KB-2610
Checkpoint — FIX7 Recheck-9 V3 R9-B6 Black-Box CLI Oracle (2026-06-10)
3 min read Revision 1
tool-kiem-thufix7recheck-9packet-v3r9-b6checkpoint2026-06-10
Checkpoint — FIX7 Recheck-9 V3 R9-B6 Black-Box CLI Oracle Lane
- Date: 2026-06-10 · Status:
FIX7_RECHECK9_V3_BLACKBOX_CLI_ORACLE_SELF_CODEX_PASS - Production mutation: NO · Codex consulted: NO · T2 dependency: NO · Seal: NOT claimed (Codex/owner authority untouched)
Codex Recheck-9 V2 verdict CODEX_RECHECK_9_V2_NEEDS_T1_FIX (R9-V2-B6: synthesized cli_exit_contract; oracle laundering — a fail-open SUT mutation passed full RERUN 22/22 while missing-doc CLI exited 0) was reproduced first-hand on V2 bytes (BYPASS_RERUN_EXIT=0, BYPASS_MISSING_DOC_CLI_EXIT=0), then closed in Packet V3:
- SUT/ORACLE/VERIFIER separated: real CLI executed as
__main__(bash OS-process gate + runpy harness) vs STATIC spec oracleCLI_ORACLE; synthesized exit fields removed,cli_exit_observed+EXECUTED_CLI_BLACKBOXrequired, inferredcli_exit_contracthard-rejected by RERUN gate 11. --emit/--verifyexecute the CLI 6× and raiseORACLE_VIOLATIONfail-closed → manifest laundering impossible (V3_BYPASS_EMIT_EXIT=1).- RERUN.sh now 13 gates; on the Codex mutation the full RERUN exits 1 at gate 6 (
OBSERVED exit 0 != 4 — FAIL-OPEN) before any PASS (V3_BYPASS_RERUN_EXIT=1). - New
blackbox_negative_suite.py(10/10 observed: missing/extra/invalid/absent-dir → exit 4, suppression, zero digest leak, no artifact; verifier-CLI exits observed for scan/tamper/sealed-claim; duplicate-on-disk = N/A with rationale + executed adjacent validator) andfailopen_regression.py(6/6, runs live in gate 8). - Adjacent self-referential scan: 9 surfaces — 4 fixed (selftest/produce synthesized exits, adversarial T2 in-process-only, verifier-CLI exit unobserved), 4 documented-by-design, 1 declared structural limit (verifier self-integrity → Codex fresh-fetch rerun backstop).
- Canonical evidence: RERUN exit 0 all 13 gates; adversarial 25/25; verify OK with 6 REAL CLI executions; tree hash
b95df0a5d2f41f80bea0cef8621c1f8bb0f6b49a40175116418494ed4141ca6d(32 files); 14 files published byte-verified; fresh-fetch reconstruction + RERUN PASS with identical tree hash. SUT (rev3 candidate49c386a9…) unchanged; membershipf2bda8…fe251reproduced.
Remaining blockers: Codex/owner authority only (N7, N8, P7, owner do-not-approve, R9-B5 digest-endpoint residual). NEXT: route Packet V3 → Codex Recheck-9 V3 rerun. Full report: reports/fix7-recheck9-v3-r9-b6-blackbox-cli-oracle-master-report-2026-06-10.md.