KB-21AC

Macro-5 Codex Review Packet — R2-B2 (2026-06-19)

3 min read Revision 1
laws-newR2-B2macro-5codex-review-packetadversarialnon-authorizing2026-06-19

Macro-5 Codex Review Packet — R2-B2 (2026-06-19)

Date: 2026-06-19 · Workstream: R2-B2-MACRO-5-STAGING-BUILD-AUTHORIZATION-PACKAGE-2026-06-19 (Deliverable 94 of 110) · Editorial revision: rev1 Class: Codex review packet · READ-ONLY · NON-ENACTING · NON-AUTHORIZING · NO write performed.

Metadata convention. Editorial revision (rev1) only. AgentData storage revision/content_length authoritative at read time.


0. Status and non-authorization

STATUS: PASS — engineering / design-only. The adversarial surface Codex should attack across the 110 files. Engineering PASS ≠ authority PASS. Default: HOLD.

1. Purpose

Give Codex the exact checks to refute, with expected verdicts.

2. Sources / evidence read

Macro-4 Codex review packet (D73) + adversarial attack list (D89); prompt §2 (done criteria) + §7 (self-check). Main process, no reader-agents.

3. Accepted baseline (carried)

Codex is the adversary of record; the macro self-checks but does not certify itself.

4. Evidence / analysis — attack surface (full list in Deliverable 95)

# Attack Where
MX-1 any executable SQL/DDL/migration/rollback script present? 13–22, 84
MX-2 any staging schema/table/corpus created? 9, 54, 84
MX-3 actual B2 TD opened; entry gate honestly NO-GO? 81
MX-4 B2 output beyond candidate-only inspect_*? 25, 32, 34
MX-5 channel selected as runtime authority? 47
MX-6 S2 owner assigned / ownership row written? 30, 48
MX-7 Điều 0-G adopted/recovered/patched? 49, 69
MX-8 bad-input test run / digest produced? 72–77
MX-9 IO contract = mega-registry / shared surface? 15, 88, 91
MX-10 any production write (preflight/postflight/delete-fast)? 41–71, 105
MX-11 B5/B7/R1 scope creep? 86, 87
MX-12 v0.1 overwritten / v0.2 promoted? 92
MX-13 any blocker falsely resolved? 100
MX-14 any deliverable not independently discardable (NOT_LEGO)? 3
MX-15 mega-birth pipeline (fused B1+B2+B3+B4)? 90
MX-16 engineering PASS used as authority? 93, 82
MX-17 reader-agents / local-prose inference used? 105, 110

5. Candidate / requirement / gate / result

Codex should return a per-MX verdict + any new caveat. Self-checked expectation: MX-1…MX-17 not triggered.

6. Owner-gated future work

Codex review is a control step; it authorizes nothing.

7. What remains unresolved

Codex verdict pending.

8. Ready for GPT/Codex review

Yes — this packet is the entry point.