Apply GH-DEC-2026-015/016 and the audit-core registration; both blockers cleared

Origin and evidence path both landed today.

T07 origin: railiance-apps deployed decisions.coulomb.social and corrected the
hostname in this repo — not the decide.coulomb.social this workplan proposed.
Verified here rather than taken on report: both paths 200, TLS verify 0, Let's
Encrypt cert valid to 2026-12-09.

T08: audit-core registered the source with every field as proposed and landed
the detection half. INFD-IN-0003 closed. Their refinements booked — reconciliation
on the high-volume class too, since rate detects a stream stopping but never a
stream missing the particular renders that mattered, which is exactly our threat
model; and PR-12, the custody locator must be a stable non-secret identifier
because redact scans data and an existence declaration arriving without its
pointer looks complete while being useless.

INFD-IN-0004 ruled as GH-DEC-2026-015: gate-house reversed itself and nesting is
permitted for this pair. The decisive ground was not the cycle argument we led
with — our binding slice canonicalizes principal and target, two of the five
digest fields, so co-reference left us performing a partial recomputation of one
act in a second vocabulary, closer to the translation R3 forbade than nesting
is. Our ordering objection was withdrawn as mistaken.

The permission is conditioned and NOT ACTIVE until approval-engine states its
presentation exclusion as normative and tested. layer.yaml is deliberately
unchanged and carries nesting_permission_active false — we do not activate on
our own initiative.

GH-DEC-2026-016 ruled NC-03. Its §5 is live rather than hypothetical and is
booked as PR-11: principal_type: human is a property of the client registration,
structurally the same shape as the gap-route tenant, so a human-in-the-loop
control must not be discharged on it as verified humanity.

T07 stays progress: the submission to key-cape is written but unsent, blocked by
the local permission classifier rather than by any repository.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
tegwick 2026-09-10 19:19:10 +02:00
parent 1614f257b6
commit 1fb17aec6b
6 changed files with 210 additions and 13 deletions

View file

@ -100,12 +100,23 @@ binding_digest_relationship:
repository MUST NOT recompute or restate approval-engine's binding digest
from its own vocabulary — it references the digest that layer computed and
recorded.
# UNDER REVIEW — INFD-IN-0004, raised 2026-09-10. approval-engine
# (docs/approval-claim.md, 62233c7) recommends the opposite of the line below:
# that our binding document carry their binding.digest as a field, which is
# the option (c) GH-DEC-2026-012 refused. The ruling stands and this file is
# unchanged pending a re-ruling. See docs/finding-r3-linkage-conflict.md.
linkage_under_review: INFD-IN-0004
# GH-DEC-2026-015 (INFD-IN-0004) re-ruled: nesting is PERMITTED for this pair,
# CONDITIONED and NOT YET ACTIVE. view_hash may carry binding.digest as a
# field, and our binding slice then stops independently canonicalizing act
# material — but only once approval-engine states its presentation exclusion
# as NORMATIVE and TESTED rather than design intent.
#
# "Co-reference remains in force until that condition is met; the permission
# activates then. You do not act on your own initiative here."
#
# So co-reference below is still the operative rule and this file is
# deliberately unchanged. See docs/finding-r3-linkage-conflict.md.
reruled_by: GH-DEC-2026-015
nesting_permitted_when: >-
approval-engine states the presentation exclusion from binding.digest as
normative and tested. Until then co-reference is in force. Do not activate
on this repository's own initiative.
nesting_permission_active: false
nesting_forbidden: >-
view_hash MUST NOT contain the binding digest, and MUST NOT travel inside
hashed request material while containing it. Option (c) was refused because