KB-1DC8

Reuse Extraction Map v0.1 — machine-readable mirror (2026-06-09)

24 min read Revision 1
tool-kiem-thureuse-extraction-mapv0.1jsonmachine-readableread-onlydenominatortrue-gapprohibited-overlap2026-06-09

{ "document": "reuse-extraction-map-v0-1", "workstream": "tool-kiem-thu", "date": "2026-06-09", "status": "REUSE_EXTRACTION_MAP_READY_FOR_GPT_REVIEW", "production_mutation": "NO", "nature": "read-only capability-by-capability reuse map; NOT a tool spec, implementation, schema, or runner", "governing_authority": { "authority_contract": "contracts/authority-contract-v0-1-2026-06-09.{md,json}", "contract_status": "AUTHORITY_CONTRACT_V0_1_READY_FOR_GPT_REVIEW", "codex_seal": "reviews/codex-seal-authority-matrix-bcdgh-2026-06-09.md (BCDGH_SEALED)", "fresh_read_closure": "reports/authority-matrix-fresh-read-closure-bcdgh-2026-06-09.{md,json} (FRESH_READ_CLOSURE_PARTIAL)", "baseline_ledger": "reports/dot-registry-directus-text-as-code-baseline-reconciliation-2026-06-09.{md,json} (live 2026-06-09 07:11 UTC, role context_pack_readonly, READ ONLY)", "reuse_audit": "reports/text-as-code-reuse-anti-duplication-audit-2026-06-09.md" }, "evidence_discipline": "every count is dated evidence with surface+denominator+timestamp+key+population+confidence; never an invariant; never collapsed to one canonical DOT number; no fresh live read taken for this map (sealed 2026-06-09 baseline stands); anything not directly read = UNVERIFIED", "classes": { "A": "REUSE_AS_IS", "B": "REUSE_WITH_ADAPTER (read-only, file-report-only)", "C": "REFERENCE_ONLY", "D": "PROHIBITED_OVERLAP", "E": "TRUE_GAP", "F": "UNVERIFIED" }, "executive_summary": { "enough_reuse_to_proceed": "yes for read/report-only surface; partial overall", "biggest_reuse_candidate": "deployed reconciliation+graph+corpus read surfaces consumed read-only (dot_tools 309 listing, v_dot_reconciliation_reliability over wf_fs_dot_bin_snapshot, universal_edges 2199 / v_kg_edges_all 2259 / entity_dependencies 142, information_unit 219 + tac_logical_unit 102 dual-report, the tool-kiem-thu report+json+checkpoint pattern)", "biggest_prohibited_overlap": "a second runner/dispatcher that invokes anything (filesystem DOT or IU command); plus a third cut/verify/manifest authority, a new logger, a new graph/duplicate/orphan/canonical-id resolver, and any TAC<->IU bridge/merge/canonical choice", "biggest_true_gap": "a command-runner that captures exit codes (the literal FIX7/Article-14 failure class) — real but out of read/report-only v0.1 scope; requires the Call Contract + Codex review", "biggest_unverified_area": "runnability of any filesystem DOT (NOT AVAILABLE, Domain B) and the actual_count=163 filter (external dot-catalog-sync artifact, UNVERIFIABLE/UNSAFE); secondary: Directus 100% DOT-control (PARTIAL_EVIDENCE_ONLY) and the UNPROVEN doc-level canonical-id gap" }, "capability_map": [ {"n": 1, "capability": "Dossier/package identification", "req_v0_1": "yes", "asset": "KB document_id+path+revision (agent-data MCP); FIX7 exact-MCP-id; P3D dry-run pkgs; context_pack_manifest; registry-pivot reports", "class": "A", "evidence": "KB list/get returns document_id+revision; FIX7 recheck-8 D pinned document_id=exact MCP id", "adapter": null, "prohibited": ["inventing a parallel id namespace"], "true_gap_remaining": "generic cross-package-type package_id envelope -> see #2", "codex_review": "no (reuse); yes for any new envelope"}, {"n": 2, "capability": "Manifest/package envelope", "req_v0_1": "deferred", "asset": "iu_core fn_iu_mark_create_manifest; cutter_governance envelope/manifest/dot_pair_signature/verify_result; context_pack_manifest; 86-units Validation Contract", "class": "C", "evidence": "reuse audit §2/§5; all domain-specific; no generic manifest exists", "adapter": null, "prohibited": ["creating a 3rd manifest/envelope