Schemas
Draft 0.1 uses JSON Schema draft 2020-12. Unknown fields are errors. A policy, an evidence record, and a decision each have a schema.
Closeout policy document, draft 0.1
A public policy file. specVersion is 0.1. Items are command or review, and the only gate is beforePR.
urn:closeout:policy:0.1
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "urn:closeout:policy:0.1",
"title": "Closeout policy document, draft 0.1",
"type": "object",
"additionalProperties": false,
"required": ["specVersion"],
"properties": {
"specVersion": { "const": "0.1" },
"description": { "type": "string", "minLength": 1, "maxLength": 500 },
"imports": {
"type": "array",
"maxItems": 64,
"items": {
"type": "object",
"additionalProperties": false,
"required": ["path", "as"],
"properties": {
"path": { "type": "string", "minLength": 1, "maxLength": 256 },
"as": { "$ref": "#/$defs/slug" }
}
}
},
"items": {
"type": "array",
"maxItems": 128,
"items": { "$ref": "#/$defs/item" }
}
},
"$defs": {
"slug": {
"type": "string",
"pattern": "^[a-z][a-z0-9]*(-[a-z0-9]+)*$"
},
"item": {
"oneOf": [{ "$ref": "#/$defs/command" }, { "$ref": "#/$defs/review" }]
},
"command": {
"type": "object",
"additionalProperties": false,
"required": ["id", "kind", "gate", "exec", "timeoutSeconds"],
"properties": {
"id": { "$ref": "#/$defs/slug" },
"kind": { "const": "command" },
"gate": { "const": "beforePR" },
"exec": {
"type": "array",
"minItems": 1,
"maxItems": 32,
"items": { "type": "string", "minLength": 1, "maxLength": 4096 }
},
"timeoutSeconds": { "type": "integer", "minimum": 1, "maximum": 86400 }
}
},
"review": {
"type": "object",
"additionalProperties": false,
"required": ["id", "kind", "gate", "skill", "independence", "failOn"],
"properties": {
"id": { "$ref": "#/$defs/slug" },
"kind": { "const": "review" },
"gate": { "const": "beforePR" },
"skill": { "type": "string", "minLength": 1, "maxLength": 256 },
"independence": {
"type": "object",
"additionalProperties": false,
"required": ["differentSession", "differentModel"],
"properties": {
"differentSession": { "type": "boolean" },
"differentModel": { "type": "boolean" }
}
},
"failOn": { "enum": ["P0", "P1", "P2", "P3"] }
}
}
}
}
Closeout evidence record, draft 0.1
One evidence record. A command record carries the argv, the exit, and the producer. A review record carries findings and does not carry an outcome.
urn:closeout:evidence:0.1
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "urn:closeout:evidence:0.1",
"title": "Closeout evidence record, draft 0.1",
"oneOf": [{ "$ref": "#/$defs/command" }, { "$ref": "#/$defs/review" }],
"$defs": {
"sha": { "type": "string", "pattern": "^([0-9a-f]{40}|[0-9a-f]{64})$" },
"digest": { "type": "string", "pattern": "^sha256:[0-9a-f]{64}$" },
"attempt": { "type": "integer", "minimum": 1, "maximum": 100000 },
"artifact": {
"type": "object",
"additionalProperties": false,
"required": ["path", "sha256"],
"properties": {
"path": { "type": "string", "minLength": 1, "maxLength": 512 },
"sha256": { "type": "string", "pattern": "^[0-9a-f]{64}$" }
}
},
"identity": {
"type": "object",
"additionalProperties": false,
"required": ["name", "version"],
"properties": {
"name": { "type": "string", "minLength": 1, "maxLength": 128 },
"version": { "type": "string", "minLength": 1, "maxLength": 64 }
}
},
"command": {
"type": "object",
"additionalProperties": false,
"required": [
"specVersion",
"recordType",
"itemId",
"base",
"head",
"policyDigest",
"attempt",
"evaluator",
"producer",
"exec",
"artifacts"
],
"properties": {
"specVersion": { "const": "0.1" },
"recordType": { "const": "command" },
"itemId": { "type": "string", "minLength": 1, "maxLength": 256 },
"base": { "$ref": "#/$defs/sha" },
"head": { "$ref": "#/$defs/sha" },
"policyDigest": { "$ref": "#/$defs/digest" },
"attempt": { "$ref": "#/$defs/attempt" },
"evaluator": { "$ref": "#/$defs/identity" },
"producer": { "$ref": "#/$defs/identity" },
"exec": {
"type": "object",
"additionalProperties": false,
"required": ["argv", "exitCode", "timedOut", "dirty", "headMoved", "durationMs", "truncated"],
"properties": {
"argv": {
"type": "array",
"minItems": 1,
"maxItems": 32,
"items": { "type": "string", "minLength": 1 }
},
"exitCode": { "type": ["integer", "null"] },
"timedOut": { "type": "boolean" },
"dirty": { "type": "boolean" },
"headMoved": { "type": "boolean" },
"durationMs": { "type": "integer", "minimum": 0 },
"truncated": { "type": "boolean" }
}
},
"artifacts": {
"type": "array",
"maxItems": 16,
"items": { "$ref": "#/$defs/artifact" }
}
}
},
"review": {
"type": "object",
"additionalProperties": false,
"required": [
"specVersion",
"recordType",
"itemId",
"base",
"head",
"policyDigest",
"attempt",
"evaluator",
"producer",
"findings",
"artifacts"
],
"properties": {
"specVersion": { "const": "0.1" },
"recordType": { "const": "review" },
"itemId": { "type": "string", "minLength": 1, "maxLength": 256 },
"base": { "$ref": "#/$defs/sha" },
"head": { "$ref": "#/$defs/sha" },
"policyDigest": { "$ref": "#/$defs/digest" },
"attempt": { "$ref": "#/$defs/attempt" },
"evaluator": { "$ref": "#/$defs/identity" },
"producer": {
"type": "object",
"additionalProperties": false,
"required": ["session", "model", "provider"],
"properties": {
"session": { "type": "string", "maxLength": 256 },
"model": { "type": "string", "maxLength": 256 },
"provider": { "type": "string", "maxLength": 256 }
}
},
"findings": {
"type": "array",
"maxItems": 200,
"items": {
"type": "object",
"additionalProperties": false,
"required": ["severity", "location", "explanation", "evidence"],
"properties": {
"severity": { "enum": ["P0", "P1", "P2", "P3"] },
"location": { "type": "string", "minLength": 1, "maxLength": 512 },
"explanation": { "type": "string", "minLength": 1, "maxLength": 8000 },
"evidence": { "type": "string", "minLength": 1, "maxLength": 8000 }
}
}
},
"artifacts": {
"type": "array",
"maxItems": 16,
"items": { "$ref": "#/$defs/artifact" }
}
}
}
}
}
Closeout decision, draft 0.1
The acceptance decision for one gate, one base, and one head. The decision is accepted, rejected, or blocked.
urn:closeout:decision:0.1
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "urn:closeout:decision:0.1",
"title": "Closeout decision, draft 0.1",
"type": "object",
"additionalProperties": false,
"required": ["specVersion", "decision", "gate", "base", "head", "candidate", "policy", "items", "warnings"],
"properties": {
"specVersion": { "const": "0.1" },
"decision": { "enum": ["accepted", "rejected", "blocked"] },
"gate": { "const": "beforePR" },
"base": { "type": "string" },
"head": { "type": "string" },
"message": { "type": "string", "maxLength": 4000 },
"candidate": {
"type": "object",
"additionalProperties": false,
"required": ["session", "model", "provider"],
"properties": {
"session": { "type": "string", "maxLength": 256 },
"model": { "type": "string", "maxLength": 256 },
"provider": { "type": "string", "maxLength": 256 }
}
},
"policy": {
"type": "object",
"additionalProperties": false,
"required": ["path", "legacy", "digest", "absent"],
"properties": {
"path": { "type": ["string", "null"] },
"legacy": { "type": "boolean" },
"digest": { "type": ["string", "null"] },
"absent": { "type": "boolean" }
}
},
"items": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": false,
"required": ["id", "kind", "state", "message"],
"properties": {
"id": { "type": "string" },
"kind": { "type": "string" },
"state": {
"enum": ["passed", "failed", "missing", "stale", "unsupported", "independence", "untrusted", "invalid"]
},
"message": { "type": "string" },
"attempt": { "type": "integer", "minimum": 1 }
}
}
},
"warnings": {
"type": "array",
"items": {
"type": "object",
"additionalProperties": false,
"required": ["code", "message"],
"properties": {
"code": { "type": "string" },
"message": { "type": "string" }
}
}
}
}
}