[[requirements]] id = "REQ-USER-INPUT-PATH-PROPOSAL" title = "THE QUOTED-PATH SUBSTRATE BOTH #300 AUTHORIZATION ARMS SHARE, BUILT INERT UNTIL ONE OF THEM IS RULED (releases#300, REMOTE-FRICTION #304, ADR-0058 Amendment 1 draft, doyle's dispatch 2026-09-11). Paths are extracted from a COMMITTED USER_INPUT payload ONLY -- never from an outbound message, never from raw terminal bytes, never from an uncommitted partial turn -- and recorded as a PROPOSAL bound to one committed input identity, that input's exact payload, and the receiving endpoint's incarnation. The proposal reuses the EXISTING scoped-reference registration path and helper guidance rather than minting a second server: ttl 24h, audience = the one receiving endpoint, at most once per (committed input, path), under the guards REQ-NOW-SIGNAL-FILE-ACCESS-HELPER already carries (the path must exist on the owning node, absolute or ~-rooted only, at most 5 per input, a directory registering a dir entry). A PROPOSAL IS NOT A GRANT: no entry is registered, no helper line is emitted and nothing is exposed until an authorization arm admits it, so with REQ-USER-INPUT-PATH-AUTHORIZATION unimplemented this path is INERT rather than half-open and the seam REFUSES BY NAME. Replay of the same committed input yields the same proposal and never re-prompts, never extends an existing grant's ttl and never widens its audience; a later controller cannot inherit an earlier input's proposal, because current controller presence was never proof of that input's origin. Gate: doc -- the attachments page's helper section stating the trigger, the proposal/grant split and the inert state; impl -- the committed-payload extraction, the proposal record and its binding, the reuse of the scoped-reference registration path, the named refusal at the unimplemented seam; unit -- extraction from a committed input and refusal for every non-committed source, each guard as its own cell, the (input, path) dedupe, a replay that re-prompts nothing and extends nothing, and the named refusal asserted to have registered NO entry." required_stages = ["doc", "impl", "unit"] [[requirements]] id = "REQ-USER-INPUT-PATH-AUTHORIZATION" title = "THE ARM THAT TURNS A QUOTED-PATH PROPOSAL INTO A SERVED GRANT IS FORKED TO THE OPERATOR AND CARRIES NO STAGES UNTIL RULED (releases#300, fork filed by doyle 2026-09-11). Two candidates, both amending what grill decision 5 accepted: a receipt-bearing input transport that preserves authenticated origin node, endpoint incarnation and lease through the harness's semantic submission boundary and returns a stable submission ID with its receipts and exact payload -- which no shipped adapter has and which needs a public adapter capability outside greenlit #304 scope; or fresh explicit local consent at the receiving client, where local approval is AUTHORIZATION AND NOT A CLAIM OF AUTHORSHIP, a handoff cancels the proposal, viewers cannot approve, and a replay never re-prompts or extends. Doyle recommends the consent arm for #304 with the transport arm minted as a separate later request; the operator has not answered. This requirement is registered so the hole is a NAMED SEAM rather than an omission a later reader mistakes for an oversight, and REQ-USER-INPUT-PATH-PROPOSAL's by-name refusal is what stands in its place meanwhile. Activating this requirement is what the lane that builds the ruled arm does; until then it carries no stages and fails nothing." required_stages = []