papa-hq reads 01 research -> 03 decision -> 02 design. The order is a scar, not a choice: 02-DESIGN existed from its initial commit, and when adr/ was finally promoted on 2026-07-13 it took the next free number rather than its place in the sequence. By then design was too settled to renumber. hal-hq was three commits old, so it is not. adr/ becomes 02-DECISIONS and 02-DESIGN becomes 03-DESIGN, and following the folder numbers now walks the process in the order it happens: research produces a decision, the decision authorises a design. 00-GENESIS becomes 00-META, matching papa's rename from the same restructure. Every path reference rewritten across documents, frontmatter, playbooks and skills. All links resolve; all 58 frontmatter blocks parse and their path fields still point at files that exist.
41 lines
1.4 KiB
Markdown
41 lines
1.4 KiB
Markdown
---
|
|
status: open
|
|
opened: 2026-08-22
|
|
located-in: []
|
|
fixed-by:
|
|
amended-design:
|
|
---
|
|
|
|
# 003 — A firewall rule's `scope:` is read by no code
|
|
|
|
## Symptom
|
|
|
|
Five module manifests declare a `scope:` key on firewall rules. The key is not part of the
|
|
firewall rule type and nothing reads it. Real scoping is expressed by a different field.
|
|
|
|
A manifest can therefore appear to restrict a port and restrict nothing.
|
|
|
|
## Why this matters
|
|
|
|
This is the failure mode [`how-we-build.md`](../../00-META/how-we-build.md) names directly:
|
|
*an unenforced rule is indistinguishable from a wrong one, and costs more, because people
|
|
believe it.* Here it is worse than unenforced — the declaration reads as a restriction, so a
|
|
reviewer checking whether a port is scoped will find that it is, and be wrong.
|
|
|
|
It also says something about the manifest as a whole: an unknown key is accepted silently. Any
|
|
misspelled or invented key behaves this way, and this one was found by reading rather than by
|
|
any check.
|
|
|
|
## Evidence
|
|
|
|
- Five manifests carry the key. Zero code paths consume it.
|
|
- Recorded as an observation on 2026-08-22.
|
|
|
|
## Open questions
|
|
|
|
- Should the manifest reject unknown keys outright? That is the general fix; this is one
|
|
instance of it.
|
|
- Were the five declarations intended to restrict something that is currently open? Each needs
|
|
checking against what the node actually exposes — the declaration cannot be trusted either
|
|
way.
|