Skip to content

docs: TRUST-DEFAULTS-POLICY and the trust/adjust defaults handover prompt - #713

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/trust-adjust-defaults-handover
Sep 2, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
docs/trust-adjust-defaults-handover

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Adds the 2026-09-02 Trustfile/Adjustfile defaults policy and the handover prompt for the session that owns the accessibility policy, exemplar Trustfile, PORT-REGISTRY prose and the template strip family. Both files existed only on one machine until now.

🤖 Generated with Claude Code

…r prompt

TRUST-DEFAULTS-POLICY.adoc codifies the 2026-09-02 ruling that every repo
ships best-of-best security defaults (Trustfile) and accessibility
defaults (Adjustfile), blanked only through `just strip-rsr-defaults`.
It carries the DNS/email/TLS/PQ control list, the headers ratchet, the
permissions dead man's handle, the badge rule and the robustifier split.

docs/handover/2026-09-02-trust-adjust-defaults-session-prompt.adoc is the
prompt for the separate session that owns the accessibility policy, the
exemplar Trustfile gap-fill, the PORT-REGISTRY prose and the template
strip family. Both files existed only on one machine until this commit.
@hyperpolymath
hyperpolymath merged commit 33c8d5f into main Sep 2, 2026
42 of 43 checks passed
@hyperpolymath
hyperpolymath deleted the docs/trust-adjust-defaults-handover branch September 2, 2026 08:58
@sonarqubecloud

sonarqubecloud Bot commented Sep 2, 2026

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: bca28c3e-d67d-494d-938d-73d712128f83

📥 Commits

Reviewing files that changed from the base of the PR and between 0ef5917 and 7bd29a3.

📒 Files selected for processing (2)
  • TRUST-DEFAULTS-POLICY.adoc
  • docs/handover/2026-09-02-trust-adjust-defaults-session-prompt.adoc

📝 Summary

Summary by CodeRabbit

  • Documentation
    • Added a comprehensive “Trust Defaults” policy documenting security standards for network, host, container, web, DNS, TLS, tooling, encryption, supply-chain tracking and infrastructure configuration.
    • Documented offline verification boundaries, standing exceptions, control-plane references and procedures for safely restoring or stripping defaults.
    • Added a self-contained session prompt covering trust and accessibility standards, verification steps, repository constraints, reporting requirements and approval boundaries.

Walkthrough

The change adds a 879-line Trust Defaults security policy. It defines defaults, verification states, removal and restoration controls, enforcement mechanisms, supply-chain requirements, and authority-watch governance. A handover prompt records the remaining standards-repository and template work.

Changes

Trust Defaults contract

Layer / File(s) Summary
Core network and web defaults
TRUST-DEFAULTS-POLICY.adoc
Defines governing principles, network controls, host and container hardening, HTTPS requirements, web headers, required paths, and server baselines.
DNS, cryptography, and infrastructure standards
TRUST-DEFAULTS-POLICY.adoc
Defines DNS records and topology, resolver transports, Cloudflare workflows, TLS and post-quantum rules, toolchain updates, shell defaults, and preferred infrastructure.
Authority review and default lifecycle
TRUST-DEFAULTS-POLICY.adoc
Defines authority-watch profiles, control-plane keys, default stripping and restoration, verification statuses, and standing exceptions.
Repository enforcement controls
TRUST-DEFAULTS-POLICY.adoc
Defines the security-header grant ratchet, permission-state handle, badge rules, self-checks, encryption-at-rest controls, supply-chain tracking, and rsr-robustifier.
Standards implementation handover
docs/handover/2026-09-02-trust-adjust-defaults-session-prompt.adoc
Records repository context, remaining policy and template work, verification procedures, issue drafting, memory updates, and execution constraints.

Estimated code review effort: 4 (Complex) | ~60 minutes

Poem

I am a rabbit with defaults in tow
I check each small gate before I go
DNS hums softly, keys shine bright
Headers stand ready through the night
I thump for safe restores, then hop home fine


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant