diff --git a/DECISIONS.md b/DECISIONS.md index aaaa689..307de16 100644 --- a/DECISIONS.md +++ b/DECISIONS.md @@ -142,7 +142,7 @@ Rows are ordered by **acceptance date**, not by D-number. A few early rows (D-03 | D-046 | ADR 0056 v3 accepted: promote `operation_class_unregistered` and `audit_chain_corruption_detected` into `decisionReasonKindSchema` in a follow-up schema PR. Both values are deny-only. `operation_class_unregistered` is non-clearable: `required_grant_kind` must be `null`, and any non-null grant kind rejects. `Decision.operation_shape_ref` remains required; missing, null, or invalid refs reject for this reason kind. `Decision.schema_version` remains `0.1.0` because this is additive enum widening, not a breaking shape change. | Closes the Phase 2.5 reason-kind drift without a system-config transitional allowlist as the durable posture. Keeps ADR acceptance separate from implementation: the schema PR must update Zod source, generated JSON Schema, tests, ontology docs, and registry status tables together. Hook-local policy-copy cleanup, split policy-lint placement, live `tiers.yaml` activation, snapshot vendoring, and scoped Ring 1 mint/audit work remain separate follow-on slices. | ADR 0056 | 2026-05-12 | | D-047 | Hook-local forbidden-pattern arrays are removed from `.claude/hooks/hcs-hook` and `.codex/hooks/hcs-hook`. Project hook bodies are thin wrappers only: delegate to `scripts/dev/hcs-hook-cli.sh` in the current Phase 0b measurement posture, and later delegate to Ring 1 RPC or an authorized generated/hash-bound runtime policy/cache sourced from system-config live policy. The interim classifier is non-authoritative, data-driven measurement code and must not be copied into hook bodies or treated as HCS policy. | Implements the approved hook cleanup slice without folding it into ADR 0056. Preserves ADR 0007's thin-hook/RPC shape and D-007's Codex-advisory boundary while removing duplicated policy from hook bodies. Claude permission-layer deny entries remain tool-native guardrails, not canonical HCS live policy. | ADR 0007 / hook cleanup | 2026-05-12 | | D-048 | Policy lint is split by authority boundary. `system-config` owns lint for canonical live policies under `policies/host-capability-substrate/`: activation metadata, provenance, forbidden-no-approval posture, grant scope/reuse, provider evidence, sandbox lease-acquire posture, structured cross-record policy rules, and no secret material. HCS owns only generated-snapshot compatibility lint once a snapshot is vendored: source commit/path/hash binding, schema-ref compatibility against generated HCS schemas, `operation_class_defaults` coverage, reason-kind compatibility, and fixture/snapshot path validation. | Implements ADR 0006's policy-source boundary for the Phase 2.5 lint placement decision. It keeps live policy authority with system-config while allowing HCS CI to reject stale or schema-incompatible vendored snapshots. This does not activate live policy, vendor a snapshot, or make `policies/generated-snapshot/` an authoring surface. | ADR 0006 / policy-lint split | 2026-05-12 | -| D-049 | HCS agent-facing contract surfaces must restate workstation authority in HCS-local wording before the rule becomes default session context. The accepted local vocabulary for the 2026-05-17 restatement pass is: actor identity, managed resource, authorization binding, and runtime evaluation. HCS work roles are local workflow roles: design owner, implementer, reviewer, maintainer, and evidence gatherer. HCS Cloudflare identity references use `jeffreyverlynjohnson@gmail.com` as the interim identity and `guardian@thenash.group` as the target after the Phase 2 Cloudflare account email migration. HCS Cloudflare MCP baseline is `cloudflare-api` at `https://mcp.cloudflare.com/mcp`, per-agent OAuth, no shared bearer, no bearer-in-argv wrapper, read-mostly grant. | Implements the operator-relayed 2026-05-17 workstation-contract restatement without changing ontology, policy, hooks, provider state, or sibling repos. Historical ADRs, decision rows, and research notes may preserve older external vocabulary as provenance, but current operating guidance must