KB-15EA rev 49

FIX7 Existing-System Refactor Execution Blueprint - Readme First

62 min read Revision 49
fix7architecturerefactor-blueprintt1readme

00 - FIX7 Existing-System Refactor Execution Blueprint - Readme First

<!-- DOC_STATUS: ACTIVE_AUTHORITY --> <!-- AUTHORITY_BOUNDARY_HOME: this file hosts the machine-readable Active-authority boundary registry (§Active-authority boundary) that scopes G-LEGACY-NO-DISPOSITION-AUTHORITY / G-ACTIVE-AUTHORITY-SCOPE / G-NO-SUPERSEDED-CONSUMPTION (doc 06) -->

Date: 2026-06-08 Author: T1 (production Agent for Agent Data) Macro: FIX7_EXISTING_SYSTEM_REFACTOR_MAPPING_EXECUTION_BLUEPRINT_WITH_INTERNAL_XHIGH_MAX_REVIEW Mode: READ-ONLY production. AUTHOR_MODE_ONLY. KB blueprint documents only.

What this package is

This is a construction blueprint for refactoring the existing production system onto the officially Codex-approved FIX7 design. It is NOT implementation, NOT live migration, NOT Stage 2.6B, NOT a permit, NOT REAL_RUN, NOT QT001 apply, NOT owner/ACL cutover, NOT manifest activation.

No production object was created, altered, dropped, owned, granted, revoked, or executed in authoring this package. The only writes performed are these KB documents and the checkpoint.

Design-approval source (confirmed)

  • Official status: FIX7_DESIGN_OFFICIALLY_APPROVED_BY_CODEX_FOR_IMPLEMENTATION_PLANNING.
  • Owner confirmation: codex-owner-confirmation-fix7-final-design-approval-2026-06-08/05-final-verdict.md (A MISROUTING_ACKNOWLEDGED, B T1_EVIDENCE_VALID, C CODEX_OWNER_APPROVES, D BOUNDARIES_CONFIRMED).
  • T1 genuine final short-review: DESIGN_READY_FOR_CODEX_FINAL_APPROVAL, 0 blocking proposals.
  • Design index: BIRTH_GATEWAY_DESIGN_INDEX.md rev 27.
  • This approval authorizes implementation-planning/authoring only. Implementation and all live gates remain blocked.

Confirmed approved-design invariants (must be preserved by any refactor)

AUTHORITY_SURFACES                 = 27   (named child contracts #01..#27)
RUNTIME_EVIDENCE_TABLES            = 11   (non-authority)
NEW_READINESS_GATES                = 0    (14 gates are DATA rows in surface #09)
NEW_TOP_LEVEL_HASH_CONTRACTS       = 0    (7 contracts H01..H07 are DATA rows in surface #10)
PRODUCTION_MUTATION                = 0
STAGE_2_6B / PERMIT / REAL_RUN / QT001_APPLY = BLOCKED
OWNER_ACL_CUTOVER / MANIFEST_ACTIVATION      = BLOCKED_OPERATOR_GATED

The central refactor finding (verified live, read-only, 2026-06-08)

The FIX7 design is a parallel green-field control-plane schema qt001_cp. Live introspection confirms:

  • qt001_cp schema: ABSENT (live schemas: cutter_governance, iu_core, public, sandbox_tac).
  • qt001_cp_owner / qt001_cp_migrator / qt001_cp_reader roles: ABSENT.
  • Legacy qt001_* objects in public, all owned by directus: 20 tables, 46 functions, 196 views (the FIX..FIX6 iteration objects that Codex repeatedly rejected as hardcode/bypass).
  • Birth gateway (birth_registry, birth_admission_permit/_v2, birth_backfill_ledger/_v2, birth_gateway_release_registry, and 5 fn_birth_*): present, owned by directus.

Therefore the refactor is not "build FIX7 from nothing" and not "edit the legacy objects in place". It is:

  1. ADD the whole qt001_cp control plane (roles, schema, domains, catalog root, anchors, 27 authority surfaces, registries, 11 runtime-evidence tables, sealed manifest DATA) - every item MISSING_ADD, all operator-gated, none authored-live by T1.
  2. REPOINT the single authoritative apply/writer path from the legacy qt001_* world to the qt001_cp manifest-driven world atomically, proven non-reachable-to-legacy by dependency_manifest #11 + authority_scope_manifest #20 (this is what every prior FIX cycle failed to do, and what writer_repoint_manifest #27 + gateway_manifest #26 encode).
  3. NEUTRALIZE then RETAIN the legacy qt001_* objects to the single uniform Option-Beta end-state (owner-isolated to qt001_cp_owner, body unchanged, effective privileges == sealed #21) and retain them forward-only - never DROP them live; rollback is a new manifest version, not deletion. (This is the uniform end-state over U_legacy_object, not a per-object disposition - doc 02 §H, Option Beta + recheck-3 set separation.)
  4. DO_NOT_TOUCH the birth gateway and the two frozen dangerous DOTs (DOT-118 dot-birth-backfill, DOT-119 dot-birth-trigger-setup); birth-neutral row anchor preserved.
  5. ROLE_CUTOVER_LATER: directus currently owns all control objects; ownership transfer to qt001_cp_owner + REVOKE of directus/PUBLIC authority is destructive and operator-gated.

Document map

Doc Content
00 This readme
01 Live existing-system inventory (read-only)
02 Design-to-live mapping (every approved component -> live state + action)
03 Gap classification matrix (gap_id, severity, action)
04 Dependency-safe construction order
05 Rollback blueprint
06 Test / guard blueprint
07 Implementation package split
08 Hard blocks and do-not-touch list
09 XHigh adversarial review
10 Max adversarial review
11 Blueprint revisions from reviews
12 Final verdict

Classification vocabulary (used exactly, no vague labels)

EXISTS_OK · EXISTS_BUT_WRONG · MISSING_ADD · LEGACY_REPLACE · LEGACY_FREEZE · LEGACY_DEPRECATE · ROLE_CUTOVER_LATER · OPERATOR_GATED · DO_NOT_TOUCH · BLOCKED_UNTIL_AUTHORITY · UNKNOWN_REQUIRES_REVIEW.

Active-authority boundary (machine-readable)

This blueprint distinguishes current load-bearing authority from retained history, so the no-disposition / set-separation guards scan current authority only and never trip on audit trail. The boundary is machine-readable two ways: (1) a DOC_STATUS: marker at the top of every numbered doc; (2) SUPERSEDED_NON_AUTHORITY BEGIN/END fences around any retained historical block inside an otherwise-active doc. The boundary lives only in this blueprint's KB document structure — it is not a Directus collection, not a #20/manifest row, and not a runtime table, so Directus has no write path to it (G-ACTIVE-AUTHORITY-SCOPE, doc 06). Recheck-4: because markers/registry/ fences are themselves mutable KB text, they are necessary classification syntax but NOT sufficient authority — the exact reviewed corpus is pinned by the immutable, content-addressed §Active-authority approval envelope below (sealed at the Codex recheck; any drift fails closed). Recheck-5: every aggregate digest in that envelope is now defined byte-exactly by the Canonical hash encoding (FIX7-CANON-V1), the manifest binds the complete authority-field roster, doc 00's self-reference is resolved (Option 1: full_document_sha256 is diagnostic; normalized_active_content_sha256 excludes the envelope region), and the SEALED copy of record is a Codex detached seal, not a self-hosted block. Recheck-6: the canonical encoding is made byte-exact and executable — a REJECT-not-escape field policy (no TAB/LF/CR/NUL/backslash/reserved-token/grammar-violating value can enter a record), one deterministic active-scope/fence/section extractor (with fail-closed statuses for every ambiguity), a closed per-record encoding schema, a closed envelope key-classification schema, and an acyclic seal hash graph that removes the recheck-6 self-reference (the manifest binds no Codex-checkpoint revision/content hash and the seal never hashes its own checkpoint; the checkpoint is anchored out-of-band by its platform revision + MCP read-back). Recheck-7 (Constitution Article 14): the single load-bearing canonical contract is now the executable SSOT artifact FIX7-CANON-V1-CANONICALIZER (pinned by canonicalizer_sha256); this section and all encoding/extractor/record descriptions are NON_AUTHORITY_EXPLANATION (no duplicate authority); the checkpoint own-revision anchor is removed (revision diagnostic-only — no self-reference, even at the revision layer); document_id must equal the exact MCP canonical id (every alias rejected); and marker_kind↔marker_literal is one consistent pair. This blueprint checkpoint (checkpoint-t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08.md) is a DERIVED NON_AUTHORITY_INDEX (REPORT_ONLY): it is not an ACTIVE member, not a self-host, and no guard or package may consume it as authority (recheck-5 blocker D) — authoring readiness is decided by the sealed envelope + the Codex detached seal only.

ACTIVE_AUTHORITY (current, load-bearing; the ONLY sections future implementation authoring may consume):

doc active scope
00 this readme except the fenced history block below
01 live existing-system inventory (whole)
02 design-to-live mapping incl. §H set model (whole; current revision)
03 gap classification (whole)
04 dependency-safe construction order (whole; current revision)
05 rollback blueprint (whole; current revision)
06 test/guard blueprint incl. the 54 guards + guard-quality rules (whole)
07 implementation package split (whole; current revision)
08 hard blocks / do-not-touch list (whole)
12 final verdict: the current Verdict, Option-Beta patch pass, Codex recheck-3 set-separation patch pass, explicit asks, verdicts on dimensions, track summary, blocking status sections only

SUPERSEDED_NON_AUTHORITY (retained as audit trail; must NOT be consumed by any package, guard, seal, construction-order step, rollback step, or implementation authoring — G-NO-SUPERSEDED-CONSUMPTION, doc 06):

location superseded content
00 §Self-verdict history the fenced pre-Option-Beta gate-chain narrative below
09 XHigh adversarial review (historical report)
10 Max adversarial review (historical report)
11 blueprint revisions from reviews (historical report)
12 historical pass sections Codex RECHECK-2 / Codex RECHECK (owner-semantics) / Codex critical-review patch passes, the A-K verdict alignment, and the Independent XHigh/Max pass narratives — each fenced as history

These superseded sections may contain pre-Option-Beta terms (the five-value disposition enum, STUB_FAIL_CLOSED, LEGACY_* rows, − DO_NOT_TOUCH subtraction). They are history of how earlier rounds were fixed, not current instructions. G-LEGACY-NO-DISPOSITION-AUTHORITY reports such terms from these fenced blocks as history and does not fail on them; it fails only if such a term appears in an ACTIVE_AUTHORITY section, or if any package consumes a superseded instruction.

Active-authority approval envelope (content-addressed; sealed at the Codex recheck)

Why (recheck-4). The §Active-authority boundary above is classified by DOC_STATUS markers, the registry table, and SUPERSEDED_NON_AUTHORITY fences — all mutable KB text. They can be edited after Codex approval, so they are necessary classification syntax but not sufficient authoring authority. This section pins the exact reviewed corpus with an immutable, content-addressed approval envelope: every ACTIVE document/section + its KB revision + a normalized SHA-256, plus registry / marker-fence / guard-set / membership / manifest hashes + the Codex recheck checkpoint anchor. After Codex PASS the envelope is sealed; any later change to content, marker, fence, registry, active section, or guard set produces ACTIVE_AUTHORITY_ENVELOPE_MISMATCH, blocks implementation-authoring planning, and the correct next step is a fresh Codex recheck — never "continue authoring" (doc 06 G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE / -HASH-MATCH / -REVISION-MATCH / -CHANGE-FAIL-CLOSED; guard-quality rule 9).

Non-runtime. This envelope is a construction-document content-address that pins the blueprint documents being authored from. It is NOT a runtime authority surface, readiness gate, #20 column, catalog family, or a top-level FIX7 runtime hash contract (H01..H07 stay 7). It adds nothing to 27/11/14/7.

Seal timing (summary; full spec below). A content hash of the approved corpus can only be computed at the approval event — now recheck 6 (recheck 5 did not seal). T1 fixes the structural values now (the corpus membership hash and canonical_encoding_version — both reproducible and stable) and the approving authority (Codex) computes and seals the per-document/aggregate content hashes and the manifest at recheck-6 PASS, recording them in the Codex detached seal (a Codex-authored block in the recheck-6 checkpoint, not a self-hosted block — recheck-5 blocker E). Pre-writing "approved" content hashes would be self-fabricated authority — the anti-pattern this chain polices. See Canonical hash encoding (FIX7-CANON-V1) and Codex detached seal anchor contract below; the guards verify live revision/content against the detached seal at authoring time.

⚠️ NON_AUTHORITY_EXPLANATION (Constitution Article 14 / NT14 — recheck-7). The single load-bearing canonical contract is the executable SSOT artifact FIX7-CANON-V1-CANONICALIZER (knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/canonicalizer-fix7-canon-v1-ssot.md), pinned in the envelope by canonicalizer_artifact_id + canonicalizer_version + canonicalizer_revision

  • canonicalizer_sha256. This "Canonical hash encoding" section, the "Active-scope / fence / section extractor" section, the "Record encoding schema" section, and every report doc are NON_AUTHORITY_EXPLANATION that describe that one artifact and MUST NOT conflict with it. If any of them conflicts with the SSOT, the SSOT wins and G-NO-DUPLICATE-CANONICAL-AUTHORITY (= Codex G-CANONICAL-CONTRACT-SSOT-NO-DUPLICATE, doc 06) fails closed. Exactly one canonicalizer exists; no doc/spec/guard/package may redefine canonicalization (G-CANONICALIZER-SSOT-ONLY). The artifact's --selftest exits 0 and reproduces membership f2bda8…fe251 and every rejection status; implementation runs that artifact, not this prose.

Canonical hash encoding (FIX7-CANON-V1). (recheck-5 blocker A; recheck-7: NON_AUTHORITY_EXPLANATION of the SSOT artifact above.) Every aggregate digest in the envelope is defined byte-exactly so any party recomputes the identical value. No aggregate hash may be described only in prose, and no aggregate hash may depend on unordered map/object serialization. The universal rules (canonical_encoding_version: FIX7-CANON-V1, pinned in the envelope; a verifier MUST reject any other version):

  • algorithm: SHA-256, output lowercase hex. shasum -a 256 and python3 hashlib.sha256().hexdigest() are byte-identical (proven this pass for membership).
  • encoding: UTF-8. No Unicode normalization (NFC/NFD) is applied; the raw UTF-8 bytes after newline normalization are hashed.
  • newline normalization: every CRLF (0x0D 0x0A) and lone CR (0x0D) is converted to LF (0x0A) before hashing. Content authority is therefore line-ending-agnostic (a pure CRLF<->LF flip does not change a content hash) but a KB edit still increments the revision and is caught by G-ACTIVE-AUTHORITY-REVISION-MATCH.
  • record / field separators: a record is terminated by exactly one LF (0x0A). Intra-record fields are joined by a single TAB (0x09). No other separators.
  • field order: fixed per record type (specified below) — never the source YAML key order. Reordering YAML keys does not change any canonical input.
  • sort key: records are emitted in ascending lexicographic order of their UTF-8 bytes, by the sort key named per hash. Unordered serialization is forbidden.
  • trailing newline: the hash input begins with the domain tag (itself LF-terminated) and every record is LF-terminated, so the whole input ends with exactly one trailing LF. Removing it changes the bytes and the digest (a specified mismatch).
  • domain tag: each hash prepends a fixed ASCII domain tag ending in LF (listed per hash), so two different hash kinds can never collide on the same input bytes.
  • path normalization: every document_id is the full canonical KB path including the knowledge/dev/reports/architecture/... prefix — no prefix stripping, no leading slash, no ./, no trailing slash, exact case (recheck-5 blocker A.1; the earlier prefix-stripped ids were the ambiguity).
  • revision representation: kb_revision is base-10 ASCII, no leading zeros (e.g. 33). The sole self-host (doc 00) uses the literal token SELF_HOST_PIN_BY_EXCLUDE_REGION_HASH instead of a number (hosting the live envelope changes its revision).
  • null / absent: no authority field may be null/absent. An intentionally-empty value is the literal token NOT_APPLICABLE; a not-yet-sealed value is the literal token SEAL_AT_CODEX_RECHECK_8; a declared-diagnostic value is NON_AUTHORITY_DIAGNOSTIC. These tokens are hashed as their literal UTF-8 bytes — there is no implicit null.
  • boolean: lowercase true / false only (never True/1/yes).
  • reproducible command (general form): printf '%s' "<canonical_input_bytes>" | shasum -a 256 == hashlib.sha256(canonical_input_bytes).hexdigest().

Field rejection policy (recheck-6 blocker A) — REJECT, never escape. Every field VALUE that enters any canonical record is validated before it is joined; there is no escaping (so the TAB/LF-delimited records are provably injective — no value can ever contain a separator or a structural sentinel). Three layers, all fail-closed:

  1. Per-field whitelist grammar. Each field has a declared value type with an exact grammar; a value that does not match → CANONICAL_FIELD_VALUE_GRAMMAR_REJECTED. The grammars (anchored, full-string): document_id (recheck-7 blocker D — canonical MCP identity, no alias; authoritative impl = canonical_document_id() in the SSOT): must equal the MCP-returned document_id byte-for-byte (case-sensitive, no identity-changing normalization); split on /, every segment matches ^[A-Za-z0-9._-]+$ (ASCII only → rejects backslash, %-encoding, and homoglyph slashes); the path ends .md, starts with the knowledge/dev/reports/architecture/ root, and rejects any . or .. segment, empty segment, //, leading slash, or trailing slash → DOCUMENT_ID_ALIAS_REJECTED; wrong root → DOCUMENT_ID_SCOPE_MISMATCH; not equal to the MCP id → DOCUMENT_ID_NOT_MCP_CANONICAL (G-DOCUMENT-ID-CANONICAL-MCP). sha256_hex = ^[0-9a-f]{64}$; kb_revision = ^[1-9][0-9]*$ or the literal SELF_HOST_PIN_BY_EXCLUDE_REGION_HASH; doc_status ∈ {ACTIVE_AUTHORITY,SUPERSEDED_NON_AUTHORITY}; boolean ∈ {true,false}; active_section_id_or_range ∈ {WHOLE_DOCUMENT,WHOLE_DOCUMENT_MINUS_SUPERSEDED_FENCES,WHOLE_DOCUMENT_MINUS_EXCLUDE_AND_SUPERSEDED}; fence_range = ^L[1-9][0-9]*-L[1-9][0-9]*$ (begin<end); superseded_id = ^<document_id>#S[1-9][0-9]*$; marker_kind ∈ {DOC_STATUS,SUPERSEDED_BEGIN,SUPERSEDED_END,ENVELOPE_EXCLUDE_BEGIN,ENVELOPE_EXCLUDE_END,AUTHORITY_BOUNDARY}; marker_literal = ^<!--.*-->$ (the one field allowed to carry marker structure); fixed-constant fields (digest_algorithm, full_document_hash_policy, canonical_encoding_version) must equal their pinned constant byte-for-byte.
  2. Forbidden-byte rejection (defense in depth). Any field value containing TAB 0x09, LF 0x0A, CR 0x0D, NUL 0x00, or backslash 0x5CCANONICAL_FIELD_RESERVED_TOKEN_REJECTED. (Backslash is rejected outright so there is no escape syntax to interpret.)
  3. Forbidden reserved-token rejection (defense in depth). Any field value other than marker_literal that contains a structural sentinel substring → CANONICAL_FIELD_RESERVED_TOKEN_REJECTED. The forbidden token list: <!-- ENVELOPE:EXCLUDE-BEGIN -->, <!-- ENVELOPE:EXCLUDE-END -->, <!-- SUPERSEDED_NON_AUTHORITY BEGIN, <!-- SUPERSEDED_NON_AUTHORITY END -->, and every domain tag (FIX7_*_V1). The bare classification tokens ACTIVE_AUTHORITY / SUPERSEDED_NON_AUTHORITY are permitted only as the value of doc_status (whitelist layer 1) and are otherwise rejected.

No null / empty. A null/absent authority field → CANONICAL_FIELD_NULL_REJECTED (use an explicit token: NOT_APPLICABLE, SEAL_AT_CODEX_RECHECK_8, or NON_AUTHORITY_DIAGNOSTIC). An empty-string value → CANONICAL_FIELD_EMPTY_REJECTED. Any rejection status blocks implementation-authoring and requires a T1 fix + a fresh Codex recheck (G-CANONICAL-FIELD-REJECT, doc 06). This policy was computed against all 15 recheck-6 self-review scenarios (report doc 02/08): TAB, LF, CR, NUL, backslash, and every reserved token inside a value are rejected; the membership digest still reproduces f2bda8…fe251.

Per-aggregate specs (domain tag | record type | field order | sort key):

  • active_corpus_membership_sha256 — tag FIX7_ACTIVE_AUTHORITY_MEMBERSHIP_V1\n | record = document_id | one field | sort = ascending document_id. Computed NOW (structural, reproducible): f2bda8effc7be19b54722828126b82d7d2d48bee5e5e5dc0c8f347ce210fe251 (10 full doc_ids; shasum == hashlib). This alone detects any missing/extra ACTIVE doc and any prefix tampering.
  • active_corpus_sha256 — tag FIX7_ACTIVE_AUTHORITY_CORPUS_V1\n | record = document_id \t doc_status \t active_section_id_or_range \t kb_revision \t normalized_active_content_sha256 (the active document record, doc 04 of the recheck-6 report) | sort = ascending document_id. Binds content → seals at recheck-7.
  • marker_fence_registry_sha256 — tag FIX7_MARKER_FENCE_REGISTRY_V1\n | record = document_id \t marker_kind \t marker_literal (marker_kind in {DOC_STATUS, SUPERSEDED_BEGIN, SUPERSEDED_END, ENVELOPE_EXCLUDE_BEGIN, ENVELOPE_EXCLUDE_END, AUTHORITY_BOUNDARY}; the markers are produced by the deterministic extractor below) | sort = ascending (document_id, marker_kind, marker_literal). Seals at recheck-7.
  • superseded_boundary_sha256 — tag FIX7_SUPERSEDED_BOUNDARY_V1\n | record = superseded_id \t fence_range where superseded_id = <document_id>#S<k> (k = 1-based ordinal of the SUPERSEDED region within the doc, ascending begin-line) and fence_range = L<begin_line>-L<end_line> (1-based inclusive, over the extractor's normalized lines) | sort = ascending superseded_id. Seals at recheck-7.
  • guard_set_sha256 — tag FIX7_GUARD_SET_V1\n; defined as normalized_active_content_sha256 of doc 06 (the guard host) so it needs no separate extraction; guard_set_revision = doc 06 kb_revision. Seals at recheck-7.
  • per-document normalized_active_content_sha256 — tag FIX7_DOC_NORMALIZED_CONTENT_V1\t<document_id>\n, then the document's normalized active bytes as produced by the Active-scope / fence / section extractor below (deterministic: normalize CRLF/CR→LF first, 1-based lines, remove SUPERSEDED fenced ranges inclusive, and for the sole self-host doc 00 also remove the ENVELOPE:EXCLUDE region inclusive, re-emit each retained line + one LF). This is the load-bearing per-doc content authority. Seals at recheck-7.
  • per-document full_document_sha256NON_AUTHORITY_DIAGNOSTIC for every member (see self-reference resolution below). Not hashed into the manifest, not depended on by any guard.
  • envelope_manifest_sha256 — tag FIX7_ACTIVE_AUTHORITY_ENVELOPE_MANIFEST_V1\n over the COMPLETE authority-field roster below, in fixed roster order (the manifest is the one digest emitted in a fixed order, not sorted; sub-lists inside it are sorted), each entry encoded as manifest_key \t value or as the relevant sorted sub-records, EXCLUDING envelope_manifest_sha256 itself, detached_seal_sha256, and every seal-layer anchor field (the Codex-checkpoint revision and content hash) — see Seal hash dependency graph (acyclic) below: the manifest is a strict predecessor of the detached seal and must not bind anything that is fixed only at or after sealing. Seals at recheck-7.
  • detached_seal_sha256 — tag FIX7_CODEX_DETACHED_SEAL_V1\n over the detached-seal authority fields in fixed seal order, each seal_key \t value, EXCLUDING detached_seal_sha256 itself and signature. Its inputs are sealed_envelope_manifest_sha256 (= envelope_manifest_sha256), sealed_active_corpus_sha256, sealed_active_membership_hash, guard_set_sha256/guard_set_revision, parent_checkpoint_id (the recheck-6 checkpoint), report_documents[] (id+revision+content hash), canonical_encoding_version, and any_change_requires_new_recheck — and it does NOT include its own checkpoint's content hash or revision (that would be self-referential). Authored + sealed by Codex in the recheck-7 checkpoint.

Envelope manifest authority-field roster (recheck-5 blocker B; recheck-6 cycle fix). envelope_manifest_sha256 binds the MANIFEST_BOUND fields, in this fixed order (the manifest is emitted in roster order, not sorted; each scalar entry is encoded manifest_key \t value \n, each sub-list as its sorted sub-records), EXCEPT the self field envelope_manifest_sha256: canonical_encoding_version; seal_version; blueprint_id; envelope_state; approved_status; approval_epoch; approved_by_role; approved_at_utc; parent_recheck_checkpoint_id; approved_by_recheck_checkpoint; next_required_recheck_on_change; digest_algorithm; full_document_hash_policy; active_corpus_membership_sha256; active_corpus_sha256; marker_fence_registry_sha256; superseded_boundary_sha256; guard_set_revision; guard_set_sha256; canonicalizer_artifact_id; canonicalizer_path; canonicalizer_version; canonicalizer_revision; canonicalizer_sha256 (the single SSOT pin, recheck-7 blocker B — id/path/version fixed now, revision/hash sealed by Codex over the artifact's MCP bytes; the artifact is a pinned TOOL, not an active_corpus membership member, so membership stays f2bda8…fe251); then the per-active-doc tuples (sorted by document_id), each document_id \t doc_status \t active_section_id_or_range \t kb_revision \t normalized_active_content_sha256; then the superseded_non_authority whole-doc list (sorted, each SUPERSEDED_WHOLE_DOC \t document_id); then the single manifest-bound anchor flag detached_seal_anchor.any_change_requires_new_recheck.

The manifest deliberately does NOT bind detached_seal_sha256, detached_seal_anchor.codex_checkpoint_kb_revision, or detached_seal_anchor.codex_checkpoint_content_sha256_excluding_seal — those are seal-layer values fixed only at/after sealing; binding them would create the cycle. Recheck-7 (blocker A): the checkpoint revision is NOT load-bearing at all (no read-back equality) — it is NON_AUTHORITY_DIAGNOSTIC; the checkpoint identity is bound via approved_by_recheck_checkpoint (a path chosen in advance) and seal integrity is the content recompute of detached_seal_sha256 (G-NO-SELF-REVISION-ANCHOR).

Closed key-classification schema (recheck-6 blocker B). Every key at every nesting level of the live envelope MUST appear in exactly one class; an unknown/extra key, a missing required key, or a key in the wrong class → fail closed (G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE):

  • MANIFEST_BOUND — all roster fields above (hashed into envelope_manifest_sha256).
  • SEAL_LAYER_CONTENT_PROTECTEDenvelope_manifest_sha256 (pinned by the detached seal), detached_seal_anchor.codex_checkpoint_id (must equal the bound approved_by_recheck_checkpoint), detached_seal_anchor.signature, detached_seal_anchor.detached_seal_sha256 (mirror of the seal's own self-hash). Protected by content recompute of detached_seal_sha256 + the detached seal, not by any revision read-back (recheck-7 blocker A: revision equality is no longer load-bearing).
  • NON_AUTHORITY_DIAGNOSTIC — every per-doc full_document_sha256 (declared by full_document_hash_policy), detached_seal_anchor.codex_checkpoint_kb_revision (recheck-7: diagnostic / post-seal audit only, gates nothing — G-NO-SELF-REVISION-ANCHOR), detached_seal_anchor.codex_checkpoint_content_sha256_excluding_seal, and notes[]. Recorded for human cross-check; no guard depends on them.
  • STRUCTURAL_CONTRACT_PROSEdetached_seal_anchor.contract (a fixed description of where the real authority lives; declared non-authority).

Active-scope / fence / section extractor (recheck-6 blocker B). Every per-doc content/marker/boundary digest is computed over the output of this one deterministic extractor; "restricted to active scope" is no longer prose. Pseudocode (full version + worked tests in recheck-6 report doc 03):

  1. Input = the raw UTF-8 bytes returned by get_document_for_rewrite(document_id) at the pinned kb_revision.
  2. Normalize first: replace every CRLF then every lone CR with LF, over the whole byte string. All later steps run on these normalized bytes.
  3. Line model: split on LF; lines are 1-based; line_text(i) = line i without its terminating LF; a trailing non-LF remainder is the final line.
  4. Marker recognition (exact, line-based): a line is a marker iff line_text(i) matches exactly one grammar — <!-- DOC_STATUS: <value> --> (whole line); the literals <!-- ENVELOPE:EXCLUDE-BEGIN --> / <!-- ENVELOPE:EXCLUDE-END -->; <!-- SUPERSEDED_NON_AUTHORITY BEGIN…--> (prefix-match, ends -->, no embedded -->) / the literal <!-- SUPERSEDED_NON_AUTHORITY END -->. Matching is not exempted inside code fences (so an accidental standalone marker line fails closed as a duplicate).
  5. Fence pairing (single stack, flat — nesting unsupported): push on any BEGIN; if the stack is non-empty when a BEGIN is seen → FENCE_NESTED_UNSUPPORTED. On an END, the stack top must be the matching kind, else FENCE_UNBALANCED (or EXCLUDE_REGION_UNBALANCED for an EXCLUDE END). At end-of-scan a non-empty stack → unbalanced. An EXCLUDE region in any doc other than the self-host doc 00 → EXCLUDE_REGION_UNBALANCED (EXCLUDE is doc-00-only).
  6. DOC_STATUS cardinality: exactly one DOC_STATUS marker — zero → ACTIVE_SCOPE_MARKER_MISSING, two+ → ACTIVE_SCOPE_MARKER_DUPLICATE; for an ACTIVE member its value must be ACTIVE_AUTHORITY.
  7. Overlap assertion: if any SUPERSEDED line-range intersects the EXCLUDE line-range → ACTIVE_SUPERSEDED_OVERLAP (structurally impossible under flat non-nesting; kept as a defense-in-depth assertion).
  8. Active bytes: removal set = all SUPERSEDED ranges (BEGIN..END inclusive) ∪ (self-host only) the EXCLUDE range inclusive. normalized_active_content = concatenation, in ascending line order, of line_text(i) + LF for every line NOT in the removal set. (Re-emitting one LF per retained line fixes the trailing newline deterministically.)
  9. Section identity (by marker structure, never by heading text): computed descriptor = WHOLE_DOCUMENT (no fences) / WHOLE_DOCUMENT_MINUS_SUPERSEDED_FENCES / (self-host) WHOLE_DOCUMENT_MINUS_EXCLUDE_AND_SUPERSEDED; if ≠ the envelope's recorded active_section_id_or_rangeSECTION_ID_MISMATCH, and a line-range form that differs → SECTION_RANGE_MISMATCH.
  10. Registry: emit (document_id, marker_kind, marker_literal) for every marker; if the live-extracted marker_fence_registry_sha256 ≠ the sealed value → MARKER_REGISTRY_MISMATCH.
  11. Fail-closed default: any status above → STOP, block authoring, return to Codex recheck; never "best effort." (G-ACTIVE-SCOPE-EXTRACTOR, doc 06.)

Record encoding schema (recheck-6 blocker C). Every load-bearing digest is a domain tag (LF-terminated)

  • records, each record = its fields joined by single TABs + one LF, every field validated by the Field rejection policy above (no null, no empty, no TAB/LF/CR/NUL/backslash/reserved token; full-path document_id). Closed roster, no human interpretation (full table in report doc 04):
record domain tag fields (fixed order) sort key
membership FIX7_ACTIVE_AUTHORITY_MEMBERSHIP_V1 document_id document_id asc
active document FIX7_ACTIVE_AUTHORITY_CORPUS_V1 document_id,doc_status,active_section_id_or_range,kb_revision,normalized_active_content_sha256 document_id asc
marker FIX7_MARKER_FENCE_REGISTRY_V1 document_id,marker_kind,marker_literal (document_id,marker_kind,marker_literal) asc
superseded boundary FIX7_SUPERSEDED_BOUNDARY_V1 superseded_id,fence_range superseded_id asc
superseded whole-doc (in manifest) SUPERSEDED_WHOLE_DOC,document_id document_id asc
guard set FIX7_GUARD_SET_V1 = normalized_active_content_sha256(doc 06); guard_set_revision=doc 06 kb_revision n/a
envelope manifest FIX7_ACTIVE_AUTHORITY_ENVELOPE_MANIFEST_V1 roster above as manifest_key \t value / sorted sub-records fixed roster order
detached seal FIX7_CODEX_DETACHED_SEAL_V1 seal fields as seal_key \t value, EXCL detached_seal_sha256+signature fixed seal order

An absent value is the explicit token NOT_APPLICABLE / SEAL_AT_CODEX_RECHECK_8 / NON_AUTHORITY_DIAGNOSTIC (never an implicit null); an empty string is rejected; a path is always the canonical full KB document_id. (G-RECORD-ENCODING-CLOSED, doc 06.)

Seal hash dependency graph (acyclic) — recheck-6 blocker D. The load-bearing digests form a directed acyclic graph (consumer ← producer); the recheck-6 cycle is removed by making the manifest a strict predecessor of the seal and the checkpoint-content hash a non-consumed diagnostic sink:

N1 normalized_active_content_sha256[d]   (leaf: extractor output, per active doc)
N2 active_corpus_membership_sha256       (leaf: document_id set)
N3 marker_fence_registry_sha256          (leaf: extractor markers)
N4 superseded_boundary_sha256            (leaf: extractor fence ranges)
N5 guard_set_sha256 (= N1[doc06]) + guard_set_revision   (leaf)
N6 active_corpus_sha256          <- N1[d]                         (∀ active d)
N7 envelope_manifest_sha256      <- N2, N3, N4, N5, N6, N1[d]     (NO checkpoint hash; NO N8)
N8 detached_seal_sha256          <- N2, N5, N6, N7, parent_checkpoint_id, report_documents[]
                                    (NOT N8; NOT the checkpoint content hash)
N9 codex_checkpoint_content_sha256_excluding_seal   = NON_AUTHORITY_DIAGNOSTIC; consumed by NOTHING (sink)

Topological order N1→N2→N3→N4→N5→N6→N7→N8→N9 exists ⇒ acyclic (verified in code, report doc 05/08). Two rules make it load-bearing (G-SEAL-HASH-GRAPH-ACYCLIC, doc 06): (i) no load-bearing node's input set may contain a node that transitively depends on it — in particular N7 must not bind any checkpoint revision/content hash or N8, and N8 must not bind N8 or its own checkpoint's content hash; (ii) the checkpoint content hash is diagnostic only (N9), consumed by no node. The old design's two back-edges — "manifest binds the Codex checkpoint content hash" and "seal_report_checkpoint_content_sha256 hashes the checkpoint that contains the seal" — are both removed; adding either back is detected as a cycle.

doc 00 self-reference resolution — Option 1 (recheck-5 blocker C). The load-bearing per-document content hash is always normalized_active_content_sha256. For the sole self-host (this doc 00) it is computed over doc-00 bytes with the ENVELOPE:EXCLUDE region removed, so it never includes the envelope (which holds the hashes) — no circularity. full_document_sha256 is NON_AUTHORITY_DIAGNOSTIC for every member (a declared exclusion policy, recorded for human cross-check only; no guard depends on it). There is therefore no full-document-vs-exclude contradiction. The live envelope block is instead tamper-protected by the detached seal: editing it changes the live envelope_manifest_sha256, which then diverges from the Codex-sealed sealed_envelope_manifest_sha256ACTIVE_AUTHORITY_ENVELOPE_MISMATCH.

Codex detached seal anchor contract — non-self-referential revision anchor (recheck-7 blocker A, Option 1). The SEALED copy of record is a CODEX_DETACHED_SEAL fenced-YAML block authored by Codex in the recheck-8 checkpoint (approved_by_recheck_checkpoint), trusted as an approval record, never by path/name. Fields (node N8): seal_version; sealed_by; sealed_at_utc; sealed_envelope_manifest_sha256 (= N7); sealed_active_corpus_sha256 (= N6); sealed_active_membership_hash (= N2); guard_set_sha256 + guard_set_revision (= N5); sealed_canonicalizer_sha256 + sealed_canonicalizer_version (the SSOT pin); parent_checkpoint_id (the recheck-7 checkpoint — a backward hash-chain link to the prior already-existing, immutable approval, whose revision is known before this write); report_documents[] (id + content_sha256); canonical_encoding_version; any_change_requires_new_recheck: true; signature or signature_not_available_in_current_tooling: true; and detached_seal_sha256 (N8 over all the above excluding detached_seal_sha256 and signature). The seal records NO revision of its own checkpoint — not its own, and not a value that only exists after this write. seal_report_checkpoint_content_sha256 (recheck-6) is removed.

Non-self-referential anchor + finite ordered sealing procedure (recheck-7 blocker A). The recheck-6 model made the recheck-N checkpoint's own platform revision load-bearing (recorded + read-back for equality). A platform revision is assigned only after the write, so recording it forces another write — a revision-layer self-reference even though the content-hash DAG (N1–N9) is acyclic. Fix (Option 1): own-revision equality is REMOVED from the load-bearing authority. The finite, predeclared, no-improvisation sequence is:

  1. T1 (now): STAGE the live envelope with SEAL_AT_CODEX_RECHECK_8 placeholders and the canonicalizer SSOT identity (id/path/version fixed; canonicalizer_revision/canonicalizer_sha256 staged).
  2. Codex (recheck 8): compute every content hash with the SSOT canonicalizer over MCP bytes; author the CODEX_DETACHED_SEAL in the recheck-8 checkpoint binding N2/N5/N6/N7 + the canonicalizer SSOT hash + parent_checkpoint_id (recheck-7, pre-existing). The seal does not contain the recheck-8 checkpoint's own revision.
  3. Platform: assigns the recheck-8 checkpoint a revision after step 2.
  4. Optional follow-on diagnostic (post-seal audit only): that revision and the checkpoint content hash MAY be recorded as NON_AUTHORITY_DIAGNOSTIC; they are not sealed, not required to equal any pre-recorded value, and gate nothing.

Authoring-entry verification (no revision equality): (a) recompute detached_seal_sha256 over the live seal block (excl detached_seal_sha256 + signature) and require == recorded (detects any edit of the seal block — no revision needed); (b) require the seal's sealed_envelope_manifest_sha256 == the live-recomputed envelope_manifest_sha256; (c) require the anchor's codex_checkpoint_id == the manifest-bound approved_by_recheck_checkpoint; (d) require live canonicalizer_sha256 == sealed. Any inequality → ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH → fail closed → new Codex recheck (G-CODEX-DETACHED-SEAL-ANCHOR, G-NO-SELF-REVISION-ANCHOR). Explicitly accepted weaker guarantee: this detects any content edit of the seal block but, by design, no longer detects a hypothetical same-content re-write at a different revision; without a cryptographic/platform-immutable signature that residual is accepted and compensated by separation of duties (the checkpoint is Codex-authored, not T1/Directus-editable) + "any checkpoint change → fresh recheck." T1 pre-writing the sealed values would be self-fabricated authority; Codex populates them at recheck 8.

Seal timing (why content hashes seal at the Codex recheck, not now). A content hash of the approved corpus can only be computed over the corpus as approved, which finalizes at the approval event (now recheck 7, since recheck 6 did not seal). So T1 fixes the structural values now — active_corpus_membership_sha256 (computed above) and canonical_encoding_version — and the approving authority (Codex) computes and seals the per-document/aggregate content hashes and the manifest at recheck-7 PASS, recording them in the detached seal. The guards then verify live revision/content against that detached seal at authoring time.

Determinism proof (this pass). printf '%s' 'FIX7-ACTIVE-AUTHORITY-ENVELOPE-REHEARSAL-v1' | shasum -a 256 = f6b773f80308260d5668f8dcfa41a318e2e05375d3e1b59615da7b393be1e7b0; and the real active_corpus_membership_sha256 over the 10 full doc_ids under FIX7_ACTIVE_AUTHORITY_MEMBERSHIP_V1 = f2bda8effc7be19b54722828126b82d7d2d48bee5e5e5dc0c8f347ce210fe251, identical under shasum -a 256 and python hashlib — the canonical encoding is byte-reproducible, not prose.

<!-- ENVELOPE:EXCLUDE-BEGIN -->
# ACTIVE_AUTHORITY_APPROVAL_ENVELOPE - machine-readable. This is the live STAGED working copy; the
# SEALED copy of record is a CODEX_DETACHED_SEAL block authored by Codex in the recheck-8 checkpoint
# (approved_by_recheck_checkpoint), NOT a self-hosted block. Per-document/aggregate content hashes +
# the manifest are computed and sealed by Codex at recheck-8 PASS (see "Seal timing" above); membership
# + canonical_encoding_version are fixed now. This whole fenced block is EXCLUDED from doc 00's own
# normalized_active_content_sha256 (ENVELOPE:EXCLUDE region) to avoid self-reference; its integrity is
# bound by envelope_manifest_sha256 == the detached seal. Seal hash graph is ACYCLIC
# (recheck-6 blocker D): the manifest is a strict predecessor of the seal and binds NO checkpoint
# revision/content hash; the seal never hashes its own checkpoint. recheck-7 (Article 14): the
# single load-bearing canonical contract is the executable SSOT canonicalizer pinned below; the
# checkpoint own-revision is NON_AUTHORITY_DIAGNOSTIC (no read-back equality -> no revision self-reference).
ACTIVE_AUTHORITY_APPROVAL_ENVELOPE:
  canonical_encoding_version: FIX7-CANON-V1            # see "Canonical hash encoding (FIX7-CANON-V1)" below; a verifier MUST reject any other version
  seal_version: SEAL_AT_CODEX_RECHECK_8               # Codex sets the seal-format version at the seal event
  blueprint_id: fix7-existing-system-refactor-execution-blueprint-2026-06-08
  envelope_state: STAGED_PENDING_CODEX_RECHECK_8      # flips to SEALED at recheck-8 PASS
  approved_status: FIX7_REFACTOR_BLUEPRINT_T1_PATCHED_AFTER_CODEX_RECHECK_7_READY_FOR_CODEX_RECHECK_8
  approval_epoch: SEAL_AT_CODEX_RECHECK_8
  approved_by_role: SEAL_AT_CODEX_RECHECK_8           # = Codex (design/approval owner) at recheck-8
  approved_at_utc: SEAL_AT_CODEX_RECHECK_8
  parent_recheck_checkpoint_id: knowledge/dev/reports/architecture/checkpoint-codex-fix7-blueprint-recheck-7-byte-exact-seal-2026-06-09.md
  approved_by_recheck_checkpoint: SEAL_AT_CODEX_RECHECK_8   # the recheck-8 sealing checkpoint id (Codex sets at seal)
  next_required_recheck_on_change: true
  digest_algorithm: "SHA-256 lowercase hex (shasum -a 256 == python hashlib.sha256); every aggregate digest uses the FIX7-CANON-V1 canonical encoding below"
  full_document_hash_policy: "NON_AUTHORITY_DIAGNOSTIC for every member; the load-bearing per-document content authority is normalized_active_content_sha256 (doc 00 self-reference resolution, Option 1)"
  active_corpus_membership_sha256: f2bda8effc7be19b54722828126b82d7d2d48bee5e5e5dc0c8f347ce210fe251   # FIX7_ACTIVE_AUTHORITY_MEMBERSHIP_V1; full doc_ids, ascending, LF, trailing LF; computed NOW + reproducible (shasum==hashlib)
  active_corpus_sha256: SEAL_AT_CODEX_RECHECK_8       # FIX7_ACTIVE_AUTHORITY_CORPUS_V1 roll-up (ids + per-doc normalized hashes); seals at recheck-8
  marker_fence_registry_sha256: SEAL_AT_CODEX_RECHECK_8     # FIX7_MARKER_FENCE_REGISTRY_V1
  superseded_boundary_sha256: SEAL_AT_CODEX_RECHECK_8       # FIX7_SUPERSEDED_BOUNDARY_V1
  guard_set_revision: SEAL_AT_CODEX_RECHECK_8         # doc 06 KB revision at seal
  guard_set_sha256: SEAL_AT_CODEX_RECHECK_8           # FIX7_GUARD_SET_V1 == normalized_active_content_sha256(doc 06)
  canonicalizer_artifact_id: FIX7-CANON-V1-CANONICALIZER   # recheck-7 blocker B: the SINGLE executable canonical SSOT (Article 14); all other canonical descriptions are NON_AUTHORITY_EXPLANATION
  canonicalizer_path: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/canonicalizer-fix7-canon-v1-ssot.md   # pinned TOOL artifact, NOT an active_corpus membership member (membership stays f2bda8...fe251)
  canonicalizer_version: FIX7-CANON-V1
  canonicalizer_revision: SEAL_AT_CODEX_RECHECK_8    # platform revision of the canonicalizer artifact, sealed by Codex (pin; never the artifact's own future revision recorded inside itself)
  canonicalizer_sha256: SEAL_AT_CODEX_RECHECK_8      # SHA-256 over the canonicalizer artifact full MCP bytes (CRLF/CR->LF); artifact --selftest must exit 0 + reproduce f2bda8...fe251 (G-CANONICALIZER-SSOT-ONLY, G-NO-DUPLICATE-CANONICAL-AUTHORITY)
  envelope_manifest_sha256: SEAL_AT_CODEX_RECHECK_8   # FIX7_ACTIVE_AUTHORITY_ENVELOPE_MANIFEST_V1 over the MANIFEST_BOUND roster in fixed order EXCEPT itself + detached_seal_sha256 + seal-layer checkpoint revision/content (acyclic, recheck-6; canonicalizer SSOT pinned, recheck-7); seals at recheck-8
  active_corpus:
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/00-readme-first.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT_MINUS_EXCLUDE_AND_SUPERSEDED
      kb_revision: SELF_HOST_PIN_BY_EXCLUDE_REGION_HASH   # sole self-host: hosting the live envelope changes this doc's KB revision, so it is pinned by its exclude-region content hash, not revision
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/01-live-existing-system-inventory.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: 6
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/02-design-to-live-mapping.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: 33
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/03-gap-classification.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: 6
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/04-dependency-safe-construction-order.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: 39
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/05-rollback-blueprint.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: 24
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/06-test-guard-blueprint.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: SEAL_AT_CODEX_RECHECK_8
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/07-implementation-package-split.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: SEAL_AT_CODEX_RECHECK_8
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/08-hard-blocks-do-not-touch-list.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT
      kb_revision: 17
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
    - document_id: knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/12-final-verdict.md
      doc_status: ACTIVE_AUTHORITY
      active_section_id_or_range: WHOLE_DOCUMENT_MINUS_SUPERSEDED_FENCES
      kb_revision: SEAL_AT_CODEX_RECHECK_8
      normalized_active_content_sha256: SEAL_AT_CODEX_RECHECK_8
      full_document_sha256: NON_AUTHORITY_DIAGNOSTIC
  superseded_non_authority:
    - knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/09-xhigh-adversarial-review.md
    - knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/10-max-adversarial-review.md
    - knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/11-blueprint-revisions-from-reviews.md
    # fenced SUPERSEDED regions inside 00 + 12 are NOT whole-doc supersessions; they are pinned by
    # superseded_boundary_sha256 (FIX7_SUPERSEDED_BOUNDARY_V1; superseded_id + fence_range), not this list
  detached_seal_anchor:
    contract: "The SEALED copy of record is a CODEX_DETACHED_SEAL block authored by Codex in approved_by_recheck_checkpoint (see 'Codex detached seal anchor contract' below). Authoring authority is that detached seal, NOT this live STAGED working copy."
    codex_checkpoint_id: SEAL_AT_CODEX_RECHECK_8              # SEAL_LAYER; verified == approved_by_recheck_checkpoint (manifest-bound id)
    codex_checkpoint_kb_revision: NON_AUTHORITY_DIAGNOSTIC   # recheck-7 blocker A: revision is NOT load-bearing (NO read-back equality); diagnostic / post-seal audit only (G-NO-SELF-REVISION-ANCHOR)
    codex_checkpoint_content_sha256_excluding_seal: NON_AUTHORITY_DIAGNOSTIC   # recheck-6: input to NOTHING; replaces the old cyclic codex_checkpoint_content_sha256
    signature: signature_not_available_in_current_tooling   # SEAL_LAYER; compensating rule (recheck-7): content recompute of detached_seal_sha256 + MCP read-back of existence (NO revision equality) + Codex authorship + separation of duties (G-CODEX-DETACHED-SEAL-ANCHOR)
    detached_seal_sha256: SEAL_AT_CODEX_RECHECK_8           # SEAL_LAYER; N8 over seal fields EXCL detached_seal_sha256 + signature (acyclic)
    any_change_requires_new_recheck: true                   # MANIFEST_BOUND
  notes:
    - "Markers/registry/fences are necessary classification syntax but NOT sufficient authority (recheck-4); the SEALED envelope + the Codex detached seal are the authority (recheck-5)."
    - "Sole self-host = doc 00 (pinned by exclude-region content hash). The blueprint checkpoint is a DERIVED NON_AUTHORITY_INDEX (REPORT_ONLY): NOT a self-host, NOT a member, and no guard/package consumes it as authority (recheck-5 blocker D)."
    - "full_document_sha256 is NON_AUTHORITY_DIAGNOSTIC for every member; load-bearing content authority is normalized_active_content_sha256 (recheck-5 blocker C, Option 1) - no full-doc-vs-exclude contradiction."
    - "envelope_manifest_sha256 binds the COMPLETE authority-field roster (recheck-5 blocker B) and is anchored by the Codex detached seal; editing this STAGED block diverges the live manifest from the sealed anchor -> ACTIVE_AUTHORITY_ENVELOPE_MISMATCH. doc 00's own content hash excludes this block, so there is no self-reference loop."
    - "All SEAL_AT_CODEX_RECHECK_8 values are computed + sealed by Codex at the recheck-8 seal event; T1 pre-writing approved content hashes would be self-fabricated authority. Membership + canonical_encoding_version + canonicalizer SSOT identity are fixed now (structural, reproducible)."
    - "Non-runtime construction-document content-address; not a runtime surface/gate/#20-col/catalog-family/runtime-hash-contract (H01..H07 stay 7)."
    - "recheck-6 blocker A: every field value is REJECTED (not escaped) on TAB/LF/CR/NUL/backslash/reserved-token/grammar violation (G-CANONICAL-FIELD-REJECT)."
    - "recheck-6 blocker B: active scope/fence/section are derived by ONE deterministic extractor (normalize-first, 1-based lines, flat non-nesting, fail-closed statuses); every envelope key is in the closed key-classification schema (MANIFEST_BOUND / SEAL_LAYER_READBACK_PROTECTED / NON_AUTHORITY_DIAGNOSTIC / STRUCTURAL_CONTRACT_PROSE)."
    - "recheck-6 blocker C: every load-bearing digest has a closed record encoding (domain tag + fixed fields + grammar + sort + no-null/no-empty + full-path); no human interpretation (G-RECORD-ENCODING-CLOSED)."
    - "recheck-6 blocker D/E: seal hash graph is ACYCLIC (N1..N8 load-bearing; N9 checkpoint-content-excl-seal is NON_AUTHORITY_DIAGNOSTIC consumed by nothing); the manifest binds NO checkpoint revision/content hash and the seal never hashes its own checkpoint; the checkpoint is anchored by platform revision + MCP read-back + Codex authorship, with the stated limitation that a fully-privileged both-sides forger is not cryptographically prevented (separation of duties compensates) (G-SEAL-HASH-GRAPH-ACYCLIC, G-CODEX-DETACHED-SEAL-ANCHOR)."
    - "kb_revision values shown are the recheck-7-patched revisions; Codex re-pins the exact revision + content hash at the recheck-8 seal."
    - "recheck-7 blocker A: the checkpoint own-revision anchor is REMOVED from load-bearing authority (a platform revision exists only after the write -> recording it is a revision-layer self-reference). Authority = detached_seal_sha256 content recompute + MCP read-back of existence; revision is NON_AUTHORITY_DIAGNOSTIC. Finite ordered seal: stage -> Codex seals (no own-revision) -> platform assigns revision -> optional diagnostic record. (G-NO-SELF-REVISION-ANCHOR)."
    - "recheck-7 blocker B/C (Article 14): exactly ONE load-bearing canonical contract = the executable SSOT canonicalizer FIX7-CANON-V1-CANONICALIZER (canonicalizer_sha256). doc 00 canonical/extractor/record sections + all report docs are NON_AUTHORITY_EXPLANATION; a second load-bearing canonical contract, a package shipping a different canonicalizer hash, or a report example conflicting with the SSOT fails closed (G-CANONICALIZER-SSOT-ONLY, G-NO-DUPLICATE-CANONICAL-AUTHORITY)."
    - "recheck-7 blocker D: document_id must equal the exact MCP canonical id byte-for-byte; . / .. / empty segment / // / leading or trailing slash / backslash / %-encoding / homoglyph slash all rejected (G-DOCUMENT-ID-CANONICAL-MCP)."
    - "recheck-7 blocker E: marker_kind is a closed enum and marker_literal must match the extractor grammar for that exact kind; kind/literal mismatch, unknown kind, or disallowed literal fails closed (G-MARKER-KIND-LITERAL-CONSISTENCY)."
<!-- ENVELOPE:EXCLUDE-END -->

Fail-closed rule. Any mismatch — in document revision, active content hash (canonical), marker/fence registry hash, superseded-boundary hash, guard-set hash/revision, active-section identity, corpus membership hash, canonical_encoding_version, the envelope-manifest hash, the manifest authority-field roster (a missing/extra/unknown authority field), or doc status → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH; and any drift of the Codex detached seal (absent / unsealed / live manifest != sealed manifest / live detached_seal_sha256 recompute != recorded / live canonicalizer_sha256 != sealed) → ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH. Recheck-7 adds (Constitution Article 14): SELF_REVISION_ANCHOR_REJECTED (any attempt to make a checkpoint's own post-write revision load-bearing), CANONICALIZER_SSOT_MISMATCH (live canonicalizer id/version/hash != the single pinned SSOT), DUPLICATE_CANONICAL_AUTHORITY (a second load-bearing canonical/extractor/record contract appears, or a report example conflicts with the SSOT), DOCUMENT_ID_ALIAS_REJECTED, DOCUMENT_ID_NOT_MCP_CANONICAL, DOCUMENT_ID_SCOPE_MISMATCH, MARKER_KIND_UNKNOWN, MARKER_LITERAL_MISMATCH, MARKER_LITERAL_NOT_ALLOWED, MARKER_KIND_LITERAL_INCONSISTENT. Recheck-6 adds byte-level fail-closed statuses that must all STOP authoring: CANONICAL_FIELD_RESERVED_TOKEN_REJECTED, CANONICAL_FIELD_VALUE_GRAMMAR_REJECTED, CANONICAL_FIELD_NULL_REJECTED, CANONICAL_FIELD_EMPTY_REJECTED (field rejection); ACTIVE_SCOPE_MARKER_MISSING, ACTIVE_SCOPE_MARKER_DUPLICATE, FENCE_UNBALANCED, FENCE_NESTED_UNSUPPORTED, ACTIVE_SUPERSEDED_OVERLAP, SECTION_ID_MISMATCH, SECTION_RANGE_MISMATCH, EXCLUDE_REGION_UNBALANCED, MARKER_REGISTRY_MISMATCH (extractor); and any seal-hash-graph back-edge (manifest binding a checkpoint hash, or the seal hashing its own checkpoint) → SEAL_HASH_GRAPH_CYCLE. Either family → implementation-authoring planning is BLOCKED until a fresh Codex recheck re-seals the envelope and the detached seal. After Codex PASS, any change to ACTIVE docs/sections/markers/fences/registry/guard-set/ canonical-encoding/manifest/detached-seal invalidates approval; the correct next step is a Codex recheck, not continued authoring (G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED, G-CODEX-DETACHED-SEAL-ANCHOR, G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE, G-CANONICAL-ENCODING-CONTRACT, G-CANONICAL-FIELD-REJECT, G-ACTIVE-SCOPE-EXTRACTOR, G-RECORD-ENCODING-CLOSED, G-SEAL-HASH-GRAPH-ACYCLIC, G-NO-SELF-REVISION-ANCHOR, G-CANONICALIZER-SSOT-ONLY, G-NO-DUPLICATE-CANONICAL-AUTHORITY, G-DOCUMENT-ID-CANONICAL-MCP, G-MARKER-KIND-LITERAL-CONSISTENCY).

Self-verdict (see doc 12)

Current (ACTIVE_AUTHORITY): FIX7_REFACTOR_BLUEPRINT_T1_PATCHED_AFTER_CODEX_RECHECK_7_READY_FOR_CODEX_RECHECK_8 (2026-06-09). The legacy-disposition model is removed (Option Beta); the set model is split into the typed U_legacy_object / U_effective_privilege_principal / U_entry_vector universes (doc 02 §H); the active/superseded boundary is content-addressed by the §Active-authority approval envelope. Recheck-7 (Constitution Article 14) makes the canonical contract a single executable SSOTFIX7-CANON-V1-CANONICALIZER (pinned by canonicalizer_sha256); this doc's encoding/extractor/record sections become NON_AUTHORITY_EXPLANATION of it (no duplicate authority); the checkpoint own-revision anchor is removed (revision is diagnostic-only, no self-reference); document_id is the exact MCP canonical id with all aliases rejected; and marker_kind↔marker_literal is one consistent pair. The recheck-6 byte-exact rejection policy, deterministic extractor, closed record/key schemas, and acyclic seal hash graph remain. 63 TEST/VERIFICATION guards (not readiness gates); invariants 27/11/14/7 preserved; all hard blocks intact. Next gate = Codex recheck 8; implementation is NOT approved.

<!-- SUPERSEDED_NON_AUTHORITY BEGIN: pre-Option-Beta gate-chain history; audit trail only; not current authority -->

Superseded history (audit trail — not current authority). An earlier self-verdict here read FIX7_REFACTOR_BLUEPRINT_T1_PATCHED_AFTER_CODEX_FAIL_READY_FOR_CODEX_RECHECK. Gate chain: authored → independent XHigh → independent Max → ..._MAX_REVIEWED_AND_REVISED_READY_FOR_CODEX_CRITICAL_REVIEW → Codex critical review FAILED it (7 blockers; A-K matrix) → T1 patched all 7 in-blueprint. That pass used a now-removed disposition model (a sealed legacy-disposition set in #20; five dispositions; stub only STUB_FAIL_CLOSED; G-NOLEGACY split PRE/POST; atomic deactivation-first rollback + G-NOMIXED-AUTHORITY; complete effective-privilege ACL snapshot; pinned writer-gateway identity; operator_authorization separated from the BLOCKED qt001_backfill_permit; guards 30 → 35). The disposition constructs were subsequently REMOVED by Option Beta and the sets separated by recheck-3; this paragraph is retained only as history of how earlier rounds were fixed. See doc 12 for the full superseded-pass record.

<!-- SUPERSEDED_NON_AUTHORITY END -->
Back to Knowledge Hub knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/00-readme-first.md