docs: mark the unknown cell, measure the coverage we asked to publish
gate-house ruled the v0.8 assent round (GH-DEC-2026-011, net-kingdom@64394e9): ask 1 declined, ask 2 adopted. Ask 1's refusal is accepted without reservation and the reason is better than the ask -- a sanctioned transitional fail_open is indistinguishable at runtime from the stance the rule forbids, and would make the rule optional at the only moment it costs anything. Ask 2 gave §13.1 a Coverage column with this repo's figures as its first entries. Since we asked for the column, we owe it accuracy: scripts/report_coverage.py measures both populations from the artifacts the runtime uses (reusing the workload-join build rather than re-deriving it), and a test asserts pep-stance.yaml's published block equals what it measures. A hand-counted number in a register that explicitly does not recompute it decays silently, and a stale figure beside a marked cell is worse than the blank the other four rows carry. pep-stance.yaml marks the unknown cell inline as a declared gap -- assent, the measured reason for not flipping, the declined ask, WARDEN-WP-0040 as route -- and a second test keeps it marked while it is fail_open, failing when it is flipped. standard_version stays 0.7 because that is what binds; v0.8 is proposed, so it gains standard_version_reviewed rather than pre-adopting. Separately, gate-house corrected GH-DEC-2026-008: the claim/decision digest comparison it originally required is unimplementable and a fail-closed consumer obeying it would have denied permanently. We had never copied the wording, so nothing to unwind -- but everything they have sent about this lane was living in an inbox thread, a bad home for a correction that only matters when someone finally wires the consume. Now wiki/ApprovalConsumption.md, leading with "nothing is wired", carrying the corrected target and the attribution gap that digest matching does not discharge. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C Assistant: claude-code Assistant-Model: opus Assistant-Process: 1276224@bnt-lap001 Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
This commit is contained in:
parent
a942ce805d
commit
5b1a508610
8 changed files with 388 additions and 2 deletions
|
|
@ -18,7 +18,13 @@
|
|||
|
||||
schema_version: "0.1"
|
||||
framework: netkingdom-security-layer-model
|
||||
# v0.7 is the accepted standard and the one in force. v0.8 is `proposed`: its
|
||||
# assent round closed 2026-09-09 (GH-DEC-2026-011) with nine corrections applied,
|
||||
# but the version is not yet accepted, so this declaration stays pinned to what
|
||||
# binds. The one cell v0.8 would change is marked inline below rather than
|
||||
# silently pre-adopted.
|
||||
standard_version: "0.7"
|
||||
standard_version_reviewed: "0.8" # reviewed and assented; see history/2026-09-09-layer-model-v08-review.md
|
||||
repository: ops-warden
|
||||
pep_shape: true
|
||||
declared_by: docs/adr/ADR-0009
|
||||
|
|
@ -36,7 +42,26 @@ stance:
|
|||
z2-protected: fail_open
|
||||
z2-continuity: fail_open
|
||||
z3-critical: fail_closed
|
||||
unknown: fail_open # versioned build profile (ADR-0009); explicit, never inferred
|
||||
# DECLARED GAP under security-layer-model v0.8 §6.4 obligation 3 (GH-DEC-2026-011,
|
||||
# net-kingdom@64394e9): unknown is not a zone and MUST resolve to fail_closed.
|
||||
# ops-warden ASSENTED to that rule — we went looking for the §5.1 read-only
|
||||
# diagnostic its reversal clause predicts and do not have one, because this map
|
||||
# governs `warden sign`, a credential-issuing side effect.
|
||||
#
|
||||
# The cell has not been flipped, and the reason is measured rather than argued:
|
||||
# 0 of 3 signing targets resolve to a zone, so converting today would fail closed
|
||||
# on essentially every certificate whenever the engine is unreachable — including
|
||||
# the certificate an operator needs to reach the host and repair it. That is
|
||||
# ADR-0006's rejected configuration reached from another direction.
|
||||
#
|
||||
# We asked for a coverage-gated transitional fail_open and were DECLINED: a
|
||||
# sanctioned transitional fail_open is indistinguishable at runtime from the
|
||||
# stance the rule forbids. Our second preference was adopted instead — §13.1 now
|
||||
# carries a Coverage column, and this repo's figures are its first entries.
|
||||
#
|
||||
# So this is tracked non-conformance with a route, not an exemption.
|
||||
# Route: WARDEN-WP-0040. Register row: §13.1, marked.
|
||||
unknown: fail_open # non-conformant at v0.8; see above
|
||||
not-applicable: fail_closed
|
||||
|
||||
# What happens when the stance is applied. §6.4 obligation 1 requires a decision
|
||||
|
|
@ -57,6 +82,23 @@ on_apply:
|
|||
# §6.4 obligation 2 — the verdict is never cached. Input claims (zone membership,
|
||||
# compiled from the flex-auth registry snapshot) are cached under their own
|
||||
# freshness rules; the answer is not.
|
||||
# Classification coverage, published beside the stance because v0.8 §6.4
|
||||
# obligation 3 now requires it and because ops-warden asked for the column.
|
||||
# Coverage is DISCLOSURE, never a transitional licence: it does not soften this
|
||||
# map's stance, does not gate it, and never makes the marked cell conformant.
|
||||
# Self-measured; regenerate with `python scripts/report_coverage.py`.
|
||||
classification_coverage:
|
||||
measured: "2026-09-09"
|
||||
attribution: self-measured
|
||||
signing_targets:
|
||||
resolved: 0
|
||||
unknown: 3
|
||||
not_applicable: 1
|
||||
routing_lanes:
|
||||
resolved: 3
|
||||
unknown: 18
|
||||
not_applicable: 12
|
||||
|
||||
verdict_caching: none
|
||||
input_claim_caching: "registry/flex-auth/production_registry_snapshot.json, rebuilt by scripts/build_flex_auth_registry.py"
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue