{
 "@context": "https://schema.org",
 "@type": "Claim",
 "@id": "https://wulfkaal.github.io/positions/2026-08-26-034",
 "identifier": "kaal:position:2026-08-26-034",
 "additionalType": "https://wulfkaal.github.io/positions/schema.json#AffirmedPositionClaim",
 "name": "Declared Filters Need Executable Decision Paths",
 "text": "An outbound domain allowlist and an audit log do not perform personal-information filtering. Enck and coauthors demonstrate the distinction in TaintDroid. Android permissions could decide whether an application accessed location, camera, microphone, or device identifiers. They provided little visibility into how that data was used after access. TaintDroid therefore labeled data at privacy-sensitive sources, propagated those labels through variables, files, and interprocess messages, and examined the labels when data reached a network or other system boundary. The implementation identified 68 instances of potential misuse across 20 of 30 applications. The mechanism was executable. Its evidence did not rest on a list of intended controls.\n\nThis evidence qualifies Kaal's repository finding. The source does not inspect Gatekeeper, its documentation, Mosaic Companion, or commit 2d920ce. It cannot establish that content inspection and personal-information filtering are absent from the named code. TaintDroid also monitors disclosures. It does not generally block them. It tracks defined sensitive sources rather than every MIME type or every form of personal information. Implicit flows can evade its analysis. The study concerns Android applications in 2010, not language model agents or sovereign local runtimes.\n\nThe institutional requirement is nevertheless precise. A declared filtering layer should correspond to an executable decision path. Personal-information control requires a source definition, propagation rule, inspected egress boundary, policy decision, and test that fails when protected data crosses that boundary. Content inspection requires its own parser coverage and failure rule. Domain approval and after-the-fact logging can remain separate controls. They cannot demonstrate that either missing layer operates. Documentation should distinguish implemented controls from proposed controls, and a release should not claim the broader filter until the named decision paths and adversarial tests exist.",
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0009-0008-7840-1847"
 },
 "datePublished": "2026-08-26",
 "dateModified": "2026-08-26",
 "creativeWorkStatus": "Affirmed",
 "responseType": "qualification",
 "keywords": [
  "institutional-design",
  "governance-design",
  "ai-and-agents",
  "privacy",
  "personal-information",
  "information-flow",
  "content-inspection",
  "audit-logging",
  "policy-enforcement",
  "open-source-and-code"
 ],
 "scope_conditions": [
  "The response is limited to the exact full-text propositions and the one mapped Kaal claim.",
  "External evidence level: peer-reviewed USENIX OSDI systems paper with complete official proceedings full text, implemented Android prototype, and empirical application study.",
  "Mapping review tier: independent substantive scholarly-growth qualification.",
  "The source does not inspect Gatekeeper, its documentation, Mosaic Companion, or commit 2d920ce and therefore cannot verify the repository finding.",
  "TaintDroid monitors and logs sensitive-data disclosures but does not generally block them.",
  "The system tracks defined sensitive sources and does not inspect every MIME type or every form of personal information.",
  "Implicit information flows can evade the analysis.",
  "The study concerns Android applications and an implemented 2010 smartphone prototype, not language model agents or sovereign local runtimes.",
  "The 30-application evaluation identifies potential misuse and suspicious handling, not adjudicated policy violations."
 ],
 "currentDebate": {
  "name": "TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones",
  "url": "https://www.usenix.org/conference/osdi10/taintdroid-information-flow-tracking-system-realtime-privacy-monitoring"
 },
 "extends": {
  "identifier": "kaal:claim:7314479-034",
  "url": "https://wulfkaal.github.io/claims/7314479-034",
  "citation": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479",
  "paper": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes",
  "authors": [
   "Wulf A. Kaal"
  ],
  "year": "2026",
  "ssrn": "https://ssrn.com/abstract=7314479",
  "source_pdf_sha256": "debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6"
 },
 "isBasedOn": [
  {
   "@id": "https://wulfkaal.github.io/claims/7314479-034"
  },
  {
   "@type": "CreativeWork",
   "name": "TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones",
   "url": "https://www.usenix.org/conference/osdi10/taintdroid-information-flow-tracking-system-realtime-privacy-monitoring"
  }
 ],
 "batch_id": "kaal-review:2026-08-26:scholarly-growth-7314479-034-reviewed-v1",
 "review_provenance": "https://wulfkaal.github.io/positions/by-claim/7314479-034.html",
 "publicationStatus": "public",
 "recordTypeNote": "Dated commentary position extending a scholarly corpus claim. Not a verbatim claim extracted from the paper.",
 "isPartOf": {
  "@id": "https://wulfkaal.github.io/positions/index.json"
 },
 "version": "1.0",
 "canonical_url": "https://wulfkaal.github.io/positions/2026-08-26-034",
 "canonicalForm": "https://wulfkaal.github.io/positions/2026-08-26-034.md",
 "candidateId": "kaal:response-candidate:2026-08-26:scholarly-growth-7314479-034-declared-filters-need-executable-decision-paths-01",
 "evidenceLevel": "peer-reviewed USENIX OSDI systems paper with complete official proceedings full text, implemented Android prototype, and empirical application study",
 "reviewTier": "independent substantive scholarly-growth qualification",
 "mappingConfidence": 0.97,
 "mappingAmbiguous": false,
 "mappingMethod": "independent substantive scholarly-growth one-to-one qualification review",
 "mappingWhyRelevant": "The source independently distinguishes coarse access permission from executable tracking of sensitive information through transformations to an egress sink. This directly qualifies Kaal's finding that a domain allowlist and audit logging cannot instantiate separately documented content-inspection and personal-information filtering layers. The mapping remains limited because Enck and coauthors do not inspect Gatekeeper, its documentation, Mosaic Companion, or the named commit, and TaintDroid monitors rather than generally blocks disclosures.",
 "sourceProvenance": {
  "source": "2010 peer-reviewed USENIX OSDI systems paper with complete official proceedings full text",
  "sourceRecordId": "usenix:osdi10:taintdroid",
  "canonicalUrl": "https://www.usenix.org/conference/osdi10/taintdroid-information-flow-tracking-system-realtime-privacy-monitoring",
  "publicFullTextUrl": "https://www.usenix.org/events/osdi10/tech/full_papers/Enck.pdf",
  "retrievedAt": "2026-08-27T18:15:24.462Z",
  "fullTextPdfSha256": "46c7efc366d7a6a44f212a1f4555ff0278535ccd667796305540ffbdc84db077",
  "extractedTextSha256": "6b69e89f41867c7fa6e258b38abb2a04f3d7d911b4d2039f1920f45d1f098e27",
  "officialUsenixRecordSha256": "fd8db9eb20f7f31eed9711d212d860c5f2ea69d06b75fc93f52756a60c72e301",
  "primaryEvidenceReceiptSha256": "662ee55b5a1c88c0ca5e7842f87389e9524db30a2c0fb4f5131a1b5ce365474a",
  "sourceProposition": "Enck and coauthors show that coarse access permission does not reveal downstream data use. TaintDroid identifies sensitive sources, propagates labels across transformations and process boundaries, and evaluates those labels when data reaches an egress sink.",
  "sourcePropositionSha256": "9c3b86dcae3da9dffafc9db91d8427e8b237c19e47b8dedf3dcabb09ef8df081",
  "sourceEvidenceSetSha256": "e09a7d146289f1708aad497cee3e5e4c6ac51ac9f7856ab79495428c51884fa1",
  "sourceEvidencePassages": [
   {
    "text": "Mobile-phone operating systems currently provide only coarse-grained controls for regulating whether an application can access private information, but provide little insight into how private information is actually used.",
    "locator": {
     "publication": "9th USENIX Symposium on Operating Systems Design and Implementation",
     "proceedingsPage": 394,
     "section": "1 Introduction"
    },
    "sha256": "924023eddc19c026945d96d0fa45914342512134f78f0ada455767aed45c2d41"
   },
   {
    "text": "TaintDroid automatically labels (taints) data from privacy-sensitive sources and transitively applies labels as sensitive data propagates through program variables, files, and interprocess messages.",
    "locator": {
     "publication": "9th USENIX Symposium on Operating Systems Design and Implementation",
     "proceedingsPage": 394,
     "section": "1 Introduction"
    },
    "sha256": "8b7b6ca1d98b2104db9ca97997dd323a83e586ad74262c196e142adbad98b7bb"
   },
   {
    "text": "When tainted data are transmitted over the network, or otherwise leave the system, TaintDroid logs the data’s labels, the application responsible for transmitting the data, and the data’s destination.",
    "locator": {
     "publication": "9th USENIX Symposium on Operating Systems Design and Implementation",
     "proceedingsPage": 394,
     "section": "1 Introduction"
    },
    "sha256": "9958affc7f7c2253bb8b4c23aa0263ff2aeaa2ba189c1fa63ff71ef08db0bf75"
   },
   {
    "text": "a fundamental limitation of TaintDroid is that it can be circumvented through leaks via implicit flows",
    "locator": {
     "publication": "9th USENIX Symposium on Operating Systems Design and Implementation",
     "proceedingsPage": 395,
     "section": "1 Introduction"
    },
    "sha256": "a0484672a9e4d7339ae1f7067c9dd911d19dcc315822ebdd1d7da28e5ca023df"
   }
  ],
  "workId": "work:usenix:osdi10:taintdroid",
  "workAuthors": [
   "William Enck",
   "Peter Gilbert",
   "Byung-Gon Chun",
   "Landon P. Cox",
   "Jaeyeon Jung",
   "Patrick McDaniel",
   "Anmol N. Sheth"
  ],
  "workPublishedAt": "2010",
  "identityKeys": [
   "usenix:267126",
