KB-40CA
Codex FIX7 Recheck - Hardcode and PG Native
2 min read Revision 1
fix7codexrecheckhardcodepg-native
08 - Hardcode / PG-Native Recheck
Verdicts
HARDCODE_NEEDS_FIXPG_NATIVE_DRIVEN_FAIL
T1 removed direct name-pattern operational authority. Remaining disguised-hardcode/PG-native risks:
live-relevanthas no closed derivation. Without a precise reverse/write-effect relevance universe, the both-EXCEPT denominator can still be selected by implementer judgment.- The five disposition values are embedded as a new typed column vocabulary without showing their FK binding to the sealed code catalog.
expected_legacy_set_sha256is authoritative but is declared not to be a hash contract. Any authoritative hash requires an explicit canonicalization, component set, ordering, null encoding, and verification contract. It cannot avoid hash-contract governance by being called a roll-up.operator_authorization_artifactlacks a specified PG-native authority home.- S15 REVOKE assumes ACL can remove owner execution, which is false in PostgreSQL.
Required T1 fix: resolve these through approved PG schema/data contracts and PostgreSQL-feasible enforcement. Do not hide new authority/hash behavior in blueprint prose.