Files
2026-09-30 20:30:56 +03:00

6.0 KiB

ADDED Requirements

Requirement: Reviewed rank-one breadth authority

The system SHALL support a code-pinned rank-one breadth profile of 61 ordered queries, at most 39 owned repositories per query, one image per repository, and exactly 2,000 unique physical repository selections and target slots. It SHALL reject arbitrary limit combinations and SHALL preserve the existing depth profile unchanged.

Scenario: Breadth profile is valid

  • WHEN configuration supplies the exact reviewed breadth selector and limits
  • THEN validation SHALL produce a distinct immutable authority hash with a physical target ceiling of 2,000

Scenario: Profile limits are mixed

  • WHEN configuration combines a selector or limit from different reviewed profiles
  • THEN startup SHALL fail before secrets, database mutation, network work, or workers initialize

Scenario: Prior authority is not released

  • WHEN another Docker experiment is nonterminal, unreleased, or fenced
  • THEN breadth cohort application and activation SHALL fail without changing either experiment

Requirement: Exact balanced physical cohort

The system SHALL deterministically select exactly 2,000 previously unscanned physical repository anchors from the existing complete frozen discovery pass, excluding every repository in the depth cohort. Selection SHALL be independent of prior finding or credential yield.

Scenario: Reviewed frozen pool is selected

  • WHEN 52 keywords have sufficient eligible repositories and nine have none
  • THEN each nonempty keyword SHALL own 38 unique repositories, the first 24 still-eligible keywords in pinned order SHALL own one additional repository, and empty keywords SHALL remain explicit zero rows

Scenario: Repository appears under several keywords

  • WHEN the next candidate is already physically owned by an earlier round-robin selection
  • THEN it SHALL consume neither another physical slot nor the selecting keyword's quota, and selection SHALL continue to that keyword's next eligible candidate

Scenario: Exact cohort cannot be formed

  • WHEN deterministic eligible selection cannot reach exactly 2,000 unique repositories with the reviewed distribution
  • THEN manifest generation or application SHALL fail closed and no partial experiment cohort SHALL activate

Requirement: Released policy history eligibility

The system SHALL admit a previously held repository only when its complete policy-event history consists exclusively of authority-valid cold/reactivate pairs owned by completed and released Docker experiments.

Scenario: Prior hold was exactly released

  • WHEN every prior cold event has one matching reverse event that restores its recorded state and matches experiment, config, policy, manifest, and audit evidence
  • THEN the unfenced unscanned repository MAY participate in the new reviewed cohort or hold manifest

Scenario: Prior history is incomplete or unrelated

  • WHEN any policy event is unreversed, malformed, belongs to an unreleased experiment, or represents an unrelated policy
  • THEN the repository SHALL remain ineligible and its queue and event history SHALL remain unchanged

Requirement: Rank-one-only execution

The system SHALL resolve at most the newest eligible immutable image for each selected repository and SHALL create no image selection above rank one.

Scenario: Repository has an eligible newest image

  • WHEN its dedicated resolver completes under a valid owner, generation, token, and experiment authority
  • THEN exactly one rank-one selection MAY consume one physical experiment target slot

Scenario: Candidate image is unsafe

  • WHEN the newest candidate is previously scanned, failed, quarantined, independently cold, fenced, or otherwise ineligible
  • THEN existing deterministic safe replacement rules SHALL apply without reactivating historical work or selecting an older image rank for depth

Scenario: Breadth work is dispatched

  • WHEN rank-one targets become available
  • THEN they SHALL use one round-robin dispatch wave with existing reservation, capacity, retry, and terminal-binding guarantees

Requirement: Reviewed handoff and reversible holds

The system SHALL activate the breadth experiment only through a stopped-runtime reviewed handoff after the depth experiment completes and releases its owned cold rows. Breadth-owned non-cohort holds SHALL remain exactly reversible.

Scenario: Canonical handoff succeeds

  • WHEN runtime is stopped, the depth experiment is completed and fence-free, its exact release SHA is approved, and the breadth cohort and hold SHAs are approved
  • THEN release and breadth activation SHALL commit through their existing experiment-row-first fenced protocols before runtime restarts

Scenario: Breadth release is reviewed

  • WHEN the breadth experiment later completes and its exact reactivation manifest is approved
  • THEN only unreversed breadth-owned cold events SHALL restore their recorded prior states

Requirement: Secret-safe breadth reporting

The system SHALL report physical coverage, globally deduplicated credential and currently-alive yield, per-keyword attribution, scan cost, and both yield measures per scanner-hour without exposing secret or target material.

Scenario: Credential repeats across keywords

  • WHEN one credential is found in a repository attributed to multiple frozen keyword observations
  • THEN global totals SHALL count it once while each eligible keyword attribution MAY receive an explicit non-additive credit

Scenario: Report measures novelty

  • WHEN findings repeat across target-scoped locations
  • THEN the decision report SHALL distinguish finding locations from detector-secret identities and credential identities and SHALL use credentials and currently-alive credentials as primary outcomes

Scenario: Report reads sensitive evidence

  • WHEN aggregate reporting accesses findings or keycheck rows
  • THEN output SHALL omit raw credentials, repositories, image targets, URLs, hashes, excerpts, DSNs, and configuration identities