diff --git a/docs/CURRENT-STATE.md b/docs/CURRENT-STATE.md index cc675c4..7a0a5cf 100644 --- a/docs/CURRENT-STATE.md +++ b/docs/CURRENT-STATE.md @@ -793,8 +793,19 @@ are host-independent and remain. **THEN OWED:** repo-lint and the gauntlet ON voffice1 -- deliberately deferred until now precisely because running them against a 105-commit-stale tree would have produced a meaningless number. - Remaining: R12-R15 standing; G18 deferred-and-gated. **All Stage-5 BLOCKING rulings (R1-R11) - are now closed.** + **R14 WITHDRAWN 2026-07-27 -- raised in error, no ruling taken** (the R2a precedent). + All three parts of its premise fail on measurement: the S5 power-key asymmetries are NOT + "ruled correct by SEC-016" (that ruling covers per-DC ISOLATION, which is satisfied; the + filename/host/custody divergence is **SEC-021(b)**, an OPEN defect whose disposition reads + "needs a naming/custody reconciliation to the dc1 shape"); the rows ALREADY carry + `sec-ref=SEC-021` and `notes-ref=n-dc0-power-key-divergence`; and `creds-matrix-notes.md` + ALREADY explains the divergence in full. **The file even warns against the exact move the + question contemplated -- "do not delete the row to make the checker green."** No schema + change is needed and none should be made: adding a suppression mechanism would have HIDDEN + an open security-ledger item. The red clears when SEC-021(b) is remediated, which is the + intended behaviour. + Remaining: R12, R13, R15 standing; G18 deferred-and-gated. **All Stage-5 BLOCKING rulings + (R1-R11) are closed.** - Position inside Stage 3: deploy step A EXECUTED 2026-07-19 (6/0/6 exact; convergence zero -- `docs/audit/outer-plan-20260719-postA-converged.txt`). **Deploy step B diff --git a/docs/audit/queued-rulings-20260727.md b/docs/audit/queued-rulings-20260727.md index 417c7b9..d06a076 100644 --- a/docs/audit/queued-rulings-20260727.md +++ b/docs/audit/queued-rulings-20260727.md @@ -586,7 +586,49 @@ --- -## R14. The register cannot express a RULED exception +## R14. WITHDRAWN 2026-07-27 -- the premise was wrong on every count + +**This question was raised in error and is withdrawn without a ruling**, like R2a. +It asked whether the credential matrix needs a ruled-exception field, on the premise +that three S5 power-key asymmetries were "RULED correct by SEC-016" and therefore +reported a permanent red a reader learns to ignore. + +**Measured, all three parts of that premise fail:** +1. **They are NOT ruled correct.** SEC-016 ruled per-DC ISOLATION -- dc1 gets its own + dedicated power key rather than reusing dc0's -- which is satisfied. It never + blessed the filename/host/custody divergence. That divergence is **SEC-021(b)**, an + OPEN ledger defect whose own disposition reads "needs a naming/custody + reconciliation to the dc1 shape" and whose stated complaint was "Per-DC rows that + should be symmetric are not, **and nothing compares them**". S5 is the thing that + now compares them. +2. **The register already ATTRIBUTES them.** Those rows carry `sec-ref=SEC-021` and + `notes-ref=n-dc0-power-key-divergence` -- measured. +3. **The register already EXPLAINS them.** `creds-matrix-notes.md` carries + `n-dc0-power-key-divergence`: "**SEC-021, per-DC asymmetry.** dc1's power key is + consolidated on the jumphost under a DC-qualified name; dc0's equivalent exists + under a DIFFERENT name and on a DIFFERENT host-role ... so the expected jumphost + rows fail EXPECTED-BUT-ABSENT while the divergent copy shows up at a declared + remote location." + +**And the file already warns against the exact move this question contemplated.** The +line immediately preceding that note reads: "failure, not a matrix error: **do not +delete the row to make the checker green.**" + +**So no schema change is needed and none should be made.** The finding is correct, +attributed and documented. Adding a suppression mechanism would have hidden an open +security-ledger item -- the opposite of what the register is for. The red clears when +SEC-021(b) is remediated, which is the intended behaviour. + +**Residual, recorded so it is not mistaken for an oversight:** whether a +ruled-exception field is EVER needed is now hypothetical -- the motivating example +turned out not to be an exception. If a genuine ruled exception arises later, the +existing `notes-ref` + `sec-ref` columns are the place to start, not a new column. + +OPERATOR UTTERANCE: *(none required -- withdrawn, not ruled)* + +--- + +## R14-ORIGINAL (superseded, kept for the audit trail). The register cannot express a RULED exception **Finding:** carried from the 2026-07-27 close and re-measured today -- 3 of the 7 standing credential findings are S5 power-key asymmetries that SEC-016 RULED to be