authority", "forking either lineage before the owner decision"], "true_gap_remaining": "generic package_manifest schema across package types (spec/schema-gated; blocked on iu_core<->cutter_governance)", "codex_review": "yes (owner lineage decision + schema)"}, {"n": 3, "capability": "Artifact existence evidence (read-only)", "req_v0_1": "yes", "asset": "KB list_documents/get_document; v_kg_edges_all 2259 / universal_edges 2199; Đ19 orphan/dead-link views; v_dot_reconciliation_reliability; wf_fs_dot_bin_snapshot mirror", "class": "A", "evidence": "fresh-read closure §6; reuse audit §3 (declared artifact resolves? = orphan/dead-link query)", "adapter": "declared-artifact existence resolver (read-only)", "prohibited": ["invoking filesystem DOT", "executing orphan/detector functions", "direct OS listing"], "true_gap_remaining": "existence=read; running the artifact is #4/gap", "codex_review": "no"}, {"n": 4, "capability": "Claim-to-evidence binding", "req_v0_1": "deferred", "asset": "P11E checker_run_status 4-case truth table + readiness sentence; 86-units Validation Contract; system_issues; evidence tables", "class": "E", "evidence": "reuse audit §6 gap #2 (nothing links a Markdown claim to a runnable test entry); P11E is vocab not binder", "adapter": "claim-inventory extractor (enumerate declared claims/tests + existence-check, no run)", "prohibited": ["asserting PASS without a run", "prose-only PASS"], "true_gap_remaining": "the run/pass half (binding a claim to an actual execution result) — needs Call Contract", "codex_review": "yes"}, {"n": 5, "capability": "Denominator separation / count matrix", "req_v0_1": "yes", "asset": "Authority Contract §3 (7-denominator contract); baseline ledger (+json); fresh-read closure §3 count table", "class": "A", "evidence": "sealed denominator contract; baseline live read 07:11 UTC", "adapter": "provenance report writer", "prohibited": ["collapsing counts into one canonical DOT number"], "true_gap_remaining": null, "codex_review": "no (sealed)"}, {"n": 6, "capability": "Registry/catalog listing", "req_v0_1": "yes", "asset": "dot_tools = CAT-006 = PIV-007 = PIV-104 = 309 (frozen 2026-04-02); pivot_results", "class": "A", "evidence": "Domain A sealed; baseline R1/R2; listing = live SELECT FROM dot_tools", "adapter": null, "prohibited": ["using 309 as runnable/file-backed count", "forking the registry"], "true_gap_remaining": null, "codex_review": "no (sealed)"}, {"n": 7, "capability": "Registry<->filesystem current diff", "req_v0_1": "yes", "asset": "v_dot_reconciliation_reliability over wf_fs_dot_bin_snapshot (code-key, all 309) = canonical; v_dot_registry_no_file (41, name-key, stale 06-03) = diagnostic; v_dot_fs_reconciliation", "class": "A", "evidence": "Domain D sealed; closure §App-4 (41-vs-4 = base+key+population); unmatched = NON-CALLABLE", "adapter": "reconciliation report (both-direction diffs + provenance)", "prohibited": ["reconciliation/registry mutation", "letting name-keyed 41 override canonical"], "true_gap_remaining": null, "codex_review": "no (sealed)"}, {"n": 8, "capability": "Filesystem DOT read-only presence", "req_v0_1": "yes", "asset": "wf_fs_dot_bin_snapshot (observed 2026-06-09 02:10:15): total 289 / OPERATIONAL 214 / NOISE_BACKUP 75 / mapped 186", "class": "A", "evidence": "Domain B sealed; closure §App-2 (mirror reproduced exactly); live OS listing BLOCKED", "adapter": null, "prohibited": ["invoking filesystem DOT", "inferring can-run from presence/exec-bit"], "true_gap_remaining": "direct live OS listing -> F (permanently unreachable read-only; mirror is canonical-available)", "codex_review": "no (B sealed)"}, {"n": 9, "capability": "Command catalog / IU command layer", "req_v0_1": "yes (report) / deferred (call)", "asset": "dot_iu_command_catalog (54: 39 mutating / 15 mutating=false, 