Repository navigation
Expand file tree
/
Copy pathsourceos-capability.schema.json
More file actions
32 lines (32 loc) · 2.13 KB
/
Copy pathsourceos-capability.schema.json
File metadata and controls
32 lines (32 loc) · 2.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://sourceos.dev/schemas/sourceos-capability.schema.json",
"title": "SourceOS Capability Definition",
"$comment": "NOT WIRED TO RUNTIME (verified 2026-08-04). `default_decision`, `requires_user_consent`, `audit`, and `privacy_impact` are declarative only: nothing in this daemon reads them to gate, prompt, or refuse anything. The two consumers that touch this file (tools/validate_json_schemas.py, tools/validate_control_plane_examples.py) check shape/schema_version only. The daemon's REAL capability-gating code is src/sourceos_syncd/orchestration_events.py, which uses a different record shape entirely (capability_id/effect_class/required_policy_outcome/approval_mode) with no connection to this schema. Before adding a fixture with requires_user_consent:true or wiring a reader here, decide: should this schema be unified into orchestration_events.py's real gate, or is it a forward-declared capability catalog that predates the gate it was meant to feed? (declared-unenforced register item #9, 2026-07-29 estate audit)",
"type": "object",
"required": [
"schema_version",
"capability",
"class",
"description",
"default_decision",
"audit",
"privacy_impact"
],
"additionalProperties": true,
"properties": {
"schema_version": { "const": "sourceos.capability.v0.1" },
"capability": { "type": "string", "pattern": "^[a-z0-9]+(\\.[a-z0-9_-]+)+$" },
"class": {
"type": "string",
"enum": ["ipc", "filesystem", "network", "identity", "telemetry", "diagnostics", "power", "parser", "browser", "ai", "update", "policy", "developer"]
},
"description": { "type": "string" },
"default_decision": { "type": "string", "enum": ["allow", "deny", "prompt", "audit"] },
"audit": { "type": "string", "enum": ["always", "on_deny", "on_use", "never"] },
"privacy_impact": { "type": "string", "enum": ["none", "low", "medium", "high", "sealed"] },
"requires_user_consent": { "type": "boolean" },
"compatible_authority_domains": { "type": "array", "items": { "type": "string" } },
"remediation": { "type": "string" }
}
}