KB-3432 rev 70

FIX7 Refactor Blueprint - Test / Guard Blueprint

76 min read Revision 70

06 - Test / Guard Blueprint

<!-- DOC_STATUS: ACTIVE_AUTHORITY --> <!-- AUTHORITY_BOUNDARY: registry in 00-readme-first.md §Active-authority boundary; these are the load-bearing verification guards consumed by implementation authoring -->

CODEX RECHECK-4 PATCH (2026-06-09) — immutable approval-envelope binding for the ACTIVE_AUTHORITY corpus. Codex recheck 4 accepted set separation, principal/entry-vector separation, uniform-end-state scope, PG-native, and 27/11/14/7, but found the ACTIVE_AUTHORITY corpus is classified only by mutable KB markers/registry/fences — a mutable authoring-authority denominator (disguised hardcode). FOUR verification guards are ADDED, total 47 → 51: G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE (a sealed content-addressed envelope exists and covers exactly the ACTIVE corpus), G-ACTIVE-AUTHORITY-HASH-MATCH (live normalized SHA-256 of every ACTIVE doc/section + registry + guard-set + membership == the sealed envelope), G-ACTIVE-AUTHORITY-REVISION-MATCH (live KB revision == sealed), G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED (any drift → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH → block authoring until a fresh Codex recheck). G-ACTIVE-AUTHORITY-SCOPE, G-NO-SUPERSEDED-CONSUMPTION, and G-LEGACY-NO-DISPOSITION-AUTHORITY are re-bound to the sealed envelope (marker syntax alone is necessary but NOT sufficient). Guard-quality rule 9 (content-addressed authoring authority) added. The envelope is a non-runtime construction-document content-address — NOT a runtime authority surface, readiness gate, #20 column, catalog family, or one of the 7 H01..H07 runtime hash contracts; 27/11/14/7 unchanged.

CODEX RECHECK-5 PATCH (2026-06-09) — canonical envelope seal. Codex recheck 5 accepted the envelope direction, guard rebinding, and invariants/boundary, but did not seal: the aggregate-hash canonicalization was incomplete, envelope_manifest_sha256 omitted authority fields, doc 00's full_document_sha256 was self-referential, the blueprint checkpoint's ACTIVE/self-host status was contradictory, and the Codex checkpoint "immutable anchor" lacked a revision/hash/signature/detached seal. T1 patched all of these (doc 00 §Canonical hash encoding FIX7-CANON-V1 + manifest roster + Option-1 self-reference resolution + Codex detached seal anchor). THREE guards are ADDED, 51 → 54: G-CANONICAL-ENCODING-CONTRACT (byte-exact domain-separated ordered encoding; no prose/unordered hash), G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE (manifest binds the complete authority-field roster; unknown/missing field fails closed), G-CODEX-DETACHED-SEAL-ANCHOR (immutable detached seal; live manifest == sealed manifest; checkpoint pinned by revision+SHA-256+MCP read-back). The four recheck-4 envelope guards + G-NO-SUPERSEDED-CONSUMPTION + G-LEGACY-NO-DISPOSITION-AUTHORITY are re-bound to the canonical encoding + the detached seal. Guard-quality rule 10 added. Still a non-runtime construction-document content-address; 27/11/14/7 unchanged (no 8th runtime hash contract). See doc 00 §Active-authority approval envelope.

CODEX RECHECK-7 PATCH (2026-06-09) — Constitution Article 14: executable SSOT + non-self-referential seal. Codex recheck 7 accepted the deterministic extractor and the N1–N9 content-hash DAG, but held approval on five Article-14 / NT14 defects. T1 patched all five in-blueprint. FIVE verification guards are ADDED, 58 → 63: G-NO-SELF-REVISION-ANCHOR (no checkpoint's own post-write revision is load-bearing — revision diagnostic only; finite ordered seal), G-CANONICALIZER-SSOT-ONLY (exactly one executable canonicalizer artifact FIX7-CANON-V1-CANONICALIZER, pinned by canonicalizer_sha256, --selftest exits 0 + reproduces f2bda8…fe251), G-NO-DUPLICATE-CANONICAL-AUTHORITY (= Codex G-CANONICAL-CONTRACT-SSOT-NO-DUPLICATE; one load-bearing canonical contract, all else NON_AUTHORITY_EXPLANATION), G-DOCUMENT-ID-CANONICAL-MCP (exact MCP id, all path aliases rejected), G-MARKER-KIND-LITERAL-CONSISTENCY (closed kind enum + literal grammar consistency). Guard-quality rule 12 added. doc 00's canonical/extractor/record sections are demoted to NON_AUTHORITY_EXPLANATION of the SSOT. Still a non-runtime construction-document content-address; 27/11/14/7 unchanged (no 8th runtime hash contract). Seal event → recheck 8. See the canonicalizer SSOT artifact + doc 00 §Canonical hash encoding banner.

CODEX RECHECK-6 PATCH (2026-06-09) — byte-exact canonicalization + acyclic seal graph. Codex recheck 6 accepted the full-path membership hash, the doc 00 self-reference resolution, the blueprint-checkpoint NON_AUTHORITY classification, the invariants/boundary, and PG-first/typed-set separation, but did not seal: FIX7-CANON-V1 still lacked byte-exact escaping/rejection and an exact active-scope/fence/section extractor, the manifest/seal record encodings still needed human interpretation, and the detached seal was circular (the envelope manifest bound the Codex checkpoint content hash while that checkpoint contained the seal binding the manifest; seal_report_checkpoint_content_sha256 hashed the checkpoint that hosts it). T1 patched all four in-blueprint (doc 00: REJECT-not-escape field policy + deterministic extractor + closed record-encoding schema + closed envelope key-classification schema + acyclic seal hash graph N1..N9; the cyclic codex_checkpoint_content_sha256 is removed and the checkpoint is anchored out-of-band by platform revision + MCP read-back). FOUR verification guards are ADDED, 54 → 58: G-CANONICAL-FIELD-REJECT, G-ACTIVE-SCOPE-EXTRACTOR, G-RECORD-ENCODING-CLOSED, G-SEAL-HASH-GRAPH-ACYCLIC. Guard-quality rule 11 added. Still a non-runtime construction-document content-address; 27/11/14/7 unchanged (no 8th runtime hash contract; H01..H07 stay 7). The seal event moves to recheck 7 (recheck 6 did not seal); SEAL_AT_CODEX_RECHECK_6 placeholders become SEAL_AT_CODEX_RECHECK_7. See doc 00 §Canonical hash encoding (FIX7-CANON-V1) + §Active-scope/fence/section extractor + §Seal hash dependency graph.

CODEX RECHECK-3 PATCH (2026-06-09) — typed set separation + active-authority guard scope. Five verification guards are ADDED, taking the total 42 → 47: (set separation, doc 02 §H) G-U-LEGACY-OBJECT-ONLY (every U_legacy_object member is a PG object identity; no principal/entry-vector member), G-PRINCIPAL-SET-SEPARATE (effective privilege is the object × principal tuple join reconciled to #21, never object membership), G-ENTRY-VECTOR-SEPARATE (entry-vectors are a fail-closed bypass-coverage relation mapped to objects, never object members); (active-authority boundary, doc 00) G-ACTIVE-AUTHORITY-SCOPE (the ACTIVE_AUTHORITY vs SUPERSEDED_NON_AUTHORITY boundary is present, machine-readable, unambiguous, not Directus-editable) and G-NO-SUPERSEDED-CONSUMPTION (no package/guard/seal/order/authoring input consumes a fenced superseded section). G-LEGACY-TARGET-CLOSED-DENOMINATOR is re-scoped to the object-shape denominator only; G-LEGACY-NO-DISPOSITION-AUTHORITY is re-scoped to ACTIVE_AUTHORITY load-bearing sections (fenced history is reported, never failed or consumed). Guard-quality rules 7 (set-type separation) and 8 (active-authority scope) added. These remain TEST/VERIFICATION guards, NOT readiness gates; 27/11/14/7 unchanged (the boundary is document metadata, not a DB surface).

OPTION-BETA PATCH (2026-06-08). Codex (design owner) approved Option Beta for the legacy-disposition blocker. Two verification guards are ADDED — G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE (the amendment's G-LEGACY-UNIFORM-NEUTRALIZATION: every U_legacy member has owner=qt001_cp_owner, unchanged definition hash, and effective privileges == exact sealed #21) and G-LEGACY-NO-DISPOSITION-AUTHORITY (no enum, LEGACY_* row, disposition field/rule/payload, label-driven branch, or STUB/body path exists) — taking the test/verification guard total 40 → 42. The previously fail-closed G-LEGACY-TARGET-SEALED and the disposition aspect of G-LEGACY-TARGET-CLOSED-DENOMINATOR are now fully operational because the amendment landed: they bind to closure(#11, roots=#20 protected_target rows) with no LEGACY_* row, no disposition, and no DO_NOT_TOUCH subtraction (boundary collisions fail closed). G-NOMIXED-AUTHORITY is forward-only (reads the derived current-active route). These remain TEST/VERIFICATION guards, NOT readiness gates; the 14/7/27/11 invariants are unchanged.

