Review layer model v0.6; publish the PEP stance map §6.4 requires
All three v0.4 findings were acted on — §9.1 split into pending/declared-gap and §5's scope rule adopted as recommended and credited, and §9.6 ruled via the load-bearing/attributive distinction with ops-warden's `# audit must not block signing` named as the estate's live example. Checked the favourable ruling rather than accepting it. §9.6's test is "no control branches on its presence": the only consumer of audit.jsonl is `warden activity`, which displays. Nothing gates on a signing record, so the lane is genuinely attributive. AuditTrail.md now records the ruling instead of the open question, and states that the trade must be revisited if a control ever gates on the trail. CONFORMANCE ACTION. §6.4 obligation 3 requires a stance map "published rather than held in code", and requires every PEP-shaped consumer to publish one so the maps can be inventoried — naming ADR-0009 as the reference shape. ops-warden was not doing it: the map lived in PolicyConfig.failure_modes, a dataclass default. Not a code comment, but not published either. pep-stance.yaml publishes it, and the test asserts the published map EQUALS the shipped default. A published map that may drift from the code is worse than no map, because it invites reliance it cannot support. Two findings sent to gate-house, in history/2026-08-29-layer-model-v06-review.md: §6.4 obligation 1 (no side effect without a decision record) contradicts obligation 3 and §9.3, with ops-warden's blessed fail-open stance as the instance; and §6.4 mandates a stance-map inventory in §13 that §13 does not implement — where ops-warden is currently the only PEP to have published one. 402 tests pass, ruff clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YWBMovyFoy9RRrfL7zKvPJ Assistant: claude-code Assistant-Model: opus Assistant-Process: 4014535@bnt-lap001 Assistant-Session: d0036016-73e8-4da1-8e47-563e3ab39a3c
This commit is contained in:
parent
ec625873fb
commit
94f32bd160
5 changed files with 272 additions and 2 deletions
|
|
@ -38,8 +38,13 @@ never blocks the primary action — but tests prove values cannot be written.
|
|||
> not altered or truncated; it does **not** prove that every action produced one.
|
||||
> Do not reason from a missing entry. This is the estate-wide bound in
|
||||
> `security-layer-model_v0.4` §9.6 — completeness is the source's obligation, and
|
||||
> whether ops-warden must make signing emission atomic is an open question with
|
||||
> gate-house (`history/2026-08-29-layer-model-v04-review.md`, Finding 3).
|
||||
> **Ruled 2026-08-29** (`security-layer-model_v0.6` §9.6): this trail is
|
||||
> **attributive**, not load-bearing — no control branches on the presence of a
|
||||
> signing record — so the non-atomic trade is legitimate, and the obligations are
|
||||
> to declare it (this note) and never to claim completeness. Atomicity is required
|
||||
> only where a control's soundness depends on an event being present or absent.
|
||||
> Registered in the standard's §13 open-gap table as self-declared. If a future
|
||||
> control ever gates on this trail, the trade must be revisited before it ships.
|
||||
|
||||
---
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue