--- status: open opened: 2026-08-22 located-in: [] fixed-by: amended-design: --- # 003 — A firewall rule's `scope:` is read by no code ## Symptom Five module manifests declare a `scope:` key on firewall rules. The key is not part of the firewall rule type and nothing reads it. Real scoping is expressed by a different field. A manifest can therefore appear to restrict a port and restrict nothing. ## Why this matters This is the failure mode [`how-we-build.md`](../../00-GENESIS/how-we-build.md) names directly: *an unenforced rule is indistinguishable from a wrong one, and costs more, because people believe it.* Here it is worse than unenforced — the declaration reads as a restriction, so a reviewer checking whether a port is scoped will find that it is, and be wrong. It also says something about the manifest as a whole: an unknown key is accepted silently. Any misspelled or invented key behaves this way, and this one was found by reading rather than by any check. ## Evidence - Five manifests carry the key. Zero code paths consume it. - Recorded as an observation on 2026-08-22. ## Open questions - Should the manifest reject unknown keys outright? That is the general fix; this is one instance of it. - Were the five declarations intended to restrict something that is currently open? Each needs checking against what the node actually exposes — the declaration cannot be trusted either way.