Every guard is PG-native (pg_constraint, pg_index, pg_depend, pg_proc, information_schema, recomputed hashes, both-EXCEPT set comparisons) - never a regex name list or a literal PASS row. "required for PASS" guards must be green before the step they gate may be sealed/activated/cut over.

guard input expected output failure meaning when run required for PASS
G-NOHARDCODE pg_get_functiondef/viewdef of all qt001_cp writer/adapter fns no operational numeric/string literal drives authority; all thresholds resolve to sealed manifest rows direct hardcode S11, S19 YES
G-NODISGUISE adapter/readback sources vs sealed #05/#06 rows every threshold/interval/capacity dereferences a sealed row, not a CASE/CHECK literal disguised hardcode S10, S11, S19 YES
G-PGNATIVE guard implementations + every operational target/authority set all guards read PG catalog/data; no name pattern, owner filter, prose count, disposition enum, or descriptive label is the binding authority for any operational set (neutralize/retain/cutover/repoint) - final authority is sealed manifest rows + catalog ownership/ACL + pg_depend closure + recomputed hash; name/owner scans are diagnostic candidates only PG-native violation / name-pattern or label binding authority (Codex CHECK_I) S00, S11, S13, S15, S19 YES
G-AUTH-27 child tables vs envelope, both-EXCEPT exactly 27 authority surfaces; count and set exact surface count drift S11, S19 YES
G-RUNTIME-NONAUTH runtime-evidence tables vs #20 typed rows exactly 11; none classed as authority runtime/authority confusion S07, S11, S19 YES
G-GATES-14 readiness_gate_manifest rows exactly 14 sealed gate rows; 0 new gate schema gate count drift S10, S19 YES
G-HASH-7 hash_component_manifest contracts exactly 7 (H01..H07); 0 new top-level contracts hash contract drift S10, S19 YES
G-HASHDET recompute H01/H02/H04/H05 over fixtures (CP-06 encoding: hex, COLLATE C, UTC, trim_scale, JSON-null, total order) byte-identical digests across two independent recomputes hash non-determinism (the FIX..FIX6 divergence loop) S10, S11, S19 YES
G-H04-SCOPE H04_SCOPE_V1 8-key order vs signoff_binding cols + UNIQUE 8 NOT NULL cols, closed set, evidence deref to evidence_registry.artifact_sha256 scope hash under-binding S10, S11 YES
G-EXACTSET-20 #20 expected vs realized pg_constraint/pg_index, both EXCEPT directions both EXCEPT empty; dropped deferred FK -> OBJECT_AUTHORITY_IMMUTABLE; any extra index fails (no BENIGN exemption) silent integrity hole S08, S11, S19 YES
G-CATALOG-SEAL catalog root bootstrap + 3 families both-EXCEPT sealed, owner-only immutable; family coverage exact FK-authority root tamper S02, S19 YES
G-DIRECTUS-READ S00-captured existing Directus SELECT set (MX-1) vs #21 rows #21 == captured existing SELECT set; SELECT-only base-table reads preserved; no view migration; stale/unknown read path blocks Directus read regression / read-path break S00, S09, S16, S19 YES
G-OWNER-CUTOVER post-cutover ownership + full ACL (incl. pg_attribute.attacl column ACL, sequence ACL, nspacl, pg_default_acl) + effective privilege via pg_auth_members role expansion vs #20/#21 expected and vs the verified S14 pre-cutover snapshot (doc 05 invariant 3, captured before the S15.1 owner transfer) all control objects owned by qt001_cp_owner; directus/PUBLIC authority reconciled to exact #21 (proven by effective privilege over non-superuser, non-owner roles, not only direct ACL rows); Directus SELECT intact; snapshot present + hash-bound + both-direction effective-privilege match. Superuser workflow_admin dispositioned (excluded from the revoked-to-zero claim; cannot be ACL-zeroed) ownership/ACL drift; column-ACL or role-membership leak; false readiness un-block; absent/unverified S14 snapshot S16, S19 YES
G-ITEMPAYLOAD adapter dependency edges (#11) vs #24 allowed input set, both-EXCEPT code_catalog_item.item_payload never operationally read; observed edges == sealed edges operational payload read S15, S19 YES
G-CATFAMILY 3 catalog families exact-set both-EXCEPT full coverage; no extra/missing family member catalog-family gap S02, S11 YES
G-SAMEHUMAN signoff_binding UNIQUE + #08 separation rows reviewer/binder human identities must differ per slot scope; slot-scoped not blanket same-human bypass S11, S19 YES
G-EVIDENCE-FK evidence/identity/principal FK integrity (RESTRICT/RESTRICT NOT DEFERRABLE) no orphan; fake/missing evidence rejected (ON DELETE RESTRICT) evidence forgery S08, S19 YES
G-RETENTION-SEAL #05 retention/archive rows; archive_required target check archive target present, immutable, versioned; data-driven not CHECK literal retention authority gap S10, S19 YES
G-EPOCH-TOCTOU activation control_epoch read vs bound epoch epoch read and bound atomically; no caller-supplied lifecycle TOCTOU activation S15 (activation is at S15.4), S19 YES
G-LEVELB-NOSQL Level-B packet execution path no manual SQL path; only sealed level_b_packet_execution via owner entrypoint manual SQL bypass S15, S19 YES
G-REPOINT-SRC live writer/gateway source_sha256 vs #27 old/new bound source matches live before/after; rollback re-point binding pinned (no legacy body artifact) unpinned repoint S13, S15 YES
G-NOLEGACY-PRE dependency_manifest #11 closure from the new entrypoints + the sealed U_legacy set (#20 roots + #11 closure) (structural/closure proof, does NOT require EXECUTE already revoked) legacy_reached = 0 from the new entrypoints (recursive structural closure, not a name list); the sealed set is complete (0 UNKNOWN_REQUIRES_REVIEW; both-EXCEPT vs the closed denominator empty; no boundary collision unresolved); the single uniform Option-Beta end-state is assigned to every member (no disposition); rollback artifacts staged (the captured S14 owner/ACL snapshot - no body artifact). Non-vacuity: the closure must prove its roots (the new entrypoints) exist and traversal reached a non-empty object set, so legacy_reached=0 cannot pass via a mis-seeded/empty closure repoint would leave a legacy object reachable, or be authored against an incomplete/unsealed set, OR a vacuous false-green S13 (PKG-D), S15 in-transaction precondition (PKG-F) YES
G-NOLEGACY-POST pg_proc/proacl/relacl effective privilege (role-membership expanded via pg_auth_members) over the sealed U_legacy set, after the S15.1 ownership transfer + S15.2 privilege reconcile non-superuser, non-owner effective EXECUTE/DML = 0 over the entire sealed set (PUBLIC / directus / any role != qt001_cp_owner), i.e. the realized privileges == the exact sealed #21 rows (which grant no EXECUTE/DML to any legacy member). directus is now a non-owner (ownership moved to qt001_cp_owner at S15.1) AND non-superuser (rolsuper=false), so its effective EXECUTE is genuinely 0 - this is reachable ONLY because ownership moved first (PostgreSQL owner-implicit-privilege; Codex recheck BLOCKER A). qt001_cp_owner owner-implicit privilege is held by an unreachable NOLOGIN principal. Superuser disposition: the cluster superuser workflow_admin (rolsuper/rolbypassrls) inherently bypasses ACL and is EXCLUDED from the =0 claim, recorded as an accepted out-of-band property (it cannot be made privilege-zero by ACL). Every member's body/definition is unchanged (Option Beta - no stub). Non-vacuity: the sealed set is non-empty and the check ran over all of it legacy bypass (the repeated FIX..FIX6 PUBLIC-EXECUTE failure) survived the cutover, OR an owner still holds implicit EXECUTE, OR any member's effective privileges != exact #21 S15 post-proof (PKG-F), S19 YES
G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE every member of the sealed U_legacy set: pg_class.relowner/pg_proc.proowner + pg_get_functiondef/pg_get_viewdef definition hash + effective privileges (proacl/relacl/pg_attribute.attacl via pg_auth_members) vs the closed-world sealed #21 rows, both-EXCEPT (the amendment's G-LEGACY-UNIFORM-NEUTRALIZATION) EVERY member has (a) owner == qt001_cp_owner; (b) definition hash UNCHANGED from the captured baseline (no body mutation); (c) effective privileges over non-superuser non-owner roles == EXACTLY the sealed #21 rows (realized − #21 = ∅ AND #21 − realized = ∅). No member is exempt by class/type/name/owner/label; unsupported class / boundary collision / incomplete #21 coverage / analyzer uncertainty / privilege mismatch FAILS CLOSED. Non-vacuity: the set is non-empty and #21 is closed-world (expected-count/hash bound) a member missed the uniform end-state, a body changed, a privilege diverged from #21, or absence was treated as authority from an incomplete #21 (Option Beta uniform-end-state violation) S09, S13, S15, S17, S19 YES
G-LEGACY-NO-DISPOSITION-AUTHORITY the ACTIVE_AUTHORITY load-bearing docs/sections as fixed by the SEALED approval envelope (exact reviewed revisions/hashes; depends on G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE / -HASH-MATCH / -REVISION-MATCH / G-ACTIVE-AUTHORITY-SCOPE) + sealed manifests + guard/package/order/rollback definitions. Fenced SUPERSEDED_NON_AUTHORITY history (as listed in the envelope) is scanned separately and reported, never failed or consumed over ACTIVE_AUTHORITY only: NO five-value disposition enum, NO LEGACY_* object_type row in #20, NO disposition/root_kind column, NO legacy_disposition catalog family, NO computed-disposition classifier/truth-table/CASE branch, NO STUB_FAIL_CLOSED/body-mutation/body-restore path, NO DO_NOT_TOUCH subtraction from U_legacy_object, and NO policy branch by relkind/prokind/name/owner/pattern/label. relkind/prokind appear ONLY to select PG syntax. Former labels appear ONLY as non-authority English in explanatory text/logs (or inside fenced superseded history) — never as manifest authority, rule I/O, guard decisions, package branches, hash members, or SQL predicates. Old terms inside a fenced SUPERSEDED_NON_AUTHORITY block are reported as history, NOT a failure a removed disposition construct re-appeared as load-bearing authority in ACTIVE_AUTHORITY, OR a future package/guard/seal consumed a SUPERSEDED_NON_AUTHORITY instruction, OR the approval envelope is absent/unsealed, OR any active doc/section revision/hash mismatches the sealed envelope (a mutable-marker scope cannot bypass this guard post-approval), OR relkind/prokind/a label selected policy rather than syntax (Option Beta removal violation) S00, S09, S13, S15, S17, S19, authoring-entry gate YES
G-U-LEGACY-OBJECT-ONLY every member of the sealed U_legacy_object set vs PG object catalogs (pg_class.oid::regclass / pg_proc.oid::regprocedure) + the object both-EXCEPT denominator (doc 02 §H.4.A) every member resolves to a live PG object identity (regclass or regprocedure); relkind/prokind is a syntax discriminator only; no member is a role/principal (pg_roles/PUBLIC) and no member is an entry-vector (pg_trigger/pg_event_trigger/scheduler/DOT); the both-EXCEPT object comparison is object-shape on both sides. Non-vacuity: the object set is non-empty a principal or entry-vector identity was injected into the object set, a member does not resolve to a live PG object, or the both-EXCEPT mixed identity types (recheck-3 type error) S00, S09, S13, S15, S17, S19 YES
G-PRINCIPAL-SET-SEPARATE U_effective_privilege_principal (PUBLIC + login/member roles via pg_auth_members) and the privilege check = the join U_legacy_object × U_effective_privilege_principal reconciled to sealed #21 (doc 02 §H.4.B) the principal universe is a role-only set; the controlled owner qt001_cp_owner is excluded from removable-privilege equality (G-OWNER-UNREACHABLE); superusers are dispositioned separately (G-SUPERUSER-BREAKGLASS); the effective-privilege check is run as the object × principal tuple join (object, principal, priv-kind, grant-option/column-scope) both-EXCEPT vs #21 — never as object-set membership; no principal is a member of U_legacy_object. Non-vacuity: the principal set includes PUBLIC + the live roles and the join is non-empty where #21 has rows a principal appears in the object set, the privilege check was evaluated as membership rather than the tuple join, or a removable role was omitted from the principal universe S09, S15, S16, S19 YES
G-ENTRY-VECTOR-SEPARATE U_entry_vector (pg_trigger / pg_event_trigger / scheduler registry / frozen DOT / external entrypoint) vs the coverage relation to U_legacy_object (doc 02 §H.4.C) every entry-vector either (a) targets a U_legacy_object member (so object neutralization covers it) or (b) is independently blocked (frozen DOT via G-DOT-FROZEN; disabled/unauthorized scheduler; operator-gated entrypoint); an uncovered vector FAILS CLOSED; no entry-vector is a member of U_legacy_object and none is subject to owner/body/#21 object proof. Live 2026-06-08: 0 trigger/event-trigger bypass vector; DOTs frozen; no scheduler enabled. Non-vacuity: the relation enumerates the actual catalog vectors, not an empty scan an entry-vector reaches protected write-state through neither a neutralized object nor an independent block, a vector was placed in the object set, or a vector was subjected to owner/body/#21 proof S00, S13, S15, S19 YES
G-ACTIVE-AUTHORITY-SCOPE the doc-status markers (DOC_STATUS: ACTIVE_AUTHORITY / SUPERSEDED_NON_AUTHORITY) + the fenced SUPERSEDED_NON_AUTHORITY BEGIN/END blocks + the doc 00 §Active-authority boundary registry + the SEALED ACTIVE_AUTHORITY_APPROVAL_ENVELOPE every load-bearing blueprint doc/section carries exactly one machine-readable DOC_STATUS marker; every retained historical block is inside a matched SUPERSEDED_NON_AUTHORITY BEGIN/END fence; the doc 00 registry enumerates the ACTIVE_AUTHORITY set and the SUPERSEDED_NON_AUTHORITY set with no overlap and no unclassified load-bearing section; the boundary lives in the blueprint KB document structure (NOT a Directus collection, NOT a #20 row, NOT a runtime table) so it is not Directus-editable; AND for authoring the classification is bound to the sealed envelope's exact reviewed revisions/hashes (G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE / -HASH-MATCH / -REVISION-MATCH) — marker/registry/fence syntax is necessary but NOT sufficient (recheck-4: markers are mutable; the sealed envelope is the authority). Non-vacuity: the registry is non-empty and every doc 00..12 is classified the boundary is absent, ambiguous (a section both/neither), an unmatched/mis-nested fence, expressed as a Directus-editable artifact, OR the active classification is taken from mutable markers rather than pinned to the sealed envelope (mutable-marker authority, recheck-4) S00, S09, S19, authoring-entry gate YES
G-NO-SUPERSEDED-CONSUMPTION every implementation-authoring / package / guard / seal / order / rollback input reference vs the SUPERSEDED_NON_AUTHORITY set as fixed by the SEALED approval envelope (the doc 00 registry + the canonical superseded_boundary_sha256 (FIX7-CANON-V1) pinned by the SEALED envelope and the Codex detached seal; depends on G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE + G-ACTIVE-AUTHORITY-SCOPE + G-CODEX-DETACHED-SEAL-ANCHOR) no package (PKG-A..I), guard, seal, construction-order step, or rollback step reads, cites, or derives authority from any SUPERSEDED_NON_AUTHORITY doc/section; future implementation authoring consumes ONLY the envelope-pinned ACTIVE_AUTHORITY load-bearing sections; superseded text is audit trail only a package/guard/seal/order/authoring step references or consumes a fenced superseded instruction (e.g. an old disposition/STUB step) as if current, OR the active/superseded partition is taken from mutable markers instead of the sealed envelope S13, S15, S17, S19, PKG inputs, authoring-entry gate YES
G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE the ACTIVE_AUTHORITY_APPROVAL_ENVELOPE (doc 00 §Active-authority approval envelope) + its Codex detached seal anchor a SEALED envelope exists and is well-formed (all required fields present: canonical_encoding_version=FIX7-CANON-V1, seal_version, blueprint_id, envelope_state, approved_status, approval_epoch, approved_by_role, approved_at_utc, parent_recheck_checkpoint_id, approved_by_recheck_checkpoint, next_required_recheck_on_change=true, digest_algorithm, full_document_hash_policy, active_corpus_membership_sha256, active_corpus_sha256, marker_fence_registry_sha256, superseded_boundary_sha256, guard_set_revision, guard_set_sha256, envelope_manifest_sha256, detached_seal_anchor{...}, per-ACTIVE-doc {document_id (full canonical path), doc_status, active_section_id_or_range, kb_revision, normalized_active_content_sha256, full_document_sha256=NON_AUTHORITY_DIAGNOSTIC}); it is anchored to the Codex detached seal (Codex-authored in the recheck checkpoint, not T1/Directus-editable post-approval); and it covers EXACTLY the ACTIVE_AUTHORITY corpus (membership both-EXCEPT vs the doc 00 registry). Non-vacuity: the corpus is non-empty and envelope_state == SEALED at authoring time envelope absent / still STAGED (unsealed) at authoring time / malformed / missing-or-extra ACTIVE doc vs the registry / canonical_encoding_version != FIX7-CANON-V1 / not anchored to a Codex detached seal → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH, block authoring authoring-entry gate, PKG-A..I input, S19 YES
G-ACTIVE-AUTHORITY-HASH-MATCH for every ACTIVE doc/section: the live normalized content SHA-256 (recomputed per the Canonical hash encoding FIX7-CANON-V1, not loose YAML/prose) vs the sealed value; plus active_corpus_membership_sha256, active_corpus_sha256, marker_fence_registry_sha256, superseded_boundary_sha256, guard_set_sha256, envelope_manifest_sha256 live-recomputed (canonical) vs sealed; and the live envelope_manifest_sha256 vs the Codex detached seal's sealed_envelope_manifest_sha256 every live canonical recompute == the sealed value AND the live manifest == the detached-seal manifest (content / membership / corpus / marker / fence / registry / guard-set / manifest all match). Non-vacuity: hashes are recomputed over present, non-empty content via the canonical encoding at check time, never trusted from a cache or a prose claim any canonical hash differs from the sealed value, OR the live manifest != the detached-seal manifest → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH; block authoring until a fresh Codex recheck authoring-entry gate, PKG-A..I input, S19 YES
G-ACTIVE-AUTHORITY-REVISION-MATCH for every ACTIVE doc: the live KB revision (canonical revision_repr: base-10 ASCII, no leading zeros) vs the sealed kb_revision (the sole self-host — doc 00 — uses SELF_HOST_PIN_BY_EXCLUDE_REGION_HASH and is pinned by its exclude-region content hash, not revision, since hosting the envelope changes its revision; the blueprint checkpoint is NON_AUTHORITY and not checked here) every live KB revision == the sealed envelope revision (a KB edit increments the revision, so any post-approval edit is caught even before hashing). Non-vacuity: every ACTIVE doc resolves to a live KB revision any ACTIVE doc's live revision != the sealed revision → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH; block authoring authoring-entry gate, PKG-A..I input, S19 YES
G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED any detected delta in content / DOC_STATUS marker / SUPERSEDED_NON_AUTHORITY fence / doc 00 registry / guard set / active-section identity-or-range / corpus membership / canonical_encoding_version / envelope-manifest / manifest authority-field roster / Codex detached seal vs the sealed envelope+seal ANY such delta produces ACTIVE_AUTHORITY_ENVELOPE_MISMATCH (or ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH) and blocks implementation-authoring planning until a NEW Codex recheck — on mismatch the correct next step is Codex recheck, NOT "continue authoring". Non-vacuity: the check runs against a present SEALED envelope + present detached seal (an absent/unsealed envelope or absent detached seal is itself a fail-closed mismatch) a change to any active doc/section/marker/fence/registry/guard-set/section-identity/canonical-encoding/manifest/detached-seal is treated as benign and authoring proceeds (silent post-approval drift) authoring-entry gate, PKG-A..I input, each authoring step, S19 YES
G-CANONICAL-ENCODING-CONTRACT the envelope canonical_encoding_version and every aggregate-hash definition (doc 00 §Canonical hash encoding FIX7-CANON-V1) canonical_encoding_version == FIX7-CANON-V1; every aggregate hash (membership, corpus, marker/fence registry, superseded boundary, guard-set, per-doc normalized content, manifest, detached seal) is computed by the byte-exact domain-separated, fixed-field-order, sorted, LF-normalized, trailing-LF encoding — never by unordered map/object serialization and never described only in prose. Non-vacuity: each hash names a domain tag + record type + field order + sort key, and the verifier reproduces it (shasum -a 256 == hashlib) canonical_encoding_version absent or != FIX7-CANON-V1; any aggregate hash defined only in prose or computed from unordered serialization, missing a domain tag/field order/sort key, or non-reproducible → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH, block authoring authoring-entry gate, PKG-A..I input, S19 YES
G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE envelope_manifest_sha256 input vs the COMPLETE authority-field roster (doc 00 §Envelope manifest authority-field roster) the manifest binds every authority-bearing field in the fixed roster order (excluding only envelope_manifest_sha256 itself and detached_seal_sha256); full_document_sha256 is excluded solely via the bound full_document_hash_policy. Non-vacuity: the roster is the closed set; the live envelope's authority fields == the roster an authority-bearing field is present in the live envelope but NOT in the manifest roster, OR a roster field is missing from the live envelope, OR an unknown/extra field is treated as authority → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH, block authoring (an authority field outside the manifest hash could be edited undetected) authoring-entry gate, PKG-A..I input, S19 YES
G-CODEX-DETACHED-SEAL-ANCHOR the CODEX_DETACHED_SEAL block in approved_by_recheck_checkpoint (Codex-authored) + the live envelope detached_seal_anchor a detached seal exists, is well-formed (seal_version, sealed_by, sealed_at_utc, sealed_envelope_manifest_sha256, sealed_active_corpus_sha256, sealed_active_membership_hash, parent_checkpoint_id, report_documents[], canonical_encoding_version, any_change_requires_new_recheck=true, and signature or signature_not_available_in_current_tooling), Codex-authored, and is pinned by the Codex checkpoint's KB revision + content SHA-256 read back via MCP at the gate; the live envelope_manifest_sha256 == sealed_envelope_manifest_sha256. Compensating rule (no crypto signature): authority = Codex authorship + revision + SHA-256 + MCP read-back + this mismatch guard. Non-vacuity: the checkpoint is read back live, not trusted by path/name detached seal absent / malformed / not Codex-authored / Codex-checkpoint revision-or-content changed since seal / live manifest != sealed manifest → ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH, block authoring until a fresh Codex recheck authoring-entry gate, PKG-A..I input, S19 YES
G-OPERAND-TYPED every policy_rule_manifest/capability_measurement_requirement operand vs operator_operand_compatibility operand type compatible with operator for every rule/requirement; no incompatible operand seals typed-operand mismatch (XH-3) S05, S11, S19 YES
G-DIRECTUS-APP-INTACT Directus authority over directus_* application tables + legitimately-owned business base tables, before/after S16 unchanged; cutover touches only qt001_cp + the sealed U_legacy control objects over-revoke breaks live CMS (XH-4) S16, S19 YES
G-BIRTH-NEUTRAL birth_registry row count + gateway norm-md5 before/after row delta = 0; gateway hash unchanged; 166 triggers intact birth gateway disturbed S15, S16, S17, S19 YES
G-ROLLBACK-SAFE post-rollback state for each step apply/permit/REAL_RUN/QT001 blocked; directus-owned restorable; birth-neutral; no body changed rollback leaves unsafe state each rollback YES
G-DOT-FROZEN DOT-118 / DOT-119 freeze flags both remain frozen (2/2) dangerous DOT unfreeze S00, S19 YES
G-DOT-NOOVERWRITE PG-native final authority: pg_namespace.nspacl of qt001_cp (no CREATE for PUBLIC / directus / any non-owner) + pg_class.relowner / pg_proc.proowner of every qt001_cp control object incl. the QT001 writer gateway (all == qt001_cp_owner) + gateway_manifest#26 / writer_repoint_manifest#27 bound source_sha256. Diagnostic/preflight only (never final authority): a scan of DOT deployment-artifact bodies for a CREATE OR REPLACE of a control object/gateway - DOTs are filesystem/KB deploy scripts, not pg_proc, so a body scan is non-PG-native and advisory (a) qt001_cp control objects + the QT001 writer gateway: a non-owner CREATE OR REPLACE/overwrite is impossible by owner-isolation, proven from catalog ownership + nspacl, NOT from any DOT text; (b) the directus-owned birth gateway (HARD_BLOCK; FIX7 never owns it, so owner-isolation cannot apply): an overwrite is DETECTED by G-BIRTH-NEUTRAL (gateway norm-md5 unchanged) and prevented-in-practice by G-DOT-FROZEN (DOT-118/119 never execute) + the section A "birth gateway modification" hard block; (c) the DOT-body diagnostic FAILS CLOSED - an unreadable/absent DOT body is treated as a candidate overwrite vector and blocks, never passes by default old/frozen DOT or non-owner overwrites gateway/control-plane S00, S15, S19 YES
G-LEGACY-RETAINED legacy qt001_* (20 tables/46 fns/196 views) owner + effective privileges + sentinel/deprecation markers after S17/S18 every retained legacy object is at the uniform end-state (owner=qt001_cp_owner; effective privileges == exact #21 → writes absent, read retained only if #21 grants it); no live-required object (birth/QT-002) depends on a retained target; never live-DROPped; definition unchanged legacy un-neutralized or retention breaks a live dependency S17, S19 YES
G-UNKNOWN-ZERO classification of every live qt001_*/control object 0 UNKNOWN_REQUIRES_REVIEW before repoint no-guess violation S00, S13 YES
G-LEGACY-TARGET-SEALED the operational target set used by S15/S16/S17 vs the sealed U_legacy set (closure(#11, roots = #20 protected_target rows), hash-bound by #26 protected_target_set_sha256) the operational set is the sealed U_legacy set (not a name pattern / owner scan / prose count / disposition); set integrity = the manifest seal (manifest_set.payload_sha256 + per-row manifest_item_envelope.item_sha256 + #26 protected_target_set_sha256) + fresh analyzer evidence (analyzer_run); 0 unclassified; no LEGACY_* row, no disposition/expected_legacy_set_sha256 column (Option Beta) operational target derived from name pattern alone / unsealed / manifest-seal mismatch / stale analyzer / an invented #20 column or hash / a disposition layer S00, S09, S15, S17, S19 YES
G-LEGACY-TARGET-CLOSED-DENOMINATOR the sealed U_legacy_object set vs the object-shape closed denominator (doc 02 §H.4.A) = the reverse write-effect object closure from #20 protected_target roots via #11/#22 + sealed analyzer body-call edges — regclass/regprocedure identities on BOTH sides; NO principal or entry-vector union into this comparison (those are the separate privilege join §H.4.B and bypass-coverage relation §H.4.C) and NO DO_NOT_TOUCH subtraction (Option Beta) both-EXCEPT empty in BOTH directions: sealed − object_denominator = ∅ AND object_denominator − sealed = ∅; 0 UNKNOWN_REQUIRES_REVIEW; no manual exclusion, no class-based exclusion, no mixed-type member. The denominator is derived ONLY from catalog/manifest facts; name/owner scans may widen candidate discovery but never define or close it. A member colliding with a protected boundary (#26 gateway identity, birth gateway, frozen DOT) is not auto-excluded - it FAILS CLOSED for a separate owner decision. Non-vacuity: each closure proves its roots are present and the traversal is non-empty a directly callable legacy writer of protected state is outside the sealed object set (the forward-#11-closure blind spot Codex recheck BLOCKER B identified), OR the denominator is name-pattern-defined / vacuous / used a subtraction / unioned a principal or entry-vector into the object comparison (recheck-3 type error) S00, S09, S13, S15, S19 YES
G-NOMIXED-AUTHORITY the PG-native route/authority fact (manifest_set.activated_at IS NOT NULL AND not superseded → an ACTIVE manifest_activation for the writer type, i.e. the new path is authoritative-routed, NOT mere manifest existence) + effective executability of the sealed legacy set, at every cutover/rollback checkpoint an ACTIVE-routed new qt001_cp path and any legacy executable path are mutually exclusive. A STAGED manifest (sealed, activated_at NULL) beside executable legacy is NOT mixed (legacy is the sole authoritative path - the S14 state); an ACTIVE manifest beside executable legacy is forbidden and cannot occur because activation (S15.4) follows legacy neutralization (S15.1-S15.3) within one atomic transaction (Codex recheck BLOCKER D). During S15 rollback the new path is proven non-authoritative by the derived current-active fact (activated_at IS NOT NULL AND superseded_by_manifest_id IS NULL yields none for the writer type after forward supersession) BEFORE any legacy EXECUTE/owner is restored - the guard reads the derived current-active route, never a cleared/edited activated_at (recheck-2 BLOCKER G; forward-only, history immutable) mixed old+new authority window (Codex BLOCKER 4 / CR-E1; recheck BLOCKER D) S14, S15, S16, each rollback, S19 YES
G-WRITER-GATEWAY-IDENTITY live active writer vs the #26-pinned gateway (regprocedure+prokind+source_sha256+owner) + #27 bindings (doc 04 §Writer-gateway-identity) post-S15 active writer == #26-bound regprocedure with matching source_sha256 and owner qt001_cp_owner (born owner-isolated, no directus phase); legacy writer/apply objects are members of the sealed U_legacy (#20-root/#11-closure) set; fn_birth_registry_auto unchanged and is NOT the QT001 gateway; no guard assumes the post-S16 owner state at S15 (phase-explicit) gateway identity ambiguous / name-pattern-bound / phase-confused owner (Codex BLOCKER 6 / CHECK_D) S13, S15, S16, S19 YES
G-NO-QT001-PERMIT-DURING-FIX7 every FIX7 package's authorization + any qt001_backfill_permit / admission-permit / REAL_RUN-authority state no FIX7 package (PKG-A..I) opens, consumes, or depends on a qt001_backfill_permit (admission/birth permit), REAL_RUN authority, or QT001 apply authority; operator_authorization is package-execution authority ONLY and grants none of those a FIX7 package conflates operator_authorization with the blocked qt001_backfill_permit / opens QT001 apply (Codex BLOCKER 7 / CHECK_J) S14, S15, S16, S17, S19 YES
G-OWNER-UNREACHABLE pg_roles (qt001_cp_owner: rolcanlogin/rolsuper) + pg_auth_members transitive closure into qt001_cp_owner + the sealed Level-B principal_registry row qt001_cp_owner is NOLOGIN + non-superuser; no rolcanlogin role (directus/runtime/app) is a direct or transitive member of qt001_cp_owner (so no login principal can SET ROLE to it); the ONLY sanctioned actor-as-owner path is the sealed Level-B migrator/owner principal (CP-09) used inside an authorized cutover transaction; qt001_cp_owner holds no grant to any login role. Non-vacuity: the role exists and the membership closure was actually traversed the owner-implicit EXECUTE was merely relocated to a reachable principal; asserting effective-EXECUTE=0 while the owner role is reachable (recheck-2 BLOCKER A) S01, S15, S16, S19 YES
G-SUPERUSER-BREAKGLASS pg_roles superusers (rolsuper/rolbypassrls; live: workflow_admin) + pg_stat_activity/audit for the cutover window + the FIX7 operator session session_user the FIX7 live steps run as the Level-B migrator principal, NEVER as workflow_admin; superuser/bypassrls use is break-glass / operator-gated only; readiness is framed as "no unauthorized superuser use path" (NOT effective-priv=0, which is impossible for a superuser); FAILS if any rolsuper/rolbypassrls session performs FIX7 authority changes outside an explicitly authorized Level-B break-glass record a superuser silently performed (or could perform) FIX7 authority changes outside break-glass; treating a superuser as ACL-zeroable (recheck-2 BLOCKER F) S15, S16, S19 YES
G-SEAL-AFTER-AUTHOR-REHEARSE the author→validate→rehearse→hash→seal→review→authorize→apply order across packages (doc 07) for #11/#20/#26/#27 + root/closure/rollback bindings every manifest is sealed ONLY after the exact artifact set it seals has been authored, statically validated, and rehearsed; seal hashes are computed from the FINAL authored artifacts; no activation precedes seal/review/authorization; #26/#27 + root/closure bindings are authored before the complete rehearsal seal a seal precedes the artifact it seals (the prior S12-before-S13 inversion), or an activation precedes seal/review/authorization (recheck-2 BLOCKER H) S11, S12, PKG seal points, S19 YES
G-OPERATOR-AUTH-PG-NATIVE each live package's authorization vs the typed PG authority model: CP-09 Level-B principal_registry/human_identity_registry + #07 authority_action + #20/#21 scope + #16 signoff_requirement + #19 quorum_requirement + #08 principal_separation + manifest_activation (candidate_payload_sha256/activation_sha256/requested_control_epoch/rollback_evidence_id) the authorization decision inputs (authorized action, scope, principal/quorum/separation, epoch, and the sealed payload hash the package applies) are ALL typed PG rows — no external artifact supplies unparsed final authority and no broad role grant substitutes for the per-transition typed contract; an external evidence_registry artifact may only support, never supply, final authority operator authorization rests on unparsed external artifact content / a broad role grant rather than typed PG authority (recheck-2 BLOCKER D) S12, S14, S15, S16, S19 YES
G-CANONICAL-FIELD-REJECT every field value entering any FIX7-CANON-V1 record (membership / corpus / marker / superseded-boundary / manifest / detached-seal) each value passes its per-field whitelist grammar AND contains no TAB(0x09)/LF(0x0A)/CR(0x0D)/NUL(0x00)/backslash(0x5C) and no reserved structural token (<!-- ENVELOPE:EXCLUDE-*/<!-- SUPERSEDED_NON_AUTHORITY */FIX7_*_V1 outside marker_literal) and is neither null nor empty — REJECT, never escape (so TAB/LF-delimited records are injective) a value could carry a separator or sentinel → records non-injective / authority spoofable; CANONICAL_FIELD_RESERVED_TOKEN_REJECTED / _VALUE_GRAMMAR_REJECTED / _NULL_REJECTED / _EMPTY_REJECTED (recheck-6 BLOCKER A) envelope build + every authoring-entry recompute YES
G-ACTIVE-SCOPE-EXTRACTOR each ACTIVE doc's raw bytes at the pinned revision active scope / fence / section produced ONLY by the deterministic extractor (doc 00: normalize CRLF/CR→LF first, 1-based lines, exact marker grammar, exactly one DOC_STATUS, flat non-nesting, re-emit retained line+LF); every ambiguity yields a fail-closed status — ACTIVE_SCOPE_MARKER_MISSING/_DUPLICATE, FENCE_UNBALANCED/FENCE_NESTED_UNSUPPORTED, ACTIVE_SUPERSEDED_OVERLAP, SECTION_ID_MISMATCH/SECTION_RANGE_MISMATCH, EXCLUDE_REGION_UNBALANCED, MARKER_REGISTRY_MISMATCH "active scope" left to prose/judgement → non-reproducible content hash (recheck-6 BLOCKER B) per-doc normalized-content hashing + authoring-entry YES
G-RECORD-ENCODING-CLOSED every load-bearing digest's record set + the complete envelope key set each digest uses its closed record schema (domain tag + fixed field list/order + per-field grammar + sort key + no-null/no-empty + full-path document_id); the manifest is fixed-roster-order, sub-lists sorted; every envelope key is in the closed key-classification schema (MANIFEST_BOUND / SEAL_LAYER_READBACK_PROTECTED / NON_AUTHORITY_DIAGNOSTIC / STRUCTURAL_CONTRACT_PROSE); unknown/extra/missing/wrong-class key fails closed a record/field needs human interpretation, or an authority key sits outside the manifest undetected (recheck-6 BLOCKER C) envelope build + authoring-entry YES
G-SEAL-HASH-GRAPH-ACYCLIC the seal hash node/edge list N1..N9 (doc 00 §Seal hash dependency graph) the graph is a DAG (a topological order exists); no load-bearing node's inputs transitively include itself; N7 envelope_manifest binds NO checkpoint revision/content hash and not N8; N8 detached_seal binds neither itself nor its checkpoint's content hash; N9 codex_checkpoint_content_sha256_excluding_seal is NON_AUTHORITY_DIAGNOSTIC consumed by nothing a load-bearing hash depends on itself (manifest binds the checkpoint that contains the seal that binds the manifest, or seal_report_checkpoint_content_sha256) → SEAL_HASH_GRAPH_CYCLE, uncomputable authority (recheck-6 BLOCKER D/E) envelope build + every Codex recheck YES
G-NO-SELF-REVISION-ANCHOR the load-bearing input set of the detached seal + the envelope authority fields NO load-bearing value is a platform-assigned revision of the artifact that carries it (a revision exists only after the write, so embedding it is circular even though the content-hash DAG is acyclic); the recheck-N checkpoint's own revision is NON_AUTHORITY_DIAGNOSTIC; seal authority = detached_seal_sha256 content recompute + MCP read-back of existence; the finite ordered seal (stage → Codex seals without own-revision → platform assigns revision → optional diagnostic) completes without improvisation a checkpoint's own post-write revision is recorded/read-back as load-bearing → SELF_REVISION_ANCHOR_REJECTED (recheck-7 BLOCKER A) envelope build + every Codex recheck + authoring-entry YES
G-CANONICALIZER-SSOT-ONLY the pinned canonicalizer_artifact_id + canonicalizer_version + canonicalizer_sha256 (doc 00 envelope) vs the live canonicalizer artifact exactly ONE executable canonicalizer/encoder SSOT exists (FIX7-CANON-V1-CANONICALIZER); its --selftest exits 0 and reproduces membership f2bda8…fe251; the live artifact's content hash == the sealed canonicalizer_sha256; every package/guard uses that one artifact (no re-implementation ships a different hash without proving the test vectors) no SSOT pinned, or a package/guard/doc ships or references a different canonicalizer hash/version → CANONICALIZER_SSOT_MISMATCH (recheck-7 BLOCKER B) envelope build + authoring-entry + every package precondition YES
G-NO-DUPLICATE-CANONICAL-AUTHORITY every ACTIVE_AUTHORITY doc/section + report doc that describes canonicalization, extraction, record encoding, or marker grammar (= Codex G-CANONICAL-CONTRACT-SSOT-NO-DUPLICATE; one guard, that string is a non-authority alias) exactly ONE load-bearing canonical contract (the SSOT artifact); all other descriptions are explicit NON_AUTHORITY_EXPLANATION that reference the SSOT identity/hash; covers exact, semantic, and structural duplication a second load-bearing canonical/extractor/record/marker contract appears in ACTIVE_AUTHORITY, or a report example conflicts with the SSOT, or an implementation package defines its own canonicalization → DUPLICATE_CANONICAL_AUTHORITY (Constitution Article 14; recheck-7 BLOCKER C) envelope build + authoring-entry + package review YES
G-DOCUMENT-ID-CANONICAL-MCP every document_id value entering any record (membership/corpus/marker/superseded) each document_id equals the MCP-returned canonical id byte-for-byte (case-sensitive, no identity-changing normalization), every /-segment matches ^[A-Za-z0-9._-]+$ (ASCII), ends .md, starts with the KB root, and contains no ./../empty segment////leading-or-trailing slash/backslash/%-encoding/homoglyph slash (authoritative impl = canonical_document_id() in the SSOT) a path alias produces a duplicate/ambiguous logical record → DOCUMENT_ID_ALIAS_REJECTED / DOCUMENT_ID_NOT_MCP_CANONICAL / DOCUMENT_ID_SCOPE_MISMATCH (recheck-7 BLOCKER D) envelope build + every authoring-entry recompute YES
G-MARKER-KIND-LITERAL-CONSISTENCY every marker record (document_id, marker_kind, marker_literal) marker_kind is in the closed enum; marker_literal matches the extractor grammar for that exact kind byte-for-byte; the (kind, literal) pair is consistent; the record encodes both; duplicate same-kind markers fail closed unless explicitly allowed (authoritative impl = check_marker() in the SSOT) unknown kind → MARKER_KIND_UNKNOWN; literal of another kind → MARKER_KIND_LITERAL_INCONSISTENT; literal not allowed for the kind → MARKER_LITERAL_NOT_ALLOWED; control byte / grammar miss → MARKER_LITERAL_MISMATCH (recheck-7 BLOCKER E) per-doc extraction + envelope build YES

Guard-quality rules (anti-false-green; Max-hardened 2026-06-08)

These rules bind every guard above; a guard that violates them is itself a defect:

  1. No vacuous pass. Any guard whose pass condition is "= 0", "empty", or "both-EXCEPT empty" (G-NOLEGACY-PRE/POST, G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE, G-LEGACY-TARGET-SEALED, G-LEGACY-TARGET-CLOSED-DENOMINATOR, G-NOMIXED-AUTHORITY, G-EXACTSET-20, G-UNKNOWN-ZERO, the G-AUTH-27 / G-RUNTIME-NONAUTH set-diffs) must ALSO assert the underlying input set/closure is non-vacuous and well-formed: the expected set is populated (27 surfaces; the sealed U_legacy set; the closed-world #21) and any closure actually traversed from present roots. A mis-seeded or empty computation must not produce a false green (the FIX5 lesson: an empty / mis-rooted closure once "proved" zero legacy reach).
  2. NULL-strict aggregates. No guard may decide PASS via bool_and(...) / bool_or(...) over a nullable column where NULL is silently ignored; use NULL-strict count-match (expected count == realized non-NULL count) so a NULL component fails closed (the FIX5/FIX6 lesson).
  3. Source-text is diagnostic, never authority. Any guard that reads pg_get_functiondef / pg_get_viewdef / DOT bodies (G-NOHARDCODE, G-NODISGUISE, G-DOT-NOOVERWRITE) uses that text only to FLAG candidates; the FINAL blocking authority is PG-native: catalog ownership/ACL, pg_constraint / pg_index, pg_depend structural closure, sealed manifest rows, or a recomputed hash. Missing source-text visibility fails closed, never passes by default.
  4. No existence-only proof. A guard may not pass because an object/row merely exists; it must test behavior, an exact set, or a recomputed value.
  5. PostgreSQL privilege semantics are explicit (Codex recheck BLOCKER A/E/H). Any effective-privilege guard (G-NOLEGACY-POST, G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE, G-OWNER-CUTOVER) (a) computes effective EXECUTE/DML over non-owner roles only - because an object owner retains implicit privileges that no REVOKE removes, so "effective = 0 for a role" is only assertable once that role is not the owner (ownership must be transferred first); and (b) explicitly dispositions superuser roles (live: workflow_admin) as inherently ACL-bypassing and outside the removable scope - a guard may NOT claim a superuser is privilege-zero, and may NOT silently include the superuser in a "=0" aggregate. A guard that expects an owner's effective privilege to be zero without an ownership transfer, or that ignores superuser bypass, is itself a defect.
  6. No disposition authority (Option Beta). No guard, package, construction-order step, rollback step, or seal may consume a five-value disposition, a LEGACY_* object_type row, a disposition column/family, a computed-disposition classifier/CASE branch, a STUB/body path, or a DO_NOT_TOUCH subtraction. relkind/prokind may be read ONLY to select PG syntax for the one uniform end-state; if a guard's outcome would differ by object class/type/name/owner/label other than syntax, it is a defect (G-LEGACY-NO-DISPOSITION-AUTHORITY).
  7. Set-type separation (recheck-3). The object set (U_legacy_object), the privilege-principal universe (U_effective_privilege_principal), and the entry-vector universe (U_entry_vector) are three distinct typed sets. No guard may both-EXCEPT-compare across unlike identity types: an object set is compared only to an object-shape denominator (doc 02 §H.4.A), privilege only as the object × principal tuple join to #21 (§H.4.B), and bypass only as entry-vector → object coverage (§H.4.C). A principal or entry-vector identity placed in the object set, or an object-membership test used where a privilege/coverage relation is required, is a defect (G-U-LEGACY-OBJECT-ONLY / G-PRINCIPAL-SET-SEPARATE / G-ENTRY-VECTOR-SEPARATE).
  8. Active-authority scope (recheck-3). Any guard that scans blueprint text/sections for removed constructs (notably G-LEGACY-NO-DISPOSITION-AUTHORITY) scopes to the ACTIVE_AUTHORITY load-bearing set as pinned by the canonical SEALED approval envelope (FIX7-CANON-V1) + the Codex detached seal (doc 00), not the mutable boundary registry alone; it FAILS on a removed construct found in ACTIVE_AUTHORITY, and it reports — never fails on — the same term inside a matched SUPERSEDED_NON_AUTHORITY fence. No package/guard/seal/order/authoring step may consume a superseded section as current authority (G-NO-SUPERSEDED-CONSUMPTION), and the boundary itself must be present, unambiguous, and not Directus-editable (G-ACTIVE-AUTHORITY-SCOPE). A scan that conflates history with current authority, or a consumer that reads superseded text, is a defect.
  9. Content-addressed authoring authority (recheck-4). Any corpus that is authority for implementation authoring (the ACTIVE_AUTHORITY set) must be pinned by an immutable, content-addressed approval envelope — exact KB revision + SHA-256 per active doc/section, plus registry / marker-fence / guard-set / membership / manifest hashes — sealed at the Codex recheck, not by mutable markers/registry/fences alone. Markers/registry/fences are necessary classification syntax but are NOT sufficient authority (they can be edited after approval). Any drift in content/marker/fence/registry/guard-set/membership/revision vs the sealed envelope FAILS CLOSED (ACTIVE_AUTHORITY_ENVELOPE_MISMATCH) and the correct response is a fresh Codex recheck, never "continue authoring" (G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE / -HASH-MATCH / -REVISION-MATCH / -CHANGE-FAIL-CLOSED). A mutable authoring-authority denominator is a disguised hardcode (Codex recheck-4). The envelope is a non-runtime construction-document integrity artifact — NOT a runtime authority surface, readiness gate, #20 column, catalog family, or a top-level FIX7 runtime hash contract (H01..H07 stay 7); it content-addresses the documents being authored from, not a runtime DB object.
  10. Byte-exact canonical content-addressing (recheck-5). Every aggregate digest that pins authoring authority must be defined by a byte-exact, domain-separated, fixed-field-order, sorted, LF-normalized, trailing-LF canonical encoding (canonical_encoding_version: FIX7-CANON-V1, doc 00). No aggregate hash may be described only in prose or depend on unordered map/object serialization. envelope_manifest_sha256 must bind the complete authority-field roster (any authority field outside the manifest hash is editable undetected → fail closed). The self-host (doc 00) must not hash its own envelope (Option-1: normalized_active_content_sha256 excludes the envelope region; full_document_sha256 is NON_AUTHORITY_DIAGNOSTIC). The SEALED copy of record is an immutable Codex detached seal pinned by checkpoint revision + content SHA-256 + MCP read-back (not trusted by path/name; no crypto signature → the compensating revision/hash/read-back mismatch rule applies). Any drift fails closed (G-CANONICAL-ENCODING-CONTRACT, G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE, G-CODEX-DETACHED-SEAL-ANCHOR). An aggregate hash specified only in prose, or an "immutable" anchor with no revision/hash/read-back, is a disguised mutable-authority path (Codex recheck-5).
  11. Byte-exact, executable, acyclic content-addressing (recheck-6). A load-bearing digest is NOT valid merely because "it has a SHA-256." It must additionally have, or it is a defect: (a) a reserved-token REJECTION (not escape) contract so no field value can contain a separator (TAB/LF) or a structural sentinel — values are whitelisted by grammar and a violation fails closed (G-CANONICAL-FIELD-REJECT); (b) one deterministic extractor for active scope / fence / section (normalize-first, 1-based lines, exact marker grammar, flat non-nesting) with a fail-closed status for every ambiguity (marker missing/duplicate, fence unbalanced/nested, overlap, section id/range, exclude unbalanced, registry mismatch) — no "best effort" (G-ACTIVE-SCOPE-EXTRACTOR); (c) a closed per-record encoding schema and a closed envelope key-classification schema (every key is MANIFEST_BOUND / SEAL_LAYER_READBACK_PROTECTED / NON_AUTHORITY_DIAGNOSTIC / STRUCTURAL_CONTRACT_PROSE; unknown/extra/missing/wrong-class fails closed) (G-RECORD-ENCODING-CLOSED); and (d) an acyclic hash dependency graph — no load-bearing hash may include a value that transitively depends on itself, an "immutable anchor" must never require any artifact to hash itself, and the checkpoint is anchored out-of-band by its platform revision + MCP read-back, never by a content hash that includes the seal (G-SEAL-HASH-GRAPH-ACYCLIC). A digest defined only in prose, an extractor that "best-efforts" an ambiguity, a record needing human interpretation, or a mutual/self hash dependency is a disguised mutable-authority path (Codex recheck-6). The reviewer should only have to confirm the result, not discover byte-level ambiguity or a dependency cycle.
  12. One executable SSOT, no duplicate authority, no self-referential anchor (Constitution Article 14 / NT14 — recheck-7). A design is NOT valid because the law/spec text reads well; it is valid only if the implementation path cannot misinterpret it. Therefore: (a) every authority/hash/guard resolves to exactly one executable/checkable SSOT — for canonicalization that is the artifact FIX7-CANON-V1-CANONICALIZER, pinned by canonicalizer_sha256, whose --selftest exits 0; (b) all other canonical/extractor/record/marker descriptions in ACTIVE_AUTHORITY and in every report are explicit NON_AUTHORITY_EXPLANATION that reference the SSOT — a second load-bearing contract, a package shipping a different canonicalizer hash, or a report example conflicting with the SSOT fails closed (G-NO-DUPLICATE-CANONICAL-AUTHORITY, G-CANONICALIZER-SSOT-ONLY); (c) no load-bearing value is a platform-assigned revision of the artifact that carries it (revision is diagnostic only; G-NO-SELF-REVISION-ANCHOR); (d) document_id is the exact MCP canonical id with every path alias rejected (G-DOCUMENT-ID-CANONICAL-MCP) and markers are a consistent closed (kind, literal) pair (G-MARKER-KIND-LITERAL-CONSISTENCY). Prose that competes with the executable SSOT is itself a defect: the implementation runs the artifact, not the prose.

