docs(records): CHAT-03 seal loads no explicit extensions, lead decision 31

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-09-26 19:34:06 -05:00
co-authored by Claude Opus 5.5
parent f0296e7763
commit 8dba3ff797
2 changed files with 15 additions and 0 deletions
+14
View File
@@ -389,3 +389,17 @@ which stay with him. Each item names who decided it and what happened.
- Filbert and Rocko review r3 only on the sections Gate E needs. A
finding in a cut section is not blocking. After r3, Dewey removes the
cut sections instead of rewording them.
31. **CHAT-03 seal: no explicit extensions.** Rocko's r3 pass (report
19e3fcff) closed his R2 blocker and found one new one in the retained
seal. An explicit extension can import a helper outside its hashed
tree, and the helper can change after review with every hash still
passing. Ruling: take his first cut. A Console-bound seat loads no
explicit extensions. It launches with `--no-extensions` and no
`--extension`, and binding refuses otherwise. Goal was the only explicit
extension any repository seat loads (`scripts/agent-host-dev.sh` line
137), and decision 30 already turns it off for bound seats, so nothing
is lost. The seal covers only built-in code tied to the pinned Pi
artifact. Reviewed extensions come back with goal in CHAT-06, which
must pin their executable dependencies. No dependency crawler. Rocko's
nonblocking note goes to the build: no-turn fence cleanup must not undo
a concurrent force-stop, overlap or revocation fence. No round 4.