forked from mosaicstack/stack
Per Mos. The choke-point executor and PG spine are not a design preference — they are forced. Twice during the mission's own first deliveries, work stopped against a security property that cannot exist at the layer needing it: D-19 (audited party controls the manifest certifying it — artifact integrity) and D-25 (audited party controls the code entering the sandbox — execution integrity). Both reduce to self-verification by the audited party is not verification, and both resolve only via an authority outside its control. Neither proof was sought; both arrived while shipping something else, from different directions, at different layers. An architecture forced by two independent impossibility proofs is stronger evidence than one argued for. RM-60 records Mos's sharper option analysis: A (unprivileged userns) does NOT fix the vulnerability — it grants a capability and leaves the ORDERING defect untouched, so B is required regardless; A without B is kernel exposure bought for nothing. B is the correct primitive, generalises to RM-59 and the choke-point executor, and may not need A at all. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>