Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003 [2026/07/18 09:32] – created nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003 [2026/07/30 05:58] (current) – nick_dido | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| ===== Statement ===== | ===== Statement ===== | ||
| - | [[dido: | + | [[dido: |
| - | ===== Source Statement | + | ===== Derived From ===== |
| - | > The system shall support artifact import packages. | + | This requirement derives from: |
| - | ===== Source ===== | + | * Crucible System Requirements Specification, |
| - | Crucible System Requirements Specification, | + | The Original Requirement states: |
| - | ===== Assessment ===== | + | > //The system shall support artifact import packages.// |
| - | The source statement identifies a required package type but does not state the required import behavior. | + | FR-AG-003: |
| - | The following Specification Discipline | + | * Replaces **The system** with the defined system name [[dido: |
| + | * Changes **shall** to the established uppercase normative form **SHALL** | ||
| + | * Replaces the weak verb **support** with the observable behavior **import** | ||
| + | * Maps **artifact import packages** to the defined [[dido: | ||
| - | * **The system** does not use the defined system name | + | No other substantive normalization |
| - | * **shall** does not follow the established uppercase normative convention | + | |
| - | * **Support** | + | |
| - | * **Artifact import packages** does not identify whether Crucible creates, validates, stores, or consumes the package | + | |
| - | * The source statement does not identify whether the package must be authorized | + | |
| - | * The source statement does not identify whether package integrity must be verified before import | + | |
| - | * The source statement does not prescribe a package format, archive technology, storage medium, or integrity mechanism | + | |
| - | The normalized Statement: | + | ===== Rationale ===== |
| - | * Replaces **The system** with [[dido: | + | A [[dido: |
| - | * Replaces **support** with the direct behavior **import** | + | |
| - | * Identifies the Artifacts as the imported subjects | + | |
| - | * Requires package authorization | + | |
| - | * Requires | + | |
| - | * Preserves implementation independence | + | |
| - | This normalization relies on the established concepts of [[dido: | + | Importing a Transfer Bundle |
| - | **Artifact Import Package** should receive a glossary definition. It may be the destination-environment role of the same transferable package created as an Artifact Export Package rather than a structurally different package type. | + | A Transfer Bundle can contain: |
| - | ===== Rationale ===== | + | * [[dido: |
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * Software packages | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * Content digests | ||
| + | * Manifests | ||
| + | * Provenance information | ||
| + | * Traceability information | ||
| - | An Artifact Import Package supplies Artifacts and metadata to a destination environment after controlled transfer. | + | This requirement establishes Transfer Bundle import without prescribing: |
| - | The import process may: | + | * The Artifacts imported from a particular Transfer Bundle |
| + | * The destination environment | ||
| + | * The destination repository | ||
| + | * The Transfer Bundle format | ||
| + | * [[dido:99_annexes: | ||
| + | * Transfer across a [[dido: | ||
| + | * Verification of [[dido: | ||
| + | * Approval or promotion of imported Artifacts | ||
| + | * Deployment of imported Artifacts | ||
| + | * Preservation of one package identity across export and import | ||
| - | * Read the package manifest | + | Separate |
| - | * Identify the included Artifacts | + | |
| - | * Verify package integrity | + | |
| - | * Verify Artifact content digests | + | |
| - | * Verify Digital Signatures | + | |
| - | * Confirm Transfer Authorization | + | |
| - | * Reject unauthorized or invalid content | + | |
| - | * Place accepted Artifacts into local repositories | + | |
| - | * Register Artifact identifiers and revisions | + | |
| - | * Preserve provenance and traceability records | + | |
| - | + | ||
| - | A package created as an Artifact Export Package may become an Artifact Import Package when the destination environment receives and processes it. | + | |
| - | + | ||
| - | FR-AG-003 does not independently authorize the imported Artifacts for deployment or operation. | + | |
| ===== Applies To ===== | ===== Applies To ===== | ||
| Line 68: | Line 67: | ||
| * [[dido: | * [[dido: | ||
| - | | + | * [[dido: |
| - | * [[dido: | + | * Transfer Bundle |
| - | * Package manifests | + | |
| - | * Artifact identifiers | + | |
| - | * Artifact revisions | + | |
| - | * Content digests | + | |
| - | * Digital signatures | + | |
| - | | + | |
| - | * [[dido: | + | |
| - | * Local Artifact repositories | + | |
| - | * [[dido: | + | |
| ===== Verification ===== | ===== Verification ===== | ||
| - | - Verification | + | Verification |
| - | - Verification SHALL confirm that [[dido:99_annexes: | + | |
| - | - Verification SHALL confirm that Crucible imports the identified Artifacts contained in a valid authorized package | + | |
| - | - Verification SHALL confirm that Crucible does not import the tested package when authorization or package-integrity verification fails | + | |
| - | Verification may include: | + | |
| - | + | - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] imports the selected Transfer Bundle | |
| - | * Authorized-package import testing | + | - The contents of the imported Transfer Bundle can be accessed after the import operation |
| - | * Unauthorized-package testing | + | - The imported contents correspond to the contents of the selected |
| - | * Modified-package testing | + | - The result of the tested import operation can be determined |
| - | * Manifest inspection | + | |
| - | * Content-digest comparison | + | |
| - | * Digital-signature verification | + | |
| - | * Local repository inspection | + | |
| - | * Import-log inspection | + | |
| - | + | ||
| - | The verification record SHALL identify: | + | |
| - | + | ||
| - | - The Artifact Import Package | + | |
| - | - The included Artifacts | + | |
| - | - The Transfer Authorization | + | |
| - | - The package-integrity verification result | + | |
| - | - The imported Artifact identifiers | + | |
| - | - The imported Artifact revisions | + | |
| - | - The destination repository | + | |
| - | - The import result | + | |
| - | - The generated | + | |
| - | + | ||
| - | ===== Outgoing Traceability ===== | + | |
| - | + | ||
| - | This requirement realizes: | + | |
| - | + | ||
| - | | + | |
| - | * [[dido:02-crusible: | + | |
| - | + | ||
| - | This requirement relates to: | + | |
| - | + | ||
| - | * [[dido: | + | |
| - | | + | |
| - | | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | | + | |
| ===== Referenced By ===== | ===== Referenced By ===== | ||
| - | The wiki Backlinks function provides the current list of pages that reference | + | The following |
| - | Incoming Traceability should be derived dynamically from backlinks | + | {{backlinks>.# |
| - | ===== ConOps Relationship | + | ===== Implementation Status |
| - | The Crucible Concept of Operations describes receipt, integrity verification, | + | Implemented |
| - | FR-AG-003 establishes the required import behavior for authorized Artifact packages. | + | ===== Requirement Status ===== |
| - | ===== Delivery Phase ===== | + | < |
| - | Phase 1 | + | ---- |
| + | ===== Issues ===== | ||
| - | ===== Implementation Status ===== | + | < |
| - | Not Assessed | + | < |
| - | + | ||
| - | ===== Requirement Status ===== | + | |
| - | Draft | + | < |
| ---- | ---- | ||
| ===== Notes for Editors ===== | ===== Notes for Editors ===== | ||
| - | This requirement page should retain | + | This requirement page retains |
| - | Changes to the Statement SHALL preserve the approved intent of the source | + | This page is a leaf requirement |
| - | The Statement should remain limited | + | The source phrase **artifact import packages** maps to the defined [[dido: |
| - | Requirements for package | + | The Statement preserves the approved source intent by requiring Crucible to import Transfer Bundles. |
| + | |||
| + | Do not introduce separate **Artifact Export Package** and **Artifact Import Package** concepts unless the controlling architecture defines different | ||
| + | |||
| + | Do not add Transfer Authorization, transfer, integrity verification, | ||
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: | ||
| Line 166: | Line 123: | ||
| {{section> | {{section> | ||
| </ | </ | ||
| - | |||
| - | Do not rename this page after an external citation unless a redirect or move plan is in place. | ||
| ---- | ---- | ||