align skills with additive project policy

This commit is contained in:
tmk241
2026-08-16 22:14:57 +02:00
parent f6d0efdfc0
commit 92a2849376
5 changed files with 25 additions and 7 deletions
+5 -3
View File
@@ -40,9 +40,11 @@ changes belong to Ink's repository authority and implementation workflow.
installed artifact identity and a demonstrably matching checkout's specification,
tests, public help text, and source; label those findings as contract/source
evidence rather than executed runtime proof.
- Global and project policy files explain only their contribution. Effective
authority also depends on all policy layers, pinned executable and contract
bytes, startup freezing, and session decisions.
- Approved global and ancestor-project rows are additive alternatives; each file
explains only its contribution. Effective authority also depends on the approved
normalized digest, restrictive child/session policy, the host floor, pinned
executable and contract bytes, startup freezing, and session decisions. Never
interpret a project file as automatically trusted.
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
as leads. Public help owns operator-facing commands; the specification owns intended
behavior; tests and source establish current checkout behavior.
+4 -3
View File
@@ -83,7 +83,8 @@ policy. Therefore:
those are already sufficient.
This gate may be removed only after the provider launch path proves that the
referenced bytes are pinned and conjoined into the child effective policy.
referenced bytes are pinned and applied as a restriction to the child's inherited
approved durable policy.
## Decision loop
@@ -107,8 +108,8 @@ referenced bytes are pinned and conjoined into the child effective policy.
## Behavior smoke
Positive: “Create a frontend writer child with only formatter and file mutation
authority” loads this skill and blocks until the named policy is actually
conjoined or the parent frozen policy already supplies that exact boundary.
authority” loads this skill and blocks until the named restrictive policy is
actually enforced or the parent frozen policy already supplies that exact boundary.
Negative: “Ask the existing reviewer to inspect this diff” does not load this
skill; it is ordinary delegation.
+3 -1
View File
@@ -194,7 +194,9 @@ exits, environment/config precedence, credential timing, dependencies, pattern
semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage
errors fail on stderr. Selector help gives value grammar, canonicalization, and a
least-authority policy row, including AND within one row and alternatives across
rows.
approved global and ancestor-project rows. Project rows are not automatically
trusted: Ink freezes the normalized effective policy and requires digest approval;
child/session policy and the host floor may only narrow it.
Keep argv unsurprising: options before operands, `--` ends options, `-` denotes a
natural stream, secrets never enter argv, and unknown, incompatible, or trailing