net-kingdom/workplans/NK-WP-0035-emission-cadence-security-profile.md
tegwick 4e07d60ff1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Validate cadence contract and require functional MFA verification
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
2026-09-05 01:28:05 +02:00

4.4 KiB

id type title domain repo status owner topic_slug planning_priority created updated related
NK-WP-0035 workplan Publish the NetKingdom emission-cadence security profile infotech net-kingdom blocked codex netkingdom P1 2026-09-04 2026-09-05
GH-DEC-2026-004
canon/standards/security-layer-model_v0.7.md

NK-WP-0035 — NetKingdom emission-cadence security profile

GH-DEC-2026-004 assigns the ecosystem-wide EmissionCadenceDeclaration contract to info-tech-canon and the importing NetKingdom security profile to this repository. This work accepts that split. It must not copy the generic schema drafted by kings-guard or make the observer the owner of source classifications.

Define the importing security profile

id: NK-WP-0035-T01
status: done
priority: high

Publish the NetKingdom MUST/SHOULD obligations over the generic contract: load-bearing classes declare cadence, attributive classes should, and rare load-bearing classes use heartbeat plus reconciliation with rate monitoring forbidden. Keep source classification owner-authored and preserve the residual that cadence detects omission only after the fact.

Implemented as proposed canon at canon/standards/emission-cadence-security-profile_v0.1.md. The profile accepts the GH-DEC-2026-004 split, requires source-owned classification, distinguishes MUST from SHOULD coverage, and records that omission detection is after the fact rather than proof of completeness.

Implement mechanical profile validation

id: NK-WP-0035-T02
status: done
priority: high

Validate a declaration against an explicitly supplied InfoTechCanon JSON Schema before applying the NetKingdom overlay. The checker must not ship a fallback generic schema, infer evidence class or rarity from event contents, or treat a SHOULD finding as a MUST failure by default.

Implemented at tools/emission-cadence-profile/emission_cadence_profile.py. It requires --contract-schema, performs generic validation first, then checks the NetKingdom overlay against caller-supplied source inventory assertions. No generic fallback schema or owner declaration instance was added here.

Verify the boundary and failure cases

id: NK-WP-0035-T03
status: done
priority: medium

Cover contract-first validation, missing and mismatched class declarations, the allowed high-volume load-bearing rate form, the forbidden rare-event rate form, both positive controls for rare load-bearing classes, duplicate classes, and advisory attributive coverage.

Verification on 2026-09-04: eight focused tests pass; the 81-test root tests/ + tools/ regression suite passes; Ruff lint and format checks pass; Python compilation and git diff --check pass.

Bind and hand off the published contract

id: NK-WP-0035-T04
status: wait
priority: high

When info-tech-canon publishes its versioned contract and schema, replace the pending import locator with its canonical coordinates and digest, validate the owner-source instances, and notify kings-guard to replace its draft-shaped fixture. This task cannot be completed from NetKingdom without the upstream artifact and must not be worked around by copying the draft.

2026-09-05 review: the upstream publication blocker is resolved by InfoTechCanon 0.7.0 / contract 0.1.0. Bound the profile to the schema coordinates, revision and SHA-256; fixed the checker to read extensions.netkingdom, removed draft reconciliation aliases, and enforced unique source IDs. Fifteen focused tests pass, including direct integration with the published owner schema and CLI exit-policy coverage.

The current owner instances (approval-engine/cadence.yaml and qonto-assistant/specs/audit-emission-cadence.yaml) were reviewed and checked; both still fail generic contract validation because they use draft envelopes. No source instance was rewritten by NetKingdom. T04 remains wait for each owner's migration and subsequent profile validation, followed by the King's Guard handoff. The profile remains proposed.

Validation: python3 -m pytest tests tools -q passed 106 tests, including 18 privacyIDEA and 15 cadence cases. Ruff lint/format, shell syntax, embedded Python compilation and git diff --check passed.

State Hub reconciliation was attempted with both the installed CLI and current checkout. Full reconciliation remains pending because API queries/writes timed out or returned connection-refused errors. Generated index/intake metadata was reviewed; the source files remain authoritative.