Commit b0fcf3c
committed
docs(vrs): define fail-closed once, where subsystems can cite it
Three subsystems state a fail-closed rule independently and none
references the others, so for a safety property the drift risk is the
failure mode that matters.
Definition and obligation are split along the existing doc-class line:
the ontology says what fail-closed means, and each subsystem's
requirements say which of its surfaces must be. The obligation stays
where it can be argued with; the definition stops being restated.
Records the asymmetry that makes the term operationally useful —
widening what counts as proven needs evidence, widening what counts as
unproven is always safe — and that fail-closed is a property of a
mechanism's unknown path, not a wish about it.
Names fail-open too, since it is usually reached by removing a check
that was accidentally load-bearing rather than by writing a permissive
one.
agent-session-id: e5217740-eef6-48eb-a794-3e5e11939e4d
agent-tool: Claude Code
agent-tool-version: 2.1.220
agent-model: claude-opus-5
agent-runtime-profile: /nix/store/i8y8b542cyqi385ywcjw5fvsq24f75v4-coding-agent-runtime-profile/share/coding-agents/profile.json
agent-skills-manifest: /nix/store/i81qxhzlrzcxrrdwpp6i8hagka2gby8y-agent-skills-corpus/share/agent-skills/manifest.json
tooling-profile: dotfiles@unknown-dirty1 parent 8722aa7 commit b0fcf3c
1 file changed
Lines changed: 23 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
161 | 161 | | |
162 | 162 | | |
163 | 163 | | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
164 | 187 | | |
165 | 188 | | |
166 | 189 | | |
| |||
0 commit comments