FIX7 Authority Closure — N7 Approval-Event Input Envelope (rev5, N6 availability updated)
FIX7 Authority Closure — N7 Approval-Event Input Envelope (rev5)
- Date: 2026-06-10 · Patched: 2026-06-11 · rev3 patches the Codex
CODEX_FIX7_FINAL_AUTHORITY_SEAL_REJECT(per-field value grammar added; provenance class system added; real N7 =encode_real_n7). - rev4 (2026-06-11): labels-only patch closing Codex
CODEX-NNODE-ACTIVE-CONFLICT. The §5 roster annotation onmembership_sha256was changed from the deprecated(N1)alias to un-numberedmembership, matching the canonical N-number reconciliation table. NO field name, roster order, N7 byte rule, DAG edge, digest, or authority semantics changed; this is an engineering-convention relabel, NOT owner/Codex ratification. - rev5 (2026-06-11): N6-availability prose update (lane
FIX7_N7_N8_P7_AUTHORITY_INPUT_PREPARATION_MACRO_2026_06_11). After Codex ratified N6d777e87c…b258cas aRATIFIED_ENGINEERING_VERIFIED_CANDIDATE(knowledge/dev/reports/architecture/codex-fix7-n-number-n6-targeted-recheck-2026-06-11/), the pre-ratification proseSEAL_REAL_N6_NOT_AVAILABLEin §6 and §6.2 is superseded/historical: the engineering N6 chain now exists. N6 remains an engineering candidate only — not an official seal/pin — and does not by itself authorize N7/N8/P7; the remaining blockers are the authority inputs (A1/A2/A3/A5, owner decision, Codex N8 signer/report set, P7 IDs) and Codex authoring. Text/labels only — the N6 digest, encoder, roster order, byte rule, DAG edges, and authority semantics are UNCHANGED, and this is NOT owner/Codex authoring of any seal. - Lane:
FIX7_FINAL_AUTHORITY_SEAL_FAILOPEN_AND_PROVENANCE_PATCH_MACRO_2026_06_11 - Authority of THIS doc: provisional-non-authority input assembly. T1 assembles candidate inputs ONLY. This document is NOT an approval event, NOT a seal, NOT N7. Codex/owner author the actual N7 at the seal.
- Owner basis:
OWNER_AUTHORIZATION_FIX7_AUTHORITY_CLOSURE_AND_SEAL_ONLY_2026_06_10(prepare + route only; no blueprint approval; no implementation). - Executable contract:
authority_seal_encoder.py(sha25613344f92cafcaf0d07dcb21700bdb642f38b89351702e08080eacb0e957144b8) +authority-seal-encoder-spec.md/.json. N7's domain tag, roster, order, encoding, value grammar (§7), and provenance classes (§8) are defined there; Codex computes a real N7 by runningencode_real_n7("N7", …, provenance, real_n6_available=True)— it invents nothing.
1. Explicit non-self-approval statement
T1 prepared this envelope under owner authorization limited to assembly and routing. T1 has NOT approved anything, has NOT computed or claimed
envelope_manifest_sha256as sealed, and CANNOT do so. Every value below is either (a) an engineering-verified candidate value reproduced from the Codex Recheck-9 V3 review, or (b) an explicitly marked MISSING_AUTHORITY_INPUT that only owner/Codex can supply. Any N7 value computed before the authority fields are supplied is fixture/rehearsal-only and invalid as a seal — and the rehearsal corpus is provenance-classedREHEARSAL, whichencode_real_n7rejects.
2. Packet V3 identity (engineering-verified, candidate inputs)
| Field | Value |
|---|---|
| packet_kb_root | knowledge/dev/laws/tool-kiem-thu/packets/fix7-codex-recheck-9-2026-06-10/ |
| packet_tree_sha256 | b95df0a5d2f41f80bea0cef8621c1f8bb0f6b49a40175116418494ed4141ca6d |
| tracked_files | 32 |
| reconstruction | Codex V3 fresh governed-MCP fetch: RECONSTRUCTION: OK, tree identical bidirectionally |
3. Canonicalizer rev3 candidate identity (engineering-verified)
| Field | Value |
|---|---|
| document_id | knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/canonicalizer-fix7-canon-v1-ssot.md |
| revision | 3 |
| utf8_bytes | 38756 |
| sha256 | 49c386a9b9666c09786fc4f89bc79776b6046eaee6f4da6d8537d2c753b734d0 |
| status | CANDIDATE — independently byte-verified by Codex V3 §8; becomes authoritative pin ONLY at P7 seal |
| membership_digest | f2bda8…fe251 |
| provenance_class_required_for_real_seal | ENGINEERING_VERIFIED_CANDIDATE (NOT REHEARSAL) |
4. Codex final-seal reject (verbatim, with source paths)
- Reject report:
knowledge/dev/reports/architecture/codex-fix7-final-authority-seal-n7-n8-p7-2026-06-10/00-readme-first.md(rev1) - Checkpoint:
knowledge/dev/reports/architecture/checkpoint-codex-fix7-final-authority-seal-n7-n8-p7-2026-06-10.md(rev1)
| Verdict | Value |
|---|---|
| Final status | CODEX_FIX7_FINAL_AUTHORITY_SEAL_REJECT |
| AS-P1 | PARTIALLY_CLOSED/FAIL (now closed by value grammar) |
| AS-P3 / AS-P4 | NOT_CLOSED (now closed by value grammar + report-set) |
| Fail-open probes | 8 ACCEPTED (now all REJECTED) |
| N6 provenance | REHEARSAL not gated (now gated) |
5. N7 fixed roster (executable — AS-P1)
N7 binds, in this exact order (domain tag FIX7_ACTIVE_AUTHORITY_ENVELOPE_MANIFEST_V1; full byte rule + value grammar in authority-seal-encoder-spec.md §3/§7):
schema_version · node_id · membership_sha256 (membership — un-numbered) · canonicalizer_sha256 (N2) · marker_fence_registry_sha256 (N3) · superseded_boundary_sha256 (N4) · guard_set_sha256 (N5) · active_corpus_sha256 (N6) · approval_event_id (A1) · approver_identity (A2) · approval_event_timestamp (A3) · owner_blueprint_decision (A5) · approval_scope
Output: envelope_manifest_sha256. N7 binds ONLY the six engineering sub-digests + the approval-event fields. N7 does NOT bind N8 or P7. Per-doc N1 digests are bound transitively through N6.
N-number label reconciliation (rev4, labels-only).
membership_sha256is the un-numberedactive_corpus_membership_sha256(frozen pinf2bda8…fe251) per the canonical reconciliation table (knowledge/dev/reports/architecture/fix7-n-node-numbering-reconciliation-under-tkt-v02-2026-06-11.json). Its historical(N1)annotation was a deprecated alias (S3:N1); under the canonical tableN1is the per-docnormalized_active_content_sha256[d](bound transitively through N6) and membership is not numbered.N2 … N6are already canonical. This relabel changes the engineering convention only — the encoder field namemembership_sha256, roster order, N7 byte rule, DAG edges (N7 → N2,N3,N4,N5,N6,N1), and all digest math are UNCHANGED — and it is not owner/Codex ratification (binding numbering still requires ratification, G-DOC-1).
6. MISSING authority inputs + standing true blocker (DO NOT fabricate)
| # | Field | Status | Exact actor | Exact next action |
|---|---|---|---|---|
| A1 | approval_event_id | MISSING_AUTHORITY_INPUT | Codex/authority | Codex mints the approval-event identifier (provenance AUTHORITY_INPUT) at seal time |
| A2 | approver_identity (owner + Codex) | MISSING_AUTHORITY_INPUT | Owner + Codex | Supplied inside the authorized seal event |
| A3 | approval_event_timestamp | MISSING_AUTHORITY_INPUT | Codex/authority | RFC3339 UTC stamp at seal time |
| A5 | owner blueprint decision (OWN-1) | MISSING_AUTHORITY_INPUT | Owner | Owner chooses an option in owner-decision-packet.md |
| N6 | real non-rehearsal N1..N6 chain | AVAILABLE — RATIFIED_ENGINEERING_VERIFIED_CANDIDATE (d777e87c…b258c, cert binding 055828db…6b96); NOT an official seal/pin; does NOT by itself authorize N7/N8/P7 |
Codex (consume at seal); owner/Codex (promote to OFFICIAL_PIN) |
Engineering half closed: real-N6 packet proved the candidate, Codex ratified it 2026-06-11. Codex sets real_n6_available=True over this candidate at seal time. The SEAL_REAL_N6_NOT_AVAILABLE text below is superseded/historical, not a current status. |
| A6 | envelope_manifest_sha256 (N7 itself) |
NOT COMPUTABLE AS SEAL BY T1 | Codex | Codex runs encode_real_n7(…) over A1/A2/A3/A5 + a real N6 chain |
6.1 Cycle correction (AS-P2)
The authoritative DAG is N7 → N2,N3,N4,N5,N6,N1; N8 → N2,N5,N6,N7; P7 → N2,N7,N8. Acyclic seal order N7 → N8 → P7 (has_cycle(EDGES) = False). Supplying detached_seal_sha256 or authority_seal_pin_sha256 to N7 is rejected SEAL_HASH_GRAPH_CYCLE.
6.2 Provenance gate (FINAL-AS-PROVENANCE, new)
encode_real_n7 requires a provenance class for every engineering and authority input. The rehearsal corpus is classed REHEARSAL and is rejected SEAL_PROVENANCE_REHEARSAL_BLOCKED. Missing → SEAL_PROVENANCE_MISSING; unknown → SEAL_PROVENANCE_UNKNOWN_CLASS; forbidden → SEAL_PROVENANCE_FORBIDDEN_CLASS.
N6 availability update (rev5, 2026-06-11). A real ENGINEERING_VERIFIED_CANDIDATE N6 chain now exists and is Codex-ratified: N6 active_corpus_sha256 = d777e87c…b258c, certificate binding 055828db…6b96, proven in knowledge/dev/reports/architecture/fix7-real-n6-provenance-under-tkt-v02-2026-06-11/ and ratified in knowledge/dev/reports/architecture/codex-fix7-n-number-n6-targeted-recheck-2026-06-11/. The pre-ratification statement SEAL_REAL_N6_NOT_AVAILABLE is therefore superseded/historical and is no longer the standing blocker. N6 remains an engineering candidate only — not an official seal/pin — and does not by itself authorize N7/N8/P7. The remaining blockers are the authority inputs (A1/A2/A3/A5, explicit owner decision, Codex N8 signer/report set, P7 authority IDs) plus Codex authoring; Codex supplies the AUTHORITY_INPUT/CODEX_AUTHORED classes and sets real_n6_available=True over this ratified candidate at seal time. Promotion of the candidate to OFFICIAL_PIN is an owner/Codex act at the seal, not performed here.
7. Routing
Route this envelope + n8-detached-seal-request.md + p7-codex-reseal-request.md + authority-seal-encoder-spec.md + authority_seal_encoder.py + owner-decision-packet.md to Codex/authority. Authority sequence (acyclic): real N6 chain → authorized approval event → Codex encode_real_n7 → encode_real_n8 → encode_real_p7.