net-kingdom/workplans/NK-WP-0035-emission-cadence-security-profile.md
tegwick ec1a59f274
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
chore(consistency): register NK-WP-0035 workplan and task identifiers
Written back by statehub fix-consistency after NK-WP-0035-T05 was added.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ek3zTdfMa35bPVDjVUyhxx

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 868701@bnt-lap001
Assistant-Session: b2e101b6-f501-40dc-9ee5-438cac36e21a
2026-09-07 08:47:38 +02:00

154 lines
6.3 KiB
Markdown

---
id: NK-WP-0035
type: workplan
title: "Publish the NetKingdom emission-cadence security profile"
domain: infotech
repo: net-kingdom
status: blocked
owner: codex
topic_slug: netkingdom
planning_priority: P1
created: "2026-09-04"
updated: "2026-09-07"
related:
- GH-DEC-2026-004
- canon/standards/security-layer-model_v0.7.md
state_hub_workstream_id: "04685f94-1991-5e62-80d2-5669913e99fc"
---
# NK-WP-0035 — NetKingdom emission-cadence security profile
GH-DEC-2026-004 assigns the ecosystem-wide
`EmissionCadenceDeclaration` contract to `info-tech-canon` and the importing
NetKingdom security profile to this repository. This work accepts that split.
It must not copy the generic schema drafted by `kings-guard` or make the
observer the owner of source classifications.
## Define the importing security profile
```task
id: NK-WP-0035-T01
status: done
priority: high
state_hub_task_id: "dc39bd1f-420d-55e9-b4d1-990c39dc251b"
```
Publish the NetKingdom MUST/SHOULD obligations over the generic contract:
load-bearing classes declare cadence, attributive classes should, and rare
load-bearing classes use heartbeat plus reconciliation with rate monitoring
forbidden. Keep source classification owner-authored and preserve the residual
that cadence detects omission only after the fact.
Implemented as proposed canon at
`canon/standards/emission-cadence-security-profile_v0.1.md`. The profile accepts
the GH-DEC-2026-004 split, requires source-owned classification, distinguishes
MUST from SHOULD coverage, and records that omission detection is after the
fact rather than proof of completeness.
## Implement mechanical profile validation
```task
id: NK-WP-0035-T02
status: done
priority: high
state_hub_task_id: "0cdfbee7-f5cd-5a43-b27f-752cc72f56f6"
```
Validate a declaration against an explicitly supplied InfoTechCanon JSON
Schema before applying the NetKingdom overlay. The checker must not ship a
fallback generic schema, infer evidence class or rarity from event contents, or
treat a SHOULD finding as a MUST failure by default.
Implemented at
`tools/emission-cadence-profile/emission_cadence_profile.py`. It requires
`--contract-schema`, performs generic validation first, then checks the
NetKingdom overlay against caller-supplied source inventory assertions. No
generic fallback schema or owner declaration instance was added here.
## Verify the boundary and failure cases
```task
id: NK-WP-0035-T03
status: done
priority: medium
state_hub_task_id: "9cbfaed0-b827-58b3-a79d-2efebb69ed58"
```
Cover contract-first validation, missing and mismatched class declarations,
the allowed high-volume load-bearing rate form, the forbidden rare-event rate
form, both positive controls for rare load-bearing classes, duplicate classes,
and advisory attributive coverage.
Verification on 2026-09-04: eight focused tests pass; the 81-test root
`tests/` + `tools/` regression suite passes; Ruff lint and format checks pass;
Python compilation and `git diff --check` pass.
## Bind and hand off the published contract
```task
id: NK-WP-0035-T04
status: wait
priority: high
state_hub_task_id: "e3fbc8b8-00d5-57ce-ba0c-19b58044c950"
```
When `info-tech-canon` publishes its versioned contract and schema, replace the
pending import locator with its canonical coordinates and digest, validate the
owner-source instances, and notify `kings-guard` to replace its draft-shaped
fixture. This task cannot be completed from NetKingdom without the upstream
artifact and must not be worked around by copying the draft.
2026-09-05 review: the upstream publication blocker is resolved by
InfoTechCanon 0.7.0 / contract 0.1.0. Bound the profile to the schema coordinates,
revision and SHA-256; fixed the checker to read `extensions.netkingdom`, removed
draft reconciliation aliases, and enforced unique source IDs. Fifteen focused
tests pass, including direct integration with the published owner schema and
CLI exit-policy coverage.
The current owner instances (`approval-engine/cadence.yaml` and
`qonto-assistant/specs/audit-emission-cadence.yaml`) were reviewed and checked;
both still fail generic contract validation because they use draft envelopes.
No source instance was rewritten by NetKingdom. T04 remains `wait` for each
owner's migration and subsequent profile validation, followed by the King's
Guard handoff. The profile remains proposed.
Validation: `python3 -m pytest tests tools -q` passed 106 tests, including 18
privacyIDEA and 15 cadence cases. Ruff lint/format, shell syntax, embedded Python
compilation and `git diff --check` passed.
State Hub reconciliation was attempted with both the installed CLI and current
checkout. Full reconciliation remains pending because API queries/writes timed
out or returned connection-refused errors. Generated index/intake metadata was
reviewed; the source files remain authoritative.
## Review the layer model's use of the profile
```task
id: NK-WP-0035-T05
status: done
priority: high
state_hub_task_id: "8bcd9d33-0ffc-567e-96a3-b93dcd8059c7"
```
`gate-house` circulated `security-layer-model_v0.8.md` into this repository with
two questions for the profile's owner: whether §17's ownership paragraph says
what NetKingdom would say in its own voice, and whether §11's new
emission-guarantee conformance item follows the profile or diverges from it.
2026-09-07 review. §17 is confirmed as written: it assigns the generic contract
to `info-tech-canon` and to this repository the MUST/SHOULD split, the
rare-class rate-monitoring prohibition, and the heartbeat-plus-reconciliation
obligation — which is the profile's §3, including the conjunction.
§11 diverged in both directions and was corrected in place. As first cut it
required a detection surface of *"heartbeat or reconciliation"* of every
load-bearing source: that withholds from a volume load-bearing class the
`expected-rate` form the profile permits, and accepts for a rare class either
control alone where the profile and
`tools/emission-cadence-profile/emission_cadence_profile.py` require both. It
also contradicted §11's own following paragraph, which admits rate monitoring
except where the class is rare. The item now defers the form to the governing
profile, carries the volume/rare split explicitly, and states that
classification is the source's to publish and never the checker's to infer.
Change log item 6 and §14 record the review; the standard remains `proposed` and
publication waits on the close of the circulation round.