Skip to content

[M1] Pre-deployment Kernel integrity hardening #167

Description

@samovers

Outcome

Harden M1 before deployment so the Kernel is trustworthy under concurrency, tenancy, temporal queries, authority decisions, evidence promotion, corrections, materialization, and frozen outputs.

Review baseline: fc800d5a1be35c95a8f348fda9d8453b06e37018.

Tracker status (2026-08-29)

Native sub-issue and blocked-by relationships now mirror the live dependency map. Foundation issues #168#174 are closed; remaining multi-capability children are classified as Tracking Epics and coherent single-capability children as Delivery issues. This tracker migration does not rewrite historical decisions or merged pull requests.

Non-negotiable boundary

Start now — no runtime behavior change

Foundation implementation

Governed semantics

Durable derivation, outputs, and truth

Critical dependency spine

(#168, #169, #171) → #174 → #172 → #173 → #175 → (#177, #178, #179) → #180 → #181 → #182 → #183

#168 → #171 → (#179, #181, #182, #183)

(#169, #170, #172, #173, #174) → #192 → #176

(#169, #170, #172, #173, #174, #175, #177, #178, #182) → #193

Parallel work is allowed where each child issue's explicit dependencies are satisfied.

Existing-issue overlap and ownership

Exit criteria

  • Adversarial multi-tenant and concurrent tests exercise the deployed application topology.
  • Every governed result is reconstructable from immutable records pinned to exact code, schema, policy, reference inputs, temporal cuts, and RuntimeBundle.
  • Unsupported or ambiguous authority/evidence/profile states fail closed.
  • No higher capability or country-compliance claim is made merely because this epic closes.

M2 integrated closeout discovered by whole-system review (2026-07-10)

These are shared Core/Kernel prerequisites, not Serbia implementations:

Additional dependency spine:

#168 → #184 (decision work)

(#170, #171, #173, #174) → #184 (implementation and forward migration) → #180 → #185 → #186

(#171, #172, #173, #174, #175, #176, #178, #179) → #185

#159 remains the SI-parity provider seam and should coordinate with #171/#184/#185 without absorbing them. #162 remains blocked Serbia work and must consume #185 rather than create an alternate country-specific write path.

The original first safe Codex handoff remains #168. These additions do not unpark #153-#156, change #139's backlog posture, or authorize law, contract, manifest, ActiveArtifactSet, profile-activation, or capability-claim changes.

First claim/read delivery alignment — 2026-09-11

Renewed canonical Phase A approval at exact PR #11 head 4494924998183fe3fa7bc1b63b76a85893335044 supplies the first authorization scope, with no promotion or runtime effect. The claim/read precursor and later true temporal child are separate milestones. #178's first Delivery covers the common protocol with one real claim consumer; integration of all other command families remains open here. No child may close on stubs or absorb an independent authority. The original broader M1 outcomes and acceptance criteria remain unchanged.

The wider programme dependency spine above is not a requirement to complete the whole #175 epic before the amended first #178 delivery. Use the concrete authorization, identity, representation and source capabilities required by that consumer. Provider and write/read transaction producers must have a valid ordering before implementation; do not replace the broad epic edge with a cyclic blanket #353 edge.

#353 still needs complete selected-rule coverage, canonical binding/promotion/extraction and real input/read/guard producers. #178 retains common identity, atomic result, single use, truthful recovery and current disclosure limits. The later #176 child must prove independent valid/knowledge cuts; ordinary readback or retry does not complete it. CP2A-DEP01 and the unresolved history proof remain open. This note changes no checkbox, other child scope, deployment gate or parked programme.

What is next: align and review existing #359's first-release design and settle real producer ordering; do not close this epic or start implementation from this note.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    tracking-epicProgramme containing multiple independently reviewable capabilities; owns no implementation PR.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions