FIX7 Refactor Blueprint - Final Verdict
12 - Final Self-Verdict
<!-- DOC_STATUS: ACTIVE_AUTHORITY --> <!-- AUTHORITY_BOUNDARY: registry in 00-readme-first.md §Active-authority boundary. ACTIVE = Verdict + Codex recheck-7 Constitution-Article-14 SSOT patch pass + Codex recheck-6 byte-exact-canonicalization patch pass + Codex recheck-5 canonical-envelope patch pass + Codex recheck-4 approval-envelope patch pass + Option-Beta patch pass + Codex recheck-3 set-separation patch pass + explicit asks + verdicts on dimensions + track summary + blocking status. The 'Codex RECHECK-2 patch pass', 'Codex RECHECK (owner-semantics) patch pass', 'Codex critical-review patch pass', 'A-K verdict alignment', 'Independent XHigh pass', and 'Independent Max pass' sections are SUPERSEDED_NON_AUTHORITY history (fenced below). -->Verdict
FIX7_REFACTOR_BLUEPRINT_T1_PATCHED_AFTER_CODEX_RECHECK_7_READY_FOR_CODEX_RECHECK_8
Status history: ... -> Codex critical review FAILED (7 blockers) -> T1 patched all 7 -> Codex RECHECK FAILED (owner semantics) -> T1 owner-semantics patch -> Codex RECHECK 2 FAILED (8 blockers) -> T1 recheck-2 patch (6.5/8 in-blueprint; routed blocker C to the design owner as
DESIGN_AMENDMENT_REQUIRED) -> Codex design-owner amendment APPROVED OPTION BETA (FIX7_LEGACY_DISPOSITION_DESIGN_AMENDMENT_APPROVED_OPTION_BETA;codex-fix7-legacy-disposition-design-amendment-2026-06-08/) -> T1 Option-Beta patch pass (2026-06-08,PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_LEGACY_DISPOSITION_OPTION_BETA_AMENDMENT): the legacy-disposition model is REMOVED and replaced by the single uniform end-state through approved primitives. This Option-Beta verdict supersedes the recheck-2REQUIRES_DESIGN_AMENDMENTtop-line. Implementation, Stage 2.6B,qt001_backfill_permit, REAL_RUN, QT001 apply, activation/repoint/owner-ACL cutover all remain BLOCKED. Codex recheck 3 then accepted the disposition removal but raised two narrow blockers (a mixed-typeU_legacydenominator; the no-disposition guard's whole-blueprint scope) → T1 recheck-3 set-separation patch pass (2026-06-09) split the typedU_legacy_object/U_effective_privilege_principal/U_entry_vectoruniverses and added the machine-readable active/superseded authority boundary. Codex recheck 4 then accepted all of that but found the active boundary was mutable KB metadata not pinned to the reviewed revisions/hashes → T1 recheck-4 approval-envelope patch pass (2026-06-09) added the immutable, content-addressedACTIVE_AUTHORITY_APPROVAL_ENVELOPE+ fail-closed guards. Codex recheck 5 then accepted the envelope direction, guard rebinding, and invariants/boundary, but did NOT seal: the aggregate-hash canonicalization was incomplete, the manifest omitted authority fields, doc 00'sfull_document_sha256was self-referential, the blueprint-checkpoint ACTIVE/self-host status was contradictory, and the Codex-checkpoint anchor was not bound to a revision/hash/signature/detached seal → T1 recheck-5 canonical-envelope patch pass (2026-06-09) defined the byte-exact Canonical hash encoding (FIX7-CANON-V1), the complete envelope-manifest authority-field roster, the Option-1 doc 00 self-reference resolution, the blueprint-checkpoint NON_AUTHORITY_INDEX classification, and the Codex detached seal anchor contract; guards 51 → 54 → 58 (recheck-6: byte-exact REJECT field policy + deterministic extractor + closed record/key schemas + acyclic seal hash graph; the recheck-6 cyclic checkpoint-content binding removed) → 63 (recheck-7, Constitution Article 14: one executable canonicalizer SSOT + no-duplicate-authority + non-self-referential revision anchor + exact-MCP document_id + marker kind/literal consistency). Next is Codex recheck 8 — not implementation.
Codex recheck-7 Constitution-Article-14 SSOT patch pass (2026-06-09)
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_RECHECK_7_CONSTITUTION_14_EXECUTABLE_SSOT_AND_NON_SELF_REFERENTIAL_SEAL
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Codex recheck 7
accepted the deterministic active extractor and the N1–N9 content-hash DAG (acyclic), and confirmed no
new runtime hardcode / PG-first regression and 27/11/14/7, but held authoring-planning approval on five
Constitution-Article-14 / NT14 defects. The governing principle Codex applied — and T1 has now made the
blueprint obey — is: a design is valid only if the implementation path cannot misinterpret it; every
authority/hash/guard must resolve to one executable/checkable SSOT, with no duplicate authority, no
ambiguous parser, no self-reference, no path alias, no marker ambiguity. T1 patched all five in-blueprint;
nothing accepted reopened.
| recheck-7 blocker | T1 patch | docs |
|---|---|---|
| A revision anchor still self-referential (checkpoint cannot contain its own post-write revision) | Removed own-revision equality from load-bearing authority (Option 1). Authority = detached_seal_sha256 content recompute + MCP read-back of existence; the recheck-N checkpoint's own revision is NON_AUTHORITY_DIAGNOSTIC. Finite ordered seal: stage → Codex seals (no own-revision) → platform assigns revision → optional diagnostic. Weaker guarantee explicitly accepted + compensated by separation of duties. +G-NO-SELF-REVISION-ANCHOR; status SELF_REVISION_ANCHOR_REJECTED. |
00, 06, 12 |
| B no single executable canonicalizer SSOT | Authored the executable SSOT artifact FIX7-CANON-V1-CANONICALIZER (canonicalizer-fix7-canon-v1-ssot.md): python reference + invocation (--selftest, exit 0) + I/O contract + frozen test vectors (membership f2bda8…fe251) + closed failure-status set + AUTHORING_REQUIREMENT. Pinned in the envelope by canonicalizer_artifact_id/path/version/revision/sha256 (id/version now; revision/hash sealed by Codex). +G-CANONICALIZER-SSOT-ONLY; status CANONICALIZER_SSOT_MISMATCH. |
00, 06, 07, 12, SSOT artifact |
| C duplicate canonical authority (Article 14) | Demoted doc 00's canonical/extractor/record sections + all report docs to NON_AUTHORITY_EXPLANATION of the SSOT; exactly one load-bearing canonical contract. A second load-bearing contract, a package shipping a different canonicalizer, or a report conflicting with the SSOT fails closed. +G-NO-DUPLICATE-CANONICAL-AUTHORITY (= Codex G-CANONICAL-CONTRACT-SSOT-NO-DUPLICATE); status DUPLICATE_CANONICAL_AUTHORITY. |
00, 06, 07, 12 |
| D document_id path alias | Tightened document_id to the exact MCP canonical id byte-for-byte; reject ./../empty segment////leading-or-trailing slash/backslash/%-encoding/homoglyph slash; ASCII-only segments; authoritative impl canonical_document_id() in the SSOT. +G-DOCUMENT-ID-CANONICAL-MCP; statuses DOCUMENT_ID_ALIAS_REJECTED/_NOT_MCP_CANONICAL/_SCOPE_MISMATCH. |
00, 06, 12, SSOT artifact |
| E marker contract not tight | Bound marker_kind ↔ marker_literal: closed kind enum + per-kind literal grammar; record encodes both; kind/literal mismatch, unknown kind, disallowed literal fail closed; impl check_marker() in the SSOT. +G-MARKER-KIND-LITERAL-CONSISTENCY; statuses MARKER_KIND_UNKNOWN/MARKER_LITERAL_MISMATCH/MARKER_LITERAL_NOT_ALLOWED/MARKER_KIND_LITERAL_INCONSISTENT. |
00, 06, 12, SSOT artifact |
Guards 58 → 63; guard-quality rule 12 added. Invariants 27/11/14/7 preserved (the SSOT
artifact is a pinned construction-document TOOL, not an active_corpus member — membership stays
f2bda8…fe251 — and not a runtime surface/gate/#20-col/catalog-family/8th-hash-contract). Seal event →
recheck 8; SEAL_AT_CODEX_RECHECK_7→_8; parent_recheck_checkpoint_id → recheck-7 checkpoint.
🔴 Method change (the user's standing ask). T1 stopped adding airtight prose (which Article 14 treats
as duplicate authority) and instead built the canonicalizer as real executable code and ran it:
python3 canonicalizer-fix7-canon-v1-ssot.py --selftest → 22/22 PASS, exit 0, reproducing
f2bda8…fe251 and every rejection status (TAB/null/empty; document_id ./..////empty/backslash/
%-encoded/homoglyph/leading-slash/scope/case; marker unknown/inconsistent/typo; and a seal
self-revision/self-hash edge detected as a cycle). The 15 Article-14 adversarial scenarios are computed,
not asserted (report doc 07). The implementation runs that one artifact, so the code path cannot
misinterpret the spec.
Codex recheck-6 byte-exact-canonicalization patch pass (2026-06-09)
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_RECHECK_6_BYTE_EXACT_CANONICALIZATION_AND_ACYCLIC_SEAL_GRAPH
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Codex recheck 6
accepted the full-path membership hash (f2bda8…fe251, independently reproduced), the doc 00
self-reference resolution, the blueprint-checkpoint NON_AUTHORITY classification, the invariants/boundary,
and the PG-first/typed-set separation, and left four byte-level / acyclicity blockers. T1 patched all
four in-blueprint; no runtime design amendment; nothing accepted reopened. The decisive lesson Codex
applied (and T1 has now internalized): a valid authority hash is not "this has a SHA-256" — it requires a
byte-exact input, a parser/extractor, escaping-or-rejection rules, domain separation, a canonical
sort/order, no reserved-token injection, and no cyclic dependency graph.
| recheck-6 blocker | T1 patch | docs |
|---|---|---|
| A canonical encoding not byte-exact (no escaping/rejection for TAB/LF/reserved tokens) | REJECT-not-escape Field rejection policy in FIX7-CANON-V1: per-field whitelist grammar + forbidden-byte (TAB/LF/CR/NUL/backslash) + forbidden reserved-token + no-null/no-empty; statuses CANONICAL_FIELD_RESERVED_TOKEN_REJECTED / _VALUE_GRAMMAR_REJECTED / _NULL_REJECTED / _EMPTY_REJECTED. +G-CANONICAL-FIELD-REJECT. |
00, 06, 12 |
| B no exact active-scope/fence/section extractor; manifest/seal records need human interpretation | One deterministic extractor (normalize CRLF/CR→LF first, 1-based lines, exact marker grammar, single DOC_STATUS, flat non-nesting, re-emit line+LF) with fail-closed statuses for every ambiguity (ACTIVE_SCOPE_MARKER_MISSING/_DUPLICATE, FENCE_UNBALANCED/_NESTED_UNSUPPORTED, ACTIVE_SUPERSEDED_OVERLAP, SECTION_ID/_RANGE_MISMATCH, EXCLUDE_REGION_UNBALANCED, MARKER_REGISTRY_MISMATCH); section identity by marker structure (controlled tokens), never heading text; closed envelope key-classification schema (every key MANIFEST_BOUND / SEAL_LAYER_READBACK_PROTECTED / NON_AUTHORITY_DIAGNOSTIC / STRUCTURAL_CONTRACT_PROSE). +G-ACTIVE-SCOPE-EXTRACTOR. |
00, 06, 07, 12 |
| C manifest/detached-seal record encoding ambiguity | Closed record-encoding schema for every record type (domain tag + fixed field list/order + grammar + sort key + no-null/no-empty + full-path document_id); manifest is fixed-roster-order with key\tvalue scalars + sorted sub-records; superseded fenced regions moved from prose into superseded_boundary_sha256 (superseded_id + L-range). +G-RECORD-ENCODING-CLOSED. |
00, 06, 12 |
| D/E detached-seal self-reference cycle | Acyclic seal hash DAG N1..N9: envelope_manifest_sha256 (N7) binds NO Codex-checkpoint revision/content hash and not the seal; detached_seal_sha256 (N8) excludes itself + signature and never hashes its own checkpoint; the removed seal_report_checkpoint_content_sha256 becomes the diagnostic codex_checkpoint_content_sha256_excluding_seal (N9), consumed by nothing. Checkpoint anchored out-of-band by platform revision + MCP read-back + Codex authorship, with the stated limitation that a fully-privileged both-sides forger is not cryptographically prevented (separation of duties compensates). +G-SEAL-HASH-GRAPH-ACYCLIC; status SEAL_HASH_GRAPH_CYCLE. |
00, 06, 12 |
Guards 54 → 58. Invariants 27/11/14/7 preserved (non-runtime construction-document
content-address; no 8th runtime hash contract; H01..H07 stay 7). The seal event moves from recheck 6 to
recheck 7 (recheck 6 did not seal); all SEAL_AT_CODEX_RECHECK_6 placeholders become
SEAL_AT_CODEX_RECHECK_7 and parent_recheck_checkpoint_id now points at the recheck-6 checkpoint.
Codex-style adversarial self-review: 15/15 PASS, hash/extractor/DAG cases COMPUTED in python (report
doc 08): TAB/LF/CR/NUL/backslash + every reserved token rejected; marker missing/duplicate, fence
unbalanced/nested, overlap, section id/range, exclude unbalanced all fail closed; canonical sort stable
under record reorder; field reorder differs; null≠empty rejected; the membership hash still reproduces
f2bda8…fe251; and the two old cyclic edges (manifest→checkpoint, seal→own-checkpoint) are detected as
cycles while the new graph topologically sorts.
Codex recheck-5 canonical-envelope patch pass (2026-06-09)
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_RECHECK_5_CANONICAL_ENVELOPE_SEALING
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Codex recheck 5
accepted the envelope direction, the guard rebinding, and the invariants/boundary
(INVARIANTS_BOUNDARY_FINAL_ACCEPTED), and left six canonical-encoding / seal / anchor blockers.
T1 patched all six in-blueprint; no runtime design amendment, nothing accepted reopened.
| recheck-5 blocker | T1 patch | docs |
|---|---|---|
| A — aggregate-hash canonicalization incomplete | Canonical hash encoding (FIX7-CANON-V1) in doc 00: domain tag + record type + field order + sort key + TAB/LF separators + newline normalization + UTF-8 + null/boolean tokens + full-path normalization + revision representation + trailing-LF + reproducible shasum/hashlib command per aggregate (membership, corpus, marker/fence registry, superseded boundary, guard-set, per-doc normalized content, manifest, detached seal). No prose-only / unordered hash. active_corpus_membership_sha256 recomputed over full canonical paths = f2bda8ef…fe251. +G-CANONICAL-ENCODING-CONTRACT. |
00, 06, 12, checkpoint |
| B — manifest omits authority fields | envelope_manifest_sha256 now binds the complete authority-field roster (canonical_encoding_version, seal_version, blueprint_id, envelope_state, approved_status/epoch/role/time, parent + sealing checkpoint ids, recheck-on-change, digest algorithm, full-doc policy, membership, corpus, marker/fence, superseded boundary, guard-set rev+hash, per-doc tuples, superseded list, detached-seal binding) EXCEPT itself + detached_seal_sha256. Unknown/missing field → fail closed. +G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE. |
00, 06, 12, checkpoint |
| C — doc 00 self-reference | Option 1: normalized_active_content_sha256 (load-bearing) excludes the ENVELOPE:EXCLUDE region; full_document_sha256 is NON_AUTHORITY_DIAGNOSTIC for every member (declared policy). No full-doc-vs-exclude contradiction; the envelope is tamper-protected by the detached seal, not by doc 00's own hash. |
00, 06, 12, checkpoint |
| D — blueprint checkpoint self-host/ACTIVE ambiguity | the blueprint checkpoint is reclassified NON_AUTHORITY_INDEX (DERIVED_STATUS / REPORT_ONLY): not a member, not a self-host, no guard/package consumes it as authority. The sole self-host is doc 00. | 00, 06, 07, 12, checkpoint |
| E — Codex checkpoint not an immutable anchor | Codex detached seal anchor contract: a Codex-authored CODEX_DETACHED_SEAL block (seal_version, sealed_by/at, sealed manifest/corpus/membership hashes, parent checkpoint, report doc ids+revisions+hashes, signature or signature_not_available_in_current_tooling). Compensating fail-closed rule: revision + SHA-256 + MCP read-back + mismatch guard. +G-CODEX-DETACHED-SEAL-ANCHOR. |
00, 06, 12, checkpoint |
| F — fail-closed guards must use canonical hashes | G-ACTIVE-AUTHORITY-HASH-MATCH / -REVISION-MATCH / -CHANGE-FAIL-CLOSED / G-NO-SUPERSEDED-CONSUMPTION / G-LEGACY-NO-DISPOSITION-AUTHORITY re-bound to the canonical FIX7-CANON-V1 digests + the Codex detached seal; guard-quality rule 10 added. |
06, 07, 12 |
Guards 51 → 54. Invariants 27/11/14/7 preserved — the canonical envelope + detached seal are a
non-runtime construction-document content-address (no runtime authority surface, readiness gate,
#20 column, catalog family, or 8th top-level runtime hash contract; H01..H07 stay 7). All hard blocks
intact. No fresh live read required. Adversarial canonicalization self-audit: 12/12 PASS (report
doc 08). Patch report:
t1-fix7-blueprint-patch-after-codex-recheck-5-canonical-envelope-2026-06-09/00..12.
Codex recheck-4 approval-envelope patch pass (2026-06-09)
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_RECHECK_4_ACTIVE_AUTHORITY_HASH_ENVELOPE
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Codex recheck 4
accepted object-only legacy universe, principal separation, entry-vector separation,
uniform-end-state scope, PG-native-final, and 27/11/14/7 + all execution boundaries. The single
remaining blocker class: the ACTIVE_AUTHORITY corpus was classified only by mutable KB
markers/registry/fences and was not pinned to the exact Codex-reviewed revisions/content hashes —
a mutable authoring-authority denominator (disguised hardcode), which also kept the no-disposition
guard, the hardcode-final check, and authoring-planning blocked. T1 patched it in-blueprint; no
runtime design amendment.
| recheck-4 blocker | T1 patch | docs |
|---|---|---|
E ACTIVE_SUPERSEDED_BOUNDARY_NEEDS_FIX (mutable boundary) |
added the immutable, content-addressed ACTIVE_AUTHORITY_APPROVAL_ENVELOPE (doc 00): every ACTIVE doc/section + KB revision + normalized SHA-256, plus registry / marker-fence / guard-set / membership / manifest hashes + the Codex recheck checkpoint anchor; sealed at the Codex recheck; the corpus-membership hash is computed now (916d6e11…), per-doc body hashes seal at recheck-5. +G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE, +G-ACTIVE-AUTHORITY-HASH-MATCH, +G-ACTIVE-AUTHORITY-REVISION-MATCH, +G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED; G-ACTIVE-AUTHORITY-SCOPE extended to verify the envelope, not only markers |
00,06,07,12 |
F NO_DISPOSITION_GUARD_NEEDS_FIX (depends on unpinned scope) |
G-LEGACY-NO-DISPOSITION-AUTHORITY and G-NO-SUPERSEDED-CONSUMPTION re-bound to the sealed envelope (exact reviewed revisions/hashes); fail if the envelope is absent/unsealed or any active doc/section revision/hash mismatches |
06 |
G HARDCODE_FINAL_NEEDS_FIX (mutable authoring denominator) |
guard-quality rule 9 (content-addressed authoring authority): an unpinned/mutable authoring-authority corpus is a disguised hardcode; the envelope pins it; PG-native runtime design unchanged (Codex accepted PG_NATIVE_FINAL) |
06 |
J AUTHORING_PLANNING_NEEDS_T1_FIX |
PKG-A gated on a SEALED, verified envelope; packages consume ONLY the envelope-pinned ACTIVE corpus; any drift → ACTIVE_AUTHORITY_ENVELOPE_MISMATCH → STOP and return to Codex recheck, never "continue authoring" |
07 |
Fail-closed semantics. Any mismatch in document revision, active content hash, marker/fence hash,
registry hash, guard-set hash, active-section identity, corpus membership, or doc status →
ACTIVE_AUTHORITY_ENVELOPE_MISMATCH → implementation-authoring planning is BLOCKED until a fresh Codex
recheck re-seals the envelope. After Codex PASS, any change to ACTIVE docs/sections/markers/fences/
registry/guard-set invalidates approval; the correct next step is Codex recheck, not continued authoring.
Seal timing. The per-document content SHA-256 of the approved corpus can only be computed over the corpus as approved, which finalizes at the approval event; T1 pre-writing "approved" hashes would itself be self-fabricated authority (the anti-pattern this chain polices). So T1 authored the envelope STAGED, pinned the real current KB revisions + the now-stable corpus-membership hash, and specified a deterministic computation; Codex computes and seals the per-document hashes at recheck-5 PASS and records the sealed envelope in the recheck-5 checkpoint (the immutable anchor).
Guards 47 → 51 (+G-ACTIVE-AUTHORITY-APPROVAL-ENVELOPE, +G-ACTIVE-AUTHORITY-HASH-MATCH,
+G-ACTIVE-AUTHORITY-REVISION-MATCH, +G-ACTIVE-AUTHORITY-CHANGE-FAIL-CLOSED; +guard-quality rule 9;
G-ACTIVE-AUTHORITY-SCOPE / G-NO-SUPERSEDED-CONSUMPTION / G-LEGACY-NO-DISPOSITION-AUTHORITY re-bound to
the sealed envelope). Invariants 27/11/14/7 preserved — the envelope is a non-runtime
construction-document content-address (it pins the blueprint docs being authored from), explicitly
NOT a runtime authority surface, readiness gate, #20 column, catalog family, or 8th top-level FIX7
runtime hash contract (H01..H07 stay 7). All hard blocks intact. No fresh live read required. Patch
report: t1-fix7-blueprint-patch-after-codex-recheck-4-active-authority-envelope-2026-06-09/00..10.
Why READY_FOR_CODEX_RECHECK_5 (not the other recheck-4 statuses)
- Not
..._PATCH_AFTER_RECHECK_4_NEEDS_MORE_T1_WORK: the single blocker class (mutable active boundary) is patched in-blueprint; the content-addressed envelope + four fail-closed guards + the re-bound scope/no-disposition/no-superseded guards + guard-quality rule 9 are in place; the ten-point adversarial self-audit passes (report doc 06). - Not
..._PATCH_AFTER_RECHECK_4_FAIL_HARDCODE_OR_PG_NATIVE_GAP: the patch REMOVES a disguised-hardcode (mutable authoring denominator) by content-addressing it; it adds no runtime name/pattern/owner authority and no runtime surface — Codex'sPG_NATIVE_FINAL_ACCEPTEDandINVARIANTS_BOUNDARY_FINAL_ACCEPTEDare preserved. - Not
READ_PATH_BLOCKED: the recheck-4 package, the recheck-3 patch, the current blueprint, the amendment/approval sources, and the prior live evidence were all readable read-only.
Codex recheck-3 set-separation patch pass (2026-06-09)
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_RECHECK_3_SET_SEPARATION_AND_SUPERSEDED_HISTORY
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Codex recheck 3
accepted the Option-Beta disposition/STUB/DO_NOT_TOUCH-subtraction removal and confirmed 27/11/14/7
- boundaries, but raised two narrow blockers. Both are patched in-blueprint; no design amendment required.
| recheck-3 blocker | T1 patch | docs |
|---|---|---|
1 mixed-type denominator (U_legacy unioned PG objects + principals + entry-vectors, then asserted object both-EXCEPT — a type error) |
split into three typed universes: U_legacy_object (PG objects only — the uniform-end-state both-EXCEPT, §H.4.A), U_effective_privilege_principal (roles — the object × principal privilege-tuple join to #21, §H.4.B), U_entry_vector (trigger/event-trigger/scheduler/DOT/external — fail-closed bypass-coverage relation, §H.4.C). U_legacy ≡ U_legacy_object; no set is a member of another. Added G-U-LEGACY-OBJECT-ONLY, G-PRINCIPAL-SET-SEPARATE, G-ENTRY-VECTOR-SEPARATE; re-scoped G-LEGACY-TARGET-CLOSED-DENOMINATOR to object-shape; guard-quality rule 7 |
02,03,04,05,06,07,08,12 |
| 2 no-disposition guard scanned the whole blueprint while history retained old disposition/STUB terms | introduced a machine-readable ACTIVE_AUTHORITY vs SUPERSEDED_NON_AUTHORITY boundary (doc 00 registry + per-doc DOC_STATUS markers + SUPERSEDED_NON_AUTHORITY BEGIN/END fences, not Directus-editable); re-scoped G-LEGACY-NO-DISPOSITION-AUTHORITY to ACTIVE_AUTHORITY (reports fenced history, never fails on it); added G-ACTIVE-AUTHORITY-SCOPE, G-NO-SUPERSEDED-CONSUMPTION; guard-quality rule 8; fenced the historical pass sections in this doc, doc 00, and the checkpoint |
00,04,06,07,08,12 |
Guards 42 → 47 (+G-U-LEGACY-OBJECT-ONLY, +G-PRINCIPAL-SET-SEPARATE, +G-ENTRY-VECTOR-SEPARATE,
+G-ACTIVE-AUTHORITY-SCOPE, +G-NO-SUPERSEDED-CONSUMPTION; guard-quality rules 7+8). Invariants
27/11/14/7 preserved (0 new authority surface, 0 new readiness gate, 0 new top-level hash contract,
0 new #20 column, 0 new catalog family; the active/superseded boundary is document metadata, not
a DB authority surface). All hard blocks intact. No fresh live read required (prior pg_roles
evidence stands: directus non-superuser; workflow_admin superuser; qt001_cp_* roles absent;
0 trigger bypass vector). Patch report:
t1-fix7-blueprint-patch-after-codex-recheck-3-set-separation-2026-06-08/00..11.
Why READY_FOR_CODEX_RECHECK_4 (not the other recheck-3 statuses)
- Not
..._PATCH_AFTER_RECHECK_3_NEEDS_MORE_T1_WORK: both narrow blockers are patched in-blueprint against existing surfaces; the three typed sets are defined with their guards, and the active/superseded boundary is machine-readable; no residual T1 gap remains. - Not
..._PATCH_AFTER_RECHECK_3_FAIL_HARDCODE_OR_PG_NATIVE_GAP: the patch adds no name/pattern/ owner/manual-history authority; object membership stays PG-object closure, privilege stays the catalog/pg_auth_memberstuple reconciliation to sealed #21, bypass stays catalog entry-vector coverage, and the boundary is document metadata under T1/Codex authoring discipline (not Directus-editable). - Not
READ_PATH_BLOCKED: the recheck-3 package, the Option-Beta patch, the current blueprint, the amendment/approval sources, and the prior live evidence were all readable read-only.
Option-Beta legacy-disposition amendment patch pass (2026-06-08)
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_LEGACY_DISPOSITION_OPTION_BETA_AMENDMENT
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Codex (design owner)
approved Option Beta for blocker C, ruling that the disposition concept is REPLACED — not
re-homed — and that every U_legacy member must converge to one uniform authority-neutralized
end-state through existing approved primitives. T1 patched the blueprint to that ruling.
| Amendment blocker | T1 patch | docs |
|---|---|---|
| 1 remove legacy-disposition model completely | removed the 5-value enum, LEGACY_* #20 object_type semantics, computed/classifier/truth-table/CASE disposition, external-artifact policy, STUB_FAIL_CLOSED/body mutation/body restore, and all policy branching by relkind/prokind/name/owner/pattern/label. Former labels survive only as non-authority English (never manifest authority/rule I/O/guard decision/package branch/hash member/SQL predicate); G-LEGACY-NO-DISPOSITION-AUTHORITY enforces this |
02,03,04,05,06,07,08,12 |
2 redefine U_legacy under Option Beta |
U_legacy = closure(#11, roots = #20 protected_target rows bound to the candidate manifest) — a single sealed in-scope set; no DO_NOT_TOUCH subtraction, no class-based exclusion; boundary collisions fail closed; both-EXCEPT vs the closed denominator; relkind/prokind select PG syntax only. Added G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE |
02,04,06,07,12 |
| 3 remove STUB/body mutation path | no legacy body mutation, no body restore, no STUB source artifact; rollback restores authority state via forward-only supersede/deactivate + the owner/ACL snapshot only; source artifacts are evidence only, never rollback body authority | 04,05,06,07,12 |
| 4 owner isolation + #21 privilege contract as the authority path | every U_legacy member: owner-isolated to qt001_cp_owner, body unchanged, effective privileges == exact closed-world sealed #21 (both-EXCEPT, role-membership-aware); directus/runtime effective authority absent unless #21 grants read-only; G-NOLEGACY-POST + G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE verify the uniform end-state, not disposition branches |
04,06,07,12 |
| 5 remove DO_NOT_TOUCH as authority exclusion | DO_NOT_TOUCH is a boundary/hard-block label for out-of-scope unrelated objects only (birth gateway, DOTs); it cannot subtract from U_legacy; a closure that collides with a boundary/hard-block fails closed / requires owner review, never auto-exclusion |
02,04,06,08,12 |
| 6 hardcode / PG-native self-review | PASS — no disposition enum, classifier, CASE policy, relkind/prokind policy branch, name/pattern/owner authority, item_payload loophole, external-artifact policy, STUB/body path, or DO_NOT_TOUCH subtraction; U_legacy sealed/hash-bound; end-state uniform and PG-native; #21 is the authority for final effective privileges (doc 07 of the patch report) |
(self-review) |
| 7 cross-layer boundaries | unchanged — implementation, Stage 2.6B, QT001 apply, qt001_backfill_permit, REAL_RUN, activation/repoint/cutover all BLOCKED; governance reconciliation / registry-pivot / Đ43 / harness alignment later; runtime evidence non-authority (doc 08 of the patch report) |
(self-review) |
Guards 40 -> 42 (+G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE, +G-LEGACY-NO-DISPOSITION-AUTHORITY;
G-LEGACY-TARGET-SEALED + G-LEGACY-TARGET-CLOSED-DENOMINATOR now fully operational with no
LEGACY_*/disposition dependency and no DO_NOT_TOUCH subtraction; the former G-LEGACY-FROZEN
reframed as G-LEGACY-RETAINED at the uniform end-state). Invariants 27/11/14/7 preserved (0 new
authority surface, 0 new readiness gate, 0 new top-level hash contract, 0 new #20 column, 0 new
catalog family). All hard blocks intact. Patch report:
t1-fix7-blueprint-patch-after-legacy-disposition-option-beta-2026-06-08/00..10.
Why READY_FOR_CODEX_RECHECK_3 (not the other Option-Beta statuses)
- Not
..._OPTION_BETA_PATCH_NEEDS_MORE_T1_WORK: every amendment blocker (1-7) is patched in-blueprint against approved primitives; the disposition model is fully removed and the uniform end-state + guards are in place; no residual T1 gap remains. - Not
..._OPTION_BETA_PATCH_FAIL_HARDCODE_OR_PG_NATIVE_GAP: the patch REMOVES (does not add) the disposition/CASE/label/name-pattern constructs; authority is PG ownership + sealed #20 roots + #11 closure + closed-world #21 + #26/#27 + manifest activation; the hardcode/PG-native self-review (doc 07 of the patch report) is clean. - Not
READ_PATH_BLOCKED: the Option-Beta amendment package, the recheck-2 patch, the current blueprint, the design-approval source, and the prior livepg_rolesevidence were all readable.
The sub-sections below are SUPERSEDED_NON_AUTHORITY history — records of how earlier rounds were fixed. The constructs they describe (the five-value disposition enum,
STUB_FAIL_CLOSED,LEGACY_*rows, the− DO_NOT_TOUCHsubtraction, the mixedrule1 ∪ rule2 ∪ rule3denominator) were REMOVED by Option Beta and superseded by the recheck-3 set separation. They are retained as audit trail and MUST NOT be consumed as current authority (G-NO-SUPERSEDED-CONSUMPTION,G-LEGACY-NO-DISPOSITION-AUTHORITYscopes to ACTIVE_AUTHORITY only).
Codex RECHECK-2 patch pass (2026-06-08) — 6.5/8 in-blueprint; blocker C → design amendment
T1 acted on PROGRAM_PATCH_T1_FIX7_BLUEPRINT_AFTER_CODEX_RECHECK_2_PG_AUTHORITY_CONTRACT_FAIL
(READ-ONLY production; blueprint KB-doc direct-revision; no production mutation). Analysis against the
approved byte-level DDL (codex-fix7-spec-artifact-correction-.../02 rev10 / /09 / /10 / /03)
and a fresh pg_roles read showed that 6.5 of 8 blockers bind to already-approved surfaces, and that
the legacy-disposition contract (C) has no approved home — so retrofitting it a third time would
repeat the recheck-1 (DDL drift) and recheck-2 (disguised hardcode) failures. Per law §4G
(governance/design change is a T1 HARD-STOP) and Codex's own decision tree, C is routed to the design
owner. Full detail: t1-fix7-blueprint-patch-after-codex-recheck-2-pg-authority-contract-2026-06-08/.
