KB-7A3F rev 17

FIX7 Refactor Blueprint - Hard Blocks and Do-Not-Touch List

13 min read Revision 17

08 - Hard Blocks and Do-Not-Touch List

<!-- DOC_STATUS: ACTIVE_AUTHORITY --> <!-- AUTHORITY_BOUNDARY: registry in 00-readme-first.md §Active-authority boundary -->

CODEX RECHECK-3 PATCH (2026-06-09) — typed set separation. The birth gateway, DOT-118/119, and the scheduler are entry-vector / boundary concerns: they belong to U_entry_vector (doc 02 §H.4.C, fail-closed bypass coverage) and the hard-block boundary list below — they are never members of the PG-object set U_legacy_object (§H.4.A) and are never subjected to owner/body/#21 object proof. A closure that reaches a boundary object fails closed (G-ENTRY-VECTOR-SEPARATE, G-LEGACY-TARGET-CLOSED-DENOMINATOR).

OPTION-BETA PATCH (2026-06-08). Codex (design owner) approved Option Beta for the blocker-C legacy-disposition amendment. The disposition model is removed: there is no LEGACY_* #20 row, no 5-value disposition enum, no computed classifier, and no STUB_FAIL_CLOSED/ body restore. Legacy neutralization is the single uniform end-state (owner-isolated to qt001_cp_owner, body unchanged, effective privileges == exact sealed #21) over the closed U_legacy set, with no DO_NOT_TOUCH subtraction (boundary collisions fail closed). The recheck-2 hard blocks remain: (F) superuser workflow_admin use is OPERATOR-gated break-glass only (§A); (D) operator_authorization is typed PG authority (CP-09 Level-B + #07/#20/#21/#16/#19/#08 + manifest_activation), not an external-artifact authority. DO_NOT_TOUCH is now used only as a boundary/hard-block label for out-of-scope unrelated objects (the birth gateway, DOTs), never as a disposition or an automatic exclusion from U_legacy. The blueprint, implementation, and every live gate remain blocked pending Codex recheck 3.

Explicit list of objects/actions that must NOT be touched now, why, and the future gate that could unlock each. This blueprint changes none of them.

A. Hard-blocked actions (must remain blocked)

action classification why blocked now future gate that could unlock
Stage 2.6B (permit/run/keyset/resume + authority revoke) BLOCKED_UNTIL_AUTHORITY separate blocked program; not authorized by FIX7 design approval its own macro after FIX7 refactor + Codex audit + permit
qt001_backfill_permit / admission permit (open birth/backfill/apply permit) BLOCKED_UNTIL_AUTHORITY no admission/backfill permit may be opened in a blueprint/planning phase. This is distinct from operator_authorization (package-execution authority for PKG-E..H; typed PG authority = CP-09 Level-B principal + ACTIVE #07 authority_action + #20/#21 scope + #16/#19/#08 + manifest_activation payload/epoch, doc 07 §Terminology; the evidence_registry artifact is supporting evidence only), which is NOT a permit, opens no apply/admission/REAL_RUN, and creates no readiness gate (Codex BLOCKER 7) a separate birth/backfill authority gate, far future - never granted by an operator_authorization
REAL_RUN BLOCKED_UNTIL_AUTHORITY scale/capability runs are real production execution separate gate after activation + operator authority
QT001 apply (fn_dot_birth_qt001_apply, sp_dot_birth_qt001_apply) BLOCKED_UNTIL_AUTHORITY apply path has been blocked since Codex NOT_SAFE; unchanged. Under FIX7 both are U_legacy members brought to the uniform end-state (owner-isolated, body unchanged, no #21 EXECUTE grant → effective EXECUTE = 0; fail-closed by unreachability, no body stub) manifest-active path + a separate QT001-apply/qt001_backfill_permit gate, far future - never unlocked by an operator_authorization alone (G-NO-QT001-PERMIT-DURING-FIX7)
owner/ACL cutover OPERATOR_GATED destructive; strips directus authority that holds readiness BLOCKED PKG-G under explicit operator authority
manifest activation / seal OPERATOR_GATED requires quorum + epoch binding seal/stage at PKG-E; activation at PKG-F (atomic, after legacy neutralization - Codex recheck BLOCKER D), quorum + operator
Directus authority change (control objects only) OPERATOR_GATED Directus owns 262 control objects; SELECT read path must be preserved. Cutover is scoped to qt001_cp + the sealed U_legacy control objects ONLY - Directus keeps authority over its own directus_* app tables and legitimately-owned business tables (XH-4) PKG-G with G-DIRECTUS-READ + G-DIRECTUS-APP-INTACT preflight
scheduler / action enablement BLOCKED_UNTIL_AUTHORITY no scheduler/DOT/action is enabled in planning separate operator gate
production writer execution BLOCKED_UNTIL_AUTHORITY live writer stays on current blocked path until PKG-F PKG-F operator cutover
superuser workflow_admin use during FIX7 (live rolsuper=true/rolbypassrls=true/login) OPERATOR_GATED (break-glass) a cluster superuser bypasses all object ACL/RLS and cannot be reduced to effective-privilege zero; FIX7 live steps run as the Level-B migrator principal, NEVER as workflow_admin; any superuser use is break-glass only (recheck-2 BLOCKER F; G-SUPERUSER-BREAKGLASS) explicit operator break-glass record only; never a normal FIX7 path
any dangerous DOT unfreeze (DOT-118/119) DO_NOT_TOUCH (boundary) embed old gateway/direct INSERT; permanently dangerous; out-of-scope unrelated objects, never part of U_legacy (a closure that reached them is a collision → fail closed) no foreseeable unlock; stay frozen
birth gateway modification (fn_birth_registry_auto/_id, birth_registry, permit/ledger) DO_NOT_TOUCH (boundary) FIX7 references the gateway only via gateway_manifest #26; any edit risks birth-neutral + 166 triggers; a CREATE OR REPLACE of the gateway is the DOT-119 hazard - because FIX7 must not (and does not) strip directus's ownership of the birth gateway, its overwrite-protection is DETECTION (G-BIRTH-NEUTRAL gateway norm-md5) + G-DOT-FROZEN (the DOT never runs) + this DO_NOT_TOUCH policy, NOT owner-isolation; owner-isolation under G-DOT-NOOVERWRITE protects only the qt001_cp control objects + the QT001 writer gateway. It is a boundary, never subtracted from U_legacy; a closure that reaches it fails closed separate explicitly-authorized birth-gateway program only
registry-pivot repoint (re-point authoritative writers onto the new registry/control-plane as system-of-record) BLOCKED_UNTIL_AUTHORITY must not occur until birth/governance/registry truth all pass; FIX7 repoint (S13-S15) is scoped to the QT001 control-plane writer/gateway, NOT a broader registry-of-record pivot a later, separately authorized registry-pivot program after governance + registry-truth gates

Resolved (no longer a hard block): the legacy-disposition contract. The recheck-2 DESIGN_AMENDMENT_REQUIRED row for the LEGACY_* #20 rows / 5-value disposition enum / sealed disposition rule / STUB_FAIL_CLOSED body restore is removed — Codex (design owner) approved Option Beta, which eliminates all of those constructs rather than authorizing them. Legacy neutralization now uses only approved primitives (PG ownership + sealed #20 roots + #11 closure + closed-world sealed #21 + #26/#27 + manifest activation) to reach one uniform end-state. There is no disposition contract to block or to author.

B. Do-not-touch objects (no modification now)

object classification why
fn_birth_registry_auto + 166 triggers / 148 tables DO_NOT_TOUCH (boundary) live birth gateway; birth-neutral invariant; FIX7 references it only via gateway_manifest #26; not in U_legacy, collision → fail closed
fn_birth_registry_auto_id (3 BIRTH_REQUIRED tables) DO_NOT_TOUCH (boundary) live secondary gateway
fn_birth_policy_decision/_resolve_identity/_register DO_NOT_TOUCH (boundary) live shared foundation fns
birth_registry (anchor 1,210,928+) DO_NOT_TOUCH (boundary) row-count anchor; any delta = birth gateway disturbed
birth_admission_permit(+v2), birth_backfill_ledger(+v2), birth_gateway_release_registry DO_NOT_TOUCH (boundary) live permit/ledger/release contract
DOT-119 dot-birth-trigger-setup, DOT-118 dot-birth-backfill DO_NOT_TOUCH (frozen boundary) frozen dangerous DOTs (Stage 0 freeze 2/2); out-of-scope unrelated objects, never part of U_legacy
legacy qt001_* (20 tables / 46 fns / 196 views), directus-owned U_legacy members → uniform end-state at PKG-F/PKG-H not deleted live; brought to owner-isolated + #21 effective-privilege end-state only after qt001_cp active + #11 non-dependence proof; never DROPped
source IU tables / iu_core / iu_staging_* DO_NOT_TOUCH source-of-truth ingestion; no FIX7 mutation; 2 birth-trigger-gap tables noted, unchanged
Directus SELECT read set on business base tables DO_NOT_TOUCH (preserve) re-granted identically via #21; never migrated to views

C. What this blueprint explicitly did NOT do

No production DB/role/grant/trigger/function/scheduler/UI mutation; no DB object creation; no live SQL; no manifest activation; no ownership/ACL change; no permit; no Stage 2.6B; no REAL_RUN; no QT001 apply; no Directus authority change; no source IU mutation; no Codex-doc edit; no LEGACY_* #20 row, no disposition, and no STUB body — these constructs are removed by Option Beta, not authored. The only writes are the KB blueprint-doc revisions, the Option-Beta patch report (t1-fix7-blueprint-patch-after-legacy-disposition-option-beta-2026-06-08/), and the checkpoints. Production was READ-ONLY throughout (the confirmatory pg_roles read from prior passes: directus rolsuper=false, workflow_admin rolsuper=true/rolbypassrls=true, qt001_cp_* roles absent).

E. Cross-layer scope boundaries (explicitly OUT OF SCOPE for this blueprint - XHigh-L)

The FIX7 refactor is the QT001 control-plane refactor only. The following adjacent concerns are NOT addressed, NOT included, and remain blocked/future; an implementer must not pull them in:

concern classification why out of scope
registry-pivot repoint (system-of-record cutover) BLOCKED_UNTIL_AUTHORITY gated on birth/governance/registry-truth passing; separate program
Đ43 context-truth reconciliation / dedup BLOCKED_UNTIL_AUTHORITY FIX7 registries (principal/human_identity/evidence) must not duplicate or override Đ43 context truth; alignment is a later cross-layer task
QT-006 universal lifecycle / death BLOCKED_UNTIL_AUTHORITY separate approved program (design index Stage 5); not this refactor
raw birth_registry as managed-object truth DO_NOT_TOUCH raw birth is birth-event truth, not managed-object/authority truth; FIX7 authority lives in sealed manifests, not raw birth rows
memory/harness/Đ43 alignment BLOCKED_UNTIL_AUTHORITY noted as a future cross-layer step if/when required; not in PKG-A..I

This blueprint asserts these boundaries so a future reader does not mistake the QT001 control-plane repoint for a broader registry/governance/lifecycle change.

D. Unlock chain summary

FIX7 design approved (DONE)
  -> this refactor blueprint (recheck 1 + recheck-2 patches applied; 6.5/8 blockers fixed in-blueprint)
  -> [Codex recheck 2: FAIL - 8 blockers; T1 patched A/B/D/E/F/G/H, routed C to design owner]
  -> [Codex design-owner amendment for blocker C: APPROVED OPTION BETA - disposition model removed]
  -> [T1 re-patch against Option Beta: this pass - DONE]                                <== current point
  -> Codex recheck 3 of the Option-Beta-patched blueprint (NEXT, external)
  -> implementation-authoring authorization (PKG-A..D author/rehearsal/read-only)
  -> Codex re-audit + operator_authorization
  -> PKG-E create+seal+stage (OPERATOR; NO activation)
  -> PKG-F atomic owner-transfer+reconcile-to-#21+activate+repoint cutover (OPERATOR)
  -> PKG-G owner/ACL cutover of remaining relations (OPERATOR)
  -> PKG-H legacy retention (uniform end-state) (OPERATOR)
  -> PKG-I post-cutover verification
  -> (separate gates) REAL_RUN / QT001 apply / Stage 2.6B

Each arrow is a gate. Nothing past "this refactor blueprint" is authorized by the current macro; the immediate next gate is Codex recheck 3.

Back to Knowledge Hub knowledge/dev/reports/architecture/t1-fix7-existing-system-refactor-execution-blueprint-2026-06-08/08-hard-blocks-do-not-touch-list.md