|
R14 WITHDRAWN: the register already does everything the question assumed it could not
Withdrawn without a ruling, following the R2a precedent. R14 asked whether the credential matrix needs a ruled-exception field, on the premise that three S5 power-key asymmetries were "ruled correct by SEC-016" and so reported a permanent red a reader learns to ignore. All three parts of that premise fail on measurement: 1. They are NOT ruled correct. SEC-016 ruled per-DC ISOLATION -- dc1 gets its own dedicated power key rather than reusing dc0's -- which is satisfied. It never blessed the filename, host and custody divergence. That is SEC-021(b), an OPEN ledger defect whose own disposition reads "needs a naming/custody reconciliation to the dc1 shape", and whose stated complaint was "Per-DC rows that should be symmetric are not, and nothing compares them". S5 is the thing that now compares them, so the finding is the register working as designed. 2. The register already ATTRIBUTES them: those rows carry sec-ref=SEC-021 and notes-ref=n-dc0-power-key-divergence. 3. The register already EXPLAINS them: creds-matrix-notes.md carries the n-dc0-power-key-divergence note describing the name and host-role divergence and why the expected jumphost rows fail EXPECTED-BUT-ABSENT. And the notes file already warns against the exact move this question contemplated. The line immediately preceding that note reads: "failure, not a matrix error: do not delete the row to make the checker green." So no schema change is needed and none should be made. Adding a suppression mechanism would have HIDDEN an open security-ledger item -- the opposite of what the register exists for. The red clears when SEC-021(b) is remediated, which is the intended behaviour. This is the third premise this audit has had to correct in its own framing, after R2a (literals already assigned under D-111) and R9 (one failure mode, not two). Worth noting the pattern: the audit's lens findings were sound as observations and repeatedly wrong as conclusions, and measurement caught it every time. Residual recorded so it is not mistaken for an oversight: whether a ruled-exception field is EVER needed is now hypothetical. If one arises, notes-ref and sec-ref are the place to start, not a new column. Revert: git revert this commit; the R14 entry is rewritten in place with the original retained beneath as R14-ORIGINAL for the audit trail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/audit/queued-rulings-20260727.md |
|---|