| # | recheck-2 blocker | disposition | docs |
|---|---|---|---|
| A | qt001_cp_owner operational reachability uncontrolled |
PATCHED — NOLOGIN (CP-01 §2.1) + no inbound pg_auth_members membership from any login role + SET-ROLE only via sealed Level-B principal (CP-09); +G-OWNER-UNREACHABLE |
04,06,08,12 |
| B | U_legacy lacks independent PG-native root denominator |
PATCHED — roots = sealed #20 protected_target TABLE rows + #26 protected_target_set_sha256 (independent, hash-sealed before use); closure derived by #24 analyzer into #11 reverse edges; dynamic/unsupported calls fail closed |
02,06,07,12 |
| C | computed disposition lacks sealed truth-table/rule; LEGACY_* #20 rows = free-text policy drift |
DESIGN_AMENDMENT_REQUIRED — no approved home (sealed exact catalog families CP-03; no #20 disposition/root_kind column; §2.7 scope; item_payload forbidden). Options α (add typed contract) / β (collapse to approved primitives). §§H.2/I withdrawn/fail-closed |
02,04,06,07,08,12 |
| D | operator authorization lacks typed PG inputs | PATCHED — bound to CP-09 Level-B + #07 authority_action + #20/#21 scope + #16/#19/#08 + manifest_activation payload/epoch; evidence artifact = supporting only; +G-OPERATOR-AUTH-PG-NATIVE |
04,06,07,08,12 |
| E | rollback artifact not uniquely bound to evidence_id |
PATCHED (forward-only) — manifest rollback re-activates the prior immutable sealed version; legacy owner/ACL rollback source = S14 snapshot uniquely bound by manifest_activation.rollback_evidence_id. The legacy STUB body-restore binding rides on the C amendment (Option β eliminates it) |
02,04,05,06,07,12 |
| F | workflow_admin superuser/bypassrls uncontrolled |
PATCHED — outside ACL-zero model; FIX7 operator session = Level-B principal, never workflow_admin; readiness = "no unauthorized superuser use path"; +G-SUPERUSER-BREAKGLASS |
04,06,08,12 |
| G | rollback clears activated_at (forward-only violation) |
PATCHED — rollback supersedes forward (new manifest_activation of prior payload + superseded_by_manifest_id); never clears/edits activated_at; G-NOMIXED reads the derived current-active route |
02,04,05,06,07,12 |
| H | author/rehearse/seal order inconsistent | PATCHED — #11/#20/#26/#27 + denominator/rollback bindings authored (PKG-B) and rehearsed in the SAME complete set PKG-C seals; PKG-D = read-only re-validation; +G-SEAL-AFTER-AUTHOR-REHEARSE | 04,06,07,12 |
Guards 36 -> 40 (+G-OWNER-UNREACHABLE, +G-SUPERUSER-BREAKGLASS, +G-SEAL-AFTER-AUTHOR-REHEARSE, +G-OPERATOR-AUTH-PG-NATIVE; G-NOMIXED-AUTHORITY corrected to forward-only; G-LEGACY-TARGET-SEALED + the disposition aspect of G-LEGACY-TARGET-CLOSED-DENOMINATOR fail-closed pending the C amendment). Invariants 27/11/14/7 preserved (0 new authority surface, 0 new readiness gate, 0 new hash contract, 0 new #20 column, 0 new catalog family). All hard blocks intact.
Why REQUIRES_DESIGN_AMENDMENT (not the other recheck-2 statuses)
- Not
..._READY_FOR_CODEX_RECHECK_3: blocker C cannot be resolved in-blueprint without either byte-DDL drift (rejected recheck 1) or disguised hardcode (rejected recheck 2); declaring READY would invite a third retrofit. Law §4G makes the disposition-model decision a design-owner HARD-STOP. - Not
..._NEEDS_MORE_T1_WORK: C is not a matter of more T1 effort — the approved 27-surface design has no typed home for the disposition enum/rule or the legacy-routine-as-authority-object; this is a design-semantics gap, not a blueprint-authoring gap. - Not
..._FAIL_HARDCODE_OR_PG_NATIVE_GAP: T1's patch REMOVES the rejected disguised-hardcode constructs (withdrawsLEGACY_*#20 rows, the computed classifier, the evidence-as-authority framing, theactivated_atclear) and re-expresses everything resolvable via approved PG-native surfaces; the remaining gap is a missing DESIGN surface, captured precisely as the amendment. - Not
READ_PATH_BLOCKED: all recheck-2 docs, prior patches, the blueprint, the approved byte DDL, and livepg_roleswere readable read-only.
Codex RECHECK patch pass (2026-06-08) - owner-semantics + recheck blockers fixed in-blueprint
Codex's recheck failed the patched blueprint with a decisive root cause: at S15 the legacy routines
were still owned by directus, and a PostgreSQL object owner keeps implicit privileges, so REVOKE
alone can never make directus effective EXECUTE = 0 - G-NOLEGACY-POST was impossible as ordered.
T1 re-patched every recheck blocker (A-H) directly in-blueprint, grounded on fresh read-only live
evidence and the approved byte-level DDL. No design amendment was required: every fix uses an
already-approved surface/column. Live grounding: directus is non-superuser (rolsuper=false),
so ownership-transfer-off-directus + REVOKE can reach effective-EXECUTE=0; the cluster superuser
workflow_admin (rolsuper/rolbypassrls) inherently bypasses ACL and is explicitly dispositioned.
| # | recheck blocker | fix | docs |
|---|---|---|---|
| A | PG owner semantics / G-NOLEGACY phase impossible | S14 STAGED (no activation); S15 atomic ordered owner-transfer (off directus→qt001_cp_owner) → REVOKE/stub → verify G-NOLEGACY-POST → activate+repoint; POST placed after the transfer that makes it possible; superuser dispositioned |
02,04,05,06,07,08,12 |
| B | legacy set has no closed PG-native denominator | closed universe U_legacy = reverse write-effect closure (#11/#22 + analyzer edges) ∪ effective-EXECUTE principals ∪ entry-vectors − DO_NOT_TOUCH; both-EXCEPT-equal; +G-LEGACY-TARGET-CLOSED-DENOMINATOR |
02,04,06,07,12 |
| C | added #20 columns/hash beyond approved byte DDL | mapped to existing approved #20 columns (object_type/protected_target/entrypoint/expected_owner_role/expected_acl_sha256/source_sha256); disposition computed (no column, no catalog family); set integrity = existing manifest seal (no expected_legacy_set_sha256 column) - 0 new column |
02,04,06,07,12 |
| D | G-NOMIXED conflicts with S14 ACTIVE | S14 STAGED (activated_at NULL); activation moved into atomic PKG-F after neutralization; G-NOMIXED tests the ACTIVE route fact, not manifest existence |
04,05,06,07,08,12 |
| E | source_sha256 is not a restorable body |
STUB body/stub restore source = sealed evidence_registry artifact (artifact_uri+artifact_sha256, read-back-verified), pinned by #27; if absent, body change not allowed (→ REVOKE_ONLY + owner isolation) |
02,04,05,06,12 |
| F | expected_legacy_set_sha256 / operator_authorization lack PG-native contract |
set-hash eliminated (manifest seal + both-EXCEPT); operator_authorization_artifact = evidence_registry row (non-authority evidence) consumed by a PG-native decision (role grant + activation quorum/epoch + live==approved both-EXCEPT) |
02,04,07,08,12 |
| G | stale "operator permit" wording in doc 08 | replaced with operator_authorization in the unlock chain; qt001_backfill_permit stays BLOCKED; grep-claim below |
08,12 |
| H | ACL snapshot execution-order dependency | snapshot captured at S14, BEFORE the S15.1 owner transfer; effective-privilege verification after transfer+revoke; superuser dispositioned | 04,05,06,07,12 |
Guards 35 -> 36 (+G-LEGACY-TARGET-CLOSED-DENOMINATOR; G-NOLEGACY-POST / G-NOMIXED-AUTHORITY / G-LEGACY-TARGET-SEALED / G-OWNER-CUTOVER tightened; guard-quality rule 5 added for PG privilege semantics). Invariants 27/11/14/7 preserved (0 new authority surface, 0 new readiness gate, 0 new hash contract, 0 new #20 column, 0 new catalog family). All hard blocks intact.
Grep claim (Codex recheck BLOCKER G): no load-bearing "operator permit" remains in the blueprint;
the only "permit" term is qt001_backfill_permit (the BLOCKED admission/backfill permit). Package
execution is operator_authorization everywhere.
