docs(architecture): define effective capability at consuming boundaries - #91909
docs(architecture): define effective capability at consuming boundaries#91909andrexibiza wants to merge 2 commits into
Conversation
Exact-head verification snapshotVerified against PR head
No runtime, generated artifact, dependency, schema, or configuration surface is changed. |
|
Closure receipt at exact current head |
Docs-only ADR + contract ( Suggestions:
The non-goals section (no speculative probing, no process-global registry, recovery may obtain fresh proofs) is well scoped. |
What does this PR do?
Defines the cross-cutting rule that configured intent cannot impersonate current effective capability.
The new contract separates the full capability lifecycle:
It requires the component that owns the side effect to obtain or revalidate an exact, scope-bound proof at the consuming boundary and to consume it atomically with the effect. It also keeps optional absence, denial, ambiguity, unavailability, and staleness distinct, and preserves the separate settlement obligation after an operation is exercised.
This is deliberately a semantic contract rather than a premature universal runtime class. Existing subsystem owners retain their native proof types and implementation topology.
Related Issue
Composes the existing architecture owners rather than opening or closing a duplicate umbrella:
Concrete evidence: #91695, #91720, and #91828.
Type of Change
Changes Made
docs/effective-capability-contract.mddocs/ADR.mdHow to Test
mainatb6bcb3e791c673e63974029bbab40cc9326803ff.docs/ADR.mdanddocs/effective-capability-contract.md.No runtime, configuration, schema, dependency, or generated artifact changes are present.
Checklist
Code
Documentation & Housekeeping
cli-config.yaml.exampleis N/A; no config keys changedCONTRIBUTING.mdandAGENTS.mdare unchanged; no contributor workflow is changedArchitecture issue receipts
Exact object
b6bcb3e791c673e63974029bbab40cc9326803ff3a4e1ba23be41ff81045fabc51f5955be3e292fc