12 reversible); dot_iu_command_run (55); dot_iu_runtime_lease (0)", "class": "A", "evidence": "Domain C sealed; closure §App-5; the 15 = candidate future governed set, not a v0.1 call set", "adapter": "command-catalog reporter (lists the 15 read-only candidates)", "prohibited": ["invoking any IU command", "treating the 15 as an authorized v0.1 call set", "new dispatcher"], "true_gap_remaining": "a governed call (the 15) — deferred to Call Contract", "codex_review": "yes (future Call Contract)"}, {"n": 10, "capability": "Checker/logger/report sink", "req_v0_1": "deferred (write) / yes (read)", "asset": "fn_tac_log_checker_issue -> system_issues (Đ23, S183; severity-map, md5 dedup, escalate); system_issues open 223,313", "class": "C", "evidence": "Domain F sealed; closure §App-6; named authoritative sink, write deferred", "adapter": null, "prohibited": ["new logger/sink", "writing system_issues in v0.1"], "true_gap_remaining": null, "codex_review": "yes (system_issues wiring timing)"}, {"n": 11, "capability": "Graph/orphan/duplicate/impact", "req_v0_1": "yes (read)", "asset": "universal_edges 2199 / v_kg_edges_all 2259 / entity_dependencies 142; fn_dot_wf_orphan_detector(v2), wf_orphan_digest_v2 6, wf_orphan_remediation_queue 145; v_birth_duplicate_issue_guard / v_rp_dedup_signature_gap / v_system_issue_semantic_duplicate_dashboard / v_system_issue_idempotency_guard", "class": "A", "evidence": "Domain G sealed (EXISTING_AUTHORITY_SUFFICIENT); closure §6; read result tables/views only", "adapter": "impact/orphan reporter (reads result surfaces)", "prohibited": ["executing detector functions", "new graph/duplicate/orphan resolver", "writing findings"], "true_gap_remaining": "doc-level canonical-id resolver = UNPROVEN (see unverified), not a true gap", "codex_review": "light (confirm no-fork); yes if a new resolver is proposed"}, {"n": 12, "capability": "Context Pack / active context", "req_v0_1": "yes", "asset": "v_context_pack_latest, context_pack_manifest.health_status, v_entity_full_classification, rendered PROJECT_MAP/LAWS_INDEX/DOT_REGISTRY/RED_ZONES (Đ43); dot-context-pack-{build,verify}.sh rev 11/5", "class": "A", "evidence": "reuse audit §2/§5; Đ43 deployed (VPS, cron)", "adapter": "approved-SSOT/scope reader", "prohibited": ["re-deriving context health", "rebuilding/mutating the pack pipeline"], "true_gap_remaining": "paired build/verify script pattern = C, not v0.1 work", "codex_review": "no"}, {"n": 13, "capability": "Text-as-Code / IU / TAC corpus", "req_v0_1": "yes", "asset": "information_unit 219 and tac_logical_unit 102; 0 joining views/functions; fn_iu* lifecycle", "class": "A", "evidence": "Domain H sealed (NO_BRIDGE_DUAL_REPORT_ONLY); closure §5; dual-report only", "adapter": "dual-corpus reporter (219 + 102 side-by-side, never joined)", "prohibited": ["TAC<->IU bridge/merge/canonical choice", "calling mutating fn_iu_*"], "true_gap_remaining": "corpus authority unresolved by design", "codex_review": "yes (corpus authority = owner+Codex)"}, {"n": 14, "capability": "Directus DOT control", "req_v0_1": "deferred (read-only observe ok)", "asset": "directus_flows (128 total / 111 active / 36 DOT-named) incl. [DOT-REG] sync / [WATCHDOG]", "class": "A", "evidence": "Domain E adopted; baseline; read-only observe", "adapter": "flow-inventory reporter", "prohibited": ["Directus mutation (CRUD)", "claiming 100% DOT control"], "true_gap_remaining": "100%-DOT-control = F UNVERIFIED (PARTIAL_EVIDENCE_ONLY)", "codex_review": "deferred (E default); yes if a write path is proposed"}, {"n": 15, "capability": "Report output format", "req_v0_1": "yes", "asset": "knowledge/dev/laws/tool-kiem-thu/ report.md+report.json+checkpoint pattern; P11E CheckerOutput; healthcheck.HealthcheckReport.to_json()", "class": "A", "evidence": "Domain I adopted; this