net-kingdom/workplans/NK-WP-0035-emission-cadence-security-profile.md
tegwick 4e07d60ff1
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Validate cadence contract and require functional MFA verification
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
2026-09-05 01:28:05 +02:00

117 lines
4.4 KiB
Markdown

---
id: NK-WP-0035
type: workplan
title: "Publish the NetKingdom emission-cadence security profile"
domain: infotech
repo: net-kingdom
status: blocked
owner: codex
topic_slug: netkingdom
planning_priority: P1
created: "2026-09-04"
updated: "2026-09-05"
related:
- GH-DEC-2026-004
- canon/standards/security-layer-model_v0.7.md
---
# NK-WP-0035 — NetKingdom emission-cadence security profile
GH-DEC-2026-004 assigns the ecosystem-wide
`EmissionCadenceDeclaration` contract to `info-tech-canon` and the importing
NetKingdom security profile to this repository. This work accepts that split.
It must not copy the generic schema drafted by `kings-guard` or make the
observer the owner of source classifications.
## Define the importing security profile
```task
id: NK-WP-0035-T01
status: done
priority: high
```
Publish the NetKingdom MUST/SHOULD obligations over the generic contract:
load-bearing classes declare cadence, attributive classes should, and rare
load-bearing classes use heartbeat plus reconciliation with rate monitoring
forbidden. Keep source classification owner-authored and preserve the residual
that cadence detects omission only after the fact.
Implemented as proposed canon at
`canon/standards/emission-cadence-security-profile_v0.1.md`. The profile accepts
the GH-DEC-2026-004 split, requires source-owned classification, distinguishes
MUST from SHOULD coverage, and records that omission detection is after the
fact rather than proof of completeness.
## Implement mechanical profile validation
```task
id: NK-WP-0035-T02
status: done
priority: high
```
Validate a declaration against an explicitly supplied InfoTechCanon JSON
Schema before applying the NetKingdom overlay. The checker must not ship a
fallback generic schema, infer evidence class or rarity from event contents, or
treat a SHOULD finding as a MUST failure by default.
Implemented at
`tools/emission-cadence-profile/emission_cadence_profile.py`. It requires
`--contract-schema`, performs generic validation first, then checks the
NetKingdom overlay against caller-supplied source inventory assertions. No
generic fallback schema or owner declaration instance was added here.
## Verify the boundary and failure cases
```task
id: NK-WP-0035-T03
status: done
priority: medium
```
Cover contract-first validation, missing and mismatched class declarations,
the allowed high-volume load-bearing rate form, the forbidden rare-event rate
form, both positive controls for rare load-bearing classes, duplicate classes,
and advisory attributive coverage.
Verification on 2026-09-04: eight focused tests pass; the 81-test root
`tests/` + `tools/` regression suite passes; Ruff lint and format checks pass;
Python compilation and `git diff --check` pass.
## Bind and hand off the published contract
```task
id: NK-WP-0035-T04
status: wait
priority: high
```
When `info-tech-canon` publishes its versioned contract and schema, replace the
pending import locator with its canonical coordinates and digest, validate the
owner-source instances, and notify `kings-guard` to replace its draft-shaped
fixture. This task cannot be completed from NetKingdom without the upstream
artifact and must not be worked around by copying the draft.
2026-09-05 review: the upstream publication blocker is resolved by
InfoTechCanon 0.7.0 / contract 0.1.0. Bound the profile to the schema coordinates,
revision and SHA-256; fixed the checker to read `extensions.netkingdom`, removed
draft reconciliation aliases, and enforced unique source IDs. Fifteen focused
tests pass, including direct integration with the published owner schema and
CLI exit-policy coverage.
The current owner instances (`approval-engine/cadence.yaml` and
`qonto-assistant/specs/audit-emission-cadence.yaml`) were reviewed and checked;
both still fail generic contract validation because they use draft envelopes.
No source instance was rewritten by NetKingdom. T04 remains `wait` for each
owner's migration and subsequent profile validation, followed by the King's
Guard handoff. The profile remains proposed.
Validation: `python3 -m pytest tests tools -q` passed 106 tests, including 18
privacyIDEA and 15 cadence cases. Ruff lint/format, shell syntax, embedded Python
compilation and `git diff --check` passed.
State Hub reconciliation was attempted with both the installed CLI and current
checkout. Full reconciliation remains pending because API queries/writes timed
out or returned connection-refused errors. Generated index/intake metadata was
reviewed; the source files remain authoritative.