Codex critical-review patch pass (2026-06-08) - 7 blockers fixed in-blueprint
T1 acted on PROGRAM_PATCH_T1_FIX7_REFACTOR_BLUEPRINT_AFTER_CODEX_CRITICAL_FAIL (READ-ONLY
production; blueprint KB-doc direct-revision only; no production mutation). Each Codex blocker was
patched and self-checked; full detail in the patch report
t1-fix7-blueprint-patch-after-codex-critical-fail-2026-06-08/00..12.
| # | Codex blocker | fix | docs | self-check |
|---|---|---|---|---|
| 1 | legacy target = disguised hardcode (owner+name pattern) | sealed legacy-disposition set in authority_scope_manifest #20 (typed identity + source/priv hash + exact-set both-EXCEPT vs catalog); name/owner scan = diagnostic candidate only; +G-LEGACY-TARGET-SEALED; G-PGNATIVE extended. Live proof of name-pattern fragility: views 0/183/196 by literal; routines 45 fns + 1 proc |
01,02,03,04,06,07,08 | PASS - target sealed/manifest/hash-bound, not pattern-bound |
| 2 | G-NOLEGACY phase-deadlock | split into G-NOLEGACY-PRE (gates PKG-F, no EXECUTE-revoked requirement) + G-NOLEGACY-POST (verifies PKG-F) | 04,06,07 | PASS - PRE gates, POST verifies; deadlock removed |
| 3 | stub-scope contradiction ("stub all" vs "apply/writer only") | 5 dispositions (REVOKE_ONLY/STUB_FAIL_CLOSED/FREEZE_NO_CHANGE/DEPRECATE_READONLY/DO_NOT_TOUCH); stub only STUB_FAIL_CLOSED; body-rollback bounded to those (pinned #27) | 02,04,05,06,07,08 | PASS - one disposition per object; symmetric rollback |
| 4 | rollback may reopen PUBLIC EXECUTE with new plane present | atomic deactivation-first rollback (supersede new path → verify BLOCKED → verify no route → restore per disposition → verify no-mixed); +G-NOMIXED-AUTHORITY | 04,05,06,07 | PASS - mixed old+new authority impossible |
| 5 | ACL snapshot incomplete | +column ACL (pg_attribute.attacl) +effective role-membership privilege (pg_auth_members) +sequence/default/PUBLIC/Directus/cp grants +snapshot hash; both-direction effective-privilege rollback verify |
05,06,07 | PASS - column ACL + effective privilege covered |
| 6 | writer gateway identity/owner ambiguous at S15/S16 | pinned #26 identity (regprocedure+source_sha256+owner), phase-explicit owner table (gateway born qt001_cp_owner, no transition); +G-WRITER-GATEWAY-IDENTITY; fn_birth_registry_auto = DO_NOT_TOUCH, not the gateway | 02,04,06,07,08 | PASS - identity/owner/hash/binding pinned per phase |
| 7 | "permit" ambiguous vs operator authorization | operator_authorization (package execution, machine-checkable artifact) vs qt001_backfill_permit (BLOCKED) vs REAL_RUN_authority (BLOCKED); +G-NO-QT001-PERMIT-DURING-FIX7; law §4G citation corrected |
03,04,07,08,12 | PASS - separated; QT001 permit stays blocked |
A-K verdict alignment (Codex doc 11 → patched state)
| Codex check | Codex verdict | patched state |
|---|---|---|
| A scope/refactor model | PASS_WITH_BLOCKING_EXECUTION_DETAILS | execution details fixed (B-H below); model unchanged |
| B MB-01 legacy neutralization | FAIL_NEEDS_T1_FIX | FIXED - sealed set + dispositions (BLOCKER 1+3) |
| C MG-01 re-audit gates | NEEDS_T1_FIX | FIXED - machine-checkable operator_authorization; permit separated (BLOCKER 7) |
| D DOT no-overwrite / PG authority | HOLD_NEEDS_IDENTITY_AND_PHASE_FIX | FIXED - phase-explicit gateway identity (BLOCKER 6) |
| E rollback/cutover safety | FAIL_NEEDS_T1_FIX | FIXED - atomic no-mixed-authority + symmetric body rollback (BLOCKER 3+4) |
| F owner/ACL snapshot | NEEDS_T1_FIX | FIXED - column ACL + effective privilege (BLOCKER 5) |
| G guard quality | FAIL_NEEDS_T1_FIX | FIXED - G-NOLEGACY PRE/POST; non-vacuity rules intact (BLOCKER 2) |
| H hardcode / disguised hardcode | FAIL | FIXED - sealed/hash-bound target, not name pattern (BLOCKER 1) |
| I PG-first/native/driven | FAIL | FIXED - G-PGNATIVE rejects name-pattern binding authority (BLOCKER 1) |
| J cross-layer/boundaries | PASS_WITH_TERMINOLOGY_FIX_REQUIRED | FIXED - permit terminology separated (BLOCKER 7) |
| K authoring-planning readiness | NOT_READY | all 7 minimum acceptance conditions (doc 10) addressed; resubmitted for Codex recheck |
The construction blueprint for refactoring the existing production system onto the officially Codex-approved FIX7 design is complete. The internal XHigh and Max adversarial reviews both ran, found real defects, and the blueprint was revised inside this macro until both passed. No fake PASS, no production mutation, no hardcode, no PG-native gap, no read-path block.
Why not the other verdicts
- Not
FIX7_REFACTOR_BLUEPRINT_NEEDS_MORE_T1_WORK: all six review findings (XH-2/3/4, MX-1/2/3) are revised and re-checked to PASS; every gap is resolved-in-plan, planned, or blocked; rollback and guards are complete. - Not
FIX7_REFACTOR_BLUEPRINT_BLOCKED_BY_READ_PATH: all required source docs and the live system were readable (read-only); the Directus read path is preserved by #21 + G-DIRECTUS-READ and the capture artifact (MX-1). - Not
FIX7_REFACTOR_BLUEPRINT_FAIL_HARDCODE_OR_PG_NATIVE_GAP: every threshold resolves to a sealed manifest row; every guard is PG-native (catalog/data/recomputed-hash/both-EXCEPT); G-NOHARDCODE, G-NODISGUISE, G-PGNATIVE all required-for-PASS.
Track summary
| track | status |
|---|---|
| existing-system inventory (doc 01) | COMPLETE - live read-only; qt001_cp absent; 20 tables/46 fns/196 views legacy (directus-owned); birth gateway + DOTs catalogued |
| design-to-live mapping (doc 02) | COMPLETE - 27/11/14/7 + foundation + legacy disposition mapped; traceability note added |
| gap classification (doc 03) | COMPLETE - 18 gaps; 7 P0 / 9 P1 / 2 P2 / 0 open |
| construction order (doc 04) | COMPLETE - S00..S19, dependency-safe, operator gates marked |
| rollback blueprint (doc 05) | ROLLBACK_BLUEPRINT_COMPLETE |
| test/guard blueprint (doc 06) | COMPLETE - 63 guards (recheck-7 added G-NO-SELF-REVISION-ANCHOR + G-CANONICALIZER-SSOT-ONLY + G-NO-DUPLICATE-CANONICAL-AUTHORITY + G-DOCUMENT-ID-CANONICAL-MCP + G-MARKER-KIND-LITERAL-CONSISTENCY; recheck-6 added G-CANONICAL-FIELD-REJECT + G-ACTIVE-SCOPE-EXTRACTOR + G-RECORD-ENCODING-CLOSED + G-SEAL-HASH-GRAPH-ACYCLIC; recheck-5 added G-CANONICAL-ENCODING-CONTRACT + G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE + G-CODEX-DETACHED-SEAL-ANCHOR; the four recheck-4 envelope guards + G-NO-SUPERSEDED-CONSUMPTION + G-LEGACY-NO-DISPOSITION-AUTHORITY re-bound to the canonical FIX7-CANON-V1 encoding + the Codex detached seal; guard-quality rule 10 added); all 54 are TEST/VERIFICATION guards, NOT readiness gates (readiness gates stay 14 DATA; top-level runtime hash contracts 7; surfaces 27; runtime 11; the canonical envelope + detached seal are a non-runtime construction-document content-address) |
| package split (doc 07) | COMPLETE - PKG-A..I, sequenced, gated, no-go each |
| hard blocks / do-not-touch (doc 08) | COMPLETE |
| XHigh review (doc 09) | 3 findings + 1 advisory -> revised -> re-checks PASS |
| Max review (doc 10) | 3 findings -> revised -> re-checks PASS |
| revisions (doc 11) | COMPLETE - all findings closed; invariants non-regressed |
Verdicts on required dimensions
- Zero-hardcode: PASS (incl. disguised; G-NOHARDCODE/G-NODISGUISE).
- PG-first/native/driven: PASS (G-PGNATIVE; all guards native).
- Authority surfaces = 27: PRESERVED (G-AUTH-27 exact-set).
- Runtime-evidence = 11 non-authority: PRESERVED (G-RUNTIME-NONAUTH).
- Readiness gates = 14 (DATA): PRESERVED (G-GATES-14); new gates = 0.
- Hash contracts = 7 (H01..H07): PRESERVED (G-HASH-7); new contracts = 0.
- Rollback: COMPLETE and safe-blocked-preserving.
- Dependency-safe order: COMPLETE (cycles deferred; linear package sequence).
Explicit asks for Codex recheck 8 (recheck-7 Constitution-Article-14 SSOT-patched blueprint)
Asks 15–19 (recheck-6) carry forward; recheck-7 added asks 20–24 for the Constitution-Article-14 blockers (the seal event is now recheck 8). Codex recheck 7 already accepted the deterministic extractor and the N1–N9 content-hash DAG — those need not be reopened.
