2.0 KiB
2.0 KiB
RM-02 Governing Claim Index
This index binds remediation claims that live in orchestrator-owned TASKS.md without modifying that file. The source heading and quoted text are the reviewable anchor; gate:verify enforces each marker-to-criterion binding. Marker completeness beyond this approved slice remains RM-54.
Prose is an enforceable claim
- Source:
docs/remediation/TASKS.md, headingD-20 — the orchestrator's own documentation overclaimed, and a reviewer disproved it empirically. - Anchored text: “The defect was not in the code — it was in this file.”
Generated-state verification scope
- Source:
docs/remediation/TASKS.md, headingD-19 — an integrity property that cannot exist at the layer it was specified. - Anchored text: “a verifier that cannot detect the attack is not a verifier.”
Execution trust boundary
- Source: RM-02 ruling recorded under
docs/remediation/TASKS.md, RM-02 clause 4, D-25. - Anchored text: “SELF-VERIFICATION BY THE AUDITED PARTY IS NOT VERIFICATION.”
- Dependency: RM-60/#1031, cross-referenced with RM-59.
Same-checkout inventory drift boundary
- Source: RM-02 ruling after D-48/CWE-353 reproduced against the round-4 baseline.
- Boundary: Detects accidental and incompetent inventory drift within a checkout; does NOT survive an adversary who rewrites baseline, manifest, and verifier consistently — that guarantee requires RM-60's external boundary.
- Negative control:
checkout-preflight/inventory-claim-overstatementrewrites the boundary as protection and must go red.
Criterion restatement provenance
- Source:
docs/remediation/TASKS.md, headingD-18 — two pre-registered criteria were mutually unsatisfiable, discoverable only at implementation. - Anchored text: “Both criteria were pre-registered. They cannot both be satisfied.”