Skip to content

Commit 31ba39b

Browse files
author
liushiao
committed
docs(LGT-021): seal context authority boundary
1 parent 1624f68 commit 31ba39b

11 files changed

Lines changed: 175 additions & 42 deletions

.legatura/contracts/context-kernel-interface.json

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,29 +3,29 @@
33
"id": "context-kernel-interface",
44
"name": "Context Kernel Interface",
55
"owner": "context-kernel",
6-
"consumers": ["change-kernel", "worker-execution"],
6+
"consumers": ["change-kernel"],
77
"maturity": "provisional",
88
"normativeSources": ["product-intent", "long-term-plan", "domain-language", "assurance-policy"],
99
"claims": [
1010
{
1111
"id": "context-materialization-binds-exact-authorized-bytes",
12-
"statement": "Given one logical compiled Context Capsule and one stable exact repository source product, Context Kernel emits a bounded canonical content-addressed manifest and process-local delivery whose ordered concrete regular-file entries exactly cover the authorized initial read scope; missing, extra, drifted, escaping, ambiguous, symlink, unreadable, duplicate, malformed, or over-limit source facts fail closed."
12+
"statement": "Given one logical compiled Context Capsule, its frozen Git-visible path inventory, and one matching opaque Assurance Runtime Repository Source Product, Context Kernel emits a bounded canonical content-addressed manifest and process-local delivery whose ordered concrete regular-file entries exactly cover the authorized initial read scope; missing, extra, cross-repository, drifted, escaping, ambiguous, symlink, non-regular, unreadable, duplicate, malformed, forged, serialized, or over-limit source facts fail closed."
1313
},
1414
{
1515
"id": "context-expansion-is-recorded-before-content-disclosure",
16-
"statement": "A Context Expansion grant persists an all-or-nothing settlement and append-only lineage bound to the exact execution, request, prior Context Session, stable source product, and Project Model impact product before any newly authorized source bytes are disclosed; persistence failure, stale binding, replay, partial grant, or scope broadening discloses no bytes."
16+
"statement": "Every Context Expansion resolution made with the exact live controller Session product appends one successor Session and settlement bound to the exact execution, request, prior Session, stable source product, and Project Model impact product, atomically consumes the prior controller product, and returns a successor controller product; a grant commits exact process-lifetime blob state and compare-and-swap lineage before minting any newly authorized delivery, while denial or compiler-derived redundancy discloses no new bytes and persistence failure, stale binding, replay, partial grant, or scope broadening leaves the prior Session and controller current."
1717
},
1818
{
1919
"id": "context-expansion-resolutions-cannot-be-worker-self-granted",
20-
"statement": "A Worker-authored Context Expansion Request remains inert and cannot supply its own grant, denial, successor Capsule, materialization, Context Impact, controller identity, or Authority; only a separately compiled controller settlement may advance Context Session bindings."
20+
"statement": "A Worker-authored Context Expansion Request remains inert: resolution authority is possession of an opaque process-local controller Session product passed only through a process-local options seam, minted for the exact Context Kernel instance and current Session, and retained outside Worker input; no request, report, observation, Execution Record, digest, plain Session record, proxy, deserialized value, caller identity, or caller-supplied grant, successor, source, scope, materialization, or impact can mint, rehydrate, or substitute that product."
2121
},
2222
{
2323
"id": "context-session-lineage-is-append-only-and-non-authoritative",
2424
"statement": "Context Session records preserve exact previous and next materialization and Context Impact digests plus granted, denied, or redundant settlement facts, while source bodies remain out of coordination records and no Context fact creates Evidence, Knowledge Closure, Outcome or Claim satisfaction, an Authority Decision, capability enforcement, semantic code impact, or Change acceptance."
2525
},
2626
{
2727
"id": "context-kernel-proof-rejects-source-scope-and-settlement-attacks",
28-
"statement": "The fixed Context Kernel proof accepts one reproducible initial materialization and one exact recorded-before-disclosure expansion, and rejects forged, stale, cross-execution, cross-source, replayed, broadened, partially persisted, manifest/blob-mismatched, path-escaping, symlink, unowned, worker-self-granted, impact-substituted, and resource-exhaustion inputs."
28+
"statement": "The fixed Context Kernel proof accepts one reproducible initial materialization and one exact recorded-before-disclosure grant, and rejects forged, serialized, proxied, wrong-kind, cross-instance, stale, consumed, cross-execution, cross-repository, cross-source, replayed, broadened, partially persisted, manifest/blob-mismatched, path-escaping, symlink, unowned, worker-self-granted, caller-self-granted, impact-substituted, storage-failed, and resource-exhaustion inputs."
2929
}
3030
]
3131
}

.legatura/contracts/project-model-interface.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,11 @@
2525
},
2626
{
2727
"id": "context-expansion-impact-is-derived-from-frozen-sources",
28-
"statement": "Given a frozen Project Model, its opaque exact path-ownership product, a current Context Session projection, and requested concrete paths, Project Model derives the exact newly disclosed path owners, Contract relations, Assurance crossings, disposition references, and Context Impact digest; worker or caller supplied owner, Module, Contract, assurance, semantic-impact, or verification classifications cannot substitute those facts."
28+
"statement": "Given a frozen Project Model, its opaque exact path-ownership product, an exact prior-disclosed path list and digest, requested concrete paths, and a stable repository source binding, Project Model derives the exact newly disclosed path owners, Contract relations, Assurance crossings, disposition references, and Context Impact digest; Context Session objects and worker or caller supplied owner, Module, Contract, assurance, semantic-impact, or verification classifications cannot substitute those neutral inputs or facts."
29+
},
30+
{
31+
"id": "context-expansion-impact-proof-rejects-binding-and-classification-attacks",
32+
"statement": "The fixed Context Impact proof accepts one exact neutral prior-path and requested-path compilation and rejects forged or serialized ownership products, stale Model or source bindings, duplicate, malformed, unowned, disposition-only, already-disclosed, broadened, over-limit, Context-Session-coupled, and caller-classified impact inputs."
2933
},
3034
{
3135
"id": "module-path-ownership-proof-rejects-coverage-and-binding-attacks",

.legatura/contracts/worker-execution-interface.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"id": "worker-execution-interface",
44
"name": "Worker Execution Interface",
55
"owner": "worker-execution",
6-
"consumers": ["change-kernel"],
6+
"consumers": ["change-kernel", "context-kernel"],
77
"maturity": "provisional",
88
"normativeSources": ["product-intent", "domain-language", "assurance-policy"],
99
"claims": [

.legatura/gates/minimum.json

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -235,7 +235,7 @@
235235
],
236236
"oracle": {
237237
"kind": "context-kernel-interface-proof-exit",
238-
"description": "The fixed Context Kernel cross-Interface proof must accept exact initial materialization and recorded-before-disclosure expansion while every declared source, scope, settlement, lineage, authority, and resource attack exits nonzero inside the scenario."
238+
"description": "The fixed Context Kernel cross-Interface proof must accept exact initial materialization and one controller-product-authorized recorded-before-disclosure expansion while every declared source, scope, capability-product, settlement, lineage, authority, storage, and resource attack exits nonzero inside the scenario."
239239
},
240240
"applicability": {
241241
"phase": "acceptance",
@@ -244,17 +244,19 @@
244244
"discriminatoryPower": {
245245
"rejects": [
246246
"initial materialization that includes bytes outside the logical Context Capsule read scope",
247-
"missing, extra, drifted, ambiguous, escaping, symlink, unreadable, duplicate, or over-limit source entries",
248-
"a Worker request that grants its own scope, successor Context, or Context Impact",
247+
"missing, extra, cross-repository, drifted, ambiguous, escaping, symlink, non-regular, unreadable, duplicate, malformed, forged, serialized, manifest/blob-mismatched, or over-limit source entries or products",
248+
"a Worker request or arbitrary caller that grants its own scope, successor Context, source product, materialization, or Context Impact",
249+
"a forged, serialized, proxied, wrong-kind, cross-instance, stale, consumed, or delivery-product-substituted controller Session product",
249250
"stale, cross-execution, cross-source, replayed, broadened, partial, or impact-substituted settlement",
250-
"new source-byte disclosure before the exact expansion ledger and blob state persist",
251+
"new source-byte disclosure before exact process-lifetime blob state and compare-and-swap expansion lineage commit",
252+
"a blob or lineage persistence failure that rotates the prior Session or mints any delivery",
251253
"Context lineage that changes write scope or creates capability, semantic-impact, Evidence, Knowledge Closure, Authority, or acceptance conclusions"
252254
]
253255
},
254256
"residualUncertainty": [
255-
"The proof establishes the local Context delivery seam, not that a same-user Worker process cannot read the repository or acquire knowledge through another channel.",
257+
"The proof establishes process-local dataflow capability and Context delivery non-forgeability, not authenticated controller identity or that a same-user Worker process cannot read the repository or acquire knowledge through another channel.",
256258
"Raw filesystem read and write enforcement remains the worker-capability-enforcement-not-proven Gap and LGT-022 responsibility.",
257-
"Real provider delivery, use of disclosed content, adapter parity, and intent-to-acceptance remain LGT-023 and LGT-024 responsibilities."
259+
"Worker adoption of successor Context, real provider delivery, use of disclosed content, adapter parity, and intent-to-acceptance remain LGT-023 and LGT-024 responsibilities."
258260
]
259261
}
260262
]

