Files
stack/docs/remediation/GATE-CLAIMS.md
coder-mos2 e910a45ab3
ci/woodpecker/pr/ci Pipeline was successful
fix(rm-02): narrow inventory drift guarantee
2026-08-01 15:09:57 -05:00

2.0 KiB

RM-02 Governing Claim Index

This index binds remediation claims that live in orchestrator-owned TASKS.md without modifying that file. The source heading and quoted text are the reviewable anchor; gate:verify enforces each marker-to-criterion binding. Marker completeness beyond this approved slice remains RM-54.

Prose is an enforceable claim

  • Source: docs/remediation/TASKS.md, heading D-20 — the orchestrator's own documentation overclaimed, and a reviewer disproved it empirically.
  • Anchored text: “The defect was not in the code — it was in this file.”

Generated-state verification scope

  • Source: docs/remediation/TASKS.md, heading D-19 — an integrity property that cannot exist at the layer it was specified.
  • Anchored text: “a verifier that cannot detect the attack is not a verifier.”

Execution trust boundary

  • Source: RM-02 ruling recorded under docs/remediation/TASKS.md, RM-02 clause 4, D-25.
  • Anchored text: “SELF-VERIFICATION BY THE AUDITED PARTY IS NOT VERIFICATION.”
  • Dependency: RM-60/#1031, cross-referenced with RM-59.

Same-checkout inventory drift boundary

  • Source: RM-02 ruling after D-48/CWE-353 reproduced against the round-4 baseline.
  • Boundary: Detects accidental and incompetent inventory drift within a checkout; does NOT survive an adversary who rewrites baseline, manifest, and verifier consistently — that guarantee requires RM-60's external boundary.
  • Negative control: checkout-preflight/inventory-claim-overstatement rewrites the boundary as protection and must go red.

Criterion restatement provenance

  • Source: docs/remediation/TASKS.md, heading D-18 — two pre-registered criteria were mutually unsatisfiable, discoverable only at implementation.
  • Anchored text: “Both criteria were pre-registered. They cannot both be satisfied.”