merge: security track group 2 — the protocol namespace replaces ServiceId

# Conflicts:
#	docs/security-track-plan.md
This commit is contained in:
Daniel Samson
2026-08-01 04:45:14 +01:00
73 changed files with 3925 additions and 364 deletions
+5 -5
View File
@@ -36,10 +36,10 @@ plain `main` checkout always tells the truth about where the work is.**
| | |
|---|---|
| Working on | **P3** — green at 109/109, adversarial review running, not yet committed |
| Branch carrying it | `feat/security-group-2` (pushed to origin) |
| On `main` | through the group 1 merge (`f3bc23c`): Phase 0, PM, H1 |
| Committed on the branch, awaiting the group 2 merge | P1 (`1ff0991`), P2 (`1379b69`) |
| Working on | **P4a** — protocol rebase onto `envelope.Define` |
| Branch carrying it | `feat/security-group-3` (cut next) |
| On `main` | Phase 0, PM, H1, P1, P2, P3 — groups 1 and 2 merged |
| Awaiting merge | nothing |
| Suite | 109 cases, all passing |
| Last updated | 2026-08-01 |
@@ -64,7 +64,7 @@ group boundary.
the manifest gained a third permission, `supervise`, which names an authorized
supervising task per contract and is deliberately **open-only**, leaving P2's
bind attestation and every refusal it makes untouched (suite 109/109)
- [ ] **merge** group 2 → main, push
- [x] **merge** group 2 → main, push
- [ ] **P4a** — clean protocols rebased onto `Define` (vfs, block, display, scanout, input)
- [ ] **P4b** — misfit protocols rebased (device-manager, power, usb-transfer)
- [ ] **P4c** — harness subscriber lift + badge-scoped per-client integers