Files
stack/docs/remediation/GATE-CLAIMS.md
coder-mos2 e910a45ab3
ci/woodpecker/pr/ci Pipeline was successful
fix(rm-02): narrow inventory drift guarantee
2026-08-01 15:09:57 -05:00

41 lines
2.0 KiB
Markdown

# RM-02 Governing Claim Index
This index binds remediation claims that live in orchestrator-owned `TASKS.md` without modifying that file. The source heading and quoted text are the reviewable anchor; `gate:verify` enforces each marker-to-criterion binding. Marker completeness beyond this approved slice remains RM-54.
## Prose is an enforceable claim
<!-- GATE-CLAIM:PROSE-IS-A-CLAIM -->
- Source: `docs/remediation/TASKS.md`, heading `D-20 — the orchestrator's own documentation overclaimed, and a reviewer disproved it empirically`.
- Anchored text: “The defect was not in the code — it was in this file.”
## Generated-state verification scope
<!-- GATE-CLAIM:GENERATED-STATE-SCOPE -->
- Source: `docs/remediation/TASKS.md`, heading `D-19 — an integrity property that cannot exist at the layer it was specified`.
- Anchored text: “a verifier that cannot detect the attack is not a verifier.”
## Execution trust boundary
<!-- GATE-CLAIM:EXECUTION-TRUST-BOUNDARY -->
- Source: RM-02 ruling recorded under `docs/remediation/TASKS.md`, RM-02 clause 4, D-25.
- Anchored text: “SELF-VERIFICATION BY THE AUDITED PARTY IS NOT VERIFICATION.”
- Dependency: RM-60/#1031, cross-referenced with RM-59.
## Same-checkout inventory drift boundary
<!-- GATE-CLAIM:INVENTORY-DRIFT-BOUNDARY -->
- Source: RM-02 ruling after D-48/CWE-353 reproduced against the round-4 baseline.
- Boundary: Detects accidental and incompetent inventory drift within a checkout; does NOT survive an adversary who rewrites baseline, manifest, and verifier consistently — that guarantee requires RM-60's external boundary.
- Negative control: `checkout-preflight/inventory-claim-overstatement` rewrites the boundary as protection and must go red.
## Criterion restatement provenance
<!-- GATE-CLAIM:CRITERION-RESTATEMENT -->
- Source: `docs/remediation/TASKS.md`, heading `D-18 — two pre-registered criteria were mutually unsatisfiable, discoverable only at implementation`.
- Anchored text: “Both criteria were pre-registered. They cannot both be satisfied.”