folder's own dual-artifact convention", "adapter": null, "prohibited": ["prose-only PASS", "writing outside knowledge/dev/laws/tool-kiem-thu/"], "true_gap_remaining": null, "codex_review": "no"}, {"n": 16, "capability": "Negative/adversarial test evidence", "req_v0_1": "deferred", "asset": "P11E §4.5 four-case truth table; dryrun.py fail-closed negatives; P9-G6 dry-run package; FIX7 recheck-failure cases", "class": "C", "evidence": "reuse audit §2/§5; design precedents / acceptance fixtures", "adapter": null, "prohibited": ["running negatives in v0.1 (no execution)"], "true_gap_remaining": "a runnable negative-test harness (deferred with #4)", "codex_review": "yes (gap-only spec)"}, {"n": 17, "capability": "Fail-closed behavior", "req_v0_1": "deferred", "asset": "dryrun.py (FailClosed->exit 3, sha256-gate-before-parse, artifact-only, env-cred refusal); P11E no-metadata->NOT_READY; Đ43 §5.8 guards", "class": "C", "evidence": "reuse audit §2; local non-production checkout (not a runtime)", "adapter": null, "prohibited": ["implementing executable fail-closed logic in v0.1 (build prohibited pre-spec)"], "true_gap_remaining": "built fail-closed verifier (deferred to post-spec)", "codex_review": "yes (at impl)"}, {"n": 18, "capability": "FIX7 pilot readiness", "req_v0_1": "deferred", "asset": "FIX7 blueprint KB docs (read); existence checks (#3); P11E verdict vocab (#4); report format (#15)", "class": "B", "evidence": "reuse audit §8 R4 (pilot only, no FIX7 resume); read/report-only pilot composable from read surfaces", "adapter": "FIX7 read/report pilot (which declared artifacts resolve / which claims lack a runnable binding)", "prohibited": ["resuming FIX7", "running its declared executables (no Call Contract)"], "true_gap_remaining": "the executable pilot (run all 5 CONSTITUTION_14_EXECUTABLE_CHECK_FAIL reasons) -> E, deferred", "codex_review": "yes"} ], "reuse_as_is": [ "dot_tools registry listing (309, listing only, Domain A)", "v_dot_reconciliation_reliability over wf_fs_dot_bin_snapshot (canonical current diff 186/100/19/4; unmatched=NON-CALLABLE; Domain D)", "v_dot_registry_no_file (41) / v_dot_fs_reconciliation (name-keyed diagnostics; must not override; Domain D)", "wf_fs_dot_bin_snapshot (presence mirror 214/186; never can-run; Domain B)", "dot_iu_command_catalog / dot_iu_command_run / dot_iu_runtime_lease (read-only reporting incl. 15 mutating=false candidate set; Domain C)", "universal_edges 2199 / v_kg_edges_all 2259 / entity_dependencies 142 (read, never write-back; Domain G)", "Đ19 orphan result surfaces (wf_orphan_digest_v2 6, wf_orphan_remediation_queue 145, orphan views; read outputs; Domain G)", "duplicate-engine result views (v_birth_duplicate_issue_guard, v_rp_dedup_signature_gap, v_system_issue_semantic_duplicate_dashboard, v_system_issue_idempotency_guard; Domain G)", "Đ43 published context pack (v_context_pack_latest, context_pack_manifest.health_status, v_entity_full_classification, rendered LAWS_INDEX/DOT_REGISTRY/RED_ZONES)", "information_unit 219 and tac_logical_unit 102 (dual-report, never joined/chosen/bridged; Domain H)", "directus_flows (read-only observe 128/111/36; Domain E)", "system_issues (read-only; named write sink fn_tac_log_checker_issue, write deferred; Domain F)", "7-denominator contract + baseline ledger (count discipline; Authority Contract §3)", "KB document_id + path + revision (native read-only identifiers)", "knowledge/dev/laws/tool-kiem-thu/ report+json+checkpoint pattern (Domain I)" ], "reuse_with_adapter_readonly_filereport_only": [ "declared-artifact existence resolver (KB list/get + v_kg_edges_all + reconciliation -> {reference, resolves?, surface, ts})", "claim-inventory extractor (enumerate declared claims/tests + existence only; does NOT run; run/pass = true gap #4)", "registry<->FS reconciliation report (canonical code-keyed view + name-keyed diagnostic shown separately, full provenance)", "dual-corpus reporter (IU 219 + TAC 102 side-by-side; structurally cannot join/choose; Domain H)", "provenance report writer (attach surface/query/ts/key/population/confidence to every count; refuse bare counts)", "FIX7 read/report pilot (which declared artifacts resolve / which claims lack a runnable binding; no resume, no execution)", "flow-inventory / command-catalog reporters (read-only candidate-set listings)" ], "reference_only": [ "cutter_agent/dryrun.py + cli.py + isolation tests (local /Users/nmhuyen/iu-cutter-build/repo/iu-cutter/, NOT production) — fail-closed verifier backbone; precedent only", "P11E checker_run_status (ran_clean|ran_with_drift|not_ready|error_running) + §4.5 truth table + readiness sentence (adopt vocab verbatim)", "P6 checker taxonomy + severity (BLOCK/ERROR/WARN/INFO) + {TYPE}-{DOMAIN}-{SEQ} registry fields", "iu_core fn_iu_mark_create_manifest / cutter_governance envelope + dot_pair_signature + verify_result (adapt at most ONE after owner decision; forking/3rd = prohibited)", "86-units 19-gate preflight + Validation Contract + exact-key dual-write rollback (--doc_code->--manifest is post-spec)", "Đ43 dot-context-pack-{build,verify}.sh paired-DOT pattern (dot_config_get no-fallback, §5.8 5-guard, generic executor_type, dual-checksum, staging->promote)", "P9-G6 dry-run package (fail-loud search_path, pg_catalog.sha256(), DROP-CASCADE 0-residue, KB-report-only)", "iu_core.healthcheck per-surface verdict-dispatch + HealthcheckReport.to_json()" ], "prohibited_overlap": [ "new runner/dispatcher of any kind (Domains B,C)", "filesystem DOT invocation (Domain B; can-run NOT AVAILABLE)", "IU command invocation (Domain C; the 15 mutating=false are a candidate future set, not a v0.1 call set)", "new registry authority / forking dot_tools (Domain A/D)", "new logger / writing system_issues in v0.1 (Domain F)", "new graph/duplicate/orphan/canonical-id resolver (Domain G; unless a read-only gap proof shows a concrete miss)", "executing detector functions / writing findings (Domain G)", "TAC<->IU bridge/merge/reconciliation/canonical choice (Domain H)", "Directus mutation CRUD (Domain E)", "registry cleanup / reconciliation mutation", "a third cut/verify/manifest authority (building on neither iu_core nor cutter_governance = a third lineage)", "collapsed counts / a single canonical DOT number", "prose-only PASS" ], "true_gaps": [ {"gap": "command-runner that captures exit codes", "why_reuse_fails": "dryrun.py deliberately refuses to run anything; no deployed asset executes a declared command and records its return code (the literal FIX7/Article-14 failure)", "v0_1_or_deferred": "DEFERRED (out of read/report-only scope; blocked on the Call Contract)", "codex_review_before_build": true}, {"gap": "claim<->executable-test run-binder (run/pass half)", "why_reuse_fails": "P11E supplies the vocab and existence resolver proves an artifact exists, but nothing binds a claim to an actual execution result", "v0_1_or_deferred": "existence half = v0.1 adapter; run/pass half = DEFERRED with command-runner", "codex_review_before_build": true}, {"gap": "generic package_manifest envelope + schema across package types", "why_reuse_fails": "existing manifests are domain-specific (IU-cut/context-section/86-units); no generic one", "v0_1_or_deferred": "DEFERRED (schema build prohibited pre-spec; blocked on iu_core<->cutter_governance owner decision)", "codex_review_before_build": true}, {"gap": "--selftest N/N counter + module_sha256 self-pin", "why_reuse_fails": "repo proves isolation by AST test, not a self-reporting pinned counter; property of built code", "v0_1_or_deferred": "DEFERRED to post-spec build (small)", "codex_review_before_build": "at