diff --git a/INTENT.md b/INTENT.md index 46a3163..874b2b5 100644 --- a/INTENT.md +++ b/INTENT.md @@ -6,9 +6,24 @@ intent_version: 0.1.0 date: "2026-09-09" domain: infotech topic_slug: netkingdom -layer: surface -role: pep-shaped # confirmed by GH-DEC-2026-012; see layer.yaml -standard: net-kingdom/canon/standards/security-layer-model_v0.7.md +# NetKingdom security layer declaration (security-layer-model §11). +# THIS FRONTMATTER IS THE DECLARATION. GH-DEC-2026-017 §1 rules that INTENT.md +# governs and that `layer.yaml` is a DERIVED artifact which must agree with it. +# +# `layer: surface` stood here from 2026-09-09 to 2026-09-21. GH-DEC-2026-017 §3 +# ruled the §3 vocabulary closed at four tokens — Taxonomy, Tooling, Engine, +# Staff — and named Staff for this repository. Changed the same day, without +# argument, as this repository pre-committed in +# docs/gate-house-decision-request-layer-vocabulary.md §3. The reasoning that +# produced `surface` is kept as history in layer.yaml; it is not erased. +# +# No standard version is carried, per GH-DEC-2026-017 §5 / A12: this declares a +# standing property, and a version here would read as a validity condition that +# every revision of the standard invalidated. Version-scoped state belongs in +# the derived conformance record. +layer: Staff +role: pep-shaped # §6.4 shape, confirmed by GH-DEC-2026-012 R1; a role is not a layer +standard: net-kingdom/canon/standards/ # the body, unversioned on purpose companion: net-kingdom/SECURITY-COMPANION.md --- @@ -186,21 +201,61 @@ not failure** — a memo sent back for improvement is the surface working. ## Layer Placement — Ruled -**PEP-shaped**, confirmed by `GH-DEC-2026-012` (answering `INFD-IN-0001`). -Not an Engine: this repository holds no state another layer reads at runtime for -a verdict, and renders no decision. Companion §5 is owed and statute §6.4 -applies in full. The declaration is `layer.yaml`, in this repository's own voice -— a layer someone else states about you is not a declaration. +**Layer: `Staff`. Role: PEP-shaped.** Both are ruled. -The **shape** is ruled; the **layer value** is open. `GH-DEC-2026-012` R1 left -the layer to this repository to declare, and `surface` was written by -elimination — the presentation-and-binding tier, the runtime a human touches. -§3 of the model does not enumerate it, which the custodian's estate-wide sweep -surfaced on 2026-09-21. This repository holds that `surface` names a real tier -§3 omits, and will change the value without argument if `gate-house` rules the -vocabulary closed and names which of the four applies. Open as `INFD-IN-0006`; -the argument is `docs/gate-house-decision-request-layer-vocabulary.md`. The -frontmatter value is unchanged pending that ruling, on purpose. +The **shape** was ruled by `GH-DEC-2026-012` R1 (answering `INFD-IN-0001`): not +an Engine — this repository holds no state another layer reads at runtime for a +verdict, and renders no decision. Companion §5 is owed and statute §6.4 applies +in full. + +The **layer value** was ruled by `GH-DEC-2026-017` §3 (answering `INFD-IN-0006`) +on 2026-09-21. §3's vocabulary is **closed** and has four tokens — `Taxonomy`, +`Tooling`, `Engine`, `Staff`; comparison is ASCII case-insensitive and nobody is +asked to re-spell anything. `surface` is not among them, and the correct value +here is `Staff`, with `role: pep-shaped` untouched. `ops-mason` and `ops-warden` +are the precedent: Staff in the layer column, PEP-shaped in the role column. + +This repository had pre-committed to changing both files the same day, without +argument, if the vocabulary was ruled closed and a value was named +(`docs/gate-house-decision-request-layer-vocabulary.md` §3). It did. **The +reasoning that produced `surface` is not erased** — it is kept as history in +`layer.yaml`, because a value written by elimination against a vocabulary that +turned out to be closed is evidence about the vocabulary, not carelessness. + +Two things follow, and are recorded rather than argued: + +- **`informed-decision` was never a §11 non-conformance.** §11's obligations + attach to estate-authored repositories **in §4**, and this repository holds no + §4 catalog row. `GH-DEC-2026-017` §4 states that a run which grades it is + over-scoped, and requires every conformance run to state its scope. The + correct report is *declared voluntarily, outside catalog scope; value not in + the vocabulary, correction identified*. The correction was this repository's + to make and it made it. +- **The declaration's form changed too.