Declare the layer per GH-DEC-2026-012; close T02
Gate House ruled all three questions within a day, attributing the speed to the request being filed before the architecture with candidate answers and their costs. R1 PEP-shaped, confirmed as proposed. The ruling settles the shape; the layer stays ours to declare, so layer.yaml is written in this repository's voice rather than transcribed from the reply. R2 yes to a presentation claim, no second catalog row, under three limits now declared in layer.yaml and tested. Limit 2 — the claim must never be an input to the decision it presents for — is load-bearing: our self-dealing argument was accepted because it holds, not despite it. Limit 3 drives architecture, since here the actor being audited and the evidence source are the same component. R3 (b) with the authority rule: binding digest authoritative for what the request is, view_hash only for what was shown, neither substitutable, and a disagreement between them is a finding against the presenting surface rather than a fact about the request. Linkage is co-reference; nesting was refused because it reproduces the GH-DEC-2026-008 hash cycle. Built to v0.8 obligation 3 rather than migrating later: axis enumerated, unknown resolves to fail_closed, absent distinguishable from unknown in the record, and published-equals-shipped asserted by test rather than claimed. Every stance is fail_closed, which is a conclusion not a shortcut — ops-warden can justify fail_open on a continuity argument that does not exist here. GH-DEC-2026-010 inherited as a declared gap in four documents: a decision cannot today be proven to have come from access-engine. The decision path must not be described as validated while FLEX-WP-0024 is open. 46 tests pass. T05 and T07 unblocked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V3W1dQG7GFFM9d94jFx7iR Assistant: claude-code Assistant-Model: opus Assistant-Process: 1565372@bnt-lap001 Assistant-Session: 16bb2f25-b34c-49ef-8e94-5fec3567a568
This commit is contained in:
parent
f36e2b789a
commit
f6376ddff5
9 changed files with 614 additions and 20 deletions
24
GOAL.md
24
GOAL.md
|
|
@ -85,6 +85,11 @@ These hold for Stage 1 and for every stage after it.
|
|||
- **`approved` is never rendered as permission to act.** It is a state of an
|
||||
object. Presenting it as "you may now do the thing" is a policy decision point
|
||||
in the browser.
|
||||
- **The decision path is not validated, and must not be described as such.**
|
||||
`GH-DEC-2026-010` requires a decision be attributable to `access-engine`, and
|
||||
no consumer can satisfy that today — the envelope is unsigned
|
||||
(`FLEX-WP-0024`). This surface records that a decision was obtained and what
|
||||
it said, and records `decision_attributable: false`.
|
||||
- **Entitlement to view is `access-engine`'s.** A `200` from `approval-engine`
|
||||
is not permission to see the approval; that engine never answers "may this
|
||||
actor do X". This surface obtains a decision before rendering and never
|
||||
|
|
@ -108,7 +113,9 @@ These hold for Stage 1 and for every stage after it.
|
|||
|
||||
> **Who owns the approver UI?**
|
||||
|
||||
The answer this repository proposes, to be ratified rather than assumed:
|
||||
**Answered 2026-09-09 by `GH-DEC-2026-012`.** The proposal below was confirmed
|
||||
in full. Recorded as proposed-then-ratified rather than rewritten as though it
|
||||
had always been settled:
|
||||
|
||||
- **informed-decision owns it** — the surface, the presentation record, the
|
||||
browser client, and the evidence of informedness.
|
||||
|
|
@ -117,13 +124,20 @@ The answer this repository proposes, to be ratified rather than assumed:
|
|||
and statute §6.4.
|
||||
- It supplies exactly one PIP-like fact — *what was presented* — as a claim
|
||||
carrying `view_hash`, issuer and freshness, and it never evaluates that fact.
|
||||
- The catalog row does not exist yet. `INFD-WP-0001-T02` asks `gate-house` and
|
||||
writes `layer.yaml` from the ruling. If `gate-house` places this component
|
||||
elsewhere, `INTENT.md` and this file change to match — the ruling wins.
|
||||
- **Ruled:** PEP-shaped, confirmed as proposed. No second catalog row for the
|
||||
presentation claim — PEP and PIP are shapes a repository has. The claim is
|
||||
permitted under three limits (presentation-only; never an input to the
|
||||
decision it presents for; evidence reaches `audit-core` independently), and
|
||||
`view_hash` versus the binding digest is settled as distinct attestations with
|
||||
an authority rule, linked by co-reference and never by nesting.
|
||||
`layer.yaml` and `pep-stance.yaml` declare it; `INTENT.md` carries the
|
||||
reasoning.
|
||||
|
||||
## Definition of done
|
||||
|
||||
1. `gate-house` has ruled on the layer placement and `layer.yaml` reflects it.
|
||||
1. ~~`gate-house` has ruled on the layer placement and `layer.yaml` reflects
|
||||
it.~~ **Done 2026-09-09** — `GH-DEC-2026-012`; `layer.yaml`,
|
||||
`pep-stance.yaml` and `tests/test_layer_conformance.py`.
|
||||
2. `key-cape` has the `client_id` and callback URI, and `KEY-WP-0013-T02` is
|
||||
unblocked with the answer traceable to this repository.
|
||||
3. The four specs exist, are reviewed against the current `approval-engine`,
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue