KB-4ECB
04 — job:cut + dot:kg Runtime Ladder
3 min read Revision 1
reportjob-cutdot-kgruntime-ladder2026-06-04
04 — job:cut + dot:kg Runtime Ladder
job:cut — first-official-process path (post-vote ready)
- Sole VERIFIED candidate (iu-cutter-v0.6, Mode.DRYRUN, RO + killswitch + 366 tests). 8 members.
- Owner UNASSIGNED, birth NOT_REQUESTED, official RP 0.
- Post-vote handler
fn_pa_handler_register_processproven BLOCKED today (no PROC-OWN-03 vote). - Path: PROC-OWN-01 (owner) → 02 (axis canon) → 03 (president vote) → governance runs the canon
INSERT into
axis_assignment(AX-PROCESS, job:cut, approval_ref=PROC-OWN-03)→ official RP 1/453.
dot:kg — REAL_RUN ladder (action-ready, not executed)
- State: correlated_dryrun. 2 DRY_RUN (single
dryrun-kgexplain+ correlated pairdryrun-pair, sourceagent_api_dispatch_correlated_pair) + 4 SIMULATED. REAL_RUN 0. - Runtime gate (
dot_config):real_run_enabled=false,execute_enabled=false,dry_run_only=true— REAL_RUN config-gated OFF. Executorincomex-agent-api-executorhealthy, loopback 127.0.0.1:8090, REAL_RUN→403 by policy. - Ladder: DRY_RUN (done) → flip
real_run_enabled(owner/operator) → REAL_RUN correlated pair → verifier-agreement threshold (suggest ≥3 inputs, 0 mismatch) → PROC-OWN-04 (family owner + authorize split) → 10-process split → PROC-OWN-05 (activate 7 process.* events).
REAL_RUN enablement checklist (operator, post-authority)
- Authority recorded (PROC-OWN-04 / explicit runtime-enable approval)
- Executor still loopback-only, read_only, cap_drop ALL
- Set
real_run_enabled=true+execute_enabled=true - One REAL_RUN pair → expect evidence_type=REAL_RUN + correlated agreeing verifier
- Confirm no unintended writes (executor is no-mutation)
Rollback
Flip both flags back to false. Observation rows are append-only audit (birth-free); no canon written by a REAL_RUN. Verification still requires the verifier-agreement threshold — REAL_RUN alone ≠ verified.
Why nothing was executed
No authority to flip real_run_enabled; flipping + executing is unsafe production execution. Held.