KB-5188

Principal Set Separation Recheck

1 min read Revision 1
fix7codexrecheck-4principal

Check B - Principal Set Separation Recheck

Verdict: PRINCIPAL_SET_SEPARATION_ACCEPTED

Principals live in U_effective_privilege_principal and are used only for effective-privilege evaluation. The proof compares U_legacy_object × U_effective_privilege_principal to sealed #21 and accounts for PostgreSQL role inheritance through pg_auth_members. Principals are not subjected to owner/body object predicates.

No remaining Check-B blocker.

Back to Knowledge Hub knowledge/dev/reports/architecture/codex-fix7-blueprint-recheck-4-final-before-authoring-2026-06-09/02-principal-set-separation-recheck.md