Problem and corrected trust boundary
#168–#172 established that Python object-construction/module/closure history cannot serve as unforgeable policy authority against arbitrary same-interpreter code. The service TCB is explicit: Keyverse owns authenticated identity/scopes; trusted Orgmetra composition/policy sources own HR authorization policy; request/model/plugin-controlled values do not. Policy/request values are revalidated and detached before evaluation, and AuthorizationDecision is PII-minimized validated data with a durable-consumer revalidation contract—not a same-process capability.
Canonical #65 exports validate_authorization_decision(...) and reconstructs an exact validated decision before durable DB authority. Current #65 remains 1caf8f760e81f1cb6954fdf1d0d13a46dbb6c0b1 on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.
Single-writer reconciliation
Canonical generic People owner #64 is now 8f986853a6f234c317e29080c4982bab34f3dc51 from the same protected base. #64/#65 overlap on hire.py, mutations.py, postgres_hire.py, and postgres_mutations.py; the overlap remains a repair finding, not a close condition.
#64 owns #215–#233 generic People/hire runtime/API-contract integrity. #229 binds exact results to pre-port target snapshots; #230 detaches direct PostgreSQL commands; #231 detaches application commands before purpose-bound callbacks; #232 requires exact built-in Assignment allocation text; #233 now aligns the public parser/OpenAPI contract with the authoritative strictly-positive (0, 1.0000] Assignment invariant and reseals deterministic manifest evidence. The #233 source repair is complete on mutable #64 but its exact hosted/security/review evidence is still non-terminal.
#63 shared-kernel exact Foundation CI is now terminal success after its predecessor 218-test/99.43%-coverage RED and three-branch test repair; remaining gates still control integration.
A further overlapping descendant is now explicit: #141 contains a valid employing-legal-Organization feature, is Draft/non-mergeable on an old base, and edits People, authorization and OpenAPI files also owned by #64/#65. It must not overwrite the owner stack.
Safe order is #63 normal integration → #64 normal integration → #65 non-force adopts protected #64 preserving #229–#233 plus authorization-decision validation and reacquires exact evidence → #141 non-force adopts resulting protected owner truth preserving its legal-employer feature → Assignment descendants adopt protected truth.
Keep #172 open until #65 reconciliation is normally integrated or a verified successor fully carries both invariant sets. Do not retarget onto mutable sibling heads, copy mutable source, force-push/rebase, self-approve, administrator-bypass, weaken gates, or transfer predecessor evidence.
Problem and corrected trust boundary
#168–#172 established that Python object-construction/module/closure history cannot serve as unforgeable policy authority against arbitrary same-interpreter code. The service TCB is explicit: Keyverse owns authenticated identity/scopes; trusted Orgmetra composition/policy sources own HR authorization policy; request/model/plugin-controlled values do not. Policy/request values are revalidated and detached before evaluation, and
AuthorizationDecisionis PII-minimized validated data with a durable-consumer revalidation contract—not a same-process capability.Canonical #65 exports
validate_authorization_decision(...)and reconstructs an exact validated decision before durable DB authority. Current #65 remains1caf8f760e81f1cb6954fdf1d0d13a46dbb6c0b1on protecteddevelop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.Single-writer reconciliation
Canonical generic People owner #64 is now
8f986853a6f234c317e29080c4982bab34f3dc51from the same protected base. #64/#65 overlap onhire.py,mutations.py,postgres_hire.py, andpostgres_mutations.py; the overlap remains a repair finding, not a close condition.#64 owns #215–#233 generic People/hire runtime/API-contract integrity. #229 binds exact results to pre-port target snapshots; #230 detaches direct PostgreSQL commands; #231 detaches application commands before purpose-bound callbacks; #232 requires exact built-in Assignment allocation text; #233 now aligns the public parser/OpenAPI contract with the authoritative strictly-positive
(0, 1.0000]Assignment invariant and reseals deterministic manifest evidence. The #233 source repair is complete on mutable #64 but its exact hosted/security/review evidence is still non-terminal.#63 shared-kernel exact Foundation CI is now terminal success after its predecessor 218-test/99.43%-coverage RED and three-branch test repair; remaining gates still control integration.
A further overlapping descendant is now explicit: #141 contains a valid employing-legal-Organization feature, is Draft/non-mergeable on an old base, and edits People, authorization and OpenAPI files also owned by #64/#65. It must not overwrite the owner stack.
Safe order is #63 normal integration → #64 normal integration → #65 non-force adopts protected #64 preserving #229–#233 plus authorization-decision validation and reacquires exact evidence → #141 non-force adopts resulting protected owner truth preserving its legal-employer feature → Assignment descendants adopt protected truth.
Keep #172 open until #65 reconciliation is normally integrated or a verified successor fully carries both invariant sets. Do not retarget onto mutable sibling heads, copy mutable source, force-push/rebase, self-approve, administrator-bypass, weaken gates, or transfer predecessor evidence.