** `INTENT.md` frontmatter **governs**; + `layer.yaml` is a **derived artifact** that must be marked derived, must name + `INTENT.md` as what it derives from, and must agree with it + (`GH-DEC-2026-017` §1 / A11). A declaration carries **no standard version** + (§5 / A12), so the `standard_version: "0.7"` this repository flagged is gone. + `ops-warden` owns the reference sidecar form and is updating it; this + repository applied the two ruled properties and follows that form for the rest. + +One thing the ruling did **not** settle, carried as `INFD-IN-0007` rather than +treated as settled: §3.4 says Staff *"MUST NOT hold state that another layer +depends on at runtime"*, and this repository's presentation records are exactly +state `audit-core` depends on. The ruling reaches `Staff` by elimination — not +Engine per `GH-DEC-2026-012` R1, and nothing else in the four is true — which is +the same route this repository walked, and it gives the value. It does not say +how a deterministic, non-agentic repository that holds evidentiary state sits +inside the layer defined by non-determinism and agentic capability. **The value +is applied regardless**; the question is asked for the next repository in this +position, not as a condition on the change. + +### §4 catalog membership — answered: yes + +`GH-DEC-2026-017` §4 deliberately did **not** enrol this repository, because a +layer stated about a repository by another is not a declaration and that rule +applies to catalogue membership at least as strongly. The question was asked, +and this repository's answer is **yes**: see `docs/section-4-catalog-row.md`. The ruling also confirmed that emitting a **presentation claim** does not require a second catalog row: PEP and PIP are shapes a repository has, and §4 diff --git a/docs/gate-house-decision-request-layer-vocabulary.md b/docs/gate-house-decision-request-layer-vocabulary.md index 06fdaf8..b364e00 100644 --- a/docs/gate-house-decision-request-layer-vocabulary.md +++ b/docs/gate-house-decision-request-layer-vocabulary.md @@ -1,5 +1,25 @@ # Decision request — is §3's layer vocabulary closed, and what is `surface`? +> **RULED, 2026-09-21 — `GH-DEC-2026-017`.** The vocabulary is **closed** at four tokens +> (`Taxonomy`, `Tooling`, `Engine`, `Staff`), comparison is case-insensitive, and the value +> for this repository is **`Staff`**, with `role: pep-shaped` untouched. That is the second +> row of §3's table below: *change both files to that value in one commit, same day, with +> no argument.* Done the same day, in `INTENT.md` (which now governs, per the same ruling) +> and in `layer.yaml` (now marked derived). The elimination reasoning below is kept as +> history in `layer.yaml` rather than erased. +> +> The ruling also held that this repository was **never a §11 non-conformance** — §11 binds +> repositories in §4 and this one has no row — and asked, rather than decided, whether it +> should take one. Answered in `docs/section-4-catalog-row.md`: **yes**. +> +> One part of §3's non-conditional request is answered as to the **value** and not as to +> the **fit**: §3.4's prohibition on Staff holding runtime state another layer depends on +> is not reached by the ruling. Asked once more as `INFD-IN-0007`. It blocks nothing and +> the value was applied regardless, as promised. +> +> **This document is not edited below this line.** It is the record of what this repository +> argued before it knew the answer, and it is more useful unretouched. + **Intake:** `INFD-IN-0006` **To:** `gate-house` (owner of §11 and of the security layer model) **Standard:** `net-kingdom/canon/standards/security-layer-model_v0.8.md` (proposed) diff --git a/docs/section-4-catalog-row.md b/docs/section-4-catalog-row.md new file mode 100644 index 0000000..4d4ad20 --- /dev/null +++ b/docs/section-4-catalog-row.md @@ -0,0 +1,164 @@ +# Should `informed-decision` hold a §4 catalog row? — answered: **yes** + +**Answers:** `GH-DEC-2026-017` §4, the open item gate-house carries as `GH-WP-0004-T06` +**To:** `gate-house` (author), `net-kingdom` (publisher of the catalog) +**Standard:** `net-kingdom/canon/standards/` — the security layer model, §3, §4, §9.6, §11 +**Intake:** `INFD-IN-0006` (closed by the ruling); this document is its second half +**Raised by:** `gate-house`, which asked rather than enrolled + +> **Derived-artifact note (§12).** This document restates §3, §4, §9.6 and §11 of the +> security layer model and quotes `GH-DEC-2026-017` and `GH-DEC-2026-018`. Derived from +> `net-kingdom/canon/standards/security-layer-model_v0.8.md` as published 2026-09-09 (the +> **proposed** cut, held by `GH-DEC-2026-019`), from the amendment set +> `gate-house/docs/amendments/v0.8-section-11-declaration-amendments.md` v0.1, and from +> `gate-house/decisions/decisions.md` as of 2026-09-21. Where they and this differ, they +> govern. + +--- + +## 1. The question, as gate-house put it + +> *"Not ruled: whether `informed-decision` should become a §4 row. It holds a ruled +> boundary, is PEP-shaped, and sits on the approval path, which is a real argument. Adding +> a catalog row is a canon change, and a repository is **asked**, not enrolled — §11's own +> rule that a layer stated about a repository by another is not a declaration applies to +> catalogue membership at least as strongly."