You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Follow-up to #10773 / PR #10934, which registered eleven dogfood proof tags and deliberately left every one bound: false — the triage ruling (13:11Z on that card) split registration from binding and sent the binding half to the spec seat's review. That review happened; this card carries out its verdict. The adjudication is recorded verbatim in the ACCEPT comment on PR #10934.
Adopt (ledger edits, each one entry gaining a proof ref)
showcase-fls-read-mask-strip → permission.fields.readable. The strongest of the three: the proof file authors a scratch permission set carrying readable: false and asserts the runtime outcome both ways — key absence on the wire, entitled contrast on the same field, row and request. ⛔ Do not also bind permission.fields.editable: the file authors that key but asserts its refusal as a consequence of unreadability rather than as the write-deny axis, which showcase-permission-zoo already pins.
showcase-crud-persona-matrix → all four of permission.objects.allowCreate / allowRead / allowEdit / allowDelete. The scope objection (one breadth proof anchoring four properties) was weighed and answered by the file's own shape: the exact allow/deny split is asserted per cell, so a narrowing sweep breaks the build rather than quietly shrinking what the four entries cite. Multi-entry binding precedent: semantic-roles binds three.
Do NOT bind yet — measurement first
sharing-rule-org-less-caller → permission.systemPermissions: blocked on a note re-verification. That entry's note reads "PARTIAL — app-entry/nav visibility only, not a general capability gate" (evidence: hono-plugin.ts:1222), while the proof measures manage_sharing acting as a real data-layer boundary at the sharing service (ADR-0111 D6). The note and the proof describe different consumers, so binding as it stands would attach a citation to an entry describing something narrower than what is proven. Re-verify the note against ADR-0111 D6 and the current sharing-service code, correct it if stale, and only then decide the binding — recording either outcome (bound, or still unbound with the reason updated) on this card.
BOUND_PROOF_PATHS in proof-registry.test.ts is the pin that catches a silent binding — expect it to move with items 1 and 2, and confirm it moves by exactly those entries.
Ledger files are packages/spec/liveness/*.json; a binding edit is a contract-adjacent surface, so clause-② applies at dispatch time.
Filed by the spec seat at end of shift (session session_01B4h3medzvhB9rpfoja9jcw) so an adjudicated decision does not evaporate with the session. Unassigned.
Follow-up to #10773 / PR #10934, which registered eleven dogfood proof tags and deliberately left every one
bound: false— the triage ruling (13:11Z on that card) split registration from binding and sent the binding half to the spec seat's review. That review happened; this card carries out its verdict. The adjudication is recorded verbatim in the ACCEPT comment on PR #10934.Adopt (ledger edits, each one entry gaining a
proofref)showcase-fls-read-mask-strip→permission.fields.readable. The strongest of the three: the proof file authors a scratch permission set carryingreadable: falseand asserts the runtime outcome both ways — key absence on the wire, entitled contrast on the same field, row and request. ⛔ Do not also bindpermission.fields.editable: the file authors that key but asserts its refusal as a consequence of unreadability rather than as the write-deny axis, whichshowcase-permission-zooalready pins.showcase-crud-persona-matrix→ all four ofpermission.objects.allowCreate/allowRead/allowEdit/allowDelete. The scope objection (one breadth proof anchoring four properties) was weighed and answered by the file's own shape: the exact allow/deny split is asserted per cell, so a narrowing sweep breaks the build rather than quietly shrinking what the four entries cite. Multi-entry binding precedent:semantic-rolesbinds three.Do NOT bind yet — measurement first
sharing-rule-org-less-caller→permission.systemPermissions: blocked on a note re-verification. That entry's note reads "PARTIAL — app-entry/nav visibility only, not a general capability gate" (evidence:hono-plugin.ts:1222), while the proof measuresmanage_sharingacting as a real data-layer boundary at the sharing service (ADR-0111 D6). The note and the proof describe different consumers, so binding as it stands would attach a citation to an entry describing something narrower than what is proven. Re-verify the note against ADR-0111 D6 and the current sharing-service code, correct it if stale, and only then decide the binding — recording either outcome (bound, or still unbound with the reason updated) on this card.Notes for whoever takes this
blockedReasonprose are inpackages/spec/scripts/liveness/proof-registry.mtsas of PR chore(spec): register the eleven unregistered dogfood proof tags, and propose their ledger bindings #10934; the other eight are recorded as having no authorable surface to bind and are not in this card's scope.BOUND_PROOF_PATHSinproof-registry.test.tsis the pin that catches a silent binding — expect it to move with items 1 and 2, and confirm it moves by exactly those entries.packages/spec/liveness/*.json; a binding edit is a contract-adjacent surface, so clause-② applies at dispatch time.Filed by the spec seat at end of shift (session
session_01B4h3medzvhB9rpfoja9jcw) so an adjudicated decision does not evaporate with the session. Unassigned.