KB-14E2

Checkpoint — Gap-only Spec rev3 after Codex PG-first/native block (REV3_READY_FOR_CODEX; verify-don't-assert self-audit; KB-first/PG-first/local-last, 2026-06-09)

8 min read Revision 1
tool-kiem-thucheckpointgap-only-scope-specrev3after-codex-pgfirst-blockpg-firstself-audittriage-onlyrev3-ready-for-codex2026-06-09

Checkpoint — Gap-only Spec rev3 after Codex PG-first/native Block

Session: PROGRAM_MACRO_REPAIR_GAP_ONLY_SPEC_REV3_AFTER_CODEX_PG_FIRST_BLOCK Date: 2026-06-09 Final status: REV3_READY_FOR_CODEX Production mutation: NO. No PG/Directus/registry/filesystem mutation, no system_issues write, no tool/schema/runner created, no command run, no detector executed, no FIX7 resumed, no denominator collapsed, no sealed decision reopened. writes_performed: 10 KB design documents under knowledge/dev/laws/tool-kiem-thu/ (the deliverables; Domain I file-report-only). Read-only verification performed + disclosed (mutates nothing): KB discovery (search_knowledge/list_documents/get_document_for_rewrite) + three read-only SELECTs via the query_pg gateway (role context_pack_readonly). Method note (per user direction — apply Codex's "verify, don't assert" method to self-checking): the two facts that most needed proof were verified by running the read before reporting: (1) the FIX7 canonicalizer artifact-resolution gap (the .py resolves on no governed surface; only a .md does); (2) the read-only PG substrate (role context_pack_readonly attributes; DB allowlist; postgres [DENIED]). Neither was asserted.

1. What happened

Codex re-sealed rev2 as GAP_ONLY_SPEC_REV2_PARTIAL_FIX_REQUIRED (Article 14 PASS; PG-first FAIL; capability/discoverability/negative-tests PARTIAL). This macro read the full re-seal review + checkpoint, read all rev2 deliverables and the Authority Contract + 00-index, ran the read-only discovery + substrate verification, then authored a rev3 layer (rev3 filenames; rev2 preserved with trace) repairing the four blocker classes with explicit design changes, revised acceptance tests, and a self-audit. Sealed B/C/D/G/H were not reopened.

2. The root of the re-seal and the structural fixes

Root: two load-bearing build boundaries were underspecified — the inspector's own policy had no governed authority (shadow-SSOT risk) and the no-run/no-write guard was internally contradictory. Fixes:

  • B-1 (decisive): v0.1 demoted to a negative/triage-only, non-authoritative inspector. READ_LEVEL_ACCEPTABLE removed; exit 0 reserved/unused; the taxonomy is PROVISIONAL_NON_AUTHORITY, versioned, fail-closed, never positive. A classifier that never emits positive authoritative truth cannot be a shadow SSOT — this single decision closes Gates 4/5/6.
  • B-2: socket ban → endpoint allowlist (KB read connector + PG read gateway); PG write risk → no direct DB driver + server-side read-only role context_pack_readonly (verified) + read-only transaction + AST SELECT-only; 10 enforcement layers + KB-vs-FS read distinction.
  • B-3: ran the discovery chain → Fixture A expected corrected to UNVERIFIED/BLOCKED_BY_UNVERIFIED_SOURCE (not deterministic FAIL); Fixture A′ added; "not adequately evidenced" ≠ "does not exist anywhere."
  • B-4: negative tests expanded to every bypass path.
  • Track 1: KB-first/PG-first/local-last made structural (READ_KB_DOC, KB-write report, FLAG_LOCAL_FIRST_AUTHORITY).

3. Deliverables (created this session)

  1. designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev3-2026-06-09.md
  2. designs/implementation-package-dot-v0-1-gap-only-scope-spec-rev3-2026-06-09.json
  3. designs/fix7-read-report-pilot-design-rev3-for-implementation-package-dot-v0-1-2026-06-09.md
  4. planning/mvp-read-report-inspector-implementation-plan-no-code-rev3-2026-06-09.md
  5. designs/acceptance-test-matrix-implementation-package-dot-v0-1-rev3-2026-06-09.md
  6. reports/codex-fix-ledger-gap-only-spec-rev3-2026-06-09.md
  7. reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-rev3-2026-06-09.md
  8. checkpoints/action-ready-blockers-after-gap-only-spec-rev3-2026-06-09.md
  9. checkpoints/checkpoint-gap-only-spec-rev3-after-codex-pgfirst-block-2026-06-09.md (this doc)
  10. 00-index.md (updated to rev3 phase)

4. Codex re-seal blocker status

All four addressed (full table in the fix ledger rev3): B-1 taxonomy authority → triage-only + non-authority versioned classifier (no green, no exit 0); B-2 guard feasibility → endpoint allowlist + verified read-only substrate + no direct driver + 10 layers; B-3 FIX7 discoverability → discovery chain run, Fixture A→UNVERIFIED, A′ added; B-4 negative tests → expanded to all bypass paths. Article 14 preserved + strengthened; B/C/D/G/H intact.

5. Self-audit (Track 9)

Check Verdict Evidence
KB-first / local-last PASS spec §0; READ_KB_DOC replaces READ_FILE; report = KB write; F18 FLAG_LOCAL_FIRST_AUTHORITY
PG-first / native / driven PASS (triage-only scope) spec §9/§16; verified context_pack_readonly; no positive verdict ⇒ no policy-SSOT-in-code
Taxonomy/rule — no shadow SSOT PASS spec §2 Option C + triage-only; PROVISIONAL_NON_AUTHORITY + versioned + fail-closed; never positive
No-run/no-write feasibility PASS (design/feasibility; build-gated B4) spec §12 allowlist + 10 layers; no direct driver + server-side role
PG read-only guard PASS verified role attrs; layers 4–6; Track-4 acceptance reqs; fail-closed on unverifiable role
FIX7 discoverability honesty PASS discovery chain run; Fixture A→UNVERIFIED; not-evidenced ≠ does-not-exist
Expanded negative tests PASS matrix #21–#37; plan §9 N16–N28
No parallel authority PASS wall §18 + Track 7; classifier non-authority; B/C/D/G/H intact
Article 14 remains PASS PASS (preserved + strengthened) §3 chain + §4.3 status unchanged; green terminal state removed
No hardcode / fake-green PASS counts dated examples; no green state ⇒ fake-green impossible

All ten checks PASS at the design/feasibility level ⇒ REV3_READY_FOR_CODEX. Honest caveats (not defects): no-run/no-write is feasible+specified but guards are unbuilt (B4 gates acceptance, not the seal); PG-first PASS is conditioned on the triage-only scope (a positive verdict is deferred to a sealed taxonomy authority — B6).

6. Verdicts

  • MVP readiness: still NOT authorized; blocked on B0″ (fresh Codex re-seal of rev3) and, for acceptance, B4 (guards built + negative tests pass). No PROGRAM_MACRO_READY claim.
  • Sealed decisions: B/C/D/G/H intact, not reopened.
  • Authority Contract: READY_FOR_GPT_REVIEW, records sealed constraints, not binding as a whole.

7. Minimal safe next step

Route reviews/codex-checkpoint-packet-gap-only-spec-and-fix7-pilot-rev3-2026-06-09.md to Codex (optionally GPT first) for re-review of the four blocker classes only. Do not implement, invoke, install, mutate, or create a tool/schema/runner before Codex re-seals rev3.

Cross-references

  • All rev3 deliverables (see §3).
  • Codex re-seal (4 blockers): reviews/codex-reseal-gap-only-spec-rev2-2026-06-09.md.
  • Constitution: knowledge/dev/laws/constitution.md (NT13 Article 13, NT14 Article 14).
Back to Knowledge Hub knowledge/dev/laws/tool-kiem-thu/checkpoints/checkpoint-gap-only-spec-rev3-after-codex-pgfirst-block-2026-06-09.md