docs(1234): close by deciding not to wire; nine baseline pairs are permanent - #1424
Merged
Merged
Conversation
…rmanent #1234's retirement half shipped in #1391; its wiring half was deferred 2026-09-19 after adversarial review and is now closed as a decision rather than a backlog item. The alternative that deferral named (`psk_file`) was filed as #1408 and closed too. `trace-link-baseline.txt`'s header said those nine pairs were "blocked on #1234" and listed REQ-CTL-04 "so that the day #1234 lands and it flips to enforced, it does not fail on arrival". That day is not coming, so the statement is false and is corrected in place — a retraction only in the ledger is not a retraction. Left alone deliberately: `inert_psk_key_id_warning` still says keystore-backed PSK loading is not implemented (#1234), which is true, and a closed issue carrying the decision is now the right pointer rather than a promise. REQ-CTL-04's registered statement keeps "No production consumer yet (#1234)" — also still true. Verification-objective: a baseline entry's stated reason must describe why it is there now, not a resolution that has been decided against Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0188ATCj6DZ9aRVQ2vSirua6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to closing #1234 (issue closed 2026-09-20 by maintainer decision, not by implementation).
#1234's retirement half shipped in #1391; its wiring half was deferred 2026-09-19 after adversarial
review and is now closed as a decision rather than a backlog item. The alternative that deferral
named —
[control_security] psk_file— was filed as #1408 and closed too, its one argument havingturned out to be false.
The correction
docs/dev/project/trace-link-baseline.txtdescribed nine of its fifteen pairs as "Blocked on#1234" and listed REQ-CTL-04 "so that the day #1234 lands and it flips to
enforced, it does notfail on arrival."
That day is not coming, so both statements are now false. I wrote them yesterday, in #1420. They are
corrected in place — a retraction that lives only in a ledger is not a retraction.
The header now says the nine are permanent, not pending, gives the three reasons the wiring stays
unbuilt, and names the only thing that would take them off the list: a real keystore consumer, whose
criterion from this thread is multi-secret storage (identity key, trust store) — not a PSK.
Left alone deliberately
inert_psk_key_id_warning(server.rs:2062) keeps its text. "Keystore-backed PSK loading isnot implemented (openpulse-keystore has no consumer: wire the keystore-backed PSK loading that server.rs promises (blocks REQ-CTL-03) #1234)" is still true, and a closed issue carrying the decision record is now the
right pointer rather than a promise that it will be. A test asserts on that string, so changing
it would be a code change in a docs sweep.
true, and
requirements.yamlis a tier-2 decision site that would demand its own review artifactfor the sake of one word the closed issue already supplies.
Scope
Docs-only, verified by filename rather than by intent (
git diff --name-only origin/main...HEADreturns nothing outside
docs/) — #1419's lesson, where a "docs-only" PR carriedengine.rsbecausethe branch had been cut from a code branch.
The ratchet is unaffected:
TRACE: PASS — 15 grandfathered unlinkable scope pair(s) (0 new, 0 stale).Only comments changed; no baseline entry moved.
Test results
Verification-objective: a baseline entry's stated reason must describe why it is there now, not a
resolution that has been decided against
Review: none — mechanical correction of statements a maintainer decision made false; the decision
itself was reviewed in docs/dev/reviews/review-1234-keystore-writer.md and recorded on #1234.
🤖 Generated with Claude Code
https://claude.ai/code/session_0188ATCj6DZ9aRVQ2vSirua6