Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared
Origin and evidence path both landed today. T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the hostname in this repo — not the decide.coulomb.social this workplan proposed. Verified here rather than taken on report: both paths 200, TLS verify 0, Let's Encrypt cert valid to 2026-12-09. T08: audit-core registered the source with every field as proposed and landed the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation on the high-volume class too, since rate detects a stream stopping but never a stream missing the particular renders that mattered, which is exactly our threat model; and PR-12, the custody locator must be a stable non-secret identifier because redact scans data and an existence declaration arriving without its pointer looks complete while being useless. INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is permitted for this pair. The decisive ground was not the cycle argument we led with — our binding slice canonicalizes principal and target, two of the five digest fields, so co-reference left us performing a partial recomputation of one act in a second vocabulary, closer to the translation R3 forbade than nesting is. Our ordering objection was withdrawn as mistaken. The permission is conditioned and NOT ACTIVE until approval-engine states its presentation exclusion as normative and tested. layer.yaml is deliberately unchanged and carries nesting_permission_active false — we do not activate on our own initiative. GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is booked as PR-11: principal_type: human is a property of the client registration, structurally the same shape as the gap-route tenant, so a human-in-the-loop control must not be discharged on it as verified humanity. T07 stays progress: the submission to key-cape is written but unsent, blocked by the local permission classifier rather than by any repository. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR Assistant: claude-code Assistant-Model: opus Assistant-Process: 1565372@bnt-lap001 Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
parent
1614f257b6
commit
1fb17aec6b
6 changed files with 210 additions and 13 deletions
|
|
@ -5,8 +5,18 @@
|
|||
**Intake:** `INFD-IN-0004`
|
||||
**Statute:** *"The statute governs on disagreement; a disagreement is a finding
|
||||
for `gate-house`."*
|
||||
**Status:** raised. **No design change made.** `GH-DEC-2026-012` R3 stands and
|
||||
`layer.yaml` is unchanged pending a ruling.
|
||||
**Status:** **Ruled `GH-DEC-2026-015` — nesting permitted for this pair,
|
||||
conditioned and not yet active.** `layer.yaml` remains unchanged: co-reference
|
||||
stays in force until `approval-engine` states its presentation exclusion as
|
||||
normative and tested. This repository does not activate on its own initiative.
|
||||
|
||||
Gate House reversed itself, and gave the real ground rather than the one we
|
||||
argued: our binding slice canonicalizes `principal` and `target`, two of the
|
||||
five digest fields, so co-reference by identifier left us performing a partial
|
||||
recomputation of one act in a second vocabulary — **closer to the translation R3
|
||||
forbade than nesting is**. Our ordering-dependency objection was withdrawn as
|
||||
mistaken; `binding.digest` is over act material and is determined before anyone
|
||||
is presented anything.
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
|
|
@ -199,8 +199,29 @@ five digest fields, so co-reference by identifier alone leaves **two
|
|||
independent canonicalizations of one act** rather than removing the duplication.
|
||||
|
||||
Raised as a finding rather than resolved bilaterally
|
||||
(`docs/finding-r3-linkage-conflict.md`). **The ruling stands and nothing has
|
||||
changed here pending a re-ruling.**
|
||||
(`docs/finding-r3-linkage-conflict.md`). **Re-ruled by `GH-DEC-2026-015`:
|
||||
gate-house reversed itself — nesting is permitted for this pair, so `view_hash`
|
||||
may carry `binding.digest` and our binding slice stops independently
|
||||
canonicalizing act material.**
|
||||
|
||||
The decisive ground was not the cycle argument we led with. It was that our
|
||||
binding slice canonicalizes `principal` and `target`, two of the five fields in
|
||||
their digest, so co-reference by identifier left us performing *a partial
|
||||
recomputation of one act in a second vocabulary* — **closer to the translation
|
||||
R3 forbade than nesting is**. Nesting removes the duplication; co-reference
|
||||
manages it.
|
||||
|
||||
**The permission is conditioned and not yet active.** It activates when
|
||||
`approval-engine` states its presentation exclusion as **normative and tested**
|
||||
rather than as design intent — our own A-17 correction applied to gate-house's
|
||||
permission, since the distinguishing case is someone widening the digest and
|
||||
that case is unobservable until approvals start failing. Co-reference remains in
|
||||
force until then, and this repository does not activate on its own initiative.
|
||||
|
||||
Our ordering-dependency objection to option (c) was **withdrawn as mistaken**
|
||||
and recorded as withdrawn: `binding.digest` is over act material, determined
|
||||
before anyone is presented anything. We stated that cost, gate-house took it
|
||||
from us, and neither of us checked it.
|
||||
|
||||
For reference, three hashes answering three questions:
|
||||
|
||||
|
|
@ -359,6 +380,57 @@ Not closed, not credited. The existence assertion narrows the erasure gap — a
|
|||
detectable non-production tells a reviewer something is missing and who owed it.
|
||||
It does not produce the missing thing.
|
||||
|
||||
## 8e. Cadence — declared, and now supportable
|
||||
|
||||
`audit-core` registered this source as proposed (`AUDIT-IN-0003`,
|
||||
`docs/informed-decision-source-registration.md`) and landed the detection half
|
||||
(`AUDIT-WP-0009` T04/T06/T07). The cadence can stop being described as
|
||||
declared-but-not-operating once heartbeats are flowing.