.legatura/gates/path-ownership.json

Lines changed: 30 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
{
22
"schemaVersion": 1,
33
"id": "path-ownership",
4-
"name": "Module Path Ownership Proof Gate",
5-
"purpose": "Produce direct Evidence that tracked-path facts are exact, Module write ownership is total and exclusive, and Context Capsules consume the same opaque ownership product.",
4+
"name": "Project Model Path and Context Impact Proof Gate",
5+
"purpose": "Produce direct Evidence that tracked-path facts are exact, Module write ownership is total and exclusive, Context Capsules consume the same opaque ownership product, and Context Expansion Impact is derived only from neutral frozen structural inputs.",
66
"appliesTo": ["assurance-runtime", "project-model", "change-kernel"],
77
"commands": [
88
{
@@ -62,6 +62,34 @@
6262
"The selector grammar is deliberately restricted to exact paths and literal recursive prefixes rather than general glob intersection."
6363
]
6464
},
65+
{
66+
"id": "context-expansion-impact-proof",
67+
"appliesTo": ["project-model"],
68+
"command": ["node", "--test", "test/project-model/context-impact.test.mjs"],
69+
"timeoutMs": 120000,
70+
"claimRefs": [
71+
"context-expansion-impact-is-derived-from-frozen-sources",
72+
"context-expansion-impact-proof-rejects-binding-and-classification-attacks"
73+
],
74+
"oracle": {
75+
"kind": "node-test-runner-exit",
76+
"description": "The fixed Project Model neutral Context Expansion Impact compilation and attack scenario must exist and exit zero."
77+
},
78+
"applicability": {
79+
"phase": "acceptance",
80+
"purpose": "context-expansion-impact-proof"
81+
},
82+
"discriminatoryPower": {
83+
"rejects": [
84+
"a Context Kernel Session object or caller classification substituted for neutral exact prior-path, request-path, ownership, Model, or source inputs",
85+
"a forged, serialized, wrong-Model, stale-path-facts, stale-source, duplicate, malformed, already-disclosed, unowned, disposition-only, or over-limit impact input",
86+
"a broadened owner, Module, Contract, assurance crossing, disposition, semantic-impact, verification, Evidence, or acceptance conclusion"
87+
]
88+
},
89+
"residualUncertainty": [
90+
"The proof derives structural Context Impact from declared Model and ownership facts; it does not infer semantic code impact, verify source behavior, enforce reads, or decide acceptance."
91+
]
92+
},
6593
{
6694
"id": "path-ownership-kernel-adoption-proof",
6795
"appliesTo": ["change-kernel"],

.legatura/knowledge-gaps.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -314,10 +314,11 @@
314314
{
315315
"id": "context-materialization-and-expansion-binding-not-proven",
316316
"status": "open",
317-
"affects": ["context-kernel", "project-model", "worker-execution", "change-kernel"],
317+
"affects": ["assurance-runtime", "context-kernel", "project-model", "worker-execution", "change-kernel"],
318318
"owner": "governance-maintainer",
319-
"statement": "No fixed proof binds a logical compiled Context Capsule to one exact bounded source-byte materialization or proves that only a controller-owned recorded-before-disclosure settlement can produce an append-only successor Context with compiler-derived Context Impact facts.",
319+
"statement": "No fixed proof binds one stable opaque Assurance Runtime source-byte product to a logical compiled Context Capsule and exact materialization, derives neutral Context Impact from frozen Project Model sources, or proves that only an unforgeable process-local controller Session product can append a recorded-before-disclosure successor Context.",
320320
"proofClaimRefs": [
321+
"context-expansion-impact-proof-rejects-binding-and-classification-attacks",
321322
"context-kernel-proof-rejects-source-scope-and-settlement-attacks"
322323
],
323324
"expansionTrigger": "Before LGT-021 is achieved or any Worker Adapter receives a Context materialization."

.legatura/modules/context-kernel.json

Lines changed: 16 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,19 +8,23 @@
88
"decisionAuthority": "module-maintainer",
99
"interface": {
1010
"entrypoints": [
11-
"createContextSession(input, options)",
12-
"resolveContextExpansion(input, options)",
11+
"createContextKernel(options)",
12+
"kernel.createContextSession(input, options)",
13+
"kernel.resolveContextExpansion(input, { controllerSessionProduct })",
14+
"kernel.readContextDeliveryFile(deliveryProduct, pathRef)",
1315
"validateContextKernelDocument(value)",
1416
"CONTEXT_KERNEL_SCHEMA_VERSION",
1517
"CONTEXT_KERNEL_PROOF_VERSION",
1618
"CONTEXT_KERNEL_LIMITS"
1719
],
1820
"invariants": [
19-
"A Context Session binds one execution, compiled Change, logical Context Capsule, stable repository source product, exact content-addressed manifest, and compiler-derived Context Impact.",
20-
"Source bodies live only in a bounded process-local delivery or content-addressed blob store; Context Session, Worker Execution, Change, HTTP, CLI, and Profile records carry manifests and digests rather than source bodies.",
21-
"Initial materialization expands only the logical Capsule read scope into concrete regular-file entries, rejects symlink and path escape, and fails closed on missing, extra, ambiguous, drifted, unreadable, duplicate, malformed, or over-limit source facts.",
22-
"A Worker-authored Context Expansion Request is inert; only a controller-owned settlement bound to the exact execution, request, prior Context Session, source product, and Project Model impact product may grant, deny, or mark it redundant.",
23-
"A granted expansion is all-or-nothing, appends lineage and persistence before disclosure, preserves write scope, adds only exact authorized bytes, and records previous and next materialization and Context Impact digests.",
21+
"A Context Session binds one execution, compiled Change, logical Context Capsule, frozen Git-visible path inventory, opaque Assurance Runtime Repository Source Product, exact content-addressed manifest, and compiler-derived Context Impact.",
22+
"Source bodies live only in bounded process-lifetime content-addressed blob state and delivery products; Context Session, Worker Execution, Change, Store, HTTP, CLI, and Profile records carry manifests and digests rather than source bodies.",
23+
"Initial materialization expands only the logical Capsule read scope over the frozen repository inventory, consumes the exact matching live source product, and fails closed on missing, extra, cross-repository, path-escaping, symlink, non-regular, ambiguous, drifted, unreadable, duplicate, malformed, forged, serialized, or over-limit source facts.",
24+
"Session creation returns distinct unforgeable process-local controller and delivery products; the controller product stays outside Worker input, cannot be reconstructed from any plain record, and is the only resolution capability for that kernel instance and Session.",
25+
"A Worker-authored Context Expansion Request is inert; the controller holder may choose only grant or deny, while redundancy, successor scope, source selection, manifest, Context Impact, and lineage are compiler-derived from exact frozen sources.",
26+
"Every resolution through the process-local controller-product options seam appends a successor Session, atomically consumes the prior controller product, and returns a successor controller product; a grant is all-or-nothing and mints delivery only after process-lifetime blob commit and compare-and-swap lineage persistence, while deny or derived redundancy discloses no new bytes and failed commit leaves the prior controller product current.",
27+
"Context Kernel does not settle or resume a Worker Execution Record; Adapter adoption of a successor Context belongs to LGT-023 and must not create a Worker Execution to Context Kernel dependency cycle.",
2428
"Context Kernel owns disclosure facts, not raw filesystem enforcement, worker knowledge, semantic code impact, Evidence, Knowledge Closure, Outcome, Claim, Authority, or Change acceptance conclusions."
2529
]
2630
},
@@ -48,6 +52,11 @@
4852
"module": "assurance-runtime",
4953
"via": "assurance-runtime-interface",
5054
"access": "interface-only"
55+
},
56+
{
57+
"module": "worker-execution",
58+
"via": "worker-execution-interface",
59+
"access": "interface-only"
5160
}
5261
]
5362
}

0 commit comments

Comments
 (0)