Two vectors for checks no vector reached: clearance, and a stale grant - #1
Merged
Merged
Conversation
Every assertion had a mutant of its own and every mutant was caught, yet two checks each implementation makes were never exercised: refusing a principal whose clearance is below the capability's sensitivity, and refusing a grant used after the data it was issued for changed. An implementation without either passed all fifteen vectors. ad-004-clearance-refusal-has-no-grant entitles a principal to a capability above their clearance and expects CLASSIFICATION_EXCEEDS_ CLEARANCE with no grant; ad-003-stale-grant-executes-nothing changes the revision between a grant and its use across the MCP boundary and expects nothing to run. Two mutants remove the checks (clearance-ignored, stale-grants-accepted): against the fifteen original vectors neither is caught; with the two new ones each is caught by its named assertion. The fifteen original vectors are unchanged. All nine subjects conform (17 vectors, 90 steps); 19/19 mutants caught by their target. Run outputs regenerated with the frameworks current today; counts in the README, claims, results, portability and findings updated, and F-012 records the gap.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Every assertion had a mutant of its own and every mutant was caught, yet two checks each implementation makes were never exercised by any vector:
CLASSIFICATION_EXCEEDS_CLEARANCE). Each refusal in the AD-004 vector is decided before clearance is reached.An implementation without either check passed all fifteen vectors.
The change
ad-004-clearance-refusal-has-no-grant:grantthe analystdetect_outliers(confidential, above their internal clearance), then request it. ExpectsREFUSED,CLASSIFICATION_EXCEEDS_CLEARANCE,AD-POL-006, no grant, nothing executed.ad-003-stale-grant-executes-nothing: a granted request, thenset_revision, then an MCPdelegateunder the earlier grant. Expects nothing executed and an error naming the revision.clearance-ignored(M07) andstale-grants-accepted(M05), each removing one of the checks.The fifteen original vector files are unchanged, so v0.1.0 as released is unaffected. This adds to the suite; it does not revise it.
Evidence
clearance-ignoredstale-grants-acceptedpytest: 407 passed. The run outputs indocs/runs/are regenerated with the frameworks current today (versions inversions.txt). The counts are updated in the README, CLAIMS, RESULTS, PORTABILITY and the package README. RESULTS keeps its 2026-09-01 figures for everything not re-measured and dates the new ones. F-012 records the gap.RELEASE.mdstill says 17/17, as history. A release that ships the new vectors would say 19/19.