Skip to content

Adopt the three adjudicated proof→ledger bindings from #10773 (and re-verify the permission.systemPermissions note first) #10957

Description

@os-elon

Follow-up to #10773 / PR #10934, which registered eleven dogfood proof tags and deliberately left every one bound: false — the triage ruling (13:11Z on that card) split registration from binding and sent the binding half to the spec seat's review. That review happened; this card carries out its verdict. The adjudication is recorded verbatim in the ACCEPT comment on PR #10934.

Adopt (ledger edits, each one entry gaining a proof ref)

  1. showcase-fls-read-mask-strippermission.fields.readable. The strongest of the three: the proof file authors a scratch permission set carrying readable: false and asserts the runtime outcome both ways — key absence on the wire, entitled contrast on the same field, row and request. ⛔ Do not also bind permission.fields.editable: the file authors that key but asserts its refusal as a consequence of unreadability rather than as the write-deny axis, which showcase-permission-zoo already pins.

  2. showcase-crud-persona-matrix → all four of permission.objects.allowCreate / allowRead / allowEdit / allowDelete. The scope objection (one breadth proof anchoring four properties) was weighed and answered by the file's own shape: the exact allow/deny split is asserted per cell, so a narrowing sweep breaks the build rather than quietly shrinking what the four entries cite. Multi-entry binding precedent: semantic-roles binds three.

Do NOT bind yet — measurement first

  1. sharing-rule-org-less-callerpermission.systemPermissions: blocked on a note re-verification. That entry's note reads "PARTIAL — app-entry/nav visibility only, not a general capability gate" (evidence: hono-plugin.ts:1222), while the proof measures manage_sharing acting as a real data-layer boundary at the sharing service (ADR-0111 D6). The note and the proof describe different consumers, so binding as it stands would attach a citation to an entry describing something narrower than what is proven. Re-verify the note against ADR-0111 D6 and the current sharing-service code, correct it if stale, and only then decide the binding — recording either outcome (bound, or still unbound with the reason updated) on this card.

Notes for whoever takes this

  • All eleven registry entries and their blockedReason prose are in packages/spec/scripts/liveness/proof-registry.mts as of PR chore(spec): register the eleven unregistered dogfood proof tags, and propose their ledger bindings #10934; the other eight are recorded as having no authorable surface to bind and are not in this card's scope.
  • BOUND_PROOF_PATHS in proof-registry.test.ts is the pin that catches a silent binding — expect it to move with items 1 and 2, and confirm it moves by exactly those entries.
  • Ledger files are packages/spec/liveness/*.json; a binding edit is a contract-adjacent surface, so clause-② applies at dispatch time.

Filed by the spec seat at end of shift (session session_01B4h3medzvhB9rpfoja9jcw) so an adjudicated decision does not evaporate with the session. Unassigned.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions