Initial server source import
This commit is contained in:
+97
@@ -0,0 +1,97 @@
|
||||
## ADDED Requirements
|
||||
|
||||
### Requirement: Reviewed rank-one breadth authority
|
||||
The system SHALL support a code-pinned rank-one breadth profile of 61 ordered
|
||||
queries, at most 39 owned repositories per query, one image per repository, and
|
||||
exactly 2,000 unique physical repository selections and target slots. It SHALL
|
||||
reject arbitrary limit combinations and SHALL preserve the existing depth
|
||||
profile unchanged.
|
||||
|
||||
#### Scenario: Breadth profile is valid
|
||||
- **WHEN** configuration supplies the exact reviewed breadth selector and limits
|
||||
- **THEN** validation SHALL produce a distinct immutable authority hash with a physical target ceiling of 2,000
|
||||
|
||||
#### Scenario: Profile limits are mixed
|
||||
- **WHEN** configuration combines a selector or limit from different reviewed profiles
|
||||
- **THEN** startup SHALL fail before secrets, database mutation, network work, or workers initialize
|
||||
|
||||
#### Scenario: Prior authority is not released
|
||||
- **WHEN** another Docker experiment is nonterminal, unreleased, or fenced
|
||||
- **THEN** breadth cohort application and activation SHALL fail without changing either experiment
|
||||
|
||||
### Requirement: Exact balanced physical cohort
|
||||
The system SHALL deterministically select exactly 2,000 previously unscanned
|
||||
physical repository anchors from the existing complete frozen discovery pass,
|
||||
excluding every repository in the depth cohort. Selection SHALL be independent
|
||||
of prior finding or credential yield.
|
||||
|
||||
#### Scenario: Reviewed frozen pool is selected
|
||||
- **WHEN** 52 keywords have sufficient eligible repositories and nine have none
|
||||
- **THEN** each nonempty keyword SHALL own 38 unique repositories, the first 24 still-eligible keywords in pinned order SHALL own one additional repository, and empty keywords SHALL remain explicit zero rows
|
||||
|
||||
#### Scenario: Repository appears under several keywords
|
||||
- **WHEN** the next candidate is already physically owned by an earlier round-robin selection
|
||||
- **THEN** it SHALL consume neither another physical slot nor the selecting keyword's quota, and selection SHALL continue to that keyword's next eligible candidate
|
||||
|
||||
#### Scenario: Exact cohort cannot be formed
|
||||
- **WHEN** deterministic eligible selection cannot reach exactly 2,000 unique repositories with the reviewed distribution
|
||||
- **THEN** manifest generation or application SHALL fail closed and no partial experiment cohort SHALL activate
|
||||
|
||||
### Requirement: Released policy history eligibility
|
||||
The system SHALL admit a previously held repository only when its complete
|
||||
policy-event history consists exclusively of authority-valid cold/reactivate
|
||||
pairs owned by completed and released Docker experiments.
|
||||
|
||||
#### Scenario: Prior hold was exactly released
|
||||
- **WHEN** every prior cold event has one matching reverse event that restores its recorded state and matches experiment, config, policy, manifest, and audit evidence
|
||||
- **THEN** the unfenced unscanned repository MAY participate in the new reviewed cohort or hold manifest
|
||||
|
||||
#### Scenario: Prior history is incomplete or unrelated
|
||||
- **WHEN** any policy event is unreversed, malformed, belongs to an unreleased experiment, or represents an unrelated policy
|
||||
- **THEN** the repository SHALL remain ineligible and its queue and event history SHALL remain unchanged
|
||||
|
||||
### Requirement: Rank-one-only execution
|
||||
The system SHALL resolve at most the newest eligible immutable image for each
|
||||
selected repository and SHALL create no image selection above rank one.
|
||||
|
||||
#### Scenario: Repository has an eligible newest image
|
||||
- **WHEN** its dedicated resolver completes under a valid owner, generation, token, and experiment authority
|
||||
- **THEN** exactly one rank-one selection MAY consume one physical experiment target slot
|
||||
|
||||
#### Scenario: Candidate image is unsafe
|
||||
- **WHEN** the newest candidate is previously scanned, failed, quarantined, independently cold, fenced, or otherwise ineligible
|
||||
- **THEN** existing deterministic safe replacement rules SHALL apply without reactivating historical work or selecting an older image rank for depth
|
||||
|
||||
#### Scenario: Breadth work is dispatched
|
||||
- **WHEN** rank-one targets become available
|
||||
- **THEN** they SHALL use one round-robin dispatch wave with existing reservation, capacity, retry, and terminal-binding guarantees
|
||||
|
||||
### Requirement: Reviewed handoff and reversible holds
|
||||
The system SHALL activate the breadth experiment only through a stopped-runtime
|
||||
reviewed handoff after the depth experiment completes and releases its owned
|
||||
cold rows. Breadth-owned non-cohort holds SHALL remain exactly reversible.
|
||||
|
||||
#### Scenario: Canonical handoff succeeds
|
||||
- **WHEN** runtime is stopped, the depth experiment is completed and fence-free, its exact release SHA is approved, and the breadth cohort and hold SHAs are approved
|
||||
- **THEN** release and breadth activation SHALL commit through their existing experiment-row-first fenced protocols before runtime restarts
|
||||
|
||||
#### Scenario: Breadth release is reviewed
|
||||
- **WHEN** the breadth experiment later completes and its exact reactivation manifest is approved
|
||||
- **THEN** only unreversed breadth-owned cold events SHALL restore their recorded prior states
|
||||
|
||||
### Requirement: Secret-safe breadth reporting
|
||||
The system SHALL report physical coverage, globally deduplicated credential and
|
||||
currently-alive yield, per-keyword attribution, scan cost, and both yield
|
||||
measures per scanner-hour without exposing secret or target material.
|
||||
|
||||
#### Scenario: Credential repeats across keywords
|
||||
- **WHEN** one credential is found in a repository attributed to multiple frozen keyword observations
|
||||
- **THEN** global totals SHALL count it once while each eligible keyword attribution MAY receive an explicit non-additive credit
|
||||
|
||||
#### Scenario: Report measures novelty
|
||||
- **WHEN** findings repeat across target-scoped locations
|
||||
- **THEN** the decision report SHALL distinguish finding locations from detector-secret identities and credential identities and SHALL use credentials and currently-alive credentials as primary outcomes
|
||||
|
||||
#### Scenario: Report reads sensitive evidence
|
||||
- **WHEN** aggregate reporting accesses findings or keycheck rows
|
||||
- **THEN** output SHALL omit raw credentials, repositories, image targets, URLs, hashes, excerpts, DSNs, and configuration identities
|
||||
Reference in New Issue
Block a user