Asks 1–14 below carry forward (the seal event is now recheck 7, since recheck 6 did not seal); recheck-6 added asks 15–19 for the byte-exact/acyclicity blockers. Codex recheck 6 already accepted the membership hash, the doc 00 self-reference resolution, the blueprint-checkpoint classification, the invariants/boundary, and the PG-first/typed-set separation — those need not be reopened.
- Confirm the disposition model is fully removed (doc 02 §H, doc 06 G-LEGACY-NO-DISPOSITION-AUTHORITY):
no 5-value enum, no
LEGACY_*#20object_typerow, nodispositioncolumn/family, no computed classifier/truth-table/CASE branch, noSTUB_FAIL_CLOSED/body mutation/body restore, no policy branch by relkind/prokind/name/owner/pattern/label; former labels are non-authority English only. - Confirm the
U_legacyredefinition (doc 02 §H.2/§H.4):closure(#11, roots = #20 protected_target rows), single sealed set, noDO_NOT_TOUCHsubtraction, no class-based exclusion, both-EXCEPT vs the closed denominator, boundary collisions fail closed;relkind/prokindselect PG syntax only. - Confirm the uniform Option-Beta end-state (doc 02 §H.3, doc 04 §S15, doc 06
G-U-LEGACY-OPTION-BETA-UNIFORM-ENDSTATE): every member owner-isolated to
qt001_cp_owner, body unchanged, effective privileges == exact closed-world sealed #21 (both-EXCEPT, role-membership-aware, superuser-dispositioned). - Confirm the STUB/body-mutation removal and forward-only rollback (doc 05): no legacy body
change, so legacy rollback is owner+ACL snapshot replay only via
manifest_activation.rollback_evidence_id;evidence_registryis evidence only, never a body-restore authority. - Confirm the invariants and boundaries hold: 27/11/14/7 preserved (0 new authority surface,
#20 column, catalog family, readiness gate, or top-level hash contract); guards now 63 are
TEST/VERIFICATION, not readiness; implementation / Stage 2.6B / QT001 apply /
qt001_backfill_permit/ REAL_RUN / activation / repoint / cutover all BLOCKED. - Confirm the typed set separation (doc 02 §H, doc 06):
U_legacy_objectis PG objects only and is the sole subject of the uniform end-state (object-shape both-EXCEPT, §H.4.A);U_effective_privilege_principalis the role-only privilege universe joined to objects and reconciled to sealed #21 (§H.4.B);U_entry_vectoris the fail-closed bypass-coverage relation (§H.4.C); no set is a member of another (G-U-LEGACY-OBJECT-ONLY/G-PRINCIPAL-SET-SEPARATE/G-ENTRY-VECTOR-SEPARATE). - Confirm the active/superseded authority boundary (doc 00 registry + per-doc
DOC_STATUS+SUPERSEDED_NON_AUTHORITYfences): it is machine-readable, unambiguous, and not Directus-editable;G-LEGACY-NO-DISPOSITION-AUTHORITYnow scans ACTIVE_AUTHORITY only (reports fenced history, never fails on it); no package/guard/seal/order step consumes superseded instructions (G-ACTIVE-AUTHORITY-SCOPE/G-NO-SUPERSEDED-CONSUMPTION). - Seal the
ACTIVE_AUTHORITY_APPROVAL_ENVELOPEunder the canonical contract + write the Codex detached seal (doc 00). Confirm the canonical membership over the full doc_ids (active_corpus_membership_sha256 = f2bda8effc7be19b54722828126b82d7d2d48bee5e5e5dc0c8f347ce210fe251,FIX7_ACTIVE_AUTHORITY_MEMBERSHIP_V1; reproducible byshasum -a 256== pythonhashlib). Then, computing every aggregate by the Canonical hash encoding (FIX7-CANON-V1): record the per-documentnormalized_active_content_sha256(load-bearing; self-host doc 00 excludes its ENVELOPE:EXCLUDE region), theactive_corpus_sha256,marker_fence_registry_sha256,superseded_boundary_sha256,guard_set_sha256/guard_set_revision, and theenvelope_manifest_sha256over the complete authority-field roster (excluding itself +detached_seal_sha256); setapproved_by_role/approval_epoch/approved_at_utc/approved_by_recheck_checkpoint/seal_version; flipenvelope_stateto SEALED; and author theCODEX_DETACHED_SEALblock in the recheck-7 checkpoint (sealed_envelope_manifest_sha256,sealed_active_corpus_sha256,sealed_active_membership_hash,parent_checkpoint_id,report_documents[]with revisions+hashes,signatureorsignature_not_available_in_current_tooling). Confirm any drift fails closed (ACTIVE_AUTHORITY_ENVELOPE_MISMATCH/ACTIVE_AUTHORITY_DETACHED_SEAL_MISMATCH) and requires a fresh recheck. The envelope + detached seal are non-runtime (add nothing to 27/11/14/7). - Confirm canonical encoding (blocker A): every aggregate hash has a domain tag + record type +
field order + sort key + TAB/LF separators + newline normalization + UTF-8 + null/boolean tokens +
full-path normalization + revision representation + trailing-LF + a reproducible command; none is
prose-only or unordered-serialization (
G-CANONICAL-ENCODING-CONTRACT). - Confirm manifest completeness (blocker B):
envelope_manifest_sha256binds the complete authority-field roster; an authority field outside the manifest, or a missing/unknown field, fails closed (G-ENVELOPE-MANIFEST-AUTHORITY-COMPLETE). - Confirm doc 00 self-reference resolution (blocker C, Option 1):
full_document_sha256is NON_AUTHORITY_DIAGNOSTIC for every member; the load-bearing hash isnormalized_active_content_sha256excluding the envelope region; no full-doc-vs-exclude contradiction. - Confirm blueprint-checkpoint classification (blocker D): it is NON_AUTHORITY_INDEX (DERIVED_STATUS / REPORT_ONLY), not a member, not a self-host, consumed by no guard/package as authority; the sole self-host is doc 00.
- Confirm the detached seal anchor (blocker E): the Codex checkpoint copy of record carries
revision + content SHA-256 + (signature or the documented
signature_not_available_in_current_toolingcompensating rule) + MCP read-back; any post-seal change to the Codex checkpoint fails closed (G-CODEX-DETACHED-SEAL-ANCHOR). - Confirm fail-closed guards use canonical hashes (blocker F):
G-ACTIVE-AUTHORITY-HASH-MATCH/-REVISION-MATCH/-CHANGE-FAIL-CLOSED/G-NO-SUPERSEDED-CONSUMPTION/G-LEGACY-NO-DISPOSITION-AUTHORITYdepend on the FIX7-CANON-V1 digests + the detached seal, not loose YAML/prose (guard-quality rule 10). - Confirm reserved-token rejection (recheck-6 blocker A): FIX7-CANON-V1 REJECTS (does not escape)
any field value containing TAB/LF/CR/NUL/backslash or a reserved structural token, and whitelists
each field by grammar (no null, no empty) → records are injective;
G-CANONICAL-FIELD-REJECT. - Confirm the deterministic extractor (recheck-6 blocker B): active scope / fence / section are
produced by one algorithm (normalize-first, 1-based lines, exact marker grammar, single DOC_STATUS,
flat non-nesting) with a fail-closed status for every ambiguity (marker missing/duplicate, fence
unbalanced/nested, active/superseded overlap, section id/range mismatch, exclude unbalanced, marker
registry mismatch); section identity is by marker structure, never heading text;
G-ACTIVE-SCOPE-EXTRACTOR. - Confirm the closed record + key encoding (recheck-6 blocker C): every load-bearing digest has a
domain tag + fixed field list/order + per-field grammar + sort key + no-null/no-empty + full-path
document_id; the manifest is fixed-roster-order withkey\tvaluescalars + sorted sub-records; every envelope key is in the closed key-classification schema (MANIFEST_BOUND / SEAL_LAYER_READBACK_PROTECTED / NON_AUTHORITY_DIAGNOSTIC / STRUCTURAL_CONTRACT_PROSE); unknown/extra/missing/wrong-class fails closed;G-RECORD-ENCODING-CLOSED. - Confirm the acyclic seal hash graph (recheck-6 blocker D): the node/edge list N1..N9 topologically
sorts;
envelope_manifest_sha256binds NO Codex-checkpoint revision/content hash and not the seal;detached_seal_sha256excludes itself +signatureand never hashes its own checkpoint; the oldseal_report_checkpoint_content_sha256is removed in favour of the diagnosticcodex_checkpoint_content_sha256_excluding_seal(consumed by nothing);G-SEAL-HASH-GRAPH-ACYCLIC, statusSEAL_HASH_GRAPH_CYCLE. - Confirm the anchor model without self-hash (recheck-6 blocker E): the Codex detached seal is
authority only if canonical encoding is accepted, the seal graph is acyclic, the seal block is authored
in the Codex recheck-7 checkpoint, the seal excludes itself, read-back verifies the seal block + the
checkpoint's platform revision, and any drift fails closed; the documented limitation (no crypto
signature → revision + read-back + Codex authorship + separation of duties; a fully-privileged
both-sides forger is not cryptographically prevented) is accepted as the compensating control;
G-CODEX-DETACHED-SEAL-ANCHOR. At recheck 8, seal the envelope + write theCODEX_DETACHED_SEALper asks 8 + 18 + 19 + 20. - Confirm the non-self-referential revision anchor (recheck-7 blocker A): the recheck-8 checkpoint's
own platform revision is NOT load-bearing (no read-back equality); authority =
detached_seal_sha256content recompute + MCP read-back of existence; the seal does not contain the recheck-8 checkpoint's own revision; the finite ordered seal completes without improvisation; the weaker-guarantee acceptance- separation-of-duties compensation are noted (
G-NO-SELF-REVISION-ANCHOR).
- separation-of-duties compensation are noted (
- Confirm the single executable canonicalizer SSOT (recheck-7 blocker B):
FIX7-CANON-V1-CANONICALIZERis pinned (canonicalizer_artifact_id/path/version/revision/sha256); its--selftestexits 0 and reproducesf2bda8…fe251; sealcanonicalizer_revision+canonicalizer_sha256over the artifact's MCP bytes at recheck 8 (G-CANONICALIZER-SSOT-ONLY). - Confirm no duplicate canonical authority (recheck-7 blocker C, Article 14): exactly one
load-bearing canonical contract (the SSOT); doc 00's canonical/extractor/record sections + all report
docs are NON_AUTHORITY_EXPLANATION; a second load-bearing contract / a divergent package canonicalizer
/ a report example conflicting with the SSOT fails closed (
G-NO-DUPLICATE-CANONICAL-AUTHORITY). - Confirm document_id canonical MCP identity (recheck-7 blocker D): exact byte-for-byte MCP id; all
aliases (
./../empty////leading-or-trailing slash/backslash/%-encoding/homoglyph) rejected (G-DOCUMENT-ID-CANONICAL-MCP). - Confirm marker kind/literal consistency (recheck-7 blocker E): closed kind enum + per-kind literal
grammar; mismatch/unknown/disallowed fail closed (
G-MARKER-KIND-LITERAL-CONSISTENCY). At recheck 8, also seal the canonicalizer SSOT hash (ask 21).
<!-- SUPERSEDED_NON_AUTHORITY BEGIN: pre-Option-Beta independent XHigh/Max review history; audit trail only; not current authority -->Carried framing asks (still standing): FIX7 is a parallel green-field
qt001_cpcontrol plane + authoritative repoint + uniform legacy neutralization (not an in-place edit); neutralization belongs in PKG-F; ACL cutover is control-object-scoped; a fresh Codex re-audit gates PKG-F and PKG-G (governance changes, law §4G).
The two sub-sections below are SUPERSEDED_NON_AUTHORITY history (the pre-Option-Beta independent XHigh and Max review passes). They predate the disposition removal and the recheck-3 set separation; retained as audit trail, not consumed as current authority.
Independent XHigh pass (2026-06-08)
An independent T1-XHigh review (separate from the embedded review) audited this blueprint, verified
it against live evidence (legacy apply/writer fns confirmed proacl=NULL = PUBLIC EXECUTE), and
directly revised it: +G-DOT-NOOVERWRITE (old/frozen DOT cannot overwrite gateway/control-plane),
+G-LEGACY-FROZEN (fixed a dangling guard reference), rollback-bypass clarification (doc 05 note 5),
hard-block rows for birth-gateway-modification + registry-pivot-repoint, cross-layer OUT-OF-SCOPE
boundaries (Đ43 / QT-006 / registry-pivot), guard-count correction (26->30), and several consistency
fixes. No blocker; no invariant changed. Status advanced to
FIX7_REFACTOR_BLUEPRINT_XHIGH_REVIEWED_AND_REVISED_READY_FOR_MAX_REVIEW. Report:
t1-xhigh-fix7-refactor-blueprint-review-2026-06-08/00..13.
Independent Max pass (2026-06-08)
An independent T1-Max review (separate from the embedded Max review and from the independent XHigh pass) audited the XHigh-revised blueprint against live production and the governing law, found 7 real defects (3 P1, 3 P2, 1 P3), and directly revised the blueprint; no blocker, no hardcode/PG-native FAIL, no invariant changed. Fixes:
- MB-01 (P1): legacy neutralization widened from a sampled "apply/writer" subset to the COMPLETE
S00-captured legacy-entrypoint set - live evidence shows ALL 46
qt001_*functions + the apply procedure areproacl=NULL/ PUBLIC EXECUTE, none SECURITY DEFINER - so S15/PKG-F REVOKE and G-NOLEGACY now cover the whole set, closing the activation->freeze window. - MC-01 (P1): G-DOT-NOOVERWRITE re-grounded on PG-native owner-isolation (
nspacl+ ownership) as final authority, with DOT-body scanning demoted to a fail-closed diagnostic (DOTs are notpg_proc); birth-gateway overwrite is detection (G-BIRTH-NEUTRAL) + DOT-frozen + policy. - MA-01 (P2): stale top-line status corrected (Verdict section above).
- ME-01 (P2): the owner/ACL rollback snapshot made concrete - ownership + table/view/function/
sequence ACLs + schema
nspacl+ default privileges (doc 05 invariant 3, doc 07 PKG-G). - MG-01 (P2): fresh Codex re-audit gates added before the two governance-change packages PKG-F and PKG-G (aligned with governing-law section 4G: a governance/authority change must be explicit and independently re-reviewed, never mechanical).
- MH-01 (P2): guard-quality rules added to doc 06 (no vacuous pass for "=0"/empty guards;
NULL-strict aggregates not
bool_andNULL-ignore; source-text diagnostic-only, never authority). - MB-02 (P3): birth-family inventory completed (10
fn_birth_*, all DO_NOT_TOUCH) and the 0-trigger bypass-vector evidence recorded.
Invariants 27/11/14/7 preserved; 30 guards unchanged (tightened, none added/removed). The MB-01
neutralization-set widening and the MG-01 re-audit gates are added to the §G / explicit-asks set
for Codex confirmation. Report: t1-max-fix7-refactor-blueprint-review-2026-06-08/00..12; checkpoint
checkpoint-t1-max-fix7-refactor-blueprint-review-2026-06-08.md.
Blocking status (Codex recheck-7 patched: ready for Codex recheck 8)
Implementation remains BLOCKED. The immediate gate is now Codex recheck 8 of the recheck-7
Constitution-Article-14 SSOT-patched blueprint (recheck 7 accepted the deterministic extractor + the
N1–N9 content-hash DAG + invariants/boundary + no runtime-hardcode/PG-first regression, but held approval
on five Article-14 defects: revision-layer self-reference, no single executable canonicalizer SSOT,
duplicate canonical authority, document_id path aliases, loose marker contract — all now patched: the
checkpoint own-revision is removed from authority (revision diagnostic-only), one executable canonicalizer
SSOT FIX7-CANON-V1-CANONICALIZER is pinned with every other description demoted to
NON_AUTHORITY_EXPLANATION, document_id is the exact MCP id with all aliases rejected, and marker_kind↔literal
is a consistent closed pair).
Before any implementation: (1) Codex recheck 8 must pass and seal the
ACTIVE_AUTHORITY_APPROVAL_ENVELOPE under the canonical contract (incl. canonicalizer_sha256) + write the Codex detached seal;
(2) an implementation-authoring package (PKG-A..) must be separately authorized and gated on the
SEALED, canonically-verified envelope + matching detached seal; (3) operator gates must be explicitly
authorized for PKG-E..H. Stage 2.6B, qt001_backfill_permit, REAL_RUN, QT001 apply, manifest
activation, repoint, and owner/ACL cutover all remain blocked. Production was READ-ONLY throughout this
pass (no fresh live read was required — the prior pg_roles evidence stands); no object was created,
altered, owned, granted, revoked, or executed. The only writes were the blueprint-doc revisions, the
recheck-7 patch report, and the checkpoints. Guard count is now 63 (historical track-summary/lower
numbers reflect prior passes; the recheck-7 / recheck-6 / recheck-5 / recheck-4 / recheck-3 / Option-Beta
sections above are authoritative). Do not claim implementation approval; next is Codex recheck 8 only.