Skip to content

Commit 1624f68

Browse files
author
liushiao
committed
docs(LGT-021): define context kernel boundary
1 parent 38f1763 commit 1624f68

9 files changed

Lines changed: 256 additions & 12 deletions
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
{
2+
"schemaVersion": 1,
3+
"id": "context-kernel-interface",
4+
"name": "Context Kernel Interface",
5+
"owner": "context-kernel",
6+
"consumers": ["change-kernel", "worker-execution"],
7+
"maturity": "provisional",
8+
"normativeSources": ["product-intent", "long-term-plan", "domain-language", "assurance-policy"],
9+
"claims": [
10+
{
11+
"id": "context-materialization-binds-exact-authorized-bytes",
12+
"statement": "Given one logical compiled Context Capsule and one stable exact repository source product, Context Kernel emits a bounded canonical content-addressed manifest and process-local delivery whose ordered concrete regular-file entries exactly cover the authorized initial read scope; missing, extra, drifted, escaping, ambiguous, symlink, unreadable, duplicate, malformed, or over-limit source facts fail closed."
13+
},
14+
{
15+
"id": "context-expansion-is-recorded-before-content-disclosure",
16+
"statement": "A Context Expansion grant persists an all-or-nothing settlement and append-only lineage bound to the exact execution, request, prior Context Session, stable source product, and Project Model impact product before any newly authorized source bytes are disclosed; persistence failure, stale binding, replay, partial grant, or scope broadening discloses no bytes."
17+
},
18+
{
19+
"id": "context-expansion-resolutions-cannot-be-worker-self-granted",
20+
"statement": "A Worker-authored Context Expansion Request remains inert and cannot supply its own grant, denial, successor Capsule, materialization, Context Impact, controller identity, or Authority; only a separately compiled controller settlement may advance Context Session bindings."
21+
},
22+
{
23+
"id": "context-session-lineage-is-append-only-and-non-authoritative",
24+
"statement": "Context Session records preserve exact previous and next materialization and Context Impact digests plus granted, denied, or redundant settlement facts, while source bodies remain out of coordination records and no Context fact creates Evidence, Knowledge Closure, Outcome or Claim satisfaction, an Authority Decision, capability enforcement, semantic code impact, or Change acceptance."
25+
},
26+
{
27+
"id": "context-kernel-proof-rejects-source-scope-and-settlement-attacks",
28+
"statement": "The fixed Context Kernel proof accepts one reproducible initial materialization and one exact recorded-before-disclosure expansion, and rejects forged, stale, cross-execution, cross-source, replayed, broadened, partially persisted, manifest/blob-mismatched, path-escaping, symlink, unowned, worker-self-granted, impact-substituted, and resource-exhaustion inputs."
29+
}
30+
]
31+
}

.legatura/contracts/project-model-interface.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"id": "project-model-interface",
44
"name": "Project Model Interface",
55
"owner": "project-model",
6-
"consumers": ["change-kernel"],
6+
"consumers": ["change-kernel", "context-kernel"],
77
"maturity": "governed",
88
"normativeSources": ["product-intent", "long-term-plan", "domain-language", "assurance-policy"],
99
"claims": [
@@ -23,6 +23,10 @@
2323
"id": "context-capsule-binds-validated-path-ownership",
2424
"statement": "Generated Context Capsule write scope is projected only from an opaque, exact-Model-and-path-facts-bound ownership product for the primary Module; absent, forged, stale, ambiguous, disposition-only, or over-limit input fails closed."
2525
},
26+
{
27+
"id": "context-expansion-impact-is-derived-from-frozen-sources",
28+
"statement": "Given a frozen Project Model, its opaque exact path-ownership product, a current Context Session projection, and requested concrete paths, Project Model derives the exact newly disclosed path owners, Contract relations, Assurance crossings, disposition references, and Context Impact digest; worker or caller supplied owner, Module, Contract, assurance, semantic-impact, or verification classifications cannot substitute those facts."
29+
},
2630
{
2731
"id": "module-path-ownership-proof-rejects-coverage-and-binding-attacks",
2832
"statement": "The fixed ownership proof rejects unowned tracked paths, overlapping Module write owners, owner/disposition conflicts, malformed disposition rules, forged or stale ownership products, and Context Capsule scope derivation that bypasses the product."

