as
federation_import_drift, a warning naming the partner rather than an error,
because a stale partner pin is not this repository's file to fix.

The review kit gains an extension-boundary-review template requiring hash count,
resolution count and conflict count as three separate lines, and an operating
rule saying one is never evidence of another. Both boundary files carry the
standing-check result.

Verified live: security-canon resolves 11 of 11, interface-canon 23 of 25 with
the two known Interface and Endpoint pins. make check passes with 58 tests,
clean validation and those two warnings.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3588@bnt-lap001
Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
2026-09-20 23:43:34 +02:00
d1254aabe6 Plan a standing check for import-manifest name resolution (INFO-WP-0028)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Federation partners pin an artifact path, a blob hash and a list of concept
names. Every review so far verified the hash and recorded the match as evidence.
A hash proves the reviewed file is the pinned file; it says nothing about whether
the concept named in the manifest exists in it. Nobody ran the second check until
INFO-WP-0027-T04, which found nine failures across the two accepted boundaries,
none of them a contested concept and all of them a citation naming the wrong
artifact or a name this canon never used.

The workplan adds a reusable import-review command in the shape emission-review
already uses, registers accepted manifests so drift is caught when this
repository changes rather than when a partner happens to look, generalises the
re-verification section into the review kit so an acceptance cannot again record
matching hashes as evidence of correct citation, and closes the two open pins
InterfaceCanon still owns.

Drift against a registered manifest is a warning, not an error: a stale partner
pin is not this repository's file to fix and must not fail its build.

Status is proposed: drafted from the INFO-WP-0027 findings, not yet reviewed by
the owner.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 3588@bnt-lap001
Assistant-Session: 24b80f66-e5a7-4e61-99fe-2d422e6d17da
2026-09-20 23:38:09 +02:00