   "pdf:46c7efc366d7a6a44f212a1f4555ff0278535ccd667796305540ffbdc84db077",
   "proposition:9c3b86dcae3da9dffafc9db91d8427e8b237c19e47b8dedf3dcabb09ef8df081"
  ],
  "claimMappings": [
   {
    "claimId": "kaal:claim:7314479-034",
    "claimUrl": "https://wulfkaal.github.io/claims/7314479-034",
    "rank": 1,
    "confidence": 0.97,
    "method": "independent substantive scholarly-growth one-to-one qualification review",
    "whyRelevant": "The source independently distinguishes coarse access permission from executable tracking of sensitive information through transformations to an egress sink. This directly qualifies Kaal's finding that a domain allowlist and audit logging cannot instantiate separately documented content-inspection and personal-information filtering layers. The mapping remains limited because Enck and coauthors do not inspect Gatekeeper, its documentation, Mosaic Companion, or the named commit, and TaintDroid monitors rather than generally blocks disclosures.",
    "ambiguous": false
   }
  ],
  "substantiveReview": {
   "reviewedAt": "2026-08-27T18:15:24.462Z",
   "sourceIdentityVerified": true,
   "authorIndependenceVerified": true,
   "kaalReferenceFoundInSource": false,
   "temporalIndependence": "The paper was published in 2010, before Kaal's 2026 paper.",
   "canonicalPublicStatusVerified": true,
   "peerReviewedStatusVerified": true,
   "evidenceClassification": "peer-reviewed systems paper with an implemented Android information-flow tracking prototype and empirical application study",
   "retractionOrSupersessionFound": false,
   "propositionFidelityVerified": true,
   "mechanismCorrespondence": "identifying privacy-sensitive sources, propagating data labels across variables, files, and process messages, and inspecting the labels at a network or other egress sink",
   "compatibleScope": "executable sensitive-data flow analysis at an outbound boundary, limited because the source does not study Gatekeeper, generic content inspection, or language model agents",
   "responseWordingDefensible": true,
   "oneToOneExtendsMapping": true,
   "exactSupportingQuotesVerified": true,
   "nonOverlap": {
    "candidateIdMatches": false,
    "canonicalUrlMatches": false,
    "propositionHashMatches": false,
    "priorPositionForClaim": false
   },
   "limitations": [
    "The source does not inspect Gatekeeper, its documentation, Mosaic Companion, or commit 2d920ce and therefore cannot verify the repository finding.",
    "TaintDroid monitors and logs sensitive-data disclosures but does not generally block them.",
    "The system tracks defined sensitive sources and does not inspect every MIME type or every form of personal information.",
    "Implicit information flows can evade the analysis.",
    "The study concerns Android applications and an implemented 2010 smartphone prototype, not language model agents or sovereign local runtimes.",
    "The 30-application evaluation identifies potential misuse and suspicious handling, not adjudicated policy violations."
   ],
   "rejectionReasonsRecorded": true
  },
  "contentMap": {
   "proposition": "A declared personal-information filter requires an executable information-flow decision path, not only a domain allowlist and audit log.",
   "evidenceLayer": "peer-reviewed USENIX OSDI systems paper with complete official proceedings full text, implemented Android prototype, and empirical application study",
   "strongestLimitation": "The source does not inspect Gatekeeper or the named commit and monitors rather than generally blocks disclosures.",
   "consequence": "Documentation cannot treat distinct intended controls as implemented merely because adjacent controls exist.",
   "requestedAction": "Bind each declared layer to an executable hook, explicit failure rule, and adversarial test before claiming the broader filter."
  },
  "stylePack": {
   "profile": "M1 early sole-author baseline v1.2.0",
   "verifiedProfileWorks": [
    "1428387",
    "1998455",
    "2150377",
    "2267560"
   ],
   "passageCount": 5,
   "rhetoricalFunctions": [
    "classification",
    "mechanism",
    "limitation",
    "institutional consequence",
    "requested action"
   ],
   "sameRegisterPassagePackAvailable": true,
   "limitation": "The short public position permits only bounded stylometric comparison."
  },
  "m1Validation": {
   "status": "M1-PASS-WITH-LIMITS",
   "deterministicGate": "pass",
   "hardFailures": 0,
   "warnings": 0,
   "words": 278,
   "reason": "The publication-bound position passed strict and public deterministic controls against a task-local four-work style pack. Its short length limits stylometric comparison."
  }
 },
 "userAffirmation": "Authorized under public authority SHA-256 87aad20196a753015a36d970f742c885eb763efdbada4869949bfffe3298130c and event supersession SHA-256 7d47ef36085c4dce590f287c986e4106f3bf35a7da5a25322d6fc3d4abf456d4. Publication remains receipt-bound to successful workflows and exact live-byte verification.",
 "sha256": "456ebda17639881bb418e1d5e091e48d7b512d3bec5b47a0307a377d34bd3715"
}