.legatura/gates/minimum.json

Lines changed: 41 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,8 @@
88
"project-model",
99
"change-kernel",
1010
"local-workbench",
11-
"worker-execution"
11+
"worker-execution",
12+
"context-kernel"
1213
],
1314
"commands": [
1415
{
@@ -216,6 +217,45 @@
216217
"Filesystem, process, network, and secret capabilities are not independently enforced until LGT-022.",
217218
"Local Authority identities remain unauthenticated and Worker observations do not prove work correctness."
218219
]
220+
},
221+
{
222+
"id": "context-kernel-interface-proof",
223+
"appliesTo": ["context-kernel"],
224+
"command": ["node", "--test", "test/context-kernel/interface.test.mjs"],
225+
"timeoutMs": 120000,
226+
"claimRefs": [
227+
"context-capsule-cannot-broaden-scope",
228+
"context-expansion-impact-is-derived-from-frozen-sources",
229+
"context-materialization-binds-exact-authorized-bytes",
230+
"context-expansion-is-recorded-before-content-disclosure",
231+
"context-expansion-resolutions-cannot-be-worker-self-granted",
232+
"context-session-lineage-is-append-only-and-non-authoritative",
233+
"context-kernel-proof-rejects-source-scope-and-settlement-attacks",
234+
"worker-execution-observations-cannot-self-ratify"
235+
],
236+
"oracle": {
237+
"kind": "context-kernel-interface-proof-exit",
238+
"description": "The fixed Context Kernel cross-Interface proof must accept exact initial materialization and recorded-before-disclosure expansion while every declared source, scope, settlement, lineage, authority, and resource attack exits nonzero inside the scenario."
239+
},
240+
"applicability": {
241+
"phase": "acceptance",
242+
"purpose": "context-materialization-and-expansion-binding-proof"
243+
},
244+
"discriminatoryPower": {
245+
"rejects": [
246+
"initial materialization that includes bytes outside the logical Context Capsule read scope",
247+
"missing, extra, drifted, ambiguous, escaping, symlink, unreadable, duplicate, or over-limit source entries",
248+
"a Worker request that grants its own scope, successor Context, or Context Impact",
249+
"stale, cross-execution, cross-source, replayed, broadened, partial, or impact-substituted settlement",
250+
"new source-byte disclosure before the exact expansion ledger and blob state persist",
251+
"Context lineage that changes write scope or creates capability, semantic-impact, Evidence, Knowledge Closure, Authority, or acceptance conclusions"
252+
]
253+
},
254+
"residualUncertainty": [
255+
"The proof establishes the local Context delivery seam, not that a same-user Worker process cannot read the repository or acquire knowledge through another channel.",
256+
"Raw filesystem read and write enforcement remains the worker-capability-enforcement-not-proven Gap and LGT-022 responsibility.",
257+
"Real provider delivery, use of disclosed content, adapter parity, and intent-to-acceptance remain LGT-023 and LGT-024 responsibilities."
258+
]
219259
}
220260
]
221261
}

.legatura/knowledge-gaps.json

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -311,6 +311,17 @@
311311
"statement": "No declared local execution profile independently proves that filesystem, process, network, or secret capability limits are enforced at the worker execution boundary rather than merely observed or requested.",
312312
"expansionTrigger": "Before LGT-022 is activated or any capability profile is described as enforced."
313313
},
314+
{
315+
"id": "context-materialization-and-expansion-binding-not-proven",
316+
"status": "open",
317+
"affects": ["context-kernel", "project-model", "worker-execution", "change-kernel"],
318+
"owner": "governance-maintainer",
319+
"statement": "No fixed proof binds a logical compiled Context Capsule to one exact bounded source-byte materialization or proves that only a controller-owned recorded-before-disclosure settlement can produce an append-only successor Context with compiler-derived Context Impact facts.",
320+
"proofClaimRefs": [
321+
"context-kernel-proof-rejects-source-scope-and-settlement-attacks"
322+
],
323+
"expansionTrigger": "Before LGT-021 is achieved or any Worker Adapter receives a Context materialization."
324+
},
314325
{
315326
"id": "authority-identity-not-authenticated",
316327
"status": "open",
Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
{
2+
"schemaVersion": 1,
3+
"id": "context-kernel",
4+
"name": "Context Kernel",
5+
"status": "provisional",
6+
"summary": "Materializes exact bounded Context bytes and settles controller-owned Context Expansions atomically without interpreting acceptance or claiming filesystem isolation.",
7+
"factAuthority": "context-kernel-facts",
8+
"decisionAuthority": "module-maintainer",
9+
"interface": {
10+
"entrypoints": [
11+
"createContextSession(input, options)",
12+
"resolveContextExpansion(input, options)",
13+
"validateContextKernelDocument(value)",
14+
"CONTEXT_KERNEL_SCHEMA_VERSION",
15+
"CONTEXT_KERNEL_PROOF_VERSION",
16+
"CONTEXT_KERNEL_LIMITS"
17+
],
18+
"invariants": [
19+
"A Context Session binds one execution, compiled Change, logical Context Capsule, stable repository source product, exact content-addressed manifest, and compiler-derived Context Impact.",
20+
"Source bodies live only in a bounded process-local delivery or content-addressed blob store; Context Session, Worker Execution, Change, HTTP, CLI, and Profile records carry manifests and digests rather than source bodies.",
21+
"Initial materialization expands only the logical Capsule read scope into concrete regular-file entries, rejects symlink and path escape, and fails closed on missing, extra, ambiguous, drifted, unreadable, duplicate, malformed, or over-limit source facts.",
22+
"A Worker-authored Context Expansion Request is inert; only a controller-owned settlement bound to the exact execution, request, prior Context Session, source product, and Project Model impact product may grant, deny, or mark it redundant.",
23+
"A granted expansion is all-or-nothing, appends lineage and persistence before disclosure, preserves write scope, adds only exact authorized bytes, and records previous and next materialization and Context Impact digests.",
24+
"Context Kernel owns disclosure facts, not raw filesystem enforcement, worker knowledge, semantic code impact, Evidence, Knowledge Closure, Outcome, Claim, Authority, or Change acceptance conclusions."
25+
]
26+
},
27+
"paths": {
28+
"include": [
29+
"src/context-kernel/**",
30+
"test/context-kernel/**"
31+
],
32+
"exclude": []
33+
},
34+
"focusedTests": [
35+
{
36+
"path": "test/context-kernel/interface.test.mjs",
37+
"command": "node --test test/context-kernel/interface.test.mjs"
38+
}
39+
],
40+
"publicContracts": ["context-kernel-interface"],
41+
"dependencies": [
42+
{
43+
"module": "project-model",
44+
"via": "project-model-interface",
45+
"access": "interface-only"
46+
},
47+
{
48+
"module": "assurance-runtime",
49+
"via": "assurance-runtime-interface",
50+
"access": "interface-only"
51+
}
52+
]
53+
}

