Files
hq/04-ISSUES/003-firewall-scope-is-read-by-no-code/00-report.md
T
jschoubben c0b35652d0 The numbering is the flow: decisions are 02, design is 03
papa-hq reads 01 research -> 03 decision -> 02 design. The order is a
scar, not a choice: 02-DESIGN existed from its initial commit, and when
adr/ was finally promoted on 2026-07-13 it took the next free number
rather than its place in the sequence. By then design was too settled to
renumber.

hal-hq was three commits old, so it is not. adr/ becomes 02-DECISIONS and
02-DESIGN becomes 03-DESIGN, and following the folder numbers now walks
the process in the order it happens: research produces a decision, the
decision authorises a design.

00-GENESIS becomes 00-META, matching papa's rename from the same
restructure.

Every path reference rewritten across documents, frontmatter, playbooks
and skills. All links resolve; all 58 frontmatter blocks parse and their
path fields still point at files that exist.
2026-08-23 18:05:11 +02:00

1.4 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
open 2026-08-22

003 — A firewall rule's scope: is read by no code

Symptom

Five module manifests declare a scope: key on firewall rules. The key is not part of the firewall rule type and nothing reads it. Real scoping is expressed by a different field.

A manifest can therefore appear to restrict a port and restrict nothing.

Why this matters

This is the failure mode how-we-build.md names directly: an unenforced rule is indistinguishable from a wrong one, and costs more, because people believe it. Here it is worse than unenforced — the declaration reads as a restriction, so a reviewer checking whether a port is scoped will find that it is, and be wrong.

It also says something about the manifest as a whole: an unknown key is accepted silently. Any misspelled or invented key behaves this way, and this one was found by reading rather than by any check.

Evidence

  • Five manifests carry the key. Zero code paths consume it.
  • Recorded as an observation on 2026-08-22.

Open questions

  • Should the manifest reject unknown keys outright? That is the general fix; this is one instance of it.
  • Were the five declarations intended to restrict something that is currently open? Each needs checking against what the node actually exposes — the declaration cannot be trusted either way.