Skip to content

RUN-319 — Participant Information-Flow Policy Enforcement #799

Description

@Brad-Edwards

Requirements

  • RUN-319

Bounded outcome

Enforce and persist governed participant ingress/egress decisions through the reference runtime using existing admission, projection, lifecycle, store, audit, idempotency, error, and security boundaries.

Non-goals

  • Selecting a participant gateway or transport.
  • A parallel policy engine, persistence store, audit channel, or exception hierarchy.
  • Claiming backend realization or universal information-flow assurance from reference-runtime tests.

Dependencies

Acceptance criteria

  • Fail closed on missing policy, authority, projection, marking, declassification basis, or required capability.
  • Revalidate transformed proposals as new attempts; project/mask/redact output before serialization; preserve source/result identity and markings.
  • Apply authenticated caller, participant subject/authority, admission, and visibility as separate gates.
  • Append-only decision and realization histories survive persistence/restart/replay and retain ordering, policy revision, evidence, provenance, loss, and audit links.
  • Unsupported or downgraded backend behavior is explicit and cannot retain a stronger claim.
  • Update the participant section of docs/explain/sdl/lineage.md with this issue's adopted intellectual lineage, exact ACES artifact mappings, delivery status, evidence links, and explicit nonclaims; update contracts/provenance/sdl-lineage-ledger-v1.json and its source audit only when normative derivation or compatibility claims change.

Required assurance evidence

  • Boundary behavioral, property, persistence/replay, and concurrency tests.
  • Negative cross-participant leakage, stale-policy, authority, transformation, redacted-error, and audit-integrity tests.
  • Bounded reference-runtime claim bindings with explicit backend nonclaims.

Parent program: #794.

Metadata

Metadata

Assignees

No one assigned

    Labels

    requirementTracks a Ground Control requirement

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions