KB-452C

Macro-4 Codex Review Packet — R2-B2 (2026-06-19)

3 min read Revision 1
laws-newR2-B2macro-4codex-review-packetadversarialnon-authorizing2026-06-19

Macro-4 Codex Review Packet — R2-B2 (2026-06-19)

Date: 2026-06-19 · Workstream: R2-B2-MACRO-4-STAGING-WORKBENCH-IO-CONTRACT-TD-ENTRY-GATE-2026-06-19 (Deliverable 73 of 90) · Editorial revision: rev1 Class: Codex adversarial review packet · READ-ONLY · NON-ENACTING · NON-AUTHORIZING · NO write performed.

Metadata convention. Editorial revision (rev1) only. Storage revision/content_length authoritative at read time.


0. Status and non-authorization

STATUS: PASS — engineering / design-only. The adversarial brief for Codex on the 90-file package. Engineering PASS ≠ authority PASS. Default: HOLD.

1. Purpose

Tell Codex exactly what to attack before the Owner-delegate accepts Macro-4.

2. Sources / evidence read

All 89 sibling deliverables; Macro-3 Codex packet (AX-1…10) + Codex review; the process caveat (read direct, main process, no reader-agents). Main process, no reader-agents.

3. Accepted baseline (carried)

Macro-3 Codex verdict PASS_WITH_CAVEATS; the process caveat was honored this run (sources read first-hand in the main process; oversized batches decoded via /tmp python = decode-scratch only, never via a reader-agent).

4. Evidence / analysis — attack surface (full list in Deliverable 89)

# Attack Where
MX-1 Is any staging deliverable a build artifact (schema/DDL/corpus)? 6–12, 57–58
MX-2 Is the IO contract envelope a mega-registry / universal write surface? 19–28, 68
MX-3 Is B2's output anything but candidate-only inspect_*? 30, 35
MX-4 Is any channel statement a selection / wiring? 61
MX-5 Is any S2 statement an assignment / ownership-row write? 62
MX-6 Is any Điều 0-G statement adoption / recovery / patch? 63
MX-7 Is any bad-input test run / digest produced? 49–54
MX-8 Is the entry gate honestly NO-GO; any actual TD present? 55–56
MX-9 Is the staging-build gate conflated with the TD gate? 57–59
MX-10 Delete-fast / no-production-touch: any production write? 10–11, 37–48, 81
MX-11 B5/B7/R1 scope creep? 66–67
MX-12 v0.1 overwritten / v0.2 promoted? 71
MX-13 Any blocker falsely resolved? 79
MX-14 Any deliverable not independently discardable (NOT_LEGO_COMPATIBLE)? 3

5. Contract / requirement / matrix / result

Codex should return a per-MX verdict + any new caveat. Default expectation: MX-1…MX-14 not triggered (self-checked), but Codex is the adversary of record.

6. Owner-gated future work

Owner-delegate acceptance follows Codex review; not enacted here.

7. What remains unresolved

Codex review pending; all blockers OPEN.

8. Ready for GPT/Codex review

Yes — this is the Codex entry point (paired with Deliverable 89's full attack list).