* + +The manner of asking is worth recording before the answer, because it is the thing being +tested. gate-house had every argument it needed to add the row and did not add it. That is +§11's declaration rule applied against its own author's convenience, which is the same move +`access-engine` made when it raised gate-house's undeclared layer against gate-house. + +**Answer: yes.** `informed-decision` asks for a §4 catalog row. + +## 2. Why — and it is not the flattering reason + +The tempting argument is that this repository holds a ruled boundary, is PEP-shaped, sits +on the approval path, and that every §4 Staff row with its shape — `ops-warden`, +`ops-mason` — is catalogued. That argument is true and it is not the one that decides it, +because it is an argument about belonging rather than about a cost anyone bears. + +**The deciding argument is that being outside §4 makes this repository's evidence +obligation uncheckable, and that is worse for the estate than for this repository.** + +`GH-DEC-2026-017` §4 is correct that §11 does not bind a repository outside §4, and +correct that a run which grades one is over-scoped. Applied here, that means: + +- `layer.yaml` declares `evidence.kind: load-bearing` — presentation evidence is *the only + record of what a human was shown before binding*; +- §9.6 and §11 make a load-bearing source declare an emission guarantee per event class, + which is what makes §9.6 **checkable rather than reviewable**; +- and no conformance run may check that here, because there is no row to check. + +So the current state is a repository asserting the strongest evidence property in the +model, voluntarily, with nothing in canon able to observe whether it holds. That is the +same shape as the defect the amendment round exists to close: a rule a careful implementer +can satisfy without doing the thing it exists to require. This repository would rather be +gradeable. + +The secondary argument is `L3-independent-evidence-path`, the limit `GH-DEC-2026-012` +attached to the presentation claim: *the copy that is evidence MUST NOT be reachable only +through the party it is evidence about*. In this component the actor and the source are +the same, which is exactly the case where an external check is load-bearing rather than +ceremonial. A repository whose architecture rests on being audited independently should be +in the catalog that makes independent auditing mechanical. + +## 3. What the row would say + +| Repository | Layer | Role | Evidence source | +| --- | --- | --- | --- | +| `informed-decision` | `Staff` | `PEP-shaped` | `yes` | + +`Staff` and `PEP-shaped` are ruled — `GH-DEC-2026-017` §3 and `GH-DEC-2026-012` R1 — and +match `ops-warden` and `ops-mason` exactly. The third column is A10's, and this repository +marks itself `yes` rather than leaving it `—`: it **emits** into the estate's evidence +stream, and A10 is explicit that custody is disjoint from emission, so `audit-core` +holding the record discharges nothing of this emitter's guarantee. + +**No second row for the presentation claim.** `GH-DEC-2026-012` R2 already settled that: +PEP and PIP are shapes a repository has; §4 records the layers it occupies. One row. + +## 4. The obligation this acquires, stated per event class + +A `yes` in the evidence-source column triggers §11's emission-guarantee check. Under A10 +that guarantee is **per event class** — *"a single repository-level guarantee over a stream +containing both a high-volume and a rare class is an average, not a declaration, and will +be satisfied by rate monitoring that cannot see the rare event go missing."* + +This repository publishes three classes. The classification is **its own**, which §11 +requires: *"which class an event falls in, and whether it is rare, is the source's +published classification; a conformance run is supplied that inventory and MUST NOT infer +it from an event name, payload, or observed rate, or the check becomes circular."