--- id: CFG-17 family: GR-CFG level: extended profiles: [storage-api] posture: normative-target added: "1.0" changed: "1.0" source: https://flowdrop.io/spec/rules/gr-cfg/cfg-17 specification: FlowDrop Workflow Specification 1.0-draft licence: CC BY 4.0 --- # CFG-17 — A hidden port cannot be filled through the bundle *GR-CFG (Part I) · level: extended · profiles: storage-api · added in 1.0* Decomposition filters on `connectable` alone, so a hidden port's key can survive the unpacking. Resolution then applies the exposure gate a second time. Two guards, one outcome: a hidden port is not fillable, by any route. ## The rule > **Normative.** This is the rule. > > 1. Decomposition of the unified `input` port (CFG-16) admits a key on the strength of `connectable` alone. > > 2. A value that reaches a hidden connectable port this way is still discarded when the parameter is resolved, because priority 1 requires the port to be exposed (CFG-4). > > 3. Bundling a value must never fill a port that could not be wired directly. ## Related rules - Names: CFG-4, CFG-16, EXPO-10 - Referenced by: CFG-16, EXPO-10 --- Rule identifiers are permanent and are never renumbered. This specification carries no implementation status: each implementation publishes its own standing against these rules. Licensed CC BY 4.0.