docs: mark the unknown cell, measure the coverage we asked to publish
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

gate-house ruled the v0.8 assent round (GH-DEC-2026-011, net-kingdom@64394e9):
ask 1 declined, ask 2 adopted.

Ask 1's refusal is accepted without reservation and the reason is better than
the ask -- a sanctioned transitional fail_open is indistinguishable at runtime
from the stance the rule forbids, and would make the rule optional at the only
moment it costs anything.

Ask 2 gave §13.1 a Coverage column with this repo's figures as its first
entries. Since we asked for the column, we owe it accuracy:
scripts/report_coverage.py measures both populations from the artifacts the
runtime uses (reusing the workload-join build rather than re-deriving it), and
a test asserts pep-stance.yaml's published block equals what it measures.
A hand-counted number in a register that explicitly does not recompute it
decays silently, and a stale figure beside a marked cell is worse than the
blank the other four rows carry.

pep-stance.yaml marks the unknown cell inline as a declared gap -- assent, the
measured reason for not flipping, the declined ask, WARDEN-WP-0040 as route --
and a second test keeps it marked while it is fail_open, failing when it is
flipped. standard_version stays 0.7 because that is what binds; v0.8 is
proposed, so it gains standard_version_reviewed rather than pre-adopting.

Separately, gate-house corrected GH-DEC-2026-008: the claim/decision digest
comparison it originally required is unimplementable and a fail-closed
consumer obeying it would have denied permanently. We had never copied the
wording, so nothing to unwind -- but everything they have sent about this lane
was living in an inbox thread, a bad home for a correction that only matters
when someone finally wires the consume. Now wiki/ApprovalConsumption.md,
leading with "nothing is wired", carrying the corrected target and the
attribution gap that digest matching does not discharge.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
This commit is contained in:
tegwick 2026-09-10 08:02:10 +02:00
parent a942ce805d
commit 5b1a508610
8 changed files with 388 additions and 2 deletions

View file

@ -18,7 +18,13 @@
schema_version: "0.1"
framework: netkingdom-security-layer-model
# v0.7 is the accepted standard and the one in force. v0.8 is `proposed`: its
# assent round closed 2026-09-09 (GH-DEC-2026-011) with nine corrections applied,
# but the version is not yet accepted, so this declaration stays pinned to what
# binds. The one cell v0.8 would change is marked inline below rather than
# silently pre-adopted.
standard_version: "0.7"
standard_version_reviewed: "0.8" # reviewed and assented; see history/2026-09-09-layer-model-v08-review.md
repository: ops-warden
pep_shape: true
declared_by: docs/adr/ADR-0009
@ -36,7 +42,26 @@ stance:
z2-protected: fail_open
z2-continuity: fail_open
z3-critical: fail_closed
unknown: fail_open # versioned build profile (ADR-0009); explicit, never inferred
# DECLARED GAP under security-layer-model v0.8 §6.4 obligation 3 (GH-DEC-2026-011,
# net-kingdom@64394e9): unknown is not a zone and MUST resolve to fail_closed.
# ops-warden ASSENTED to that rule — we went looking for the §5.1 read-only
# diagnostic its reversal clause predicts and do not have one, because this map
# governs `warden sign`, a credential-issuing side effect.
#
# The cell has not been flipped, and the reason is measured rather than argued:
# 0 of 3 signing targets resolve to a zone, so converting today would fail closed
# on essentially every certificate whenever the engine is unreachable — including
# the certificate an operator needs to reach the host and repair it. That is
# ADR-0006's rejected configuration reached from another direction.
#
# We asked for a coverage-gated transitional fail_open and were DECLINED: a
# sanctioned transitional fail_open is indistinguishable at runtime from the
# stance the rule forbids. Our second preference was adopted instead — §13.1 now
# carries a Coverage column, and this repo's figures are its first entries.
#
# So this is tracked non-conformance with a route, not an exemption.
# Route: WARDEN-WP-0040. Register row: §13.1, marked.
unknown: fail_open # non-conformant at v0.8; see above
not-applicable: fail_closed
# What happens when the stance is applied. §6.4 obligation 1 requires a decision
@ -57,6 +82,23 @@ on_apply:
# §6.4 obligation 2 — the verdict is never cached. Input claims (zone membership,
# compiled from the flex-auth registry snapshot) are cached under their own
# freshness rules; the answer is not.
# Classification coverage, published beside the stance because v0.8 §6.4
# obligation 3 now requires it and because ops-warden asked for the column.
# Coverage is DISCLOSURE, never a transitional licence: it does not soften this
# map's stance, does not gate it, and never makes the marked cell conformant.
# Self-measured; regenerate with `python scripts/report_coverage.py`.
classification_coverage:
measured: "2026-09-09"
attribution: self-measured
signing_targets:
resolved: 0
unknown: 3
not_applicable: 1
routing_lanes:
resolved: 3
unknown: 18
not_applicable: 12
verdict_caching: none
input_claim_caching: "registry/flex-auth/production_registry_snapshot.json, rebuilt by scripts/build_flex_auth_registry.py"