* + +| Event class | Kind | Classification | Detection surface required | +| --- | --- | --- | --- | +| `presentation` | load-bearing | **volume** — one per render | Rate monitoring is permitted for this class, with a positive window and a positive minimum, **plus** reconciliation | +| `disposition` | load-bearing | **rare** | Heartbeat **and** reconciliation. Rate monitoring is forbidden for this class | +| `stance-application` | load-bearing | **rare** | Heartbeat **and** reconciliation | + +All three are **load-bearing**. None is attributive, so none takes the attributive escape +of declaring a trade and stating that completeness is not claimed. + +`disposition` is the class the whole obligation is about. A disposition is the binding act +— the moment a named human commits their identity to an act, in the vocabulary +`accept` / `decline` / `return` / `escalate`. Dispositions are rare by construction, and a +quiet month of them is indistinguishable from suppression by rate alone, which is +`approval-engine`'s argument for its own classes and is correct here for the same reason. +Classifying `disposition` as volume because it shares a stream with `presentation` is +precisely the averaging A10 forbids, and this repository names the three classes separately +so that the averaging is not available to it. + +The design already exists at `docs/evidence-path-design.md` §5: reconciliation as the +primary form, per class — this repository's own count against `audit-core`'s event count +per class, divergence a finding — plus a heartbeat for the low-volume classes. + +## 5. What this repository cannot yet do, said plainly + +**The guarantee is owed and is not yet declarable.** It needs the local transactional +outbox (§9.4), a `cadence.yaml` in the form `approval-engine` set as the reference +instance, and sender registration with `audit-core`; the cadence depends on +`AUDIT-WP-0009` T04/T06, which are open. `docs/evidence-path-design.md` says the cadence +is declared and *"will not be described as operating until those land"*, and that stays +true here. + +**This is not a reason to delay the row, and this repository asks that it not be treated as +one.** A10 already provides the honest shape: *"an unassessed row carries `—` and §11's +check reports it as unassessed rather than as conforming."* The row can land now, with the +evidence-source marking `yes` and the emission guarantee reported as **owed and not yet +declared** — a tracked non-conformance under §11's own four-state table, which is a state +the model has and which is more informative than absence. `informed-decision` would rather +be in the catalog as a source with an open guarantee than outside it with a load-bearing +evidence claim nobody may check. + +If the catalog's authors prefer the row to wait until the guarantee is declarable, that is +their call to make and this repository does not contest it. It asks only that the reason be +recorded as a sequencing choice and not as a finding that this repository is not a source. + +## 6. What this does not ask for + +- **Not a second PDP, and not a decision surface.** `layer.yaml` declares + `decision_surfaces_exposed: none` and §6 is untouched. A row records a layer occupied, + never a permission acquired. +- **Not a change to §3.** The four-token vocabulary is closed and this repository declares + inside it, as ruled. `surface` is not being re-argued here; it is history in `layer.yaml`. +- **Not a resolution of the §3.4 question.** `INFD-IN-0007` asks how a deterministic, + non-agentic, evidence-holding repository sits in the layer §3.4 defines by + non-determinism and agentic capability. The row would make that question sharper, since a + catalogued Staff row is measured against §3.4 directly. It is asked, it blocks nothing, + and this repository takes `Staff` either way. +- **Not enrolment by correspondence.** This document is a declaration in this repository's + own voice, which is the only form §11 accepts. It is an answer to a question, and the + canon change is `gate-house`'s and `net-kingdom`'s to make or decline. + +## 7. Summary + +1. **Yes** — `informed-decision` asks for a §4 catalog row. +2. The row is `Staff` / `PEP-shaped` / evidence source `yes`; one row, no second row for + the presentation claim. +3. The deciding reason is that a load-bearing evidence claim outside §4 is uncheckable, not + that this repository belongs in the company of the rows that are there. +4. The emission guarantee is accepted **per event class**: `presentation` (load-bearing, + volume), `disposition` (load-bearing, rare), `stance-application` (load-bearing, rare) — + the two rare classes requiring heartbeat **and** reconciliation, not either alone. +5. The guarantee is **owed and not yet declarable**; the row should land with it marked + owed rather than wait for it, and either sequencing is the catalog authors' to choose. diff --git a/intakes/intakes.md b/intakes/intakes.md index 8bd99a6..547429b 100644 --- a/intakes/intakes.md +++ b/intakes/intakes.md @@ -314,7 +314,7 @@ state_hub_intake_id: "01a0c14e-f965-788f-8efb-4424f1f1ad08" id: INFD-IN-0006 kind: intake title: Is section 3's layer vocabulary closed, and what is `surface`? -status: open +status: closed origin: coordination origin_ref: the-custodian/docs/assessments/2026-09-21-layer-declaration-boundaries.md priority: medium @@ -327,6 +327,26 @@ tags: - conformance created: '2026-09-21' updated: '2026-09-21' +resolved_by: GH-DEC-2026-017 +resolution: >- + RULED 2026-09-21. The section 3 vocabulary is CLOSED and has four tokens — + Taxonomy, Tooling, Engine, Staff — with comparison ASCII case-insensitive, so + no repository is asked to re-spell anything. `surface` is not a layer and this + repository's correct declaration is `layer: Staff, role: pep-shaped`, which + the ruling notes this repository's own file already reasons from twice. + Applied the same day in one commit, in INTENT.md and in layer.yaml, with no + argument, exactly as pre-committed; the elimination reasoning that produced + `surface` is kept as history in layer.yaml because the ruling's own reversal + condition names it. The ruling also held that this repository was NEVER a + section 11 non-conformance — section 11 binds estate-authored repositories IN + section 4 and this repository has no catalog row, so a run that grades it is + over-scoped — and it changed the declaration's FORM: INTENT.md governs, + layer.yaml is a derived artifact that must be marked derived and agree, and a + declaration carries no standard version, which removes the + `standard_version: "0.7"` this repository had flagged. Two things spawn from + it rather than close with it: INFD-IN-0007 (the section 3.4 fit, asked once + more) and the section 4 catalog-row question, answered YES in + docs/section-4-catalog-row.md. description: >- This repository declares `layer: surface` in both INTENT.md frontmatter and layer.yaml. Section 3 of security-layer-model_v0.8.md enumerates four layers — @@ -372,3 +392,53 @@ description: >- docs/gate-house-decision-request-layer-vocabulary.md. state_hub_intake_id: "01a0c14f-17b6-72fb-8951-8c933bd05d6b" ``` + +## INFD-IN-0007 — How does section 3's determinism cut reach Staff for this repository? + +```yaml +id: INFD-IN-0007 +kind: intake +title: How does section 3's determinism cut reach Staff for this repository? +status: open +origin: residual +origin_ref: INFD-IN-0006 +priority: low +owner: gate-house +repo: informed-decision +lane: blue +tags: +- decision-request +- cross-repo +- conformance +created: '2026-09-21' +updated: '2026-09-21' +blocks_nothing: true +description: >- + GH-DEC-2026-017 closed INFD-IN-0006 and named the value: this repository is + `layer: Staff, role: pep-shaped`, and that value is APPLIED — both files + changed the day the ruling arrived, unconditionally, as pre-committed. This + intake is not a reservation on it and nothing waits on it. INFD-IN-0006 asked + one non-conditional question in two parts: WHICH value, and HOW section 3's + determinism cut reaches it given GH-DEC-2026-012 R1. The first part is + answered squarely. The second is answered by elimination — not an Engine per + R1, and nothing else in the four is true, therefore Staff, with ops-mason and + ops-warden as the precedent for Staff in the layer column and PEP-shaped in + the role column. That gives the value and it does not reach the objection this + repository actually raised, which was not about elimination but about fit: + section 3.4 defines Staff as interactive and NON-deterministic, working + through agentic capability, and says Staff repositories MUST NOT hold state + that another layer depends on at runtime. This repository is deterministic by + test (the same approval rendered to the same principal in the same role yields + the same view_hash), forbids an agent from completing its protected act at all + (AGENTS.md: humans bind, agents draft), and holds presentation evidence + audit-core depends on. Section 3 makes determinism the primary cut and this + repository falls on the deterministic side of it while being assigned the + non-deterministic layer. ASK: that the answer be written down for the next + repository in this position, which was the stated reason for asking the first + time — either that section 3.4's prohibitions bind a catalogued Staff row + differently than the elimination that reaches the layer, or that the cut is + not what this repository read it to be, or that this is a real tension carried + openly. Taking the section 4 row (docs/section-4-catalog-row.md) sharpens it, + since a catalogued Staff row is measured against section 3.4 directly. This + repository takes Staff either way and is not asking to be moved. +``` diff --git a/layer.yaml b/layer.yaml index 1458076..0491065 100644 --- a/layer.yaml +++ b/layer.yaml @@ -1,50 +1,160 @@ -# informed-decision — NetKingdom security layer declaration +# informed-decision — NetKingdom security layer declaration (DERIVED) # -# Framework: net-kingdom/canon/standards/security-layer-model_v0.7.md -# Companion: net-kingdom/SECURITY-COMPANION.md v0.2 +# THIS FILE DOES NOT GOVERN. GH-DEC-2026-017 §1 (A11) rules that the `layer:` +# key