impl"}, {"gap": "audit_dead_links() doc-level broken-ref engine over declared references", "why_reuse_fails": "named to-build in Đ23; persistent engine does not exist; a read-only dead-link report over v_kg_edges_all is reusable now (adapter), the persistent engine+sink is the bounded new work", "v0_1_or_deferred": "read-only report = v0.1 adapter; engine+sink = DEFERRED (reuse v_kg_edges_all + system_issues, no new graph/sink)", "codex_review_before_build": true} ], "not_a_true_gap": {"doc_level_canonical_id_duplicate_authority_resolver": "UNPROVEN (Domain G) — deployed duplicate engines target DB entities not KB-document canonical-id, but a concrete miss has not been demonstrated; must be proven by running existing engines read-only under separate authorization before it is a gap or built; listed under unverified"}, "unverified": [ "actual_count=163 (CAT-006) filter — external dot-catalog-sync on-deploy artifact; no DB writer; UNVERIFIABLE/UNSAFE as denominator", "direct live OS listing of /opt/incomex/dot/bin and /opt/incomex/scripts — read_file allowlist + no shell; permanently unreachable read-only; PG mirror is canonical-available", "runnability (can run) of any filesystem DOT — NOT AVAILABLE in v0.1 (Domain B)", "Directus 100% DOT-control — PARTIAL_EVIDENCE_ONLY; no mutation path until proven (Domain E)", "doc-level canonical-id / duplicate-authority gap — UNPROVEN; needs a read-only gap proof against existing engines first (Domain G)", "iu_core <-> cutter_governance canonical cutting/manifest/verify lineage — owner decision, unresolved", "TAC <-> IU corpus authority + any bridge — unresolved by design (Domain H); owner+Codex decree required", "/opt/incomex/scripts '42' surface — resolved as separate non-DOT surface (wf_fs_script_snapshot, 42, mapped=0); excluded from DOT authority (fixed out-of-scope, not an open question)" ], "gap_only_spec_readiness": { "verdict": "PARTIAL_READY", "ready_now": "read/report-only gap surface — existence resolver, claim-inventory extractor (existence half), dual-corpus reporter, reconciliation report, provenance writer, read-only dead-link report, FIX7 read/report pilot", "must_be_carved_out": "execution-dependent gaps — command-runner with exit codes, run/pass half of the claim<->test binder, generic manifest schema — blocked behind the Call Contract and two unresolved owner decisions (iu_core<->cutter_governance; TAC<->IU corpus)", "why_not_ready": "the headline FIX7 capability (actually running declared executables) is deferred; specifying it now would violate Domains B/C/H and pre-empt owner decisions", "why_not_blocked": "the read-only skeleton is fully reusable; nothing the map could reach is missing" }, "minimal_next_step": "GPT review Reuse Extraction Map (then, if approved, a Gap-only Scope Spec scoped to the read/report-only gap surface only). No tool/schema/runner, no call, no mutation until reviewed and a spec is approved.", "parallel_authority_risk": { "new_runner_authority": "NO", "new_registry_authority": "NO", "new_logger_authority": "NO", "new_graph_duplicate_authority": "NO", "new_tac_iu_corpus_authority": "NO" }, "cross_references": { "authority_contract": "contracts/authority-contract-v0-1-2026-06-09.{md,json}", "codex_seal": "reviews/codex-seal-authority-matrix-bcdgh-2026-06-09.md", "fresh_read_closure": "reports/authority-matrix-fresh-read-closure-bcdgh-2026-06-09.{md,json}", "decision_matrix": "reports/authority-decision-matrix-draft-after-baseline-2026-06-09.{md,json}", "baseline": "reports/dot-registry-directus-text-as-code-baseline-reconciliation-2026-06-09.{md,json}", "reuse_audit": "reports/text-as-code-reuse-anti-duplication-audit-2026-06-09.md", "main_map": "reports/reuse-extraction-map-v0-1-2026-06-09.md", "checkpoint": "checkpoints/checkpoint-reuse-extraction-map-v0-1-2026-06-09.md" } }