Guard family coverage check (vs macro SUPERTRACK F)

All required guard families are mapped: no hardcode (G-NOHARDCODE), no disguised hardcode (G-NODISGUISE), PG-first/native/driven (G-PGNATIVE), authority=27 (G-AUTH-27), runtime=11 (G-RUNTIME-NONAUTH), gates=14 (G-GATES-14), hashes=7 (G-HASH-7), H04/H02/H05 determinism (G-HASHDET, G-H04-SCOPE), constraint exact-set both-EXCEPT (G-EXACTSET-20), Directus read preflight (G-DIRECTUS-READ), owner/ACL cutover (G-OWNER-CUTOVER), item_payload no operational read (G-ITEMPAYLOAD), catalog-family exact-set (G-CATFAMILY), same-human slot-scope (G-SAMEHUMAN), evidence FK integrity (G-EVIDENCE-FK), retention authority seal (G-RETENTION-SEAL), control_epoch TOCTOU (G-EPOCH-TOCTOU), Level-B no manual SQL (G-LEVELB-NOSQL), rollback safe-blocked (G-ROLLBACK-SAFE). Plus refactor-specific additions: G-REPOINT-SRC, G-NOLEGACY-PRE + G-NOLEGACY-POST (phase-split; legacy entrypoint blocked, not merely unreachable), G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE (Option Beta uniform end-state), G-LEGACY-NO-DISPOSITION-AUTHORITY (Option Beta removal), G-BIRTH-NEUTRAL, G-DOT-FROZEN, G-DOT-NOOVERWRITE (old/frozen DOT cannot overwrite gateway/control-plane

  • XHigh-2), G-LEGACY-RETAINED (uniform-end-state retention), G-UNKNOWN-ZERO, G-OPERAND-TYPED (XH-3), G-DIRECTUS-APP-INTACT (XH-4), G-LEGACY-TARGET-SEALED (Codex BLOCKER 1), G-LEGACY-TARGET-CLOSED-DENOMINATOR (Codex recheck BLOCKER B), G-NOMIXED-AUTHORITY (Codex BLOCKER 4), G-WRITER-GATEWAY-IDENTITY (Codex BLOCKER 6), G-NO-QT001-PERMIT-DURING-FIX7 (Codex BLOCKER 7), G-OWNER-UNREACHABLE (recheck-2 A), G-SUPERUSER-BREAKGLASS (recheck-2 F), G-SEAL-AFTER-AUTHOR-REHEARSE (recheck-2 H), G-OPERATOR-AUTH-PG-NATIVE (recheck-2 D); plus the recheck-3 set-separation + active-authority additions: G-U-LEGACY-OBJECT-ONLY (object-only set), G-PRINCIPAL-SET-SEPARATE (object × principal privilege join), G-ENTRY-VECTOR-SEPARATE (entry-vector bypass coverage), G-ACTIVE-AUTHORITY-SCOPE (machine-readable active/superseded boundary), G-NO-SUPERSEDED-CONSUMPTION (no package consumes superseded history); plus the recheck-4 approval-envelope additions: G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE (sealed content-addressed envelope covers exactly the ACTIVE corpus), G-ACTIVE-AUTHORITY-HASH-MATCH (live SHA-256 == sealed), G-ACTIVE-AUTHORITY-REVISION-MATCH (live KB revision == sealed), G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED (any drift → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH → fresh Codex recheck).

Total guards: 63 (was 26 High → 30 after the independent XHigh/Max passes → 35 after the Codex critical-review patch pass → 36 after Codex RECHECK patch pass → 40 after the Codex RECHECK-2 patch pass → 42 after the Option-Beta legacy-disposition amendment patch 2026-06-08: +G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE, +G-LEGACY-NO-DISPOSITION-AUTHORITY; G-LEGACY-TARGET-SEALED and G-LEGACY-TARGET-CLOSED-DENOMINATOR are now fully operational (no LEGACY_*/disposition dependency, no DO_NOT_TOUCH subtraction); the former G-LEGACY-FROZEN is reframed as G-LEGACY-RETAINED (uniform end-state) → 47 after the Codex recheck-3 set-separation + active-authority patch 2026-06-09 (+G-U-LEGACY-OBJECT-ONLY, +G-PRINCIPAL-SET-SEPARATE, +G-ENTRY-VECTOR-SEPARATE, +G-ACTIVE-AUTHORITY-SCOPE, +G-NO-SUPERSEDED-CONSUMPTION; G-LEGACY-TARGET-CLOSED-DENOMINATOR re-scoped to the object-shape denominator only; G-LEGACY-NO-DISPOSITION-AUTHORITY re-scoped to ACTIVE_AUTHORITY; guard-quality rules 7+8 added) → 51 after the Codex recheck-4 approval-envelope patch 2026-06-09 (+G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE, +G-ACTIVE-AUTHORITY-HASH-MATCH, +G-ACTIVE-AUTHORITY-REVISION-MATCH, +G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED; G-ACTIVE-AUTHORITY-SCOPE / G-NO-SUPERSEDED-CONSUMPTION / G-LEGACY-NO-DISPOSITION-AUTHORITY re-bound to the sealed envelope; guard-quality rule 9 added) → 54 after the Codex recheck-5 canonical-envelope patch 2026-06-09 (+G-CANONICAL-ENCODING-CONTRACT, +G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE, +G-CODEX-DETACHED-SEAL-ANCHOR; the four recheck-4 envelope guards + G-NO-SUPERSEDED-CONSUMPTION + G-LEGACY-NO-DISPOSITION-AUTHORITY re-bound to the canonical FIX7-CANON-V1 encoding + the Codex detached seal; guard-quality rule 10 added); → 58 after the Codex recheck-6 byte-exact-canonicalization patch 2026-06-09 (+G-CANONICAL-FIELD-REJECT, +G-ACTIVE-SCOPE-EXTRACTOR, +G-RECORD-ENCODING-CLOSED, +G-SEAL-HASH-GRAPH-ACYCLIC; the prior canonical/ envelope/seal guards re-bound to the REJECT field policy + the deterministic extractor + the closed record & key-classification schemas + the acyclic seal hash graph; guard-quality rule 11 added); → 63 after the Codex recheck-7 Constitution-Article-14 SSOT patch 2026-06-09 (+G-NO-SELF-REVISION-ANCHOR, +G-CANONICALIZER-SSOT-ONLY, +G-NO-DUPLICATE-CANONICAL-AUTHORITY, +G-DOCUMENT-ID-CANONICAL-MCP, +G-MARKER-KIND-LITERAL-CONSISTENCY; one executable canonicalizer SSOT, all other canonical descriptions demoted to NON_AUTHORITY_EXPLANATION, checkpoint own-revision removed from authority; guard-quality rule 12 added). The prior recheck-2 additions remain: +G-OWNER-UNREACHABLE, +G-SUPERUSER-BREAKGLASS, +G-SEAL-AFTER-AUTHOR-REHEARSE, +G-OPERATOR-AUTH-PG-NATIVE; G-NOMIXED-AUTHORITY forward-only.) These 63 are PG-native TEST/VERIFICATION guards in this doc - NOT readiness gates. The invariants are unchanged: readiness gates remain 14 (DATA rows in surface #09), top-level runtime hash contracts remain 7 (H01..H07), authority surfaces remain 27, runtime-evidence 11; there is no sealed legacy-disposition set, no new surface, and no new #20 column. The recheck-4 ACTIVE_AUTHORITY_APPROVAL_ENVELOPE is a non-runtime construction-document content-address (it pins the blueprint docs being authored from), explicitly NOT an 8th runtime hash contract. The SUPERTRACK-G families the High draft under-covered are now explicit: "legacy entrypoint blocked, not merely unreachable" (G-NOLEGACY-POST), "old DOT/gateway overwrite impossible" (G-DOT-NOOVERWRITE), "no name-pattern or disposition authority" (G-LEGACY-TARGET-SEALED + G-LEGACY-NO-DISPOSITION-AUTHORITY + G-PGNATIVE), "uniform neutralized end-state" (G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE), and "no mixed authority on rollback" (G-NOMIXED-AUTHORITY).

Negative-test requirement (from approved design §2.5 + Option-Beta amendment doc 07 instr. 8)

Each of the 27 contracts must run the full negative suite (missing/extra/orphan/wrong-manifest child, NULL required, unknown FK, duplicate key, invalid hash length, Directus DML, PUBLIC DML, sealed UPDATE/DELETE, wrong count, noncontiguous ordinal, payload-hash mismatch) plus family-specific CHECK/UNIQUE/FK mutations. No negative test may be a literal PASS row - each must produce a real DDL/permission rejection or seal/activation rejection. This is the explicit defense against the historical false-green pattern.

Option-Beta negative tests (added; amendment doc 07 instruction 8). The following must each produce a real rejection / fail-closed, proving labels/class/type/name/pattern cannot change the desired result:

  • a member's relkind/prokind is changed → the uniform end-state (owner, #21 effective privileges) is UNCHANGED; only the emitted PG syntax differs (no policy/outcome change);
  • a former label (REVOKE_ONLY/FREEZE_NO_CHANGE/DEPRECATE_READONLY/STUB_FAIL_CLOSED/DO_NOT_TOUCH) is injected as a manifest field / rule input / guard input / package branch → REJECTED by G-LEGACY-NO-DISPOSITION-AUTHORITY;
  • an attempt to add a LEGACY_* object_type row, a disposition column, or a legacy_disposition catalog family → REJECTED (catalog families are a sealed exact set; #20 §2.7 scope; no new column);
  • a STUB body replacement / body-restore path is introduced → REJECTED (no body change permitted);
  • U_legacy is computed with a DO_NOT_TOUCH subtraction or a manual exclusion → REJECTED by G-LEGACY-TARGET-CLOSED-DENOMINATOR;
  • the #11 closure reaches a protected-boundary object (#26 gateway identity / birth gateway / frozen DOT) or an unsupported object class → the package FAILS CLOSED for a separate owner decision (never auto-excluded, never routed later);
  • #21 is left incomplete and a member's privilege absence is treated as authority → REJECTED by the closed-world both-EXCEPT check in G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE.

Codex recheck-3 negative tests (added; set separation + active-authority boundary). Each must produce a real rejection / fail-closed:

  • a principal/role identity is injected into U_legacy_object (or into the object both-EXCEPT denominator) → REJECTED by G-U-LEGACY-OBJECT-ONLY / G-LEGACY-TARGET-CLOSED-DENOMINATOR (mixed-type member);
  • an entry-vector (trigger/event-trigger/scheduler/DOT) is placed in U_legacy_object or subjected to owner/body/#21 object proof → REJECTED by G-ENTRY-VECTOR-SEPARATE;
  • the effective-privilege check is run as object-set membership instead of the U_legacy_object × U_effective_privilege_principal tuple join → REJECTED by G-PRINCIPAL-SET-SEPARATE;
  • a role-membership change adds a new effective grantee not in #21 → the privilege-tuple both-EXCEPT is non-empty → REJECTED (G-NOLEGACY-POST / G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE over the join);
  • an entry-vector reaches protected write-state through neither a neutralized object nor an independent block (uncovered vector) → FAILS CLOSED (G-ENTRY-VECTOR-SEPARATE);
  • an old disposition/STUB term appears in an ACTIVE_AUTHORITY load-bearing section → REJECTED by G-LEGACY-NO-DISPOSITION-AUTHORITY (ACTIVE_AUTHORITY scope);
  • the SAME term appears inside a matched SUPERSEDED_NON_AUTHORITY fence → reported as history, NOT failed (proves the boundary distinguishes history from current authority);
  • a future package/guard/seal/order step references or consumes a SUPERSEDED_NON_AUTHORITY instruction → REJECTED by G-NO-SUPERSEDED-CONSUMPTION;
  • the active/superseded boundary is removed, made ambiguous, or expressed as a Directus-editable artifact → REJECTED by G-ACTIVE-AUTHORITY-SCOPE.

Codex recheck-4 negative tests (added; approval-envelope drift). Each must produce a real fail-closed ACTIVE_AUTHORITY_ENVELOPE_MISMATCH and BLOCK authoring until a fresh Codex recheck:

  • an ACTIVE doc body is edited after approval (KB revision increments) → G-ACTIVE-AUTHORITY-REVISION-MATCH fails; G-ACTIVE-AUTHORITY-HASH-MATCH also fails;
  • a DOC_STATUS marker or a SUPERSEDED_NON_AUTHORITY BEGIN/END fence is changed (e.g. a superseded block flipped to active, or vice-versa) with no body change → marker_fence_registry_sha256 mismatch → G-ACTIVE-AUTHORITY-HASH-MATCH / -CHANGE-FAIL-CLOSED fail;
  • the doc 00 registry alone is edited (add/remove an active doc) → registry / active_corpus_membership_sha256 mismatch → fail; a missing/extra ACTIVE doc also fails G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE;
  • a guard definition (doc 06) is edited only → guard_set_sha256 / guard_set_revision mismatch → fail;
  • an active SECTION is moved/renumbered without content change → active_section_id_or_range identity mismatch → fail;
  • a superseded history block is edited but the envelope still lists it as superseded → it remains non-authority; promoting it to active would require re-enveloping (a new sealed envelope + fresh Codex recheck), never a silent flip;
  • the envelope is absent or still STAGED (unsealed) at authoring time → G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE fails (no authoring on an unsealed corpus);
  • after ANY mismatch, an attempt to "continue authoring" → BLOCKED; the only valid next step is a fresh Codex recheck (G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED, guard-quality rule 9);
  • the active corpus is identified from mutable Directus/marker state instead of the sealed envelope → REJECTED (mutable-marker state is not final authority).

Codex recheck-5 negative tests (added; canonical-envelope / detached-seal drift). Each must produce a real fail-closed mismatch and BLOCK authoring until a fresh Codex recheck:

  • an active doc's full canonical document_id prefix is changed/stripped → active_corpus_membership_sha256 (FIX7_ACTIVE_AUTHORITY_MEMBERSHIP_V1, full paths) mismatch → G-ACTIVE-AUTHORITY-HASH-MATCH / G-CANONICAL-ENCODING-CONTRACT fail;
  • the envelope YAML fields are reordered with no value change → canonical encoding emits the fixed field order, so the manifest hash is STABLE (specified non-mismatch); reordering corpus entries is re-sorted by document_id → also stable;
  • a trailing newline is removed / CRLF is introduced in a hashed input → newline-normalization + trailing-LF rule make a pure line-ending flip content-stable but the KB revision still increments (G-ACTIVE-AUTHORITY-REVISION-MATCH); removing the specified trailing LF from the canonical input is a specified digest mismatch (G-CANONICAL-ENCODING-CONTRACT);
  • the doc 00 envelope block alone is edited (it sits in the EXCLUDE region, so doc 00's normalized_active_content_sha256 is unchanged → no self-reference loop) → the live envelope_manifest_sha256 diverges from the detached seal's sealed_envelope_manifest_sha256G-CODEX-DETACHED-SEAL-ANCHOR / ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH fail;
  • an authority-bearing field is added to the live envelope but not to the manifest roster → G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE fail (no authority field outside the manifest hash);
  • the blueprint checkpoint is edited → NO effect on authoring authority (it is NON_AUTHORITY_INDEX / REPORT_ONLY, not a member, consumed by no guard/package); attempting to take authority from it → G-ACTIVE-AUTHORITY-SCOPE rejects (authority only from the sealed envelope + detached seal);
  • the Codex recheck checkpoint hosting the detached seal is changed after seal (revision increments or content SHA-256 changes) → G-CODEX-DETACHED-SEAL-ANCHOR / ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH fail (the read-back catches it; not trusted by path/name);
  • an aggregate hash is presented as a prose definition or computed via unordered serialization → G-CANONICAL-ENCODING-CONTRACT rejects (must use the FIX7-CANON-V1 byte-exact ordered encoding).
Back to Knowledge Hub knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/06-test-guard-blueprint.md