in INTENT.md frontmatter IS the declaration, and that an equivalent +# declaration file is a DERIVED ARTIFACT which must be marked as derived, must +# name INTENT.md as what it derives from, and must agree with it. §11 already +# said a repository declares its layer in its own INTENT.md; the file form was +# added to give the declaration a machine-readable shape, not a second +# authority. +# +# A disagreement between the two forms is a finding in its own right and must be +# reported rather than resolved away by precedence. There is none here: both +# files carried `surface` in the same casing before the ruling and both carry +# `Staff` after it, changed in one commit. +# +# Framework: net-kingdom/canon/standards/ — the body, UNVERSIONED on purpose. +# Companion: net-kingdom/SECURITY-COMPANION.md # Voice: INTENT.md (this repository's own, per §11 "who must declare") -# Ruling: GH-DEC-2026-012 (gate-house@0a1d1d9) answered INFD-IN-0001 +# Rulings: GH-DEC-2026-012 (INFD-IN-0001) — the shape +# GH-DEC-2026-017 (INFD-IN-0006) — the layer value, the form, the version # # Reference form: ops-warden's, adopted by audit-core and kings-guard, with -# kings-guard's adaptation for a repository with no Tooling contacts. -# -# GH-DEC-2026-012 R1 confirmed the SHAPE. The layer is declared here, in this -# repository's own voice, because a layer someone else states about you is not -# a declaration. +# kings-guard's adaptation for a repository with no Tooling contacts. ops-warden +# owns that form and is updating it for GH-DEC-2026-017 §1 and §5 in a parallel +# session; this file applies the two RULED properties (derived marking, absence +# of a standard version) and follows ops-warden's shape for everything else +# rather than inventing one. schema_version: "0.1" framework: netkingdom-security-layer-model -standard_version: "0.7" -companion_version: "0.2" repository: informed-decision -# §3 vocabulary — UNDER RULING, value deliberately unchanged (INFD-IN-0006). +# §11 derived-artifact rule + GH-DEC-2026-017 §1. +derived: true +derives_from: INTENT.md +derives_from_note: >- + INTENT.md frontmatter governs. This file is regenerated from it by hand and + changes in the same commit, so it is derived at the same commit by + construction; if the two ever disagree, INTENT.md is this repository's answer + and the disagreement is itself a finding. + +# NO standard_version, and no companion_version — GH-DEC-2026-017 §5 (A12). +# A layer declaration asserts a STANDING property: which layer this repository +# is. That does not change when the standard is revised, and a version here +# makes every revision read as though it invalidated the declaration. The field +# was flagged by this repository on 2026-09-21 and by access-engine in its own +# file; the ruling removes it estate-wide from ops-warden's reference form. +# Version-scoped state belongs in the derived conformance record, which must +# carry the version it was derived at. `companion_version` is removed on the +# same reasoning; it is a version pin in a declaration and nothing in the +# ruling's argument distinguishes it. Raised with ops-warden as part of the +# reference-form update rather than decided here for the estate. + +# §3 vocabulary — RULED CLOSED, value corrected 2026-09-21 (INFD-IN-0006). # -# `surface` denotes the presentation-and-binding tier: the runtime a human -# touches, where a decision rendered elsewhere is shown to a named person, that -# person binds their identity to the act, and the evidence that the presentation -# happened is produced. It was chosen by elimination: GH-DEC-2026-012 R1 ruled -# this repository out of Engine and left the layer to it to declare, and each -# remaining §3 value is false of it — not Staff (deterministic by construction, -# and holding state audit-core depends on at runtime, which §3.4 forbids Staff), -# not Tooling (persists nothing another layer reads), not Taxonomy (nothing but -# a runtime position). +# GH-DEC-2026-017 §3: the §3 vocabulary is CLOSED and has four tokens — +# Taxonomy, Tooling, Engine, Staff. Comparison is ASCII case-insensitive (§2 / +# A9), so no repository is asked to re-spell anything. `surface` is not among +# them: "surface is not a layer... Its correct declaration is layer: Staff, role: +# pep-shaped, which its own file already reasons from two ways." ops-mason and +# ops-warden are the precedent: Staff in the layer column, PEP-shaped in the +# role column. # -# §3 of security-layer-model_v0.8.md does not enumerate `surface`, and -# flex-auth's validator reads the vocabulary as closed. Surfaced 2026-09-21 by -# the custodian's estate-wide sweep extending FLEX-WP-0030; never raised against -# this repository before. This repository holds that `surface` names a real tier -# §3 does not enumerate, and will change both files the same day without -# argument if gate-house rules the vocabulary closed and names the value. -# Changing it ahead of the ruling would pre-empt gate-house and destroy the -# evidence of what this repository actually concluded. -# -# Request: docs/gate-house-decision-request-layer-vocabulary.md -layer: surface +# Changed the same day the ruling was received, in one commit, with no argument +# — exactly as this repository pre-committed in +# docs/gate-house-decision-request-layer-vocabulary.md §3. `role: pep-shaped` is +# untouched and was already right; a role is not a layer (GH-DEC-2026-012 R2, +# restated by GH-DEC-2026-017 §3 for the declaration field). +layer: Staff role: pep-shaped declared_by: INTENT.md -declared_at: "2026-09-09" -ruling: GH-DEC-2026-012 +declared_at: "2026-09-09" # the declaration; the VALUE was corrected 2026-09-21 +value_corrected_at: "2026-09-21" +ruling: GH-DEC-2026-017 +shape_ruling: GH-DEC-2026-012 + +# --------------------------------------------------------------------------- +# HISTORY — why `surface` was written. KEPT ON PURPOSE, not erased. +# +# GH-DEC-2026-017 §3's reversal condition names this reasoning directly, so it +# has to remain readable: "§3's closure reverses on an argued amendment to §3, +# from a repository that bears a cost under the four-layer cut." +# +# From 2026-09-09 (commit f6376dd) to 2026-09-21 this file and INTENT.md both +# declared `layer: surface`, in the same casing, meaning the +# presentation-and-binding tier: the runtime a human touches, where a decision +# rendered elsewhere is shown to a named person, that person binds their +# identity to the act, and the evidence that the presentation happened is +# produced. +# +# It was chosen by ELIMINATION, not casually. GH-DEC-2026-012 R1 ruled this +# repository out of Engine and left the layer to it to declare, and each +# remaining §3 value was read as false of it: +# - not Staff — deterministic by construction (the same approval rendered to +# the same principal in the same role yields the same +# view_hash, asserted by test), and holding state audit-core +# depends on at runtime, which §3.4 forbids Staff; +# - not Tooling — persists nothing another layer reads; +# - not Taxonomy— nothing but a runtime position. +# Faced with picking a value it believed false or writing the true word and +# carrying the finding, this repository wrote the word and asked for a ruling. +# It did not ask for §3 to be amended in its favour, and it does not now. +# +# The ruling reaches Staff by the same elimination from the other end — not an +# Engine, and nothing else in the four is true, so Staff — and gives the value, +# which is what was asked for and what binds. The part of the elimination above +# that the ruling does not address is recorded as INFD-IN-0007 below. It is a +# question, not a reservation: the value is applied unconditionally. +# +# Request: docs/gate-house-decision-request-layer-vocabulary.md +# --------------------------------------------------------------------------- + +# OPEN, non-blocking — INFD-IN-0007. +# +# §3.4 defines Staff as interactive and non-deterministic, working through +# agentic capability, and says Staff repositories MUST NOT hold state that +# another layer depends on at runtime. This repository is deterministic by test, +# forbids an agent from completing its protected act at all, and holds +# presentation evidence audit-core depends on. It is Staff by ruling and the +# declaration above says so. What is not yet written down is how §3's +# determinism cut reaches a deterministic, non-agentic, evidence-holding +# repository — the derivation this repository asked for as a non-condition, and +# which the ruling answers as far as the VALUE and not as far as the FIT. +# Asked once more of gate-house; no deadline, no dependency, nothing waits on it. +section_3_4_fit: + status: open + intake: INFD-IN-0007 + blocks_nothing: true + +# §4 catalog membership — ASKED by GH-DEC-2026-017 §4, ANSWERED here. +# +# gate-house deliberately did not enrol this repository: adding a row is a canon +# change, and §11's own rule — a layer stated ABOUT a repository BY another is +# not a declaration — applies to catalogue membership at least as strongly. The +# question was put, not decided. This repository's answer is YES, with the +# obligation that comes with it accepted rather than negotiated. +# +# Full argument: docs/section-4-catalog-row.md. Carried by gate-house as +# GH-WP-0004-T06. +catalog: + section_4_row_today: false + declared_voluntarily: true + scope_report: declared-voluntarily-outside-catalog-scope + requested: true + requested_at: "2026-09-21" + requested_row: + repository: informed-decision + layer: Staff + role: pep-shaped + evidence_source: "yes" + accepts_emission_guarantee: true + note: >- + Until the row exists, §11 does not bind this repository and a run that + grades it is over-scoped (GH-DEC-2026-017 §4). That is the reason to ask for + the row, not a reason to avoid it: this repository's presentation evidence + is the only record of what a human was shown before binding, and an evidence + obligation nobody is allowed to check is the weaker position. # §6.4 — informed-decision is PEP-shaped: it causes a protected side effect on # the far side of a decision (recording an approver entry against an approval @@ -160,7 +270,11 @@ binding_digest_relationship: this linkage must be revisited before the widening ships — a fail-closed consumer obeying a cyclic claim denies permanently. -# §5 applies to Staff. This is a browser-facing surface with no Tooling contact. +# §5 applies to Staff, and this repository is now Staff by ruling — so the line +# below is the §11 mechanical check landing on it directly rather than by +# analogy. It is a browser-facing surface with no Tooling contact, so the check +# is total with an empty map and this repository is CONFORMING on §5, not +# blocked-clean and not a declared gap. tooling_contacts: [] # §11 — record non-Tooling clients so the check is total. @@ -202,6 +316,35 @@ evidence: residual: compromised-surface-presents-x-attests-y residual_closed: false custody: same-bound-as-every-other-source # §16 decided: no stronger archive + # A10 (GH-DEC-2026-018 §5) — emission is marked, never inferred. This + # repository EMITS into the estate's evidence stream; audit-core holds + # custody, which is disjoint from emission and discharges nothing of this + # emitter's guarantee. + emission_guarantee_owed: true + event_classes: + - id: presentation + kind: load-bearing + classification: volume + note: >- + One per render. Classified volume by this repository, which is the + classification a conformance run is SUPPLIED and MUST NOT infer. + - id: disposition + kind: load-bearing + classification: rare + note: >- + The binding act. Rare and security-relevant: heartbeat AND + reconciliation, never rate monitoring alone — a quiet month of + dispositions is indistinguishable from suppression by rate. + - id: stance-application + kind: load-bearing + classification: rare + note: Fail-closed stance applied at a binding attempt. Same form as disposition. + emission_guarantee_status: not-yet-declarable + emission_guarantee_blocked_on: >- + The local transactional outbox (§9.4) and the cadence declaration are + designed (docs/evidence-path-design.md §5) and depend on audit-core's + AUDIT-WP-0009 T04/T06 and on sender registration. Declared as owed rather + than described as operating. note: >- GH-DEC-2026-012 states the residual is not closed in those words, and this repository is not credited with closing it. Same disposition as diff --git a/tests/test_layer_conformance.py b/tests/test_layer_conformance.py index bd731d7..e26fe15 100644 --- a/tests/test_layer_conformance.py +++ b/tests/test_layer_conformance.py @@ -197,3 +197,44 @@ def test_classification_coverage_is_dated_and_complete_against_the_axis(stance_d cov = stance_doc["classification_coverage"] assert cov["as_of"] assert cov["axis_values_enumerated"] == cov["axis_values_in_schema"] == len(AXIS_VALUES) + + +# -------------------------------------------------------------------------- +# GH-DEC-2026-017 — INTENT.md governs; layer.yaml is derived and must agree; +# the vocabulary is closed at four tokens and case-insensitive; no version. +# -------------------------------------------------------------------------- + +LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"} + + +@pytest.fixture(scope="module") +def intent_frontmatter() -> dict: + text = (ROOT / "INTENT.md").read_text(encoding="utf-8") + _, front, _ = text.split("---\n", 2) + return yaml.safe_load(front) + + +def test_intent_declares_a_layer_inside_the_closed_vocabulary(intent_frontmatter): + assert intent_frontmatter["layer"].casefold() in LAYER_VOCABULARY + + +def test_layer_is_staff_as_ruled(intent_frontmatter): + assert intent_frontmatter["layer"].casefold() == "staff" + assert intent_frontmatter["role"] == "pep-shaped" + + +def test_sidecar_is_marked_derived_from_intent(layer_doc): + assert layer_doc["derived"] is True + assert layer_doc["derives_from"] == "INTENT.md" + + +def test_sidecar_agrees_with_intent(layer_doc, intent_frontmatter): + assert layer_doc["layer"].casefold() == intent_frontmatter["layer"].casefold() + assert layer_doc["role"] == intent_frontmatter["role"] + + +def test_declaration_carries_no_standard_version(layer_doc, intent_frontmatter): + for doc in (layer_doc, intent_frontmatter): + assert "standard_version" not in doc + assert "companion_version" not in doc + assert "_v0." not in str(intent_frontmatter.get("standard", ""))