Commit d149a4f
feat(trust): tighten Trustfile template + new SEAMS spec
- Lean4 → Idris2 sweep: all .lean → .idr, lake build → idris2 --build,
[LEAN4_PROOFS] → [IDRIS2_PROOFS], lean_proof: → idris2_proof:,
context URL updated to a2ml.org/ns/v3 + idris-lang.org/ns/v2
- New [VERIFICATION_LADDER] section (four tiers: idris2-proven / zig-assured /
elixir-disciplined / external-trust)
- New [SEAMS] section with example seam entry and seam-check policy
- New [SECRETS_HYGIENE] section (SOPS+age intent, per-repo adoption status,
Rokur gate, RGTV alpha note)
- New [SAFE_HACKING] + [VULNERABILITY_DISCLOSURE] sections
- New [PROOF_METADATA] section after [IDRIS2_PROOFS]
- New [SUPPLY_CHAIN_DEPS] section after [CONTAINER_SUPPLY_CHAIN]
- New [PLACEHOLDER_TRACKING] section before [SIGNATURE_BLOCK]
- [CLOUDFLARE]: added operator_trust_anchor vendor-risk statement
- [CLOUDFLARE_EDGE_SECURITY]: added four-tier rate_limiting architecture
(edge/gateway/BEAM/cartridge) with RFC 9530 headers, Turnstile, HMAC signing
- [NETWORK]: ipv6_compatibility → ipv6_posture (IPv6-only at origin,
dual-stack at Cloudflare edge)
- New [ORIGIN_PROTECTION] section (Cloudflare Tunnel, mTLS pulls,
CF Access for admin, backup Tunnel, leak checks)
- docs/SEAMS-SPEC.adoc: new ~300-line normative spec defining seams,
classification, seam-register format, seam-check rule, failure modes,
verification tier mapping, worked examples, contractile future work
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent fec2c9d commit d149a4f
2 files changed
Lines changed: 727 additions & 68 deletions
0 commit comments