Skip to content

feat(storage): stamp policy version at decision time - #741

Open
thesageak wants to merge 6 commits into
DobermanCore:mainfrom
thesageak:fix/515-policy-version
Open

thesageak wants to merge 6 commits into
DobermanCore:mainfrom
thesageak:fix/515-policy-version

Conversation

@thesageak

@thesageak thesageak commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Pull Request

Slice

What this PR does

  • Stamps decision log rows with the pv1: version of the effective policy snapshot used at decision time.
  • Preserves the resolved effective enforcement state when stamping decisions across proxy and host-hook writer paths.
  • Keeps decision persistence fail-open with respect to policy-version stamping: if version calculation or catalogue recording fails, the decision row is still written with policy_version = NULL.
  • Rejects malformed policy-version identifiers rather than persisting them.
  • Exposes policy_version through doberman log --jsonl without exposing canonical policy contents.
  • Adds to_version to policy-history --json by matching policy observations to ledger timestamps.
  • Reports policy versions first seen without a corresponding ledger entry as unledgered in policy-versions --verify.

Tests added (run in CI)

  • Decision rows persist valid policy-version stamps.
  • Policy-version stamping failure does not prevent decision persistence.
  • Invalid policy-version identifiers are not persisted.
  • Decisions after a policy change receive the new policy version.
  • JSONL decision output includes policy_version without canonical policy contents.
  • Policy-history JSON links matching ledger entries to to_version.
  • Policy-version verification reports unledgered versions.
  • Existing proxy and host-hook tests cover propagation of effective enforcement state.

Changelog

  • changelog.d/741.added.md fragment added (one line per user-visible change, see changelog.d/README.md), or this change is invisible to users

Public-release safety (doberman-core only)

  • Contains nothing from the "not allowed" list: no enterprise/hosted code, no proprietary detection, no customer data, no secrets, no commercial-license code
  • Core still builds/tests/runs with NO enterprise package installed

Security checklist

  • Fails closed on error / uncertainty
  • No secret, full file, or unredacted prompt logged or committed
  • Any guardrail/learning change is raise-only (no silent loosening)
  • Every BLOCK/AUTH carries reason codes + a human explanation
  • doberman-core does not import doberman_enterprise

Edge cases covered / Deviations from plan / Risks introduced

  • Historical decision rows remain NULL for policy_version; the schema migration intentionally does not backfill them.
  • Policy-version stamping failures do not alter or drop an already-enforced decision.
  • A policy version first observed through observed/decision, or through a change observation without a ledger timestamp, is reported as unledgered.
  • Local full-suite run: 5,786 passed, 2 failed, 5 skipped, 1 xfailed; coverage 92.66%. The 2 failures appear unrelated to decision log: stamp the policy version on every decision and surface the matching #515: temporary plugin discovery could not import doberman, and the Tk brand-block height measured 57px against a 48px assertion.
  • ruff check ., ruff format --check ., Markdown link validation, import-linter, changelog validation, parity generation check, and the 90% coverage requirement pass.

AI assistance: AI was used for design guidance and test review. All changes were reviewed and tested locally.

Closes #515

@thesageak thesageak changed the title Fix/515 policy version feat(storage): stamp policy version at decision time - #515 Oct 5, 2026
@thesageak thesageak changed the title feat(storage): stamp policy version at decision time - #515 feat(storage): stamp policy version at decision time Oct 5, 2026
@thesageak
thesageak marked this pull request as ready for review October 5, 2026 07:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

decision log: stamp the policy version on every decision and surface the matching

1 participant