Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
3.9 KiB
| id | type | title | domain | repo | status | owner | topic_slug | planning_priority | created | updated | state_hub_workstream_id |
|---|---|---|---|---|---|---|---|---|---|---|---|
| NK-WP-0030 | workplan | Implement deterministic security scenario composition | infotech | net-kingdom | finished | codex | netkingdom | P1 | 2026-08-23 | 2026-08-23 | 8a884593-b7f9-508a-9e15-bfd901463ac1 |
NK-WP-0030 — Deterministic security scenario composition
Authorized by the operator as the first implementation increment following the 2026-08-23 scope-to-intent gap assessment. This work closes the locally owned part of G1 without moving playbook execution into NetKingdom.
Define the scenario composition contract
id: NK-WP-0030-T01
status: done
priority: high
state_hub_task_id: "c071698f-6a5a-5845-9f22-042d100f3958"
Published proposed security-scenario-composition_v0.1 canon and its scenario
schema. It requires exact provider pins under ambiguity, explicit initial trust,
fail-closed sequencing, owner attribution, readiness obligations, and an
unconditional non-execution boundary.
Implement the canonical composer
id: NK-WP-0030-T02
status: done
priority: high
state_hub_task_id: "0372da5c-83ee-5e03-bb45-5cae81e5330b"
Implemented tools/security-scenario-composer/. It consumes Playbook Capability
Contract v0.1 declarations, rejects invalid or ambiguous inputs, validates
authority-bound parameter overrides, orders selected declarations by explicit
trust transitions, and emits a deterministic owner-routed JSON plan with a
content digest and execution.permitted: false. The older conformance-demo
selector now also refuses ambiguity and overrides targeting unselected
declarations.
Publish a C0 reference composition
id: NK-WP-0030-T03
status: done
priority: high
state_hub_task_id: "99392b0f-c0a4-5abd-afdb-ef15c964ae1f"
Published capabilities/playbooks/net-kingdom.local-identity.yaml and
examples/security-scenarios/c0-local-identity.yaml. The non-secret reference
selects the exact local provider, starts from explicit bare_host_trust, and
plans the readiness obligations for bootstrap_identity_trust without
executing the CLI entry point.
Obtain lightweight-provider declarations
id: NK-WP-0030-T04
status: done
priority: high
state_hub_task_id: "41fd145d-7a37-5c65-ae72-142ac6d49144"
Ask the KeyCape/Railiance owners to publish conformant C1 and selected C2
declarations beside their execution entry points. Do not fabricate provider
authority in NetKingdom. The complete lightweight SSO scenario remains blocked
until those declarations exist and pass the canonical composer. Routed to
key-cape in State Hub message 64d247e4-9170-4d18-b7ed-d8b071282104.
KeyCape published the authoritative C1 and C2b declarations at revision
34fadae and notified NetKingdom in State Hub message
1d5f5f15-d137-4c11-8386-c8cc58c17bb8. Both pass the canonical declaration
validator. examples/security-scenarios/c1-c2b-key-cape.yaml pins the exact
providers, sequences C1 before C2b through runtime_identity_trust, and emits
plan digest
sha256:cd7aeba3c83c83e2de7bc9a64d2dd9922f4f39a4de81c41760f9f9a431a820a6
with execution forbidden. C2a remains outside the scenario and is not implied.
Verify the fail-closed and reference paths
id: NK-WP-0030-T05
status: done
priority: medium
state_hub_task_id: "7db26092-35c4-52c6-9a3e-3f24bc3e26c7"
Added eleven composer tests and five regression tests for the legacy declaration
validator/demo selector, including secret-reference syntax enforcement.
Exact selection, ambiguity refusal, bad pins, override boundaries, duplicate
ids, dependency ordering, unresolved trust, responsibility/readiness mapping,
and the checked-in C0 and KeyCape C1+C2b compositions pass. The current root
repository suite passes 88 tests; the isolated local-identity suite passes 142
tests. JSON/YAML parsing, Python compilation, both reference CLI paths, and
git diff --check also pass.