align skills with additive project policy
This commit is contained in:
@@ -40,9 +40,11 @@ changes belong to Ink's repository authority and implementation workflow.
|
||||
installed artifact identity and a demonstrably matching checkout's specification,
|
||||
tests, public help text, and source; label those findings as contract/source
|
||||
evidence rather than executed runtime proof.
|
||||
- Global and project policy files explain only their contribution. Effective
|
||||
authority also depends on all policy layers, pinned executable and contract
|
||||
bytes, startup freezing, and session decisions.
|
||||
- Approved global and ancestor-project rows are additive alternatives; each file
|
||||
explains only its contribution. Effective authority also depends on the approved
|
||||
normalized digest, restrictive child/session policy, the host floor, pinned
|
||||
executable and contract bytes, startup freezing, and session decisions. Never
|
||||
interpret a project file as automatically trusted.
|
||||
- Treat handovers, READMEs, examples, hidden source branches, and remembered argv
|
||||
as leads. Public help owns operator-facing commands; the specification owns intended
|
||||
behavior; tests and source establish current checkout behavior.
|
||||
|
||||
@@ -83,7 +83,8 @@ policy. Therefore:
|
||||
those are already sufficient.
|
||||
|
||||
This gate may be removed only after the provider launch path proves that the
|
||||
referenced bytes are pinned and conjoined into the child effective policy.
|
||||
referenced bytes are pinned and applied as a restriction to the child's inherited
|
||||
approved durable policy.
|
||||
|
||||
## Decision loop
|
||||
|
||||
@@ -107,8 +108,8 @@ referenced bytes are pinned and conjoined into the child effective policy.
|
||||
## Behavior smoke
|
||||
|
||||
Positive: “Create a frontend writer child with only formatter and file mutation
|
||||
authority” loads this skill and blocks until the named policy is actually
|
||||
conjoined or the parent frozen policy already supplies that exact boundary.
|
||||
authority” loads this skill and blocks until the named restrictive policy is
|
||||
actually enforced or the parent frozen policy already supplies that exact boundary.
|
||||
|
||||
Negative: “Ask the existing reviewer to inspect this diff” does not load this
|
||||
skill; it is ordinary delegation.
|
||||
|
||||
@@ -194,7 +194,9 @@ exits, environment/config precedence, credential timing, dependencies, pattern
|
||||
semantics, and one realistic pipeline. Explicit help succeeds on stdout; usage
|
||||
errors fail on stderr. Selector help gives value grammar, canonicalization, and a
|
||||
least-authority policy row, including AND within one row and alternatives across
|
||||
rows.
|
||||
approved global and ancestor-project rows. Project rows are not automatically
|
||||
trusted: Ink freezes the normalized effective policy and requires digest approval;
|
||||
child/session policy and the host floor may only narrow it.
|
||||
|
||||
Keep argv unsurprising: options before operands, `--` ends options, `-` denotes a
|
||||
natural stream, secrets never enter argv, and unknown, incompatible, or trailing
|
||||
|
||||
Reference in New Issue
Block a user