INTENT.md frontmatter governs and layer.yaml is marked derived from it. standard_version is removed from both forms (A12). The checker and its tests change in the same commit: they no longer require the field, they reject it, they fold case against the four-token vocabulary (A9) instead of comparing with plain equality, and they still fail a layer disagreement that survives the fold (A11). Neither layer value is re-spelled. The ruling answers kings-guard's "validated-against" reading of the field (§5: version-scoped state belongs in the derived conformance record), so that version now lives in the checker as VALIDATED_AGAINST and is printed in every run's output. The standard: path in INTENT.md is unversioned to match the reference form. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
178 lines
8.2 KiB
YAML
178 lines
8.2 KiB
YAML
# kings-guard — DERIVED form of the NetKingdom security layer declaration
|
|
#
|
|
# THIS FILE DOES NOT GOVERN. The declaration is the `layer:` key in INTENT.md's
|
|
# frontmatter; this file is a derived artifact under §11's derived-artifact rule
|
|
# and must agree with it (GH-DEC-2026-017 §1, amendment A11). A disagreement
|
|
# between the two forms is a finding in its own right and is reported by
|
|
# scripts/check_layer_conformance.py, never resolved away by precedence.
|
|
#
|
|
# Framework: net-kingdom/canon/standards/security-layer-model
|
|
# Assent: decisions/decisions.md KG-DEC-2026-001 (kings-guard's own voice, §11)
|
|
# Validate: python3 scripts/check_layer_conformance.py
|
|
#
|
|
# §11 (v0.7) requires a machine-readable declaration: prose cannot distinguish a
|
|
# declaration from a transcribed review. Form adapted from ops-warden's
|
|
# reference implementation, offered under §11.
|
|
#
|
|
# kings-guard's position is unusual and this file is shaped to state it exactly:
|
|
# there are NO Tooling contacts. Not a narrow one, not a read-only one. The
|
|
# capabilities that would need them sit at zero instead. Under §11 that is
|
|
# BLOCKED-CLEAN, which MUST NOT rank below conforming.
|
|
#
|
|
# RULED, 2026-09-21 — GH-DEC-2026-017, applied here (closes KG-IN-0007):
|
|
# * Precedence: INTENT.md governs; this file is derived (§1 / A11). Hence
|
|
# `derived: true` and `derived_from: INTENT.md` below.
|
|
# * Case: §3's vocabulary is closed at four tokens {Taxonomy, Tooling, Engine,
|
|
# Staff} and comparison is ASCII case-insensitive (§2, §3 / A9). `layer:
|
|
# staff` below and `layer: Staff` in INTENT.md are THE SAME VALUE and neither
|
|
# is re-spelled. Do not "fix" either to match the other; the checker folds.
|
|
# * Version: a layer declaration MUST NOT carry a standard version (§5 / A12).
|
|
# `standard_version: "0.7"` is removed from this file and from INTENT.md.
|
|
#
|
|
# History of the unruled state (kept, not rewritten): before the ruling this
|
|
# block recorded both questions as OPEN and changed neither file, because
|
|
# picking a form would have been kings-guard authoring a ruling gate-house holds.
|
|
# It also argued that `standard_version` here meant the version this declaration
|
|
# was VALIDATED against, not an assent version, so flex-auth's B4 might not
|
|
# reach it. GH-DEC-2026-017 §5 answers that reading rather than leaving room for
|
|
# it: version-scoped state — which is what "validated against" is — belongs in
|
|
# the derived conformance record, and keeping the field "for information" was
|
|
# declined because a field that is present will be branched on. The
|
|
# validated-against version therefore now lives in the checker, as
|
|
# VALIDATED_AGAINST in scripts/check_layer_conformance.py, and is printed in
|
|
# every run's output (`make check-layer`). Assent versions still live with each
|
|
# assent in decisions/decisions.md.
|
|
# Assent to §9.5 at v0.8 is KG-DEC-2026-004 and does not move this file.
|
|
|
|
schema_version: "0.1"
|
|
framework: netkingdom-security-layer-model
|
|
|
|
# §11 derived-artifact marking (GH-DEC-2026-017 §1 / A11).
|
|
derived: true
|
|
derived_from: INTENT.md
|
|
|
|
# NO `standard_version` KEY, AND DO NOT ADD ONE BACK (GH-DEC-2026-017 §5 / A12).
|
|
# Absence is enforced by scripts/check_layer_conformance.py.
|
|
|
|
repository: kings-guard
|
|
layer: staff
|
|
declared_by: decisions/decisions.md#KG-DEC-2026-001
|
|
declared_at: "2026-08-29"
|
|
|
|
# §4 catalog entry, transcribed so drift between the catalog and this file is
|
|
# visible. The standard is authoritative for the row; this records what we
|
|
# understand ourselves to have been assigned.
|
|
# §3.4 — the four rules binding the agent principal. kings-guard offered to
|
|
# assent to these sight-unseen before they were written into v0.7.
|
|
agent_principal_rules:
|
|
no_standing_credential: true
|
|
tool_use_shapes: ["5.2-conduit", "engine-api"]
|
|
memory_is_not_a_state_plane: true
|
|
reconstructable_as_caller: true
|
|
|
|
# Honest split between what is mechanically checked and what remains an
|
|
# assertion. A claim in this file is not a test; the `form` column is.
|
|
agent_principal_rule_checks:
|
|
no_standing_credential:
|
|
form: test
|
|
checked_by: scripts/check_layer_conformance.py
|
|
tool_use_shapes:
|
|
form: assertion
|
|
note: >-
|
|
No third route is claimed. The Tooling-client scan covers the Tooling
|
|
half of "no third route". Distinguishing an Engine API call from an
|
|
ordinary Python call is not mechanical here; remaining assertion.
|
|
memory_is_not_a_state_plane:
|
|
form: test
|
|
checked_by: tests/test_immune_memory.py
|
|
reconstructable_as_caller:
|
|
form: mixed
|
|
tested: EffectorRequest origin fields (KG-WP-0003-T06)
|
|
remainder: >-
|
|
Full reconstructability of every agent action as the caller's is still
|
|
assertion; session and harness traces are glas-harness's.
|
|
|
|
catalog_entry:
|
|
owns:
|
|
- adaptive defence and judgment
|
|
- observation of Staff-reachable sources
|
|
pending:
|
|
- identity observation
|
|
- secret observation
|
|
proposes_but_does_not_own:
|
|
# §9.2 — actuation is an Engine concept held at zero. kings-guard proposes
|
|
# containment and never performs it. This is not our gap to close.
|
|
- containment
|
|
|
|
# §5 / §11: every direct contact with a Tooling-layer system (a §4 Tooling row),
|
|
# one entry each. Empty is a claim, and scripts/check_layer_conformance.py is
|
|
# what makes it checkable rather than asserted.
|
|
tooling_contacts: []
|
|
|
|
# §11 requires non-Tooling clients to be recorded "so the check is total".
|
|
non_tooling_clients:
|
|
- id: state-hub-work-records
|
|
target: state-hub
|
|
layer: not-catalogued
|
|
operation: "HTTP to the Custodian State Hub for work records and progress events"
|
|
write: true
|
|
note: >-
|
|
Outside §5 by the v0.5 scope rule: "Tooling-layer system" means a §4
|
|
Tooling row, and state-hub is not one. Recorded, not policed. Carries no
|
|
security authority and no secret payload.
|
|
|
|
# §11 blocked-clean. These are NOT §5.3 declared gaps: there is no contact to
|
|
# declare. Fields follow the §5.3 shape so one register can hold both kinds
|
|
# (§13 now carries the state column that keeps them distinct — raised by
|
|
# kings-guard against v0.4).
|
|
unowned_capabilities:
|
|
|
|
- id: authentication-assurance-evidence
|
|
state: unowned-capability
|
|
capability: >-
|
|
Token assurance, attestation outcomes and authentication anomalies exposed
|
|
as an engine surface, for identity-drift posture.
|
|
intended_owner: "identity layer + audit-core"
|
|
owner_status: "access-engine declined (v0.6 §13); reproposed, not assented"
|
|
blocked_on: >-
|
|
No engine exposes authentication evidence. key-cape is Tooling, so §5
|
|
forbids the direct route, and the capability stays at zero rather than
|
|
being taken locally.
|
|
review: "2026-11-28"
|
|
consequence: "identity-drift posture lane stays fixture-driven"
|
|
|
|
- id: secret-use-evidence
|
|
state: unowned-capability
|
|
capability: >-
|
|
Lease, revocation, mount and rotation metadata exposed as an engine
|
|
surface, for secret-abuse posture.
|
|
intended_owner: secrets-engine
|
|
owner_status: "snapshot parsing admitted; posture admission pending"
|
|
blocked_on: >-
|
|
secrets-engine now exposes `secret-use snapshot`, a non-secret local
|
|
evidence surface with a 1d heartbeat declaration. Envelope and scoped lane
|
|
parsing are admitted under KG-WP-0006; event provenance, heartbeat evidence
|
|
and posture admission remain pending under KG-IN-0005.
|
|
review: "2026-11-28"
|
|
consequence: "secret-abuse posture lane stays fixture-driven"
|
|
|
|
- id: actuation-surface
|
|
state: unowned-capability
|
|
capability: >-
|
|
Reduce authority, require step-up, isolate a workload — as a deterministic
|
|
engine API carrying a decision record.
|
|
intended_owner: "access-engine + runtime PEPs"
|
|
owner_status: "proposed; access-engine has not reviewed (FLEX-DEC-2026-002)"
|
|
blocked_on: >-
|
|
Ruled in v0.6 §9.2 to be an Engine concept, unowned and held at zero.
|
|
kings-guard proposes containment and does not own it, so this row is
|
|
recorded here as a dependency, not as a kings-guard gap to close.
|
|
review: "2026-11-28"
|
|
consequence: "no containment is possible anywhere in the estate"
|
|
|
|
# §5.1 read-only diagnostic observation of Tooling: none declared, none taken.
|
|
# §5.2 conduit: none. kings-guard runs no tool under a caller's identity.
|
|
declared_shapes:
|
|
"5.1": []
|
|
"5.2": []
|
|
"5.3": []
|