.legatura/modules/project-model.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,7 @@
1313
"validateProjectModel(model)",
1414
"publicProjectModel(model)",
1515
"compileChangeAgainstGovernance(change, baseline, { modulePathOwnershipProduct })",
16+
"compileContextExpansionImpact(input, { modulePathOwnershipProduct })",
1617
"compileChangePlanAuthoringProjection(baseline)",
1718
"parseChangePlanRefs(value)",
1819
"compileOutcomePlanAmendment(input)",
@@ -32,6 +33,7 @@
3233
"Project Model alone compiles one opaque bounded Module path ownership product bound to the exact Model and exact tracked-path facts: Module and disposition selectors use only canonical exact paths or literal recursive prefixes with include-minus-exclude matching; every disposition has a stable id, kind ungoverned, canonical include and exclude lists, and substantive rationale; every latent or concrete owner-owner, owner-disposition, or disposition-disposition overlap fails without precedence; every tracked path has exactly one Module write owner or one disposition; and a disposition never grants write authority.",
3334
"For an exact compiled Context write scope, the same ownership product validates one bounded digest-bound scope selection as a narrowing of the authoritative Module scope and projects closed concrete path decisions that distinguish ownership authority, selected-scope membership, and final write allowance; forged, broadened, malformed, stale, duplicate, or over-limit selections fail closed, and consumers never interpret selectors or dispositions.",
3435
"Generated Context Capsule write scope is projected only from the exact ownership product for its primary Module; absent, forged, stale, ambiguous, disposition-only, or over-limit inputs fail closed, and callers may narrow but never widen that scope.",
36+
"Context Expansion Impact is derived only from the frozen Project Model, an opaque exact ownership product, the current Context Session projection, and requested concrete paths; caller or Worker classifications cannot create owner, Contract, Assurance, disposition, semantic-impact, or verification facts.",
3537
"The ownership product enters Change compilation only through a process-local options seam and is never serialized into worker, HTTP, Store, or browser input.",
3638
"Unrelated Claims require an explicit authority-bound mapping.",
3739
"Acceptance Evidence eligibility is compiled from canonical Claim Gate routes at exact Gate and command identity, filtered to routes applicable to the primary Module through acceptance-eligible Gates; cross-Claim mappings expose exact source routes, and integration-only full Gate routes never enter acceptance mappings.",
@@ -62,6 +64,7 @@
6264
"include": [
6365
"src/core/project-model.mjs",
6466
"src/core/change-compiler.mjs",
67+
"src/core/context-impact.mjs",
6568
"src/core/outcome-evolution.mjs",
6669
"src/core/outcome-transitions.mjs",
6770
"src/core/architecture-profile.mjs",
@@ -89,6 +92,8 @@
8992
".legatura/gates/brownfield-adoption.json",
9093
".legatura/modules/worker-execution.json",
9194
".legatura/contracts/worker-execution-interface.json",
95+
".legatura/modules/context-kernel.json",
96+
".legatura/contracts/context-kernel-interface.json",
9297
"examples/brownfield-app-apk-relay/**",
9398
".legatura/modules/project-model.json",
9499
".legatura/contracts/project-model-interface.json"

.legatura/modules/worker-execution.json

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,5 +39,11 @@
3939
}
4040
],
4141
"publicContracts": ["worker-execution-interface"],
42-
"dependencies": []
42+
"dependencies": [
43+
{
44+
"module": "context-kernel",
45+
"via": "context-kernel-interface",
46+
"access": "interface-only"
47+
}
48+
]
4349
}

0 commit comments

Comments
 (0)