live in HCS-owned contract docs. The first local artifact is `docs/host-capability-substrate/workstation-surface-contract.md`; the inventory is `docs/host-capability-substrate/restatement-inventory-2026-05-17.md`; the relayable readout is `docs/host-capability-substrate/usable-state-readout-2026-05-17.md`; `just agent-contract-identity-scan` guards the default and near-default agent-facing surfaces during `just verify`. | docs-only restatement / ADR 0001 / ADR 0006 / ADR 0007 | 2026-05-17 | +| D-049 | HCS agent-facing contract surfaces must restate workstation authority in HCS-local wording before the rule becomes default session context. The accepted local vocabulary for the 2026-05-17 restatement pass is: actor identity, managed resource, authorization binding, and runtime evaluation. HCS work roles are local workflow roles: design owner, implementer, reviewer, maintainer, and evidence gatherer. HCS Cloudflare identity references use `REDACTED-operator-google-account` as the interim identity and `guardian@thenash.group` as the target after the Phase 2 Cloudflare account email migration. HCS Cloudflare MCP baseline is `cloudflare-api` at `https://mcp.cloudflare.com/mcp`, per-agent OAuth, no shared bearer, no bearer-in-argv wrapper, read-mostly grant. | Implements the operator-relayed 2026-05-17 workstation-contract restatement without changing ontology, policy, hooks, provider state, or sibling repos. Historical ADRs, decision rows, and research notes may preserve older external vocabulary as provenance, but current operating guidance must live in HCS-owned contract docs. The first local artifact is `docs/host-capability-substrate/workstation-surface-contract.md`; the inventory is `docs/host-capability-substrate/restatement-inventory-2026-05-17.md`; the relayable readout is `docs/host-capability-substrate/usable-state-readout-2026-05-17.md`; `just agent-contract-identity-scan` guards the default and near-default agent-facing surfaces during `just verify`. | docs-only restatement / ADR 0001 / ADR 0006 / ADR 0007 | 2026-05-17 | | D-050 | The HCS restatement guard applies to default and near-default agent-facing surfaces, not to every historical, research, runbook, ontology, ADR, or decision-ledger record. Those non-default records may preserve source labels, external infrastructure names, and technical terms such as parent process/context or upstream dependency ordering when they are provenance or implementation vocabulary rather than active HCS operating authority. Future promotion from those records into `AGENTS.md`, `README.md`, `CLAUDE.md`, `IMPLEMENT.md`, the workstation contract, the tooling matrix, setup docs, policy fixture docs, or project agent config must be restated in HCS-owned wording first. | Implements the 2026-05-18 second-pass scan recorded in `docs/host-capability-substrate/restatement-inventory-2026-05-17.md`. This prevents destructive bulk rewrites of evidence history while keeping the default session contract clean and guarded by `just agent-contract-identity-scan`. | docs-only restatement / D-049 | 2026-05-18 | | D-051 | HCS opens the generated-snapshot lane by vendoring the first live HCS policy snapshot from `system-config` commit `136dbaa` into `policies/generated-snapshot/tiers.yaml`. The HCS live-to-vendor binding is external to the vendored YAML and recorded in `policies/generated-snapshot/snapshot-binding.json` with source path `policies/host-capability-substrate/tiers.yaml` and source policy SHA-256 `sha256:e06442e02db50604e8ae8cbc1572a4ecec91ae87bfac6705e52161fd450ae68b`. `scripts/ci/snapshot-binding-check.sh` owns the HCS-side D-048 generated-snapshot checks: binding triple presence, vendored-file digest match, schema-ref compatibility with current Zod literals, `operation_class_defaults` coverage against `operationShapeOperationClassSchema`, reason-kind compatibility against `decisionReasonKindSchema`, and snapshot path validation. | Implements the HCS side of D-048's split after `system-config` activated the live Phase 2.5 tiers file. This does not edit `system-config`, change HCS schema source, activate Ring 1 service behavior, create an execution broker, add mutating endpoints, draft a Ring 1 ADR, or perform provider operations. | D-048 / generated-snapshot lane | 2026-05-18 | | D-052 | ADR 0057 accepts the first Ring 1 service boundary: a mint/audit-only service for authoritative record minting and audit-chain validation. The accepted scope covers the six audit-chain-committed entities Decision, ApprovalGrant, Lease, Run, Principal, and Session; AgentClient minting is blocked pending a future AgentClient canonical-hash amendment while `kernel_agent_client_resolver` remains a forward producer reservation. The producer allowlist has eight producer classes across entity-envelope and evidence-only scopes, with `kernel_dashboard` deferred. The service owns producer allowlist enforcement, KnowledgeChunk transitive authority-graph rejection, sandbox-source rejection, cycle-only use of `audit_chain_corruption_detected`, fail-closed depth overflow pending a distinct reason_kind, kernel-resolved audit attribution, service-wide fail-closed reason-kind discipline, ApprovalGrant grant-kind clearing rules, and a standalone FK-closure inventory. | Accepts ADR 0057 after three review cycles: round 1 produced seven blockers; round 2 produced one architect blocker plus one unresolved ontology finding; round 3 returned five of five `yes` verdicts with zero new findings. This does not authorize Ring 1 service implementation code, schema source edits, live policy or `tiers.yaml` changes, generated-snapshot changes, `system-config` edits, execution broker behavior, gateway behavior, capability registration, tool resolution, host-state service behavior, dashboard human-in-the-loop flows, agent-direct mutation endpoints, provider operations, or follow-up ADR drafting. | ADR 0057 / Ring 1 mint/audit service | 2026-05-18 | diff --git a/docs/host-capability-substrate/restatement-inventory-2026-05-17.md b/docs/host-capability-substrate/restatement-inventory-2026-05-17.md index 1207828..d3abfb9 100644 --- a/docs/host-capability-substrate/restatement-inventory-2026-05-17.md +++ b/docs/host-capability-substrate/restatement-inventory-2026-05-17.md @@ -67,7 +67,7 @@ The first pass now covers: - local HCS work roles: design owner, implementer, reviewer, maintainer, and evidence gatherer; - Cloudflare operator identity transition: - `jeffreyverlynjohnson@gmail.com` now, `guardian@thenash.group` after the + `REDACTED-operator-google-account` now, `guardian@thenash.group` after the Phase 2 Cloudflare account email migration; - Cloudflare MCP OAuth baseline: `cloudflare-api` at `https://mcp.cloudflare.com/mcp`, per-agent OAuth, no diff --git a/docs/host-capability-substrate/usable-state-readout-2026-05-17.md b/docs/host-capability-substrate/usable-state-readout-2026-05-17.md index 350adf7..ff0303f 100644 --- a/docs/host-capability-substrate/usable-state-readout-2026-05-17.md +++ b/docs/host-capability-substrate/usable-state-readout-2026-05-17.md @@ -80,7 +80,7 @@ Coverage: - HCS work roles are restated locally: design owner, implementer, reviewer, maintainer, evidence gatherer. - Cloudflare operator identity transition is recorded locally: - jeffreyverlynjohnson@gmail.com interim, guardian@thenash.group target after + REDACTED-operator-google-account interim, guardian@thenash.group target after the Phase 2 account email migration. - Cloudflare MCP baseline is recorded locally: cloudflare-api at https://mcp.cloudflare.com/mcp, per-agent OAuth, no shared bearer, diff --git a/docs/host-capability-substrate/workstation-surface-contract.md b/docs/host-capability-substrate/workstation-surface-contract.md index 26aa9ae..e93acd4 100644 --- a/docs/host-capability-substrate/workstation-surface-contract.md +++ b/docs/host-capability-substrate/workstation-surface-contract.md @@ -72,7 +72,7 @@ review burden and should usually split into smaller slices. HCS docs or local config that reference the operator's Cloudflare identity use this explicit transition: -- Interim identity: `jeffreyverlynjohnson@gmail.com` +- Interim identity: `REDACTED-operator-google-account` - Target identity after the Phase 2 Cloudflare account email migration: `guardian@thenash.group` - Target date for the migration: 2026-07-15