Skip to content
docsv0.19.0

SubjectAttestation

A producer's statement of what THIS call's change is made of — the producer of one axis, `subject`. ── WHY THE DECLARATION CANNOT SAY IT ──────────────────────────────────────────────────────────── {@see Subject} is declared, not derived: three static readers failed to infer it from what a handler touches, so an operation states its ceiling once. But some operations carry their change as DATA — a promotion carries the diff a trial produced — and what that change is made of differs per call. The declaration can only be the worst case (`Executable`: a promotion MAY install code). Held there, the axis is dead to consent: a human who tightens a grant to `subject ≤ configuration` mints a grant nothing can ever satisfy (greenhouse decisions/0080, measured on the published packages). ── WHO MAY LOWER IT, AND HOW FAR ─────────────────────────────────────────────────────────────── Only the producer that OWNS the payload — the trial workspace owns the diff — and only by attesting what it can check: a concrete list of changed paths, judged by an allowlist, where anything it cannot vouch for keeps the ceiling. Composition then lowers `subject` to the attested level, with this producer and provenance on the receipt, and touches nothing else. It never raises: an attestation at or above the effective subject is not a reduction and leaves no receipt. Like {@see TrialConfinement}, it is a LIVE producer, not a signed artefact — its trust is the check the producer actually ran, recorded as provenance so an auditor can repeat it after the fact.

SubjectAttestation::__construct()

public function __construct(Milpa\Command\Effect\Subject $subject, string $producer, string $provenance):

Parameters

Parameters of __construct()
NameTypeDescription
$subjectSubjectwhat the change is made of, as the producer could verify it
$producerstringwho attests — the name composition records on the reduction
$provenancestringwhat the producer checked, e.g. the digest of the diff it classified