Skip to content

services: Say fail secure, not fail closed - #535

Merged
chrysh merged 1 commit into
OpenPRoT:ocp-global-demo-wipfrom
9elements:wording-fail-secure
Oct 3, 2026
Merged

chrysh merged 1 commit into
OpenPRoT:ocp-global-demo-wipfrom
9elements:wording-fail-secure

Conversation

@chrysh

@chrysh chrysh commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

"Fail closed" comes from firewalls and policy engines. NIST's word for the same property is fail secure: on failure the system stays in a state that accepts nothing unverified.

"Fail safe" would be the wrong swap. In hardware it means the opposite, a lock that unlocks when power drops, and NIST uses it for preventing damage rather than preserving a secure state.

Wording only: 31 occurrences across the orchestrator state machine, the driver, the capabilities crate and the driver README. No behaviour change, and grep -rniE "fail[- ]closed|fails closed" over the repo comes back empty.

@chrysh
chrysh marked this pull request as ready for review October 3, 2026 19:46
Fail closed comes from firewalls and policy engines. NIST's word for the
same property, and the one this codebase should speak, is fail secure:
on failure the system stays in a state that accepts nothing unverified.

Wording only, 31 occurrences across the orchestrator SM, the driver, the
capabilities crate and the driver README. No behaviour change.

Assisted-by: Claude
@chrysh
chrysh force-pushed the wording-fail-secure branch from 2d177c3 to 45d8b8d Compare October 3, 2026 19:46
@chrysh
chrysh merged commit 2304c8e into OpenPRoT:ocp-global-demo-wip Oct 3, 2026
2 checks passed
@chrysh
chrysh deleted the wording-fail-secure branch October 3, 2026 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant