Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared

Origin and evidence path both landed today.

T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the
hostname in this repo — not the decide.coulomb.social this workplan proposed.
Verified here rather than taken on report: both paths 200, TLS verify 0, Let's
Encrypt cert valid to 2026-12-09.

T08: audit-core registered the source with every field as proposed and landed
the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation
on the high-volume class too, since rate detects a stream stopping but never a
stream missing the particular renders that mattered, which is exactly our threat
model; and PR-12, the custody locator must be a stable non-secret identifier
because redact scans data and an existence declaration arriving without its
pointer looks complete while being useless.

INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is
permitted for this pair. The decisive ground was not the cycle argument we led
with — our binding slice canonicalizes principal and target, two of the five
digest fields, so co-reference left us performing a partial recomputation of one
act in a second vocabulary, closer to the translation R3 forbade than nesting
is. Our ordering objection was withdrawn as mistaken.

The permission is conditioned and NOT ACTIVE until approval-engine states its
presentation exclusion as normative and tested. layer.yaml is deliberately
unchanged and carries nesting_permission_active false — we do not activate on
our own initiative.

GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is
booked as PR-11: principal_type: human is a property of the client registration,
structurally the same shape as the gap-route tenant, so a human-in-the-loop
control must not be discharged on it as verified humanity.

T07 stays progress: the submission to key-cape is written but unsent, blocked by
the local permission classifier rather than by any repository.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
tegwick 2026-09-10 19:19:10 +02:00
parent 1614f257b6
commit 1fb17aec6b
6 changed files with 210 additions and 13 deletions

View file

@ -199,8 +199,29 @@ five digest fields, so co-reference by identifier alone leaves **two
independent canonicalizations of one act** rather than removing the duplication.
Raised as a finding rather than resolved bilaterally
(`docs/finding-r3-linkage-conflict.md`). **The ruling stands and nothing has
changed here pending a re-ruling.**
(`docs/finding-r3-linkage-conflict.md`). **Re-ruled by `GH-DEC-2026-015`:
gate-house reversed itself — nesting is permitted for this pair, so `view_hash`
may carry `binding.digest` and our binding slice stops independently
canonicalizing act material.**
The decisive ground was not the cycle argument we led with. It was that our
binding slice canonicalizes `principal` and `target`, two of the five fields in
their digest, so co-reference by identifier left us performing *a partial
recomputation of one act in a second vocabulary* — **closer to the translation
R3 forbade than nesting is**. Nesting removes the duplication; co-reference
manages it.
**The permission is conditioned and not yet active.** It activates when
`approval-engine` states its presentation exclusion as **normative and tested**
rather than as design intent — our own A-17 correction applied to gate-house's
permission, since the distinguishing case is someone widening the digest and
that case is unobservable until approvals start failing. Co-reference remains in
force until then, and this repository does not activate on its own initiative.
Our ordering-dependency objection to option (c) was **withdrawn as mistaken**
and recorded as withdrawn: `binding.digest` is over act material, determined
before anyone is presented anything. We stated that cost, gate-house took it
from us, and neither of us checked it.
For reference, three hashes answering three questions:
@ -359,6 +380,57 @@ Not closed, not credited. The existence assertion narrows the erasure gap — a
detectable non-production tells a reviewer something is missing and who owed it.
It does not produce the missing thing.
## 8e. Cadence — declared, and now supportable
`audit-core` registered this source as proposed (`AUDIT-IN-0003`,
`docs/informed-decision-source-registration.md`) and landed the detection half
(`AUDIT-WP-0009` T04/T06/T07). The cadence can stop being described as
declared-but-not-operating once heartbeats are flowing.
**Per class, not per source** — the shape this repository argued for and
`audit-core` adopted. A per-source heartbeat from a mixed-volume emitter is
satisfied by its chattiest class and says nothing about the quiet,
security-relevant one, which is the only reason heartbeats exist.
| Class | Volume | Heartbeat | Reconciliation |
| --- | --- | --- | --- |
| `presentation` | one per render | yes — legitimately silent for days at Stage 1 | yes |
| `disposition` | low, security-relevant | yes | yes |
| `stance_application` | low, security-relevant | yes | yes |
Reconciliation applies to **every** class including the high-volume one: rate
detects a stream stopping, never a stream missing the particular renders that
mattered.
A heartbeat is an **ordinary event** — same envelope, same append-only custody,
same chain. Deliberately so: a heartbeat stored outside the chain would be the
one record that could be back-dated.
Note `no_heartbeat_since_registration`: declaring a heartbeat and never sending
one is **its own finding**, not a skip.
### The bound on both controls
Reconciliation compares `audit-core`'s counts against counts we compute from our
own state. **Where the emitter is compromised, both controls agree with it** — a
compromised surface suppresses the event and its own count together, and emits a
truthful-looking `nothing-to-report`.
Both cover loss, outage, drain failure and accident, which is most of what
actually goes wrong. **Neither covers the residual we already declare**, and
neither may be described as covering it. Closing it needs an observer
independent of the emitter, which §16 put outside `audit-core`'s scope.
### Tenant provenance is not in the envelope
`audit-core`'s tenant is not an identity claim they resolve; it is a value our
credential is permitted to write, checked by exact string equality. Recording a
route in the audit event would be them restating something they did not observe
— the same error as claiming an event occurred. It lands in the registration
document instead, whose authority is `GH-DEC-2026-013`'s bounded gap rather than
a populated directory record. If that gap closes, the entry is revisited rather
than assumed still correct.
## 9. Signed attributes (L4+, horizon)
When AES/QES arrives, the signed attributes carry `memo_id`, `memo_version`,