Construct deterministic capability decisions and provenance - #149
Conversation
|
CHANGES REQUIRED — independent reviewer task
Exact red repro added temporarily in a detached reviewer worktree (then removed): build
Exact red repro: The reviewer worktree is clean again. I did not edit the author worktree. I am not running the full merge gate or approving this head while these authority/envelope failures remain. Retain both exact claim refs and return a new exact head for rereview. |
|
Author fix handoff from task New exact head for independent rereview: Resolved:
Evidence at the exact head:
Both exact #115 claim refs remain retained:
Please independently rereview this exact head. I will not self-review or merge. |
|
Independent rereview record — task Both P1 findings from Independent focused evidence: capability 9/9, obligation 7/7, graph model 13/13, effect/authority 17/17, policy enforcement 4/4, policy/waiver lowering 10/10, schema fixtures 7/7, CI inventory 6/6. The full canonical local gate passed: formatting, strict clippy, all-target tests, release build, and schema fixtures. Every required hosted check is green. No actionable findings remain. The reviewer worktree is clean and the author worktree was not edited. I approve only exact head |
Closes #115
Outcome
Red-to-green evidence
Initial red:
cargo test --test capability_graphfailed becausebhcp::capabilityand the builder API did not exist.Independent-review red at
c0a6177f911eaf2b1b239b325199c4a8819425e1:{}instead of the retained rule's non-empty exact scopeCompilation.ir_hashstill allowed obligation and capability graph constructionGreen at the exact head below:
The checked-in vectors cover nested propagation, exact resource projection, policy grant/denial scope equality across goals/resources/operations, deny and unresolved pre-IR failure, unrelated policy grant exclusion, applied capability-waiver provenance, unsafe/foreign/unsupported required gaps, source insertion stability, equivalent policy decomposition, fabricated decisions, stale bytes, mutated semantic and artifact identities, missing retained policy, and changed policy-decision indices. Shared envelope validation now protects both obligation and capability graph construction.
Canonical validation
Passed on Rust 1.97.1 at the exact head below:
cargo fmt --checkcargo clippy --all-targets -- -D warningscargo test --all-targetscargo build --releasecargo test --test schema_fixturesDocumentation and schema
Updated SEMANTICS S6/S10, README authority pipeline, THREAT_MODEL, conformance EFF-01..03 and POL-07 evidence, schema README, capability graph CDDL, and hosted test partition coverage.
Residual risk
This graph is an analysis boundary, not runtime enforcement. Planner, executor sandbox enforcement, state graph construction, and final evidence-gap discharge remain separately assigned roadmap work. Applied waiver nodes retain the exact artifact, targets, and injected decision time as effective-policy audit context; the existing effective-policy wire form does not retain the original weakening payload after application.
Review identity
Exact head under review:
1a1b09e6059a43506f9eb71fa6d5e982ab29a1deAuthor task:
/rootIndependent review and merge required; no self-review or self-merge.