Extension SPI 1.0 · v0.50.0

Extend RuleOak without forking the authority kernel

The public SPI validates extension descriptors and keeps private/commercial implementations outside the public authority path.

Supported extension kinds

Hard boundary

Inspector intelligence is rejected if it attempts to return authority decisions. Authority Envelope, ExecutionLease, EffectReceipt, Policy v2, basic Inspector, Flight Recorder verification and basic CrashLab remain public trust foundations.