feat: finish ZONE-WP-0003 Engine/PIP freeze and claim mapping
Declare the layer in layer.yaml, check it against INTENT.md, and fail make check on a new Tooling client or HTTP decision surface. Record the six statute §10 artifacts for the 2026-08-23 cut, name access-engine on the README, and offer a non-schema PIP field mapping to Taxonomy. Assistant: grok Assistant-Session: 01a04ceb-0745-7ae1-9e26-0d10e5d52b8b
This commit is contained in:
parent
e9d0fecede
commit
acfd93fc86
11 changed files with 682 additions and 35 deletions
22
SCOPE.md
22
SCOPE.md
|
|
@ -28,10 +28,11 @@ Declared in `INTENT.md` frontmatter, in this repository's own voice:
|
|||
| Tooling contacts | none |
|
||||
| Conformance | conforming for Tooling contact; the live Engine API is not a missing capability this repository currently owes |
|
||||
|
||||
The machine-readable `layer.yaml` form and a conformance check that fails a
|
||||
new Tooling client or a new decision surface are not yet evidenced here.
|
||||
Until they are, the declaration is the `INTENT.md` frontmatter and the prose
|
||||
in that file.
|
||||
The machine-readable declaration is `layer.yaml`. `tools/check_layer_conformance.py`
|
||||
fails if that file disagrees with `INTENT.md` frontmatter, if a Tooling-layer
|
||||
client appears under `tools/`, or if an HTTP authorization decision surface
|
||||
appears. The six statute §10 artifacts for the already-completed layer cut
|
||||
are `history/2026-08-29-layer-change-artifacts.md`.
|
||||
|
||||
`access-engine` (currently `flex-auth`) is the only PDP. Zone stance and
|
||||
failure mode remain owner policy and PEP configuration. This repository
|
||||
|
|
@ -82,8 +83,8 @@ This repository provides:
|
|||
- an offline exception checker with an explicit evaluation instant, covering
|
||||
grant authority, maximum duration, exclusive expiry, overlap, renewal,
|
||||
wildcard rejection, and durable-authority bounds; and
|
||||
- reusable manifests, profiles, exception fixtures, evidence, and 29 unit
|
||||
tests.
|
||||
- reusable manifests, profiles, exception fixtures, evidence, and unit
|
||||
tests covering resolver, exceptions, lineage, and layer conformance.
|
||||
|
||||
The resolver consumes already-located declarations and already-resolved
|
||||
workload-reference projections. It does not discover a fleet, repair an
|
||||
|
|
@ -91,9 +92,10 @@ ambiguous join, read a live clock, or publish a consumer registry. Its profile
|
|||
fixture records owner-approved v0.1 behavior; only the referenced owner policy
|
||||
and PEP configuration can change a live effect.
|
||||
|
||||
The resolver output is a reference membership/admission record. It is not yet
|
||||
a statute §17 request-claim. Taxonomy owns that schema and has not published
|
||||
it. This repository must not ship a competing dialect.
|
||||
The resolver output is a reference membership/admission record. It is not a
|
||||
statute §17 request-claim. Taxonomy owns that schema and has not published
|
||||
it. The field mapping offered to Taxonomy is `docs/pip-claim-boundary.md`.
|
||||
This repository must not ship a competing dialect.
|
||||
|
||||
## Authority boundary
|
||||
|
||||
|
|
@ -140,6 +142,8 @@ decision point.
|
|||
|
||||
- Reproducing or extending v0.1 conformance fixtures.
|
||||
- Checking direct declarations or explicit Repo Manager projections offline.
|
||||
- Mapping those membership facts onto a future request-claim
|
||||
(`docs/pip-claim-boundary.md`) without shipping a schema.
|
||||
- Verifying a versioned owner profile is total and fully attributed.
|
||||
- Testing an owner exception implementation against the lifecycle boundaries.
|
||||
- Reviewing a net-kingdom canon lifecycle/content change, including the
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue