KB-1CBA rev 117

00-index.md

101 min read Revision 117
tool-kiem-thuv0.2-hardeningcontent-bindingnon-authority

00 — Index — tool-kiem-thu

Central index for the Implementation Package DOT initiative. One line per document. Updated: 2026-06-10 · Current phase: T1 rev4 repair complete → GAP_ONLY_SCOPE_SPEC_v0_1_REV4_READY_FOR_CODEX (after the Codex rev3 guard block GAP_ONLY_SPEC_REV3_PARTIAL_FIX_REQUIRED). rev4's decisive move: the MVP is re-scoped to an offline, packet-derived, NON-GATING inspector (no network, no PG driver, no live query, no KB write, no secret, no arbitrary local-FS; reads a governed-provenance export packet; writes a local report) running inside a deny-by-default sandbox that is named/specified and provisioned + negative-tested as build scope (B4′) — the honest answer to Codex's "ungrounded process-level assertions": it removes the live attack surface rather than asserting an unproven sandbox. Denial-authority repair: decision_effect=NONE / may_gate=false / 5 bounded scoped verdicts / scope_of_denial / non-global disclaimer. MVP implementation remains unauthorized; rev4 makes the decision adjudicable, not granted. Internal-proof update (2026-06-09, no Codex consulted): an internal evidence proof (reports/internal-evidence-proof-rev4-phase2-readiness-2026-06-09.{md,json}) closed every internally-provable layer (scope lock 12/12, guard requirements 14/14, negative coverage 16/16, Article 13+14 PASS) and determined INTERNAL_PROOF_PARTIAL / Decision D — TRUE_BLOCKER (owner/operator + resource): the load-bearing gate is the owner/operator provisioning the §12.1 deny-by-default sandbox host (M5/B4′, specified-not-deployed); B0‴ (Codex re-seal) is a parallel, owner-waivable authority gate, not the load-bearing blocker. No rev5 design defect found. Sandbox-feasibility update (2026-06-09, no Codex consulted): a sandbox-feasibility + build-go macro (reports/sandbox-feasibility-and-phase2-build-go-decision-2026-06-09.{md,json}) reclassified the TRUE_BLOCKER reading to SANDBOX_DECISION_READY / build-go B — BUILD_PROMPT_READY_BUT_OPERATOR_SANDBOX_ACTION_REQUIRED. Decisive new governed-native evidence: a read-only list_docker shows the Docker runtime is already deployed + 11 live containers on the host (incl. ephemeral pg-restore-test-…), so a deny-by-default container (Option B) is realizable on the existing runtime — no install. The guard harness (sandbox profile + L2/L3 guards + negatives) is build-scope and authorable now; only the operator attestation (B4′) and the owner's B0‴ disposition stand before an accepted build — neither a true blocker. A gated build prompt + an operator action packet were authored. Next = owner disposes B0‴ + operator attests the §12.1 sandbox, then execute the gated build prompt. Sandbox-attestation update (2026-06-09, no Codex; B0‴ owner-WAIVED for this offline-MVP prototype-prep scope only): a provision-and-attest macro attempted to close B4′ end-to-end and determined SANDBOX_ATTESTATION_PARTIAL — operator action required; B4′ remains BLOCKED. Decisive constraint: no agent execution surface can run/attest a sandbox — the governed VPS Docker socket is read-only by design (no run/exec/create tool), and a Mac-local attestation is rejected as a B4′ substitute (owner direction; Article-14 venue-confusion). The agent therefore authored a complete reproducible deny-by-default profile (designs/deny-by-default-sandbox-profile-…: Dockerfile distroless, seccomp-deny-by-default.json 4a targeted-deny + 4b hardened, exact docker run, 12 attestation probes with expected EPERM/EROFS/empty-keyset outputs, evidence schema) + a command-level operator blocker packet to run on the VPS throwaway container or an approved CI runner. Build-prompt v2 was not created (precondition 2 still UNMET). Article 13 + 14 PASS; no fake-green; no SANDBOX_ATTESTED_READY. Next = operator runs the blocker packet on VPS/CI and returns §7 evidence; a follow-up agent verifies read-only and binds to matrix #24–#37. End-to-end close attempt (2026-06-10, no Codex): a program macro tried to close the whole Phase-2 offline-MVP path end-to-end (KB SSOT → venue → B4′ → build → tests → FIX7 → matrix binding) and determined B4_PRIME_OPERATOR_ACTION_REQUIRED — it stops at Track 2 (venue/runtime) because the same load-bearing blocker holds: a fresh read-only list_docker (11 containers) re-confirms the VPS Docker socket is read-only by design (no run/exec/create tool), no approved CI runner is agent-reachable, and Mac-local is rejected. Build/tests/FIX7/matrix-binding are downstream of B4′ and were correctly NOT fabricated. New docs: checkpoints/action-ready-blocker-after-phase2-offline-mvp-execution-path-2026-06-09.md + checkpoints/checkpoint-phase2-offline-mvp-execution-path-2026-06-09.md. These route to (do not duplicate) the canonical operator-blocker-packet-sandbox-attestation-2026-06-09.md.

Documents (chronological)

Path Kind Status Hook
README.md readme active What the initiative is + folder rules.
00-index.md index active This file.
planning/implementation-package-dot-v0-1-feasibility-plan-2026-06-09.md plan SUPERSEDED (maturity + readiness) First feasibility plan. Useful for the 8-check shape only. Its "PARTIAL / mostly design" framing understated the estate.
reports/text-as-code-reuse-anti-duplication-audit-2026-06-09.md audit RATED UNSAFE by Codex Reuse/anti-duplication audit. Found much deployed infra, but omitted the count ledger → Codex CLAUDE_AUDIT_UNSAFE_TO_USE_FOR_PLANNING. Read with the baseline + Codex review.
reviews/codex-crosscheck-text-as-code-reuse-audit-2026-06-09.md review (Codex) active Adversarial cross-check: CLAUDE_AUDIT_UNSAFE_TO_USE_FOR_PLANNING / NEEDS_FRESH_BASELINE_FIRST. Confirms the DOT-count was several different sets/dates; lists 10 authority gates.
reports/dot-registry-directus-text-as-code-baseline-reconciliation-2026-06-09.md baseline BASELINE_READY_FOR_AUTHORITY_DECISION Read this for any count. Fresh live (07:11 UTC) denominator-separated ledger: registry 309 / operational-FS 214 / fs-confirmed 186 / actual_count 163 / command-catalog 54 / registry-no-file 41; flows 128; IU 219 / TAC 102 (no compat view). Counts NOT collapsed.
reports/dot-registry-directus-text-as-code-baseline-reconciliation-2026-06-09.json baseline (machine) active Machine-readable snapshot of the same ledger (surfaces[], denominator/query/mode/ts/confidence/conflicts).
reports/authority-decision-matrix-draft-after-baseline-2026-06-09.md decision matrix (DRAFT) AUTHORITY_MATRIX_READY_FOR_GPT_REVIEW The decision frame. 10 authority domains A–J, each with recommended option + confidence + evidence + risks + prohibition + Codex-required + blocks-spec. Decide-now: A/E/F/I/J. Codex-seal: C/D/G/H(+B). Fresh-read: actual_count filter / OS listing / scripts-42 / Đ23 inverse-check. Does NOT decide — frames decisions.
reports/authority-decision-matrix-draft-after-baseline-2026-06-09.json decision matrix (machine) active Machine-readable mirror: domains[] with recommended/confidence/evidence/risks/prohibited/codex/blocks + closure_plan + ip_dot_impact + questions_for_review.
reports/authority-matrix-fresh-read-closure-bcdgh-2026-06-09.md fresh-read closure FRESH_READ_CLOSURE_PARTIAL Read this for B/C/D/G/H. Read-only closure of the 5 deferred domains. Resolves: G=EXISTING_AUTHORITY_SUFFICIENT, H=NO_BRIDGE_DUAL_REPORT_ONLY, 41-vs-4 fully explained, "42 surface"=/opt/incomex/scripts (separate, not DOT). 🔴 C's 186∩command-catalog formula WITHDRAWN — join=0, disjoint spaces; safe read-only set exists only on IU layer (15 mutating=false). actual_count=163 = external-sync artifact, UNVERIFIABLE/UNSAFE.
reports/authority-matrix-fresh-read-closure-bcdgh-2026-06-09.json fresh-read closure (machine) active Machine-readable mirror: domains B/C/D/G/H + counts[] + safe_call_set_result + tac_iu_result + duplicate_graph_orphan_result + matrix_patch + permanently_unverifiable_readonly.
reviews/codex-seal-authority-matrix-bcdgh-2026-06-09.md Codex authority seal BCDGH_SEALED Read this for final B/C/D/G/H authority wording. B=no filesystem calls in v0.1; C=no calls until separate contract; D=fresh code-keyed current diff; G=reuse existing/no new resolver; H=dual-report/no bridge authority.
contracts/authority-contract-v0-1-2026-06-09.md authority-contract draft AUTHORITY_CONTRACT_V0_1_READY_FOR_GPT_REVIEW — not yet binding Records sealed B/C/D/G/H + proposed/adopted-default A/E/F/I/J. Its authority status must be normalized before MVP; do not treat review-ready as binding.
contracts/authority-contract-v0-1-2026-06-09.json authority contract (machine) active Machine-readable mirror: status/scope/denominator_contract/allowed/prohibited/reuse/unresolved/gate/sealed_decisions A–J/parallel_authority_risk.
reports/reuse-extraction-map-v0-1-2026-06-09.md reuse extraction map REUSE_EXTRACTION_MAP_READY_FOR_GPT_REVIEW The reuse map. 18 capabilities each classified A REUSE_AS_IS / B REUSE_WITH_ADAPTER (read-only) / C REFERENCE_ONLY / D PROHIBITED_OVERLAP / E TRUE_GAP / F UNVERIFIED. Biggest reuse = deployed reconciliation+graph+corpus read surfaces (read-only). Biggest prohibited = any 2nd runner/invoker + 3rd manifest/logger/graph-resolver/TAC↔IU bridge. True gaps (all DEFERRED): command-runner+exit-codes, claim↔test run-binder, generic manifest schema, --selftest+module_sha256, audit_dead_links() engine. Gap-only Spec readiness = PARTIAL_READY (read-only surface ready; execution gaps carved out).
reports/reuse-extraction-map-v0-1-2026-06-09.json reuse extraction map (machine) active Machine-readable mirror: capability_map[] (18) + reuse_as_is/adapter/reference/prohibited/true_gaps/unverified + gap_only_spec_readiness + parallel_authority_risk.
designs/implementation-package-dot-v0-1-gap-only-scope-spec-2026-06-09.md gap-only scope spec GAP_ONLY_SCOPE_SPEC_v0_1_READY_FOR_CODEX_CHECKPOINT The read/report-only scope spec. What v0.1 is/is-not, allowed read inputs, report+JSON contract, verdict vocab (strongest positive EVIDENCE_PRESENT (not proof-of-run)), 12 failure modes, 7-denominator separation, claim/evidence inventory, dual-report TAC/IU, canonical reconciliation, 20-item prohibited-overlap wall, 8 read-only adapters in scope, 8 execution carve-outs deferred. READY (read surface) / DEFERRED (execution).
designs/implementation-package-dot-v0-1-gap-only-scope-spec-2026-06-09.json gap-only spec (machine) active Machine mirror: denominator_contract/allowed_inputs/output_contract/verdict_vocabulary/failure_modes/in_scope_adapters/deferred_carveouts/prohibited_overlaps. Design artifact, NOT a runtime schema.
designs/fix7-read-report-pilot-design-for-implementation-package-dot-v0-1-2026-06-09.md FIX7 read/report pilot FIX7_READ_REPORT_PILOT_DESIGN_READY_FOR_CODEX_CHECKPOINT Catches the Recheck-8/Article-14 "claim-without-evidence" class at read level. 7 reasons (C1–C7) → read-only verdicts; checks whether each executable claim has a resolvable evidence artifact; runs nothing (no canonicalizer/command/hash recompute). Two fixtures: real dossier + stripped negative (Acceptance Test #20).
planning/mvp-read-report-inspector-implementation-plan-no-code-2026-06-09.md MVP plan (no code) active — build BLOCKED until seal Future read/report-only MVP: 11 proposed modules (no runner/logger/registry/resolver/bridge), inputs/outputs, 7 internal phases, 7 validation gates + 4 manual gates, 10-case negative plan, fallback + fail-closed exit semantics, what stays blocked until the Call Contract. NO code/schema/runner.
designs/acceptance-test-matrix-implementation-package-dot-v0-1-2026-06-09.md acceptance matrix ACCEPTANCE_MATRIX_v0_1_READY_FOR_CODEX_CHECKPOINT 20 in-scope fail-closed tests (missing identity/blueprint/revision; executable/selftest/hash/exit claims w/o evidence; command-without-call-contract; collapsed denominator; TAC/IU chosen; registry mismatch; stale source; prose-only PASS; invoke/write/mutate/resolver attempts; missing JSON/checkpoint; FIX7 Recheck-8 stripped → FLAG) + 7 deferred tests.
planning/future-contracts-queue-after-v0-1-2026-06-09.md future contracts queue active 7 deferred contracts: Call Contract (keystone), proof-of-run semantics, system_issues write, Directus DOT-control proof, TAC↔IU bridge/resolver, registry cleanup/reconciliation, OPA/Conftest/Squawk/CI integration. Each: why deferred / unlocks / must-prove / Codex-mandatory.
reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-2026-06-09.md Codex checkpoint packet reviewed — blockers returned Compact input packet; its intended greenlight was rejected by Codex review.
reviews/codex-review-gap-only-spec-fix7-pilot-mvp-readiness-2026-06-09.md Codex adversarial review BLOCKED_BY_AUTHORITY_OR_ARTICLE14_RISK Read this first. Finds structural Article-14 fake-green, hardcoded normative counts, incomplete claim discovery/evidence binding, exit-0-for-FLAG, and insufficient FIX7 pilot. MVP build = NO.
checkpoints/action-ready-blockers-after-gap-only-spec-2026-06-09.md action-ready blockers superseded by Codex review Its “no engineering omissions” claim is rejected; exact correction blockers are in the Codex review.
checkpoints/checkpoint-gap-only-spec-and-fix7-pilot-design-2026-06-09.md checkpoint historical — readiness rejected T1 session claimed PROGRAM_MACRO_READY; Codex review rejected that readiness due Article-14, hardcode, fake-green, and authority blockers.
checkpoints/checkpoint-implementation-package-dot-v0-1-feasibility-plan-2026-06-09.md checkpoint active First plan session.
checkpoints/checkpoint-text-as-code-reuse-anti-duplication-audit-2026-06-09.md checkpoint active Reuse-audit session.
checkpoints/checkpoint-dot-registry-directus-text-as-code-baseline-reconciliation-2026-06-09.md checkpoint active Baseline-reconciliation session.
checkpoints/checkpoint-authority-decision-matrix-draft-after-baseline-2026-06-09.md checkpoint active Authority-decision-matrix-draft session.
checkpoints/checkpoint-authority-matrix-fresh-read-closure-bcdgh-2026-06-09.md checkpoint active B/C/D/G/H fresh-read closure session.
checkpoints/checkpoint-codex-seal-authority-matrix-bcdgh-2026-06-09.md checkpoint active Codex seal snapshot: BCDGH_SEALED, no production mutation, Authority Contract v0.1 next.
checkpoints/checkpoint-authority-contract-v0-1-2026-06-09.md checkpoint active Authority Contract v0.1 session: AUTHORITY_CONTRACT_V0_1_READY_FOR_GPT_REVIEW, no mutation, Reuse Extraction Map next.
checkpoints/checkpoint-reuse-extraction-map-v0-1-2026-06-09.md checkpoint active Reuse Extraction Map v0.1 session: REUSE_EXTRACTION_MAP_READY_FOR_GPT_REVIEW, Gap-only Spec readiness PARTIAL_READY, no mutation, GPT review next.
checkpoints/checkpoint-codex-review-gap-only-spec-fix7-pilot-mvp-readiness-2026-06-09.md checkpoint active Codex checkpoint result: Article 14 FAIL, hardcode/fake-green FAIL, FIX7 pilot FAIL, MVP readiness FAIL.
reports/codex-fix-ledger-gap-only-spec-rev2-2026-06-09.md Codex fix ledger (rev2) CODEX_FIX_LEDGER_REV2_COMPLETE Read this to see the 12 fixes. Maps each Codex §7 fix → rev2 doc/section → repair → completed (12/12 = YES) → residual risk.
designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev2-2026-06-09.md gap-only scope spec (rev2) GAP_ONLY_SCOPE_SPEC_v0_1_REV2_READY_FOR_CODEX The repaired master spec. Article-14 adequacy chain (claim→type→required class→artifact→capability→adequacy→verdict); verdicts READ_LEVEL_ACCEPTABLE/FAIL/BLOCKED/UNVERIFIED + article14_status (no READ_REPORT_PASS); 12 evidence classes; 13 claim types; denominator source-records (no literal gates); capability enums + static/runtime guard; fake-green-proof exit semantics; PG-first/native/driven. Supersedes rev1.
designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev2-2026-06-09.json gap-only spec rev2 (machine) active Machine mirror: verdict_model/evidence_class_model/claim_type_matrix/denominator_rules/capability_model/exit_semantics/writes_performed. Design artifact, NOT a runtime schema.
designs/fix7-read-report-pilot-design-rev2-for-implementation-package-dot-v0-1-2026-06-09.md FIX7 read/report pilot (rev2) FIX7_READ_REPORT_PILOT_DESIGN_REV2_READY_FOR_CODEX Scope narrowed to the read-level adequacy half; adds Fixture C (resolvable-but-insufficient/contradictory evidence) ⇒ READ_LEVEL_FAIL+NOT_PROVEN, never EVIDENCE_PRESENT; full Recheck-8 run-proof deferred to the Call Contract. Supersedes rev1.
planning/mvp-read-report-inspector-implementation-plan-no-code-rev2-2026-06-09.md MVP plan rev2 (no code) build BLOCKED until re-seal Modules declare allowed_actions; gates G1–G9 (G2 no >=2; G7 role/key not 41/4; G8 no fake-green; G4/G5 capability guards); negative capability tests. Supersedes rev1.
designs/acceptance-test-matrix-implementation-package-dot-v0-1-rev2-2026-06-09.md acceptance matrix (rev2) ACCEPTANCE_MATRIX_v0_1_REV2_READY_FOR_CODEX 25 fail-closed tests covering every Codex failure mode (resolvable-but-insufficient #21, missing-artifact #20, high-risk-unparsed #23, hardcoded-denominator #9/#12, exit-0 fake-green #18, module-declares-prohibited #14, contract-overclaim #24, selftest-no-ledger #5, command-no-call-contract #8) + 7 deferred. Fixtures named as fixtures; no literal count invariant. Supersedes rev1.
reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-rev2-2026-06-09.md Codex checkpoint packet (rev2) REV2_READY_FOR_CODEX Compact re-review request: 11 deltas + 8 questions; requested disposition GAP_ONLY_SPEC_REV2_SEALED or RETURN_BLOCKERS. Supersedes rev1 packet.
checkpoints/action-ready-blockers-after-gap-only-spec-rev2-2026-06-09.md action-ready blockers (rev2) active No "no engineering omissions" claim. B0′ (fresh re-seal) + B4 (capability guards built + negative tests) gate the read/report MVP; B5 bounds positive verdicts; B1/B2/B3 gate the execution surface. Supersedes rev1.
checkpoints/checkpoint-gap-only-spec-rev2-after-codex-block-2026-06-09.md checkpoint (rev2) REV2_READY_FOR_CODEX — reviewed T1 repair session and self-audit; readiness claim superseded by Codex re-seal below.
reviews/codex-reseal-gap-only-spec-rev2-2026-06-09.md Codex adversarial re-seal GAP_ONLY_SPEC_REV2_PARTIAL_FIX_REQUIRED Article 14 PASS; PG-first/native/driven FAIL for build readiness; capability enforcement and policy authority need narrow rev3.
checkpoints/checkpoint-codex-reseal-gap-only-spec-rev2-2026-06-09.md Codex checkpoint active Re-seal snapshot: MVP implementation NO; production mutation NO; next = return to T1 for rev3.
designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev3-2026-06-09.md gap-only scope spec (rev3) GAP_ONLY_SCOPE_SPEC_v0_1_REV3_READY_FOR_CODEX — reviewed, partial The rev3 repair attempt. Correctly closes FIX7 discoverability and improves the other blocker classes, but Codex returned residual negative-authority and structural-guard blockers. v0.1 = negative/triage-only, non-authoritative (no READ_LEVEL_ACCEPTABLE, no exit 0; ceiling = UNVERIFIED); taxonomy PROVISIONAL_NON_AUTHORITY+versioned+fail-closed; KB-first/PG-first/local-last §0; endpoint-allowlist capability guard + verified context_pack_readonly substrate (§9.1); FIX7 discovery chain (§12.1/§21). Article 14 preserved + strengthened. Supersedes rev2.
designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev3-2026-06-09.json gap-only spec rev3 (machine) active Machine mirror: triage-only verdict model (no positive/exit-0), taxonomy_governance, capability_model (allowlist + no-direct-driver), verified_substrate, fix7_discovery_chain, self_audit. Design artifact, NOT a runtime schema.
designs/fix7-read-report-pilot-design-rev3-for-implementation-package-dot-v0-1-2026-06-09.md FIX7 read/report pilot (rev3) FIX7_READ_REPORT_PILOT_DESIGN_REV3_READY_FOR_CODEX Adds the read-only discovery chain (§3.1) + the grounded run record (§3.2): the canonicalizer resolves only as a .md; the .py resolves on no governed surface ⇒ BLOCKED_BY_UNVERIFIED_SOURCE. Fixture A → UNVERIFIED (not FAIL); Fixture A′ (pure discoverability) added; proves_global_absence:false. Supersedes rev2.
planning/mvp-read-report-inspector-implementation-plan-no-code-rev3-2026-06-09.md MVP plan rev3 (no code) build BLOCKED until re-seal Modules declare allowed_actions {READ_KB_DOC, READ_ONLY_QUERY, WRITE_KB_REPORT}; gates G1–G11 (G4/G5 expanded capability; G10 local-last; G11 read-only-role); §12 PG read-only acceptance reqs; expanded negative tests N16–N28. Supersedes rev2.
designs/acceptance-test-matrix-implementation-package-dot-v0-1-rev3-2026-06-09.md acceptance matrix (rev3) ACCEPTANCE_MATRIX_v0_1_REV3_READY_FOR_CODEX 39 fail-closed tests: no-green (#1/#3), taxonomy-non-authority (#18/#19), PG read-only (#20–#24), bypass paths (#25–#33), local-last (#34/#35), FIX7 discoverability incl. Fixture A′ (#36/#37) + 8 deferred. No positive verdict, no exit 0, no literal count invariant. Supersedes rev2.
reports/codex-fix-ledger-gap-only-spec-rev3-2026-06-09.md Codex fix ledger (rev3) CODEX_FIX_LEDGER_REV3_COMPLETE Read this for the 4 blocker classes. Track-0 extraction → repair → status → residual risk; gate-by-gate disposition; Codex's 5 required corrections mapped.
reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-rev3-2026-06-09.md Codex checkpoint packet (rev3) REV3_READY_FOR_CODEX Compact re-review request — 4 blocker classes only (does NOT ask Codex to re-review history); 5 deltas + 7 questions; disposition GAP_ONLY_SPEC_REV3_SEALED or RETURN_BLOCKERS. Supersedes rev2 packet.
checkpoints/action-ready-blockers-after-gap-only-spec-rev3-2026-06-09.md action-ready blockers (rev3) active B0″ (fresh re-seal) + B4 (guards built + negative tests) gate the read/report MVP; B5 + B6 (no governed taxonomy authority ⇒ triage-only, no green) bound it; B1/B2/B3 gate the execution surface. Supersedes rev2.
checkpoints/checkpoint-gap-only-spec-rev3-after-codex-pgfirst-block-2026-06-09.md checkpoint (rev3) REV3_READY_FOR_CODEX — reviewed T1 rev3 repair session and self-audit; readiness claim superseded by Codex re-seal below.
reviews/codex-reseal-gap-only-spec-rev3-2026-06-09.md Codex adversarial re-seal GAP_ONLY_SPEC_REV3_PARTIAL_FIX_REQUIRED FIX7 discoverability PASS; taxonomy/KB-first/PG guard/negative tests PARTIAL; structural no-run/no-write guard FAIL; MVP build NO.
checkpoints/checkpoint-codex-reseal-gap-only-spec-rev3-2026-06-09.md Codex checkpoint active Re-seal snapshot: production mutation NO; MVP implementation NO; next = return to T1 for rev4.
reports/codex-fix-ledger-gap-only-spec-rev4-2026-06-09.md Codex fix ledger (rev4) CODEX_FIX_LEDGER_REV4_COMPLETE Read this for the 6 guard/authority blockers. Track-0 extraction → rev4 repair → residual risk → MVP-still-blocked; gate-by-gate disposition (Gate 3/7 FAIL reframed feasible); Codex's 5 "minimal next step" corrections mapped (incl. the honest "no bounded KB writer ⇒ MVP does not write KB").
designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev4-2026-06-09.md gap-only scope spec (rev4) GAP_ONLY_SCOPE_SPEC_v0_1_REV4_READY_FOR_CODEX The rev4 master spec. MVP re-scoped offline / packet-derived / NON-GATING (§2): no network/driver/live-query/KB-write/secret/local-FS; reads a governed-provenance packet; writes a local report. §4.0 non-gating non-global denial contract (decision_effect=NONE, may_gate=false, 5 bounded scoped verdicts, scope_of_denial, non-global disclaimer, READ_LEVEL_FAIL="not acceptable for PASS"). §12.1 deny-by-default sandbox (no-net ns, RO input mount, WO output mount, scrubbed env, seccomp) = the named substrate; in-process guards demoted to secondary. §12.6 deferred export step = named query IDs only (MVP issues no SQL). §10/§13 no bounded KB writer claimed. Article 14 preserved + strengthened. Supersedes rev3.
designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev4-2026-06-09.json gap-only spec rev4 (machine) active Machine mirror: offline-packet decisive decision, non_gating_non_global_denial_contract, capability_model (sandbox primary + in-process secondary), deferred_governed_export_step (named-query-ids), output_contract (local, no KB write), mvp_readiness_model (C+A discipline), self_audit. Design artifact, NOT a runtime schema.
designs/fix7-read-report-pilot-design-rev4-for-implementation-package-dot-v0-1-2026-06-09.md FIX7 read/report pilot (rev4) FIX7_READ_REPORT_PILOT_DESIGN_REV4_READY_FOR_CODEX Re-based on the offline-packet model; discovery-chain logic unchanged (Gate 5 PASS preserved). .py existence renamed NOT_EVIDENCED_IN_ALLOWED_SURFACES (= "not adequately evidenced via allowed surfaces," never global absence; FLAG_GLOBAL_DENIAL_WORDING guards it). Adds C11 unsafe-access / C12 global-denial checks + Fixture D (global-denial trap). Non-gating, non-global, no live read, no KB write. Supersedes rev3.
planning/mvp-read-report-inspector-implementation-plan-no-code-rev4-2026-06-09.md MVP plan rev4 (no code) build BLOCKED until re-seal Modules declare allowed_actions ⊆ {READ_PACKET_ITEM, WRITE_LOCAL_REPORT} (rev3 live verbs removed); gates G1–G12 (G5 sandbox-invariant = primary; G8 non-gating; G11 non-global-denial; G12 unsafe-access); §12 report-persistence boundary (local output, KB upload separate); enforcement-bound negative tests N1–N32. Readiness Option C gated on the guard harness. Supersedes rev3.
designs/acceptance-test-matrix-implementation-package-dot-v0-1-rev4-2026-06-09.md acceptance matrix (rev4) ACCEPTANCE_MATRIX_v0_1_REV4_READY_FOR_CODEX 45 fail-closed tests, each capability/bypass test tied to a named enforcement layer (L1 host-sandbox / L2 static-build-guard / L3 runtime-self-check / L4 verdict-output-guard / L5 export-step-deferred) + block point + proof-of-block evidence (Codex blocker 6): non-gating/non-global denial (#18–#23/#45), structural sandbox bypass (#24–#37, incl. #27 corrected to process-level egress), local-last/authority-status (#38–#40), FIX7 incl. Fixture A′/D (#41–#45) + 11 deferred (side-effect-fn #32 → export contract). Supersedes rev3.
reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-rev4-2026-06-09.md Codex checkpoint packet (rev4) REV4_READY_FOR_CODEX Compact re-review request — 6 guard/authority blockers only (not history/baseline/sealed B-H/Article-14); the one decision + six repairs; 7 adjudication points + 7 questions; disposition GAP_ONLY_SPEC_REV4_SEALED or RETURN_BLOCKERS. Supersedes rev3 packet.
checkpoints/action-ready-blockers-after-gap-only-spec-rev4-2026-06-09.md action-ready blockers (rev4) active B0‴ (Codex re-seal) + B4′ (offline guard harness built + enforcement-bound negative tests pass against a real sandbox; gates acceptance) gate the read/report MVP; B6 (triage-only, no green); B7 (deferred online surface: live governed export step + named-query-catalog/driver/network-policy + path-scoped KB writer + downstream gate-consumer); B1/B2/B3 (execution surface). Recommendation = Option C + A-discipline, hard fallback B. Supersedes rev3.
checkpoints/checkpoint-gap-only-spec-rev4-after-codex-guard-block-2026-06-09.md checkpoint (rev4) REV4_READY_FOR_CODEX T1 rev4 repair session + self-audit (10/10 design-level PASS); the decisive offline-packet move; blocker disposition; documents created; readiness recommendation. MVP NOT authorized.
reports/internal-evidence-proof-rev4-phase2-readiness-2026-06-09.md internal evidence proof (no Codex) INTERNAL_PROOF_PARTIAL Read this for the rev4 build-readiness determination. Internal proof (KB readback + rev4 evidence + self-test design; no Codex consulted) of whether Phase 2 can build the offline packet MVP prototype now. 12 tracks: scope lock 12/12 PASS; Codex-blocker→acceptance-test ledger PASS/PARTIAL (all 6 "still blocked"); guard requirements 14/14; negative coverage 16/16; Article 13 + 14 PASS. Decision = D — TRUE_BLOCKER (owner/operator + resource): the load-bearing gate is provisioning the §12.1 sandbox host (M5/B4′, specified-not-deployed); B0‴ Codex re-seal is a parallel owner-waivable gate. A not reachable; B not required; C not load-bearing.
reports/internal-evidence-proof-rev4-phase2-readiness-2026-06-09.json internal proof (machine) active Machine mirror: build_readiness_decision (D) + track1–12 verdicts + action-ready blockers + minimal_safe_next_step. Validated JSON. Evidence only, never authority.
checkpoints/action-ready-blockers-after-internal-proof-rev4-2026-06-09.md action-ready blockers (internal proof) active B-EXT-1 (load-bearing): sandbox host not provisioned — owner/operator resource action, gates build acceptance. B-EXT-2: B0‴ rev4 Codex re-seal open (offline-packet architecture unreviewed) — owner may honor (→Codex) or waive with documented risk. B-DEF-1..6 deferred future-phase contracts. No "no engineering omissions" claim; no rev5 design defect found.
checkpoints/checkpoint-internal-proof-rev4-phase2-readiness-2026-06-09.md checkpoint (internal proof) INTERNAL_PROOF_PARTIAL Session checkpoint: decision D, MVP NOT authorized, production mutation NO, Codex consulted NO; documents created; minimal next step = owner provisions sandbox host (M5) + disposes B0‴.
reports/sandbox-feasibility-and-phase2-build-go-decision-2026-06-09.md sandbox feasibility + build-go (no Codex) SANDBOX_DECISION_READY / build-go B Read this for the sandbox reclassification. Reclassifies TRUE_BLOCKER → B (BUILD_PROMPT_READY_BUT_OPERATOR_SANDBOX_ACTION_REQUIRED) on governed evidence that the Docker runtime is already deployed (list_docker, read-only). 13 tracks: KB readback; blocker re-classification (B-EXT-1/B0‴/B4′ none a true blocker); sandbox option matrix A–F (B Docker/Podman primary, C bwrap fallback, D CI, reject A/F); minimum sandbox; harness build-scope = PARTIAL; Codex = not now; A–F rejections. Article 13+14 PASS.
reports/sandbox-feasibility-and-phase2-build-go-decision-2026-06-09.json sandbox feasibility (machine) active Machine mirror: build_go_decision B + tracks 1–13 + option matrix + remaining_blockers + minimal_safe_next_step. Evidence only, never authority.
planning/build-offline-packet-mvp-with-guard-harness-program-macro-prompt-2026-06-09.md gated build prompt BUILD_PROMPT_READY_GATED The Phase-2 build prompt (design artifact, NOT authorization). Hard preconditions: B0‴ disposed (owner) + sandbox attested (operator). Specifies harness L1/L2/L3 (gating, first), packet reader, provenance validator, Article-14 adequacy classifier, non-global reporter, local report writer, fixtures incl. FIX7/A′/D, 45 L1–L5-bound tests, Article 13/14 audits, full prohibition wall.
checkpoints/operator-action-packet-sandbox-host-for-phase2-mvp-2026-06-09.md operator action packet active B4′ provisioning request to the operator: exact §12.1 requirement, Option B (Docker/Podman on existing runtime) recommended / C bwrap fallback / D CI venue, what to provide, read-only attestation evidence Agent will verify (seccomp EPERM / mount table / env keyset), risk if waived, fallback. No destructive commands; no assumed approval.
checkpoints/checkpoint-sandbox-feasibility-and-phase2-build-go-2026-06-09.md checkpoint (sandbox decision) SANDBOX_DECISION_READY Session checkpoint: build-go B, runtime-present evidence, A–F decisions, self-audit all-PASS, remaining blockers (B4′ operator attestation, B0‴ owner disposition — neither a true blocker), minimal next step.
designs/deny-by-default-sandbox-profile-phase2-offline-mvp-2026-06-09.md sandbox profile (reproducible) SANDBOX_PROFILE_SPECIFIED_NOT_ATTESTED The B4′ substrate recipe. rev4 §12.1 realized: Dockerfile (distroless, no shell), seccomp-deny-by-default.json (4a targeted-deny concrete + 4b default-deny hardened, honest iterate caveat), exact docker run (no-net/RO-rootfs/2-binds/cap-drop-all/no-new-privs/scrubbed-env; explicitly no privileged/host-ns/home/docker-sock/secret), Podman/bwrap fallbacks, 12 probes (§6) with proof-of-block, evidence schema (§7). Output artifact, NOT authority; attests nothing.
reports/sandbox-host-attestation-for-phase2-offline-mvp-2026-06-09.md sandbox attestation (no Codex) SANDBOX_ATTESTATION_PARTIAL Read this for the B4′ status. 7 tracks: KB readback PASS; runtime present-but-not-agent-reachable (RO governed Docker); profile SPECIFIED; attestation tests 0-run/12-specified (no execution surface); build-prompt-v2 not created; Article 13 + 14 PASS. B4′ BLOCKED; no fake-green.
reports/sandbox-host-attestation-for-phase2-offline-mvp-2026-06-09.json sandbox attestation (machine) active Machine mirror: decisive_constraint + track1–7 + failure_classification (OWNER_OPERATOR_REQUIRED + no-exec-surface) + remaining_blockers + venue_rule (VPS/CI only, no Mac-local) + minimal_safe_next_step. Evidence only.
checkpoints/operator-blocker-packet-sandbox-attestation-2026-06-09.md operator blocker packet B4_PRIME_BLOCKED_OPERATOR_ACTION_REQUIRED Command-level packet to run on VPS throwaway container or approved CI runner (Mac-local NOT accepted): exact build/run steps, 12 probes → exact expected outputs, evidence-bundle schema, how B4′ closes. No destructive command; provisions nothing.
checkpoints/checkpoint-sandbox-attestation-phase2-offline-mvp-2026-06-09.md checkpoint (sandbox attestation) SANDBOX_ATTESTATION_PARTIAL Session checkpoint: B4′ BLOCKED, decisive no-exec-surface constraint, B0‴ waiver applied (this scope only), runtime discovery verdict, docs created, Article 13/14 PASS, minimal next step = operator runs packet on VPS/CI.
checkpoints/action-ready-blocker-after-phase2-offline-mvp-execution-path-2026-06-09.md action-ready blocker (program-macro, end-to-end) B4_PRIME_OPERATOR_ACTION_REQUIRED Records that the end-to-end Phase-2 close attempt (2026-06-10) re-verified the same B4′ blocker at the program-macro level: live list_docker confirms the VPS Docker socket is read-only by design (no run/exec/create), no approved CI runner reachable, Mac-local rejected. Routes operator to the canonical command-level packet; does NOT duplicate it. Build + tests + FIX7 + matrix binding all NOT REACHED (correctly not fabricated).
checkpoints/checkpoint-phase2-offline-mvp-execution-path-2026-06-09.md checkpoint (program-macro, end-to-end) B4_PRIME_OPERATOR_ACTION_REQUIRED Session checkpoint for the end-to-end close attempt: Track 1 KB readback PASS; Track 2 venue = RUNTIME_PRESENT_BUT_NOT_AGENT_REACHABLE (stop); Tracks 3–8 NOT REACHED; Article 13+14 PASS; no production mutation / no Codex / no Mac-local evidence; next = operator runs the blocker packet on VPS/CI.

Current verdict & phase

Current authoritative status: GAP_ONLY_SCOPE_SPEC_v0_1_REV4_READY_FOR_CODEX. T1 repaired rev3 into rev4 against the six Codex rev3 guard/authority blockers (1 negative verdicts → shadow denial authority; 2 DB allowlist ≠ process egress; 3 no sandbox for secret/local/network; 4 no bounded KB writer; 5 SELECT-only ≠ side-effect-fn safe; 6 tests not tied to enforcement). The decisive move: the MVP is re-scoped to an offline, packet-derived, NON-GATING inspector — no network, no PG driver, no live query, no KB write, no secret, no arbitrary local-FS; it reads a governed-provenance export packet (KB/PG-derived, per-item provenance) and writes a local report; it runs inside a deny-by-default sandbox (no network namespace; read-only input mount; write-only output mount; no secret mounts; scrubbed env; seccomp execve/socket/connect/ptrace deny) that is named and specified and provisioned + negative-tested as build scope (B4′), not pretended to already exist. This is the honest answer to Codex's "ungrounded process-level assertions": it removes the live attack surface (blockers 2/3/5 collapse — no network to allowlist, no SQL to validate, no driver to misuse) rather than asserting a sandbox that cannot be proven, and is the prompt-sanctioned fallback ("design MVP to use a bounded exported input packet"). Blocker 1 (denial authority): every output carries decision_effect=NONE + may_gate=false; v0.1 cannot declare global truth and emits only 5 bounded scoped verdicts (NOT_EVIDENCED_IN_ALLOWED_SURFACES, INSUFFICIENT_EVIDENCE_FOR_CLAIM, BLOCKED_BY_UNVERIFIED_SOURCE, BLOCKED_BY_UNSAFE_ACCESS, CONTRACT_VIOLATION_IN_DESIGN); READ_LEVEL_FAIL = "not acceptable for reporting PASS," not "false"; mandatory scope_of_denial + non-global disclaimer + FLAG_GLOBAL_DENIAL_WORDING; all gate use deferred to a sealed consumer contract (B7). Blocker 4: the MVP does not write KB (no bounded writer is claimed to exist); it writes a local artifact, and KB upload is a separate governed step. Blocker 6: every capability/bypass test is bound to a named enforcement layer (L1–L5) + block point + proof-of-block evidence (seccomp EPERM / mount table / env keyset / build-time rejection); #27 corrected to a process-level egress denial. Article 14 preserved + strengthened; FIX7 discoverability (Gate 5 PASS) preserved. T1 self-audit = 10/10 PASS at the design/feasibility level. MVP implementation remains unauthorized — gated on a Codex rev4 re-seal (B0‴) and the offline guard harness built + enforcement-bound negative tests passing against a real sandbox (B4′); the live export step, bounded KB writer, and any gate-consumer are deferred (B7). Sealed B/C/D/G/H are unchanged and not reopened. Honest caveat: the sandbox host is specified, not deployed. Recommended readiness = Option C (offline packet-only) + the A discipline (guard harness in build scope), hard fallback to B.

Prior authoritative status: GAP_ONLY_SPEC_REV3_PARTIAL_FIX_REQUIRED. Codex re-sealed rev3 and accepted the FIX7 discoverability correction, but did not seal MVP implementation because negative-authority and process-level structural guard gaps remain. T1 authored the rev3 layer (rev3 filenames; rev2 preserved with trace) attempting to repair the four Codex re-seal blocker classes with explicit design changes, a partially grounded read-only substrate, revised acceptance tests, and a self-audit. Codex accepted FIX7 discoverability but returned residual authority and structural-guard blockers. The decisive repair (B-1): v0.1 is demoted to a negative/triage-only, non-authoritative inspector — READ_LEVEL_ACCEPTABLE and exit 0 are removed; the claim/evidence/verdict taxonomy is PROVISIONAL_NON_AUTHORITY, versioned, fail-closed, and never positive (positive authority is removed, but Codex found that negative FAIL/BLOCKED outputs can still become a shadow denial authority; all automated gate effects remain blocked). B-2: rev3 proposes an endpoint allowlist and a governed context_pack_readonly PG gateway, but Codex found no concrete process-level sandbox/egress/secret/local-FS/path-scoped-KB-writer enforcement; DB allowlist is not process egress allowlist, and SELECT-only does not alone prove side-effect-function denial. B-3: the FIX7 read-only discovery chain was actually run — the declared canonicalizer resolves only as a .md on KB while the load-bearing .py resolves on no governed surface (wf_fs_dot_bin_snapshot scope /opt/incomex/dot/bin, disjoint) ⇒ existence BLOCKED_BY_UNVERIFIED_SOURCE; Fixture A's expected outcome is corrected to UNVERIFIED (not deterministic FAIL) and Fixture A′ (pure discoverability) is added; v0.1 proves "not adequately evidenced via allowed surfaces," never "does not exist anywhere." B-4: negative tests expanded to all bypass paths (shell/subprocess, dynamic import, off-allowlist network, credential, PG-write-via-read-client, multi-statement, side-effect fn, direct driver, FS write, Directus write, local-first, taxonomy-as-authority). Article 14 is preserved unchanged and only strengthened (the single green terminal state is removed). T1 self-audit claimed 10/10 PASS; Codex re-seal returned GAP_ONLY_SPEC_REV3_PARTIAL_FIX_REQUIRED. MVP implementation remains unauthorized — gated on a narrow rev4 plus another Codex re-seal. Sealed B/C/D/G/H are unchanged and not reopened.

Prior authoritative status: GAP_ONLY_SPEC_REV2_PARTIAL_FIX_REQUIRED. Codex re-sealed the v0.1 rev2 planning/design layer and found the Article-14 core repaired, but the 12-fix ledger only partially closed because structural no-run/no-write enforcement and PG-driven policy authority remained unresolved (rev3 improved them but did not fully close them). T1 had repaired the v0.1 planning/design layer against all 12 Codex required fixes (reports/codex-fix-ledger-gap-only-spec-rev2-2026-06-09.md, 12/12 = YES). The structural core: an Article-14 evidence-adequacy chain (claim→type→required evidence class→artifact→capability→adequacy→dossier verdict) where a resolving reference yields only ARTIFACT_EXISTENCE_EVIDENCE and never a positive verdict; READ_REPORT_PASS is removed (verdicts READ_LEVEL_ACCEPTABLE/FAIL/BLOCKED/UNVERIFIED + a separate article14_status that forces ARTICLE14_NOT_PROVEN_EXECUTION_UNVERIFIED for any execution claim); literal counts demoted to dated fixtures; >=2 and 41/4/219/102 checks replaced by role/key/provenance/separation; exit 0 reserved for ACCEPTABLE only (no fake-green); no-run/no-write enforced by capability enums + static/runtime guard + negative tests; claim extraction demoted to best-effort with claim_inventory_completeness=UNVERIFIED; FIX7 pilot scope narrowed + a resolvable-but-insufficient Fixture C; Authority Contract status normalized (READY_FOR_GPT_REVIEW, not binding as a whole). T1 self-audit claimed all-PASS; Codex re-seal returned GAP_ONLY_SPEC_REV2_PARTIAL_FIX_REQUIRED. The prior Codex block BLOCKED_BY_AUTHORITY_OR_ARTICLE14_RISK and its rev1 docs (gap-only spec, FIX7 pilot, MVP plan, acceptance matrix, checkpoint packet, action-ready blockers, gap-only checkpoint) are SUPERSEDED by their rev2 counterparts listed in the table above (rev1 rows retained for trace). MVP implementation remains unauthorized — gated on a narrow T1 rev3 that resolves PG-driven policy authority, structural no-run/no-write enforcement, and the actual FIX7 artifact-resolution boundary, followed by another Codex re-seal. The sealed B/C/D/G/H decisions are unchanged and not reopened.

Prior authoritative status: REUSE_EXTRACTION_MAP_READY_FOR_GPT_REVIEW (on top of AUTHORITY_CONTRACT_V0_1_READY_FOR_GPT_REVIEW and BCDGH_SEALED). The Reuse Extraction Map v0.1 (reports/reuse-extraction-map-v0-1-2026-06-09.{md,json}) is now written — it maps all 18 required capabilities into the six reuse classes against the sealed Authority Contract, with no mutation. It downgrades the pre-seal reuse audit's "call directly" reuse to read-only reads and reclassifies the command-runner "true gap" as DEFERRED behind the not-yet-sealed Call Contract. Gap-only Spec readiness = PARTIAL_READY: the read/report-only gap surface (existence resolver, claim-inventory extractor existence-half, dual-corpus reporter, reconciliation report, provenance writer, read-only dead-link report, FIX7 read/report pilot) may be specced; the execution-dependent gaps (command-runner, run/pass binder, generic manifest schema) are carved out behind the Call Contract and the two unresolved owner decisions. Next = GPT review of the map.

Prior authoritative status: AUTHORITY_CONTRACT_V0_1_READY_FOR_GPT_REVIEW (on top of BCDGH_SEALED). The Authority Contract v0.1 (contracts/authority-contract-v0-1-2026-06-09.md) is written — it records sealed B/C/D/G/H plus proposed/adopted-default A/E/F/I/J in a review-ready, nonbinding-as-a-whole constraint draft, with the denominator contract, allowed/prohibited envelope, reuse map, unresolved list, and the gate to the Reuse Extraction Map phase. It creates no new law/tool/schema/runner and mutated nothing. Codex sealed B/C/D/G/H with fail-closed modifications: v0.1 invokes nothing; the latest code-keyed reliability view is canonical for the current registry→filesystem diff while older name-keyed output remains separately labelled; existing graph/duplicate/orphan authorities must be reused; TAC and IU remain dual-report-only with no bridge/canonical selection. Counts remain runtime evidence, never constants.

Historical matrix status: AUTHORITY_MATRIX_READY_FOR_GPT_REVIEW on top of BASELINE_READY_FOR_AUTHORITY_DECISION. Its denominator separation remains valid: 309 registry ≠ 214 operational-FS ≠ 186 fs-confirmed ≠ 163 actual_count ≠ 54 command-catalog ≠ 41 registry-no-file. Never collapse these into one DOT count. The matrix’s pending B/C/D/G/H decisions are superseded by the Codex seal; TAC↔IU corpus authority remains unresolved by design, and Directus 100%-DOT-control remains unproven.

Historical fresh-read closure: FRESH_READ_CLOSURE_PARTIAL supplied the evidence later sealed by Codex. Its durable findings remain: G existing-authority sufficient; H no-bridge dual-report-only; D’s 41-vs-4 divergence is explained by base/key/population; C’s 186 ∩ command-catalog formula is withdrawn; filesystem-186 is not directly callable; CAT-006 actual_count=163 is unsafe as an authority denominator; /opt/incomex/scripts is a separate non-DOT surface. Final B/C/D/G/H wording is only in the Codex seal report.

Live reconciliation surfaces already deployed (reuse, don't rebuild)

dot_tools, meta_catalog (CAT-006), pivot_definitions/pivot_results (PIV-007/PIV-104), wf_fs_dot_bin_snapshot, _recon_dot_fs_inventory, v_dot_fs_reconciliation, v_dot_registry_no_file, v_dot_reconciliation_reliability, dot_iu_command_catalog/_run/_runtime_lease, dot_operations, law_dot_enforcement, directus_flows (watchdog/sync), fn_tac_log_checker_issuesystem_issues, universal_edges/v_kg_edges_all/entity_dependencies, Đ19/Đ23 engines, information_unit/tac_logical_unit.

Minimal next step (exactly one)

Two parallel action-ready items (per SANDBOX_DECISION_READY / build-go B, 2026-06-09 — supersedes the Decision-D "owner provisions then author build macro" sequencing; the gated build prompt is now already authored): (1) operator provisions + attests the §12.1 deny-by-default sandbox per checkpoints/operator-action-packet-sandbox-host-for-phase2-mvp-2026-06-09.md (Option B Docker/Podman on the already-deployed host runtime; C bwrap fallback; D CI venue) → B4′ acceptance; (2) owner disposes of B0‴ — honor (route reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-rev4-2026-06-09.md to Codex) or waive with documented risk. Once both clear, execute the gated build prompt planning/build-offline-packet-mvp-with-guard-harness-program-macro-prompt-2026-06-09.md. Do not implement, invoke, install, mutate, provision-by-Claude, or create a tool/schema/runner/sandbox before both clear. B4′ is now command-ready for the operator (2026-06-09): the deny-by-default profile + a command-level operator blocker packet are authored (designs/deny-by-default-sandbox-profile-…, checkpoints/operator-blocker-packet-sandbox-attestation-2026-06-09.md); B4′ stays BLOCKED until the operator runs the packet on the VPS throwaway container or an approved CI runner (Mac-local evidence is NOT accepted) and returns the §7 evidence bundle, which a follow-up agent verifies read-only against matrix #24–#37. B0‴ is WAIVED for this offline-MVP prototype-prep scope only. See reports/sandbox-host-attestation-for-phase2-offline-mvp-2026-06-09.{md,json} (SANDBOX_ATTESTATION_PARTIAL). See reports/sandbox-feasibility-and-phase2-build-go-decision-2026-06-09.{md,json} + checkpoints/checkpoint-sandbox-feasibility-and-phase2-build-go-2026-06-09.md.

Execution-substrate + offline-MVP path close (2026-06-10, READ-ONLY except KB doc writes; NO Codex, NO Mac-local evidence, NO prod mutation, NO container run, NO external publish, MVP NOT built) → APPROVED_CI_OR_OPERATOR_PACKET_READY (terminal state B). Drove the whole Phase-2 execution-substrate + offline-MVP path end-to-end. KB readback PASS (14 docs). 🔴 Blocker reclassified: missing host Docker → missing authorized execution substrate/trigger — fresh list_docker = 11 up, VPS Docker socket read-only by design (no run/create/exec/shell tool); the agent cannot create/run a container on any approved venue. Inventoried 10 surfaces (route-decision report Track 2): no agent-runnable approved substrate, but two human/CI-triggerable ones are now turnkey. 🔴 New: the CI route is reachable — local gh authenticated (Huyen1974, scope workflow,repo) → authored a complete GitHub-Actions workflow + 12-probe harness + §7 evidence emitter running on an ephemeral, non-Mac-local, Docker-capable hosted runner (planning/ci-sandbox-attestation-workflow-draft-2026-06-10.md + checkpoints/ci-attestation-packet-phase2-sandbox-2026-06-10.md), collapsing the operator's hardest prerequisite (live VPS docker run) to "authorize repo → trigger → download artifact." Operator/VPS route consolidated (checkpoints/operator-execution-packet-phase2-sandbox-final-2026-06-10.md, references 06-09 SSOT). Routes 1/4/5 rejected with evidence (read-only socket / no design defect / safe path exists). Residual = B4_PRIME_AUTHORIZATION_AND_EXECUTION_REQUIRED (owner authorizes ONE venue: CI-A create private repo [publishes harness] · CI-B existing approved repo/runner · VPS operator — then human/CI runs it, returns §7 bundle, follow-up agent verifies read-only vs matrix #24–#37, then runs gated build prompt). Build correctly gated (B4′ not PASS → P1/L3 fails-closed; ~11/45 L1 tests can't pass). Tracks 4/7/8/9 honestly NOT RUN (no fake-green); no B4′/MVP evidence fabricated. Article 13+14 PASS. Reports: reports/phase2-execution-substrate-and-route-decision-2026-06-10.{md,json}; blocker checkpoints/action-ready-blocker-after-phase2-execution-substrate-2026-06-10.md; checkpoint checkpoints/checkpoint-phase2-execution-substrate-and-offline-mvp-path-2026-06-10.md.

2026-06-10 — FIX7 Recheck-9 R9-B1..B5 packet hardening lane → FIX7_RECHECK9_PACKET_HARDENED_SELF_CODEX_PASS

Codex Recheck-9 rejected packet V1 (CODEX_RECHECK_9_NEEDS_T1_FIX: verifier hash-subset-only, produce not fail-closed, RERUN unenforced, KB packet incomplete/divergent, KB byte seal unproven). This lane reproduced every Codex failure first, then closed R9-B1..R9-B5 as one lane: B1 manifest V2 authority/explanatory split — ENTIRE authority recomputed+deep-diffed+schema-closed at --verify (literal tamper → exit 1); B2 P-EXT-2 applied (SSOT rev2→rev3, 144eb3d9…49c386a9…, byte-exact re-fetch proven) — --produce fail-closed: missing/extra/duplicate/invalid member → ALL candidate digests SUPPRESSED_CORPUS_NOT_OK + exit 4, membership over PRESENT+VALID members, selftest 36→45; B3 RERUN.sh strict (set -euo pipefail+trap, 10 live gates incl. shasum -c, forbidden scan, full verify, adversarial suite) — Codex's exact probes now abort full RERUN exit 1; B4 packet fully KB-native (19 docs at packets/fix7-codex-recheck-9-2026-06-10/, corpus via canonical blueprint ids, divergent old copy deleted) + kb_fetch_reconstruct.py fresh-fetch proof: reconstructed tree IDENTICAL 21752e19…480, RERUN PASS; B5 independent SHA-256 over governed-MCP bytes for 10 docs (all == pins) + SSOT (rev2==144eb3d9… verified — the value Codex couldn't recompute), revision-bound, deterministic; named residual = no server-side digest endpoint (action-ready, doesn't block rerun). Adversarial suite 22/22 (12 tamper classes, runs in every RERUN). Article 13+14 PASS. NO Codex/production mutation. Objects TKT-OBJ-069..086 (registry md rev5/json rev6). Reports: reports/fix7-recheck9-*-2026-06-10.md (7); handoff checkpoints/fix7-codex-recheck-9-rerun-packet-v2-handoff-2026-06-10.md; checkpoint checkpoints/checkpoint-fix7-recheck9-r9-b1-b5-hardening-2026-06-10.md; current-state knowledge/current-state/reports/fix7-recheck9-packet-v2-current-state-2026-06-10.md. NEXT = route packet V2 to Codex for fresh Recheck-9 rerun/seal (N7/N8/P7 + authoritative values; owner do-not-approve stands).

2026-06-10 — FIX7 Recheck-9 V3 R9-B6 black-box CLI oracle lane → FIX7_RECHECK9_V3_BLACKBOX_CLI_ORACLE_SELF_CODEX_PASS

Codex Recheck-9 V2 rejected packet V2 (CODEX_RECHECK_9_V2_NEEDS_T1_FIX; R9-B2/B4/B5 + Article 13 PASS, R9-B1/B3 + Article 14 FAIL via R9-V2-B6: negative tests inferred cli_exit_contract=4 from in-process produce() instead of executing the CLI — Codex flipped sys.exit(4)→0, regenerated manifest/HASH with the packet's own tools, and full RERUN passed 22/22 while missing-doc actual CLI exited 0 = oracle laundering). This lane reproduced the attack first-hand on V2 bytes (BYPASS_RERUN_EXIT=0, BYPASS_MISSING_DOC_CLI_EXIT=0), then closed R9-B6 in Packet V3: SUT/ORACLE/VERIFIER separated — real CLI executed as __main__ at OS-process level (RERUN gate 6, bash-observed $?==4 ×4 + suppression + zero digest leak) and via a runpy harness vs STATIC spec oracle CLI_ORACLE (never SUT-derived); synthesized exit fields REMOVED → cli_exit_observed/EXECUTED_CLI_BLACKBOX (inferred cli_exit_contract hard-rejected by gate 11); --emit/--verify execute the CLI 6× and raise ORACLE_VIOLATION fail-closed → manifest laundering impossible (mutated copy: emit exit 1, full RERUN exit 1 at gate 6 BEFORE any PASS, suites nonzero); new blackbox_negative_suite.py (10/10 observed; missing/extra/invalid/absent-dir; verifier-CLI exits observed; duplicate-on-disk = honest N/A + executed adjacent validator) + failopen_regression.py (6/6, live in gate 8); adversarial suite 22→25 expectations; adjacent self-referential scan (9 surfaces: 4 fixed incl. synthesized selftest/produce exit contracts, 4 by-design, 1 declared verifier-self-integrity limit backstopped by Codex fresh-fetch rerun). Canonical: RERUN exit 0 (13 gates), tree b95df0a5… (32 files), 14 KB uploads byte-verified, fresh-fetch reconstruction + RERUN PASS identical tree. SUT UNCHANGED (rev3 candidate 49c386a9…); membership f2bda8…fe251. Article 13+14 PASS. NO Codex consult/production mutation/T2 dependency. Objects TKT-OBJ-087..102 (registry md rev6/json rev7); blocker ledger rev3. Reports: reports/fix7-recheck9-v3-*-2026-06-10.md (6); handoff checkpoints/fix7-codex-recheck-9-rerun-packet-v3-handoff-2026-06-10.md; checkpoint checkpoints/checkpoint-fix7-recheck9-v3-r9-b6-blackbox-cli-oracle-2026-06-10.md; current-state knowledge/current-state/reports/fix7-recheck9-packet-v3-current-state-2026-06-10.md. NEXT = route Packet V3 → Codex Recheck-9 V3 rerun (N7/N8/P7 + authoritative values remain Codex/owner; do-not-approve stands).

2026-06-10 — FIX7 Authority Closure Packet lane → FIX7_AUTHORITY_CLOSURE_PACKET_READY

Codex Recheck-9 V3 returned CODEX_RECHECK_9_V3_AUTHORITY_BLOCKED: engineering PASS, Article 13 PASS, Article 14 PASS, no hardcode defect; Packet V3 (tree b95df0a5…ca6d, 32 files) survived Codex fresh-fetch 13-gate RERUN + its own V2-attack replay; canonicalizer rev3 candidate verified (revision 3, 38756 bytes, 49c386a9b9666c09786fc4f89bc79776b6046eaee6f4da6d8537d2c753b734d0). Owner issued OWNER_AUTHORIZATION_FIX7_AUTHORITY_CLOSURE_AND_SEAL_ONLY_2026_06_10 (prepare + route ONLY; no blueprint approval, no implementation, no mutation). This lane converted the state to a clean authority-decision-ready packet at packets/fix7-authority-closure-2026-06-10/: N7 approval-event input envelope (md+json; candidate inputs + A1–A6 MISSING_AUTHORITY_INPUT table, explicit non-self-approval, codex_sealed_values_present:false), N8 detached seal request ("T1 cannot author this seal"), P7 re-seal request (rev3 fresh-hash-then-seal procedure), owner decision packet (4 cumulative options + risks + standing non-authorization list), implementation precondition checklist (11 hard gates; seal + owner approval required; rollback before apply; REAL_RUN/QT001/cutover each separately approved). Blocker ledger (TKT-OBJ-066) → rev4: authority-only (N7/N8/P7/OWN-1-partially-lifted) + R9-B5-RES tooling residual (disclosed, non-blocking) + NA-DUP rationale. No engineering contradiction found in Codex V3 evidence (cross-checked 4 sources). Objects TKT-OBJ-103..112 (registry md rev7/json rev8). Master report reports/fix7-authority-closure-packet-master-report-2026-06-10.md; checkpoint checkpoints/checkpoint-fix7-authority-closure-packet-2026-06-10.md; current-state knowledge/current-state/reports/fix7-authority-closure-packet-ready-2026-06-10.md (supersedes V3 current-state). NO production mutation / Codex call / self-approval / fabricated seals / implementation. NEXT = owner/Codex seal decision (owner supplies A1–A5 → Codex authors N7→N8→P7); after a pass, FIX7 implementation macro gated by the precondition checklist.

2026-06-10 — FIX7 Authority Closure SELF-CODEX dry-run → FIX7_AUTHORITY_CLOSURE_SELF_CODEX_READY_FOR_CODEX

Before spending a Codex checkpoint, T1 inspected the authority closure packet the way Codex would (live-read 17 sources). Independently re-verified the load-bearing canonicalizer rev3 pin first-hand: on-disk fresh-fetch evidence copy = 38756 bytes, SHA-256 49c386a9b9666c09786fc4f89bc79776b6046eaee6f4da6d8537d2c753b734d0, live KB revision 3; the 38735 content_length (chars) + 21 bytes from 11 non-ASCII chars = 38756 bytes (same file, not a discrepancy). Packet V3 root revisions confirmed against master report §2. Completeness matrix 10/10 files + 12-source field consistency; N7/N8/P7 seal-readiness all READY-for-Codex (exact candidates; A1–A6 MISSING with exact actor; "T1 cannot author"); owner-scope CLEAR (sufficient for seal review, insufficient for seal/implementation by design — OWN-1, not NEEDS_OWNER_INPUT); anti-overclaim scan PASS (no overclaim text). Result: packet self-clean — NO safe T1 packet fix needed; blocker ledger UNCHANGED at rev4; packet docs TKT-OBJ-103..109 UNCHANGED. Objects TKT-OBJ-113..120 (registry md rev8 / json rev9). Deliverables: reports/fix7-authority-closure-self-codex-readiness-report-2026-06-10.md, …-packet-completeness-matrix-…, …-n7-n8-p7-seal-readiness-matrix-…, …-owner-authorization-scope-analysis-…, …-anti-overclaim-scan-…; checkpoint checkpoints/checkpoint-fix7-authority-closure-self-codex-ready-2026-06-10.md; current-state knowledge/current-state/reports/fix7-authority-closure-self-codex-ready-2026-06-10.md (supersedes packet-ready current-state). NO production mutation / Codex call / self-approval / fabricated seal / implementation. NEXT = owner picks an option in owner-decision-packet.md (Option 2+ supplies A2/A5) → Codex authors N7→N8→P7.

Subfolders

  • contracts/active. Authority-contract drafts/records; status must be read from each contract (Authority Contract v0.1 is review-ready, nonbinding as a whole).
  • designs/active. Gap-only Scope Spec (+JSON), FIX7 read/report pilot design, acceptance test matrix.
  • planning/active. Feasibility plan (superseded), no-code MVP implementation plan, future-contracts queue.
  • reviews/active. Codex cross-check, authority seal, checkpoint packet, and current blocking adversarial review.
  • reports/active. Baseline ledger, decision matrix, fresh-read closure, reuse extraction map, reuse audit (+JSON mirrors).
  • checkpoints/active. Per-session checkpoints, incl. the action-ready blocker packet.
  • references/ — pointers to consumed foundations.