|
||||
|
||||
**Per class, not per source** — the shape this repository argued for and
|
||||
`audit-core` adopted. A per-source heartbeat from a mixed-volume emitter is
|
||||
satisfied by its chattiest class and says nothing about the quiet,
|
||||
security-relevant one, which is the only reason heartbeats exist.
|
||||
|
||||
| Class | Volume | Heartbeat | Reconciliation |
|
||||
| --- | --- | --- | --- |
|
||||
| `presentation` | one per render | yes — legitimately silent for days at Stage 1 | yes |
|
||||
| `disposition` | low, security-relevant | yes | yes |
|
||||
| `stance_application` | low, security-relevant | yes | yes |
|
||||
|
||||
Reconciliation applies to **every** class including the high-volume one: rate
|
||||
detects a stream stopping, never a stream missing the particular renders that
|
||||
mattered.
|
||||
|
||||
A heartbeat is an **ordinary event** — same envelope, same append-only custody,
|
||||
same chain. Deliberately so: a heartbeat stored outside the chain would be the
|
||||
one record that could be back-dated.
|
||||
|
||||
Note `no_heartbeat_since_registration`: declaring a heartbeat and never sending
|
||||
one is **its own finding**, not a skip.
|
||||
|
||||
### The bound on both controls
|
||||
|
||||
Reconciliation compares `audit-core`'s counts against counts we compute from our
|
||||
own state. **Where the emitter is compromised, both controls agree with it** — a
|
||||
compromised surface suppresses the event and its own count together, and emits a
|
||||
truthful-looking `nothing-to-report`.
|
||||
|
||||
Both cover loss, outage, drain failure and accident, which is most of what
|
||||
actually goes wrong. **Neither covers the residual we already declare**, and
|
||||
neither may be described as covering it. Closing it needs an observer
|
||||
independent of the emitter, which §16 put outside `audit-core`'s scope.
|
||||
|
||||
### Tenant provenance is not in the envelope
|
||||
|
||||
`audit-core`'s tenant is not an identity claim they resolve; it is a value our
|
||||
credential is permitted to write, checked by exact string equality. Recording a
|
||||
route in the audit event would be them restating something they did not observe
|
||||
— the same error as claiming an event occurred. It lands in the registration
|
||||
document instead, whose authority is `GH-DEC-2026-013`'s bounded gap rather than
|
||||
a populated directory record. If that gap closes, the entry is revisited rather
|
||||
than assumed still correct.
|
||||
|
||||
## 9. Signed attributes (L4+, horizon)
|
||||
|
||||
When AES/QES arrives, the signed attributes carry `memo_id`, `memo_version`,
|
||||
|
|
|
|||
|
|
@ -192,6 +192,35 @@ registration's authority, which `GH-DEC-2026-013` permits only as a bounded gap.
|
|||
undifferentiated or absent provenance is a validation failure, not a default.
|
||||
`trace: GH-DEC-2026-013 §5; key-cape 329e48f`
|
||||
|
||||
**PR-11 [rev-3] — A human-in-the-loop control is never discharged on an
|
||||
unverified assertion of humanity.**
|
||||
`GH-DEC-2026-016` requires that where an approval is *declared* as discharging a
|
||||
human-in-the-loop control, the approver must be a human principal and
|
||||
`approval-engine` must refuse at bind time. Its §5 lands here: what makes a
|
||||
principal `human` belongs to the identity layer and **inherits A-16** — if
|
||||
`human` is reachable by two routes, the control must not be discharged on a
|
||||
registration-supplied claim. Refusing a service principal while accepting an
|
||||
unverified assertion of humanity moves the defect rather than closing it.
|
||||
|
||||
**This is live for us, not hypothetical.** `principal_type: human` is a property
|
||||
of the *client registration*, the same shape as our registration-supplied
|
||||
`tenant`. Until its provenance is distinguishable, this surface treats it as
|
||||
registration-supplied and does not present it as verified humanity.
|
||||
*Pass:* `principal_type` is stored with its provenance like `tenant` (PR-09); no
|
||||
copy, export field or evidence record describes a bind as human-verified on the
|
||||
strength of the claim alone.
|
||||
`trace: GH-DEC-2026-016 §5; A-16 with the marker-independence rider; PR-09`
|
||||
|
||||
**PR-12 [rev-3] — The custody locator is a stable non-secret identifier.**
|
||||
`audit-core` applies `secret_policy: redact`, which scans `data`. A
|
||||
credentialed URL or secret-shaped path in the custody field is redacted out and
|
||||
the existence declaration (PR-53) arrives without its pointer. It fails visibly
|
||||
— `details.redaction.paths` records it — but the declaration is then useless.
|
||||
*Pass:* the custody locator is an identifier the custodian resolves, never a
|
||||
credentialed URL; a redaction finding on the custody field is a build-breaking
|
||||
defect, not a warning.
|
||||
`trace: audit-core docs/informed-decision-source-registration.md`
|
||||
|
||||
**PR-10 — A memo renders question, requested act, binding level, brief and
|
||||
consequences before any action control is reachable.**
|
||||
*Pass:* the disposition controls are not operable until the brief region has
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue