Finish companion catalog work and reconcile completed approval tasks
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 4s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 16:15:01 +02:00
parent 41e4c4a3d8
commit e33f9c3ca5
18 changed files with 472 additions and 87 deletions

View file

@ -13,9 +13,9 @@ its own right, reported rather than resolved away by precedence.
Layer values are compared against §3's closed four-token vocabulary after an
ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled:
`Engine` and `engine` are one token. Neither form carries a standard version
(GH-DEC-2026-017 §5, amendment A12 r2 / GH-DEC-2026-020), and its return is
rejected. The rule reaches content, not a key name: every key and value of the
INTENT.md frontmatter and of layer.yaml is walked, so a versioned `standard:` or
(GH-DEC-2026-017 §5, amendment A12 r3 / GH-DEC-2026-021), and its return is
rejected. The estate reference detector walks every key and value of the
INTENT.md frontmatter and of layer.yaml, so a versioned `standard:` or
`companion:` path and a `companion_version` are caught as well as a
`standard_version`. Comments and `schema_version` are not reached. Stance maps
and evidence classifications (pep-stance.yaml, evidence-classification.yaml)
@ -60,29 +60,51 @@ DECISION_SURFACE = re.compile(
LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
EXPECTED_LAYER = "engine"
# The standard text this checker was built and validated against, printed on
# every run (GH-DEC-2026-020 §4, A12 r2). v0.7 is the accepted text in force;
# the v0.8 §11 amendments it already applies are named alongside. Bump this
# when the checker is re-validated against a newer accepted text.
VALIDATED_AGAINST = "net-kingdom/canon/standards/security-layer-model_v0.7.md"
AMENDMENTS_APPLIED = "v0.8 A9, A11, A12 r2 (GH-DEC-2026-017, GH-DEC-2026-020)"
# The accepted text and rulings enforced by this run (GH-DEC-2026-021 §2).
# Update together with the reference detector when the accepted text changes.
VALIDATED_AGAINST = (
"net-kingdom/canon/standards/security-layer-model_v0.7.md (net-kingdom@66dc491) "
"as amended by GH-DEC-2026-017, GH-DEC-2026-020 and GH-DEC-2026-021 "
"(A9-A13, A12 r3; gate-house@39d9287)"
)
SCOPE = (
"declaration = INTENT.md frontmatter + layer.yaml (every key and value); "
"source = src/secrets_engine/**/*.py; "
"not reached by A12: pep-stance.yaml, evidence-classification.yaml"
)
# A12 r2: a version of the standard or its companion, anywhere in the
# declaration. `schema_version` is the declaration file's own schema and is
# not reached.
VERSION_KEY = re.compile(r"version", re.IGNORECASE)
UNREACHED_KEYS = {"schema_version"}
VERSIONED_REF = re.compile(
r"(?i)(security-layer-model|security-companion|layer-model|companion)"
r"[^\s]*?(?:[_@-]v?\d+(?:\.\d+)*|\bv\d+(?:\.\d+)*)"
)
STANDARD_KEYS = {"standard", "companion", "framework"}
BARE_VERSION = re.compile(r"(?i)(?:^|[_@\s-])v?\d+\.\d+(?:\.\d+)*\b")
# Estate reference detector, GH-DEC-2026-021 §3.
VERSION_KEY = re.compile(r"(standard|companion).*version|version.*(standard|companion)", re.I)
VERSION_IN_VALUE = re.compile(r"[_\-.]v\d+(\.\d+)*(\.md)?\b|@v?\d+\.\d+", re.I)
NOT_REACHED_KEYS = {"schema_version"}
IDENTITY_KEYS = {"standard", "companion"}
IDENTITY_VERSION = re.compile(r"\bv?\d+\.\d+", re.I)
def find_version_pins(node, where: str = "", identity: bool = False) -> list[str]:
"""Every place in a parsed declaration that carries a standard/companion version.
Walks every key and value (comments are gone after parsing, which is the
A12 r2 exclusion). Returns human-readable locations; empty means clean.
"""
pins: list[str] = []
if isinstance(node, dict):
for k, v in node.items():
here = f"{where}.{k}" if where else str(k)
if str(k) in NOT_REACHED_KEYS:
continue
if VERSION_KEY.search(str(k)):
pins.append(f"{here} (key names a standard/companion version)")
continue
pins.extend(find_version_pins(v, here, str(k).lower() in IDENTITY_KEYS))
elif isinstance(node, list):
for i, v in enumerate(node):
pins.extend(find_version_pins(v, f"{where}[{i}]", identity))
elif isinstance(node, str) and VERSION_IN_VALUE.search(node):
pins.append(f"{where} = {node!r} (value carries a version)")
elif isinstance(node, str) and identity and IDENTITY_VERSION.search(node):
pins.append(f"{where} = {node!r} (identity-bearing value carries a version)")
return pins
def _fold(value: object) -> str:
@ -90,37 +112,13 @@ def _fold(value: object) -> str:
return str(value).strip().encode("ascii", "ignore").decode().lower()
def _version_hits(data: object, path: str = "") -> list[str]:
"""Every place a standard or companion version appears in a declaration."""
hits: list[str] = []
if isinstance(data, dict):
for key, value in data.items():
here = f"{path}.{key}" if path else str(key)
if str(key) in UNREACHED_KEYS:
continue
if VERSION_KEY.search(str(key)):
hits.append(f"key {here!r}")
continue
if isinstance(value, str) and str(key).lower() in STANDARD_KEYS:
if BARE_VERSION.search(value):
hits.append(f"{here}: {value!r}")
continue
hits.extend(_version_hits(value, here))
elif isinstance(data, list):
for n, item in enumerate(data):
hits.extend(_version_hits(item, f"{path}[{n}]"))
elif isinstance(data, str) and VERSIONED_REF.search(data):
hits.append(f"{path}: {data!r}")
return hits
def _no_standard_version(where: str, data: dict) -> None:
hits = _version_hits(data)
hits = find_version_pins(data)
if hits:
print(
f"MALFORMED: {where} carries a standard or companion version at "
f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any "
"key or value (§11 as amended by A12 r2, GH-DEC-2026-020 §1-§2)"
"key or value (§11 as amended by A12 r3, GH-DEC-2026-021 §1-§3)"
)
raise SystemExit(2)
@ -231,7 +229,7 @@ def main() -> int:
ap = argparse.ArgumentParser()
ap.add_argument("--report", action="store_true")
args = ap.parse_args()
print(f"validated against: {VALIDATED_AGAINST} [{AMENDMENTS_APPLIED}]")
print(f"validated against: {VALIDATED_AGAINST}")
print(f"scope: {SCOPE}")
front = intent_frontmatter()