Require explicit cadence profile assessment and correct contract pins

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e77d-47a4-7771-8e34-7339c7fac0e4
This commit is contained in:
tegwick 2026-09-28 12:40:07 +02:00
parent 9383b94019
commit 36303d25a3
7 changed files with 281 additions and 20 deletions

View file

@ -7,8 +7,8 @@ status: proposed
version: "0.1"
owner: net-kingdom
created: "2026-09-04"
updated: "2026-09-05"
last_reviewed: "2026-09-05"
updated: "2026-09-28"
last_reviewed: "2026-09-28"
review_interval: 3m
scope: evidence-completeness
validator:
@ -34,14 +34,21 @@ This profile imports that contract and defines only NetKingdom security
obligations over conforming declarations.
The import is InfoTechCanon `standard/emission-cadence`, document version
`0.1.0`, schema version `0.1` (published in canon 0.7.0; upstream status: draft).
`0.2.0`, schema version `0.1` (canon 0.7.0; upstream status: candidate).
- Contract: `info-tech-canon/infospace/standards/emission-cadence/InfoTechCanonEmissionCadenceStandard.md`
- Schema: `info-tech-canon/infospace/schemas/emission-cadence.schema.yaml`
- Schema ID: `https://info-tech-canon.local/schemas/emission-cadence.schema.yaml`
- Reviewed schema revision: `b081d39da1353201f879ee6832d4e3e52b791c73`
- Reviewed contract/schema revision: `4d0851c3fca306538b53838421f4499baf352778`
- Owner-published candidate bundle digest: `b08b4d95fc4b0bd3`
- Schema SHA-256: `6d52692eb1e4d1325e0d6062d95acded98beddaae5bcfe24c6f0e91f1b6be6ae`
The candidate bundle digest identifies the exported contract, including its
standard text and example; it is not the schema SHA-256. The September 28
review confirmed that the wire schema is byte-identical to the earlier import.
InfoTechCanon corrected its adoption brief: `972c0b6701d1693f` identified the
0.1.0 draft bundle, not candidate 0.2.0.
The schema ID is an identifier; supply the file from the owner checkout, not a
network download from that hostname. This profile remains proposed pending
owner-instance migration and validation. The King's Guard draft is provenance,
@ -118,9 +125,26 @@ contract and refuses to profile a document that fails the imported schema.
from the source's authoritative event-class inventory; they are not guesses by
the checker. Rare load-bearing assertions imply load-bearing.
MUST failures or generic contract failures produce a non-zero exit. Missing
attributive declarations produce a SHOULD finding and succeed by default;
`--fail-on-should` is available for a stricter caller policy.
The report separates `contract_valid` (JSON Schema validity) from
`profile_assessed` and nullable `conformant`. A profile assessment is performed
only after schema validation and with a nonempty supplied inventory. The report
records those assertions under `inventory` and marks `assessment_scope` as
`supplied-inventory`; its result covers only that inventory, not independently
verified completeness or operational emission.
Without inventory, default mode returns `profile_assessed: false`,
`conformant: null`, `assessment_scope: inventory-missing` and exit 2. Explicit
`--schema-only` returns `assessment_scope: schema-only` and exit 0 for a valid
schema instance, while leaving profile conformance unassessed. It cannot be
combined with inventory flags or `--fail-on-should`. Invalid schema/declaration
results return exit 1 with profile conformance unassessed. CLI/input errors
return exit 2.
MUST failures from an assessed profile produce exit 1. Missing attributive
declarations produce a SHOULD finding and succeed by default;
`--fail-on-should` is available for a stricter caller policy. Callers must check
`profile_assessed == true` and `conformant == true` before claiming profile
success; an empty findings list or schema-only success is insufficient.
## 5. Adoption gate