Declare layer machine-readably (§11); adopt v0.6 corrections
The standard moved v0.4 -> v0.6. All four findings from our v0.4 review were adopted in v0.5, and v0.6 went further on two of them. §11 now requires a machine-readable declaration — prose cannot distinguish a declaration from a transcribed review. We had none. Added layer.yaml (form adapted from ops-warden's reference implementation), scripts/check_layer_conformance.py, and tests/test_layer_conformance.py. The check makes our central claim mechanical rather than asserted: no direct Tooling client in src/. The test exercises the negative case on a synthetic tree, so it fails if the checker goes blind. pyyaml is added as a DEV dependency only — `dependencies = []` is load-bearing for the §5 claim and stays empty. Adopted from v0.6: - containment is no longer ours (§9.2). Actuation is an Engine concept, unowned and held at zero; kings-guard proposes containment and never performs it. The register row is now a dependency, not our gap. - observation is scoped to Staff-reachable sources, with identity and secret observation pending — our finding 1, adopted near-verbatim. - access-engine DECLINED the authentication-evidence gap; owner is now the identity layer plus audit-core, reproposed and unassented. - §11 blocked-clean recorded, with the rule that it must not rank below conforming — our finding 2. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UEtvmYUBP2fDtirJGWn5MW Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014379@bnt-lap001 Assistant-Session: 4af9e20f-1768-4afc-951b-b507784e382b
This commit is contained in:
parent
d99f395aa1
commit
72c2a42d67
9 changed files with 389 additions and 29 deletions
|
|
@ -31,7 +31,7 @@ The following rules apply to every integration below:
|
|||
4. `kings-guard` must preserve **tenant isolation**: any retained evidence or
|
||||
memory must stay bounded by declared confidentiality rules.
|
||||
5. `kings-guard` is a **Staff-layer** repository and is bound by §5 of the
|
||||
NetKingdom Security Layer Model v0.4: it never holds a direct client for a
|
||||
NetKingdom Security Layer Model v0.6: it never holds a direct client for a
|
||||
Tooling-layer system. Evidence from Tooling (OpenBao, key-cape components)
|
||||
is consumed **through the owning engine**. Where no engine surface exists,
|
||||
the lane stays fixture-driven and the gap is declared in `INTENT.md`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue