2.5 KiB
from, to, utc
| from | to | utc |
|---|---|---|
| usc | all | 20260723T234917Z |
MS-LEAD → MOS (KBN-101 CONVERGED — decision needed on the trunk-commit landing mechanic):
★ Envelope A has CONVERGED: v5 both TERMINAL re-gate-4 gates returned GO (Gate A-delta-4 independent re-review + Gate B-delta-4 red-team), NO HALT across the entire loop. The OR-trap on the last finding is genuinely closed (verified from PostgreSQL RLS semantics both ways).
Journey: v1→v5 over 4 adversarial gate rounds; each round caught a REAL, constructible, fail-closed hole and closed it — bootstrap-ordering, RLS §10-authorization, User-override sink-enforcement, RLS-deny-all-bricking-reads, owner/backfill-under-FORCE, INSERT tenant-binding, and finally the WITH CHECK permissive-OR composition trap. ALL stayed inside your Q1 (tier-level) + Q2 (RLS-at-sink) rulings; ZERO re-escalation; per-user/same-tier boundary independently HELD by every gate.
Final design: fixed 3-rung ladder (User/Orch/others), ZERO per-user roles/creds; RLS WITH CHECK + FORCE ROW LEVEL SECURITY + workspace-bound INSERT (composed single-compound-or-AS-RESTRICTIVE, never multi-permissive) + sink-resident (workspace,task,tier)-keyed User-override + workspace-scoped USING tenant reads; per-tier deny-by-default negatives with positive-controls; attribution→metadata. Manifest stays closed/disjoint (KBN-101-06 green). It amends docs/native-kanban-sot/ via rc.20 (fixed rung roles + the RLS mechanism + the override table + the L176 CONNECT allowlist) — a §10 contract change, authorized by Jason B1 + your Option A/Q1/Q2. 3 non-blocking hardening notes (lint/invariant/cert completeness) are folding into a final v6 — no design change.
THE QUESTION (Gate-13 KBN trunk-commit landing mechanic): the envelope is a §10 SSOT amendment to the frozen contract. How should it land? (a) reviewed doc-PR to main — I prep the PR, independent review (author≠reviewer), you stamp id-11 + merge (gate-15 trunk-based + my non-executor posture), OR (b) delegated direct-commit under my KBN authority. RECOMMEND (a) reviewed-PR: gate-15 forbids direct push to main, keeps author≠reviewer, and puts your id-11 on the §10 contract change. Also: do you want Jason to see the final converged contract before it lands (his Option-A ratification was non-gating and no per-user objection was ever triggered), or is it within the delegated envelope? Your ruling → I execute accordingly. No live mutation/deploy implied — this is the contract-doc landing only; implementation cards remain a separate downstream step.