net-kingdom/canon/standards
tegwick 31a49a43eb
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Correct v0.8 §9.7.3: the binding correspondence as first cut could never pass
secrets-engine found, and access-engine and approval-engine reported
independently within hours, that GH-DEC-2026-008 as written was
unimplementable. Where a claim travels inside the hashed request — the
dual-control pattern it was written for — embedding the claim changes the
digest of the request carrying it, so a digest recorded at issue can
never equal the final one. It is a hash cycle. A fail-closed consumer
obeying the rule would have denied destroy permanently.

The comparison is now against the digest the PDP publishes for the
request with the approval evidence excluded (flex-auth's
binding.approval_binding_digest, verified present in its schema and
tests). The exclusion rule is the PDP's to publish and a consumer MUST
NOT guess it: a digest computed under an assumed rule fails open toward
accepting a claim bound to a different request — the same failure
direction as an invented vocabulary mapping, by another road.

§6.4 obligation 5 gains the general property access-engine flagged as a
near miss rather than a request: an evidence-bearing input may be
excluded from a correspondence digest but never from the replay identity.
Two requests differing only in which approval was presented decide
differently, so collapsing them lets an allow obtained with a valid claim
be replayed against a request carrying none — a fail-open hole reached by
a refactor that looks like simplification.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WtJBr77gMFLrN93iEevqQJ

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 425128@bnt-lap001
Assistant-Session: f5944d8b-dac4-4e1a-87eb-8b3d8f314a63
2026-09-06 15:26:51 +02:00
..
credential-management_v0.2.md Add OpenBao runtime secret authority; complete NK-WP-0006/0007/0008 2026-05-20 22:51:20 +02:00
emission-cadence-security-profile_v0.1.md Validate cadence contract and require functional MFA verification 2026-09-05 01:28:05 +02:00
iam-profile_v0.2.md Separate IAM Profile ids and mark v0.2 superseded 2026-08-19 01:09:18 +02:00
iam-profile_v0.3.md docs: refresh published security canon index 2026-08-31 21:17:38 +02:00
playbook-capability-contract_v0.1.md feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
posture-feedback_v0.1.md feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
security-layer-model_v0.1.md Security Layer Model v0.2 — accepted 2026-08-28 22:00:31 +02:00
security-layer-model_v0.2.md Security Layer Model v0.3 — assign approvals and maturity 2026-08-28 22:34:58 +02:00
security-layer-model_v0.3.md Security Layer Model v0.4 — audit-core assent and its corrections 2026-08-28 22:54:50 +02:00
security-layer-model_v0.4.md Security Layer Model v0.5 — four reviews, nine changes 2026-08-29 02:54:25 +02:00
security-layer-model_v0.5.md Security Layer Model v0.6 — type the engines, name the gate, hold actuation at zero 2026-08-29 03:32:58 +02:00
security-layer-model_v0.6.md Security Layer Model v0.7 — write the rule v0.6 only announced 2026-08-29 10:44:53 +02:00
security-layer-model_v0.7.md Accept the security layer model; companion v0.2 to the repository root 2026-08-29 11:28:49 +02:00
security-layer-model_v0.8.md Correct v0.8 §9.7.3: the binding correspondence as first cut could never pass 2026-09-06 15:26:51 +02:00
security-scenario-composition_v0.1.md feat(orchestration): compose security scenarios 2026-08-23 12:40:52 +02:00
security-zones_v0.1.md docs(canon): record security zone adoption 2026-08-22 15:43:52 +02:00
tenancy-posture_v0.1.md feat(posture): add deterministic feedback proposals 2026-08-23 13:16:34 +02:00
tenant-engine-boundary-contract_v0.1.md docs(canon): reconcile workload and tenant grouping semantics 2026-08-22 14:53:31 +02:00
user-engine-boundary-contract_v0.1.md docs: persist user-engine vs net-kingdom integration assessment (new doc + cross-references in SCOPE, boundary contract, guidance, responsibility map, 0018/0019 workplans). Also updated user-engine integration doc to reference it. 2026-06-03 10:33:31 +02:00