Activate nesting per GH-DEC-2026-015: view_hash carries binding.digest

approval-engine met the condition. Verified here rather than taken on report:
their docs/approval-claim.md carries "Presentation exclusion — GH-DEC-2026-015
§4" in normative language, and I ran
tests/test_claim_contract.py::test_presentation_changes_cannot_change_the_approved_act
myself — 1 passed. That test pins the digest input set from BOTH sides, and the
narrowing half is what makes it real: without it a digest over four fields, or
over a constant, would pass the widening half perfectly.

view_hash now carries binding.digest and the act-scope is no longer
independently canonicalized here, so the act has exactly one canonicalization
computed by the layer that owns it. approval_binding_digest is validated for
shape and refused without its approval id — it is carried, never computed.

The three published vectors are unchanged: they do not carry the new key, so
pick omits it. Asserted, not assumed.

The cycle condition did not disappear, its protection moved — from refusing
nesting to approval-engine's normative exclusion. layer.yaml carries it as
cycle_condition with a test, so a future widening meets a rule rather than
silence.

One thing not assumed. Both gate-house and approval-engine said our binding
slice canonicalizes principal and target, two of their five fields. target
plainly is act material and is now dropped. But their principal is the party ON
WHOSE BEHALF the approval was issued, while ours is the person being BOUND — the
approver. Different roles, and dropping ours would remove who was shown this
from view_hash and gut the promise. Kept it, declared principal_role_overlap
open in layer.yaml, tested that changing the approver still moves view_hash, and
raised it rather than silently resolving it either way.

L0/L2 are unaffected: with no approval there is no digest to defer to, and
test_act_scope_still_binds_when_there_is_no_carried_digest pins that.

100 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1565372@bnt-lap001
Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
tegwick 2026-09-10 20:58:22 +02:00
parent d0302e1046
commit 4e103f62a0
7 changed files with 240 additions and 50 deletions

View file

@ -11,9 +11,13 @@ binding slice committing *which scope this act is being entered into*.
from __future__ import annotations
import re
from dataclasses import dataclass, field, replace
from enum import Enum
#: approval-engine's digest format. We validate the shape and NEVER compute one.
APPROVAL_DIGEST_RE = re.compile(r"^sha256:[0-9a-f]{64}$")
class BindingLevel(str, Enum):
ACKNOWLEDGMENT = "acknowledgment"
@ -186,16 +190,32 @@ class Memo:
highlights: tuple[Highlight, ...] = ()
locale: str = "en"
ui_release: str = "informed-decision@0.1.0"
#: Co-reference to the act this memo presents (GH-DEC-2026-012 R3).
#: The identifier only — never approval-engine's binding digest, which we
#: do not recompute or restate. Nesting is permitted by GH-DEC-2026-015 but
#: NOT ACTIVE; see layer.yaml nesting_permission_active.
#: Co-reference to the act this memo presents.
approval_id: str | None = None
#: approval-engine's binding.digest over the five act fields, CARRIED here
#: under GH-DEC-2026-015 (activated 2026-09-10 once approval-engine stated
#: the presentation exclusion as normative and tested).
#:
#: It is referenced, never recomputed: this repository must not restate that
#: digest from its own vocabulary. When present, the act-scope stops being
#: independently canonicalized here, so the act has exactly ONE
#: canonicalization — computed by the layer that owns it.
approval_binding_digest: str | None = None
sealed: bool = False
def __post_init__(self) -> None:
if not self.question:
raise ValueError("a memo without a question does not render")
if self.approval_binding_digest is not None:
if not APPROVAL_DIGEST_RE.match(self.approval_binding_digest):
raise ValueError(
"approval_binding_digest must be approval-engine's "
"sha256:<64 hex> form; it is carried, never computed here"
)
if self.approval_id is None:
raise ValueError(
"a carried binding digest needs the approval it belongs to"
)
packet_ids = {p.item_id for p in self.packet}
for h in self.highlights:
if h.item_id not in packet_ids:
@ -225,6 +245,11 @@ class Memo:
"brief": self.brief,
"locale": self.locale,
"ui_release": self.ui_release,
**(
{"approval_binding_digest": self.approval_binding_digest}
if self.approval_binding_digest is not None
else {}
),
"packet": [{"item_id": p.item_id, "hash": p.hash} for p in self.packet],
"highlights": [
{
@ -240,15 +265,31 @@ class Memo:
}
def _binding_document(self) -> dict:
target: dict = {
"kind": self.binding.target.kind,
"id": self.binding.target.id,
"label": self.binding.target.label,
"requires_new_bind": self.binding.target.requires_new_bind,
}
if self.binding.target.environment is not None:
target["environment"] = self.binding.target.environment
out: dict = {"principal": self.binding.principal.as_document(), "target": target}
"""The binding slice, minus whatever the carried digest already covers.
Where ``approval_binding_digest`` is present, the **act-scope** is
omitted: `target` is act material and is covered by that digest, so
canonicalizing it again here would be the partial recomputation in a
second vocabulary that GH-DEC-2026-015 exists to remove.
``principal`` is **kept**. approval-engine's `principal` is the party
*on whose behalf* the approval was issued; ours is the person being
bound the approver. Different roles, so dropping ours would remove
*who was shown this* from `view_hash` and gut the promise this
repository exists to make. Raised with approval-engine rather than
assumed; if the two are the same field, this drops too.
"""
out: dict = {"principal": self.binding.principal.as_document()}
if self.approval_binding_digest is None:
target: dict = {
"kind": self.binding.target.kind,
"id": self.binding.target.id,
"label": self.binding.target.label,
"requires_new_bind": self.binding.target.requires_new_bind,
}
if self.binding.target.environment is not None:
target["environment"] = self.binding.target.environment
out["target"] = target
if self.binding.terms is not None:
out["terms"] = self.binding.terms
if self.binding.justification is not None: