ADR-A69: Pack Trust Model and Safe SPARQL Subset

Status: Proposed Date: 2026-09-23 Related: Architecture Review §5.7 (S-5), G-12, ADR-A75 Drafted by: Agent, autonomous session (P0.1.13). Pending human ratification — see phase-0-status.md.

Context

A pack is untrusted content until verified: it can carry SPARQL that, if unrestricted, becomes an exfiltration or write-scope-escape channel (SERVICE calls to attacker-controlled endpoints, LOAD of network content, writes outside declared target graphs).

Decision

Pack trust model

Component Control
Signature verification Tenant-configured trust root; every pack verified before any activation
Closure pinning No network-resolvable imports; all dependencies inlined by digest
Safe SPARQL subset No SERVICE, no LOAD, no arbitrary INSERT/DELETE outside declared target graphs
SHADOW phase New graphs run in parallel with the current graph before promotion; outputs compared on a live sample

Safe SPARQL subset (normative for all pack content)

This is the inverse of what an ad-hoc reasoning/query service may permit — packs are restricted precisely because they run with elevated, activation-scoped trust, unlike ad-hoc user queries which run under the requesting principal’s own visibility.

Consequences