docs: finish zone reference hardening workplan
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
parent
4f676e2439
commit
6f667d20c2
10 changed files with 308 additions and 129 deletions
87
docs/evidence/reference-contract-hardening-2026-08-23.md
Normal file
87
docs/evidence/reference-contract-hardening-2026-08-23.md
Normal file
|
|
@ -0,0 +1,87 @@
|
|||
# Reference-contract hardening evidence — 2026-08-23
|
||||
|
||||
`ZONE-WP-0002` closes the executable gaps without creating a zone-engine
|
||||
runtime.
|
||||
|
||||
## Revisions reviewed
|
||||
|
||||
| Repository | Revision | Role |
|
||||
| --- | --- | --- |
|
||||
| zone-engine | `be29c28` | Reference resolver, profile/exception fixtures, lineage checker, and tests |
|
||||
| net-kingdom | `3491c29` checkout; canonical artifact last changed at `104d5c6` | Canon publication and lifecycle |
|
||||
| repo-manager | `7b9fdaa` | RMGR-ADR-004 v1 workload-reference authority |
|
||||
| flex-auth | `00a7bc4`; profile owner baseline `e521e7b` | Adopted declaration and pre-sign stance |
|
||||
| ops-warden | `c8fa02a`; profile/PEP baseline `7ce58ae` | Adopted declaration, failure modes, and consumer registry |
|
||||
|
||||
No owner repository was changed by this workplan.
|
||||
|
||||
## Canon lineage
|
||||
|
||||
`make canon-lineage CANON_ROOT=/home/worsch/net-kingdom` passed. Both the
|
||||
reviewed `104d5c6` artifact and current checkout hash to
|
||||
`32e71e9c0d6946bb14099eb66193822da26f199de0e11d8488464207f3bd9906`
|
||||
and report lifecycle `proposed`. A mutation fixture proves content drift fails;
|
||||
a separate fixture proves lifecycle drift fails.
|
||||
|
||||
The local standard text is no longer a second normative copy. It is a pointer
|
||||
to canon with a machine-readable lineage record.
|
||||
|
||||
## Resolved-view replay
|
||||
|
||||
`fixtures/manifests/adoption.yaml` resolved the two live declarations and one
|
||||
native catalog subject:
|
||||
|
||||
| Subject | Result | Effective zone | Membership revision |
|
||||
| --- | --- | --- | --- |
|
||||
| flex-auth | `satisfied` | `z1-operational` | `sha256:841d3a251ca9f9fb5eb263b4fd90b557cb06de031ec3be06034c5e011039c16c` |
|
||||
| ops-warden | `satisfied` | `z1-operational` | `sha256:0407d7a90e7f259163a0e1ec0907551a06ad7023a100261b911dcde62899bd5b` |
|
||||
| human-operator | `not-applicable` | none | none |
|
||||
|
||||
The reference manifest also proves the managed Repo Manager tuple
|
||||
`(rapp-fixture, fixture-workload, fixture-workload)`. Direct and managed
|
||||
bindings, source revisions, guarantees, `unknown`, `unsatisfied`, and
|
||||
`not-applicable` are explicit. Paths, repository ownership, reefs, actors, and
|
||||
lane names cannot manufacture membership.
|
||||
|
||||
Snapshot tests prove deterministic additions, removals, changes, source
|
||||
revision sensitivity, and order insensitivity. A missing source revision emits
|
||||
no digest and no source-bound guarantee.
|
||||
|
||||
## Profile authority
|
||||
|
||||
Core membership resolution emits no controls. Projection requires
|
||||
`profiles/netkingdom-build-v0.1.yaml`, whose version pins the previously
|
||||
accepted owner revisions. Every row includes policy owner, PEP owner, and
|
||||
policy reference, and the profile is total over all five zones plus `unknown`.
|
||||
|
||||
Fixtures reject missing coverage, ownerless/unqualified controls, invalid
|
||||
stance/failure combinations, and unversioned profiles. Profile failure leaves
|
||||
the independently resolved membership record intact and marks the overall
|
||||
projection unsuccessful.
|
||||
|
||||
## Exception lifecycle
|
||||
|
||||
The offline checker evaluates only a supplied document, owner policy, and
|
||||
explicit instant. It validates designated grant authority, exact workload and
|
||||
zone scope, maximum duration, exclusive `not_after`, strict relaxation,
|
||||
renewal ids, overlap, wildcard/unknown rejection, and durable-authority expiry.
|
||||
Invalid or unevaluable records are inactive. It stores nothing, grants nothing,
|
||||
reads no live clock, and is absent from every decision path.
|
||||
|
||||
## Verification
|
||||
|
||||
- zone-engine: `make check` — 29 tests passed; reference and exception fixture
|
||||
commands passed, including expected rejection of the overlap fixture.
|
||||
- canon lineage: passed at net-kingdom `104d5c6` and current checkout.
|
||||
- flex-auth: `go test ./...` passed.
|
||||
- ops-warden: 390 tests passed, 4 integration tests deselected; Ruff passed.
|
||||
- net-kingdom tenancy validator: flex-auth and ops-warden declarations valid.
|
||||
- repository whitespace checks passed.
|
||||
|
||||
## Outcome
|
||||
|
||||
The repository is safe to retain as a bounded reference and safe to archive
|
||||
after handoff. The selected non-destructive disposition is retain while canon
|
||||
v0.1 remains proposed, with only owner-driven conformance and lineage changes
|
||||
permitted. No runtime, live policy authority, or estate-migration backlog was
|
||||
created.
|
||||
Loading…
Add table
Add a link
Reference in a new issue