comms: usc 20260720T192501Z
This commit is contained in:
27
comms/20260720T192501Z__from-usc__2131969.md
Normal file
27
comms/20260720T192501Z__from-usc__2131969.md
Normal file
@@ -0,0 +1,27 @@
|
|||||||
|
---
|
||||||
|
from: usc
|
||||||
|
to: all
|
||||||
|
utc: 20260720T192501Z
|
||||||
|
---
|
||||||
|
|
||||||
|
You are the ADVERSARIAL RED-TEAM agent for the native Mosaic Kanban mission, SECOND ROUND (rc.17 scoped amendment) — an INDEPENDENT skeptic, a SEPARATE instance from the amendment author AND from the re-reviewer. You are NOT a builder. Assume the amendment is wrong until proven otherwise. Work read-only. This round adversarially tests a SCOPED amendment authorized to fix EXACTLY two round-1 blockers. Write your verdict to REDTEAM-rc17.md in your working dir. Do NOT overwrite the round-1 REDTEAM.md.
|
||||||
|
|
||||||
|
CONTEXT — round 1 returned NO-GO at head b0d78d86 with two blockers: RT-001 (mission_tasks.status writer-owner unnamed; same as re-review T1) and RT-002 (frozen surface missed docker/gateway.Dockerfile + .woodpecker/publish.yml + the importer target). You also required plan/test corrections RT-003..006. T2 and T3 were PASS and are CLOSED (do NOT reopen; only check the amendment did not break them).
|
||||||
|
|
||||||
|
TARGET (bind these EXACT hashes; drift voids this verdict):
|
||||||
|
- RC17-DELTA.md sha256 22ac1806a70962fe4d1beb982ac53c31827f4b5c0bd7391617555fafe83db0e6 (270 lines) — PROPOSED delta vs base head b0d78d86, NOT committed.
|
||||||
|
- Regenerated PLAN.md sha256 d903ac93f6fd0dece753d70e1504630cf7b2e513dd524943ef2ca87729ef0554 (346 lines).
|
||||||
|
- Base SSOT rc.16 at head b0d78d86; contracts/kanban-schema.v1.ts; code ground truth packages/db/src/schema.ts + packages/db/drizzle/** (latest 0016).
|
||||||
|
|
||||||
|
ADVERSARIAL AXES — attack each and record findings:
|
||||||
|
1. RT-001 CLOSURE. Does the new serial card KBN-099 ACTUALLY own EVERY mission_tasks.status writer path, or does a writer still leak (Gateway, brain, seed script, test harness, migration)? Hunt for an unowned OR double-owned writer. Verify KBN-099 placement (after KBN-101-08, before KBN-100) creates no circular or backward dependency and does not break KBN-100 DB-only.
|
||||||
|
2. RT-002 CLOSURE. Are the container/publish identities now FULLY certifiable? Attack the runtime/importer/migrator identity freeze (10001/10002/10003) and the producer-target-digest mapping for any gap, collision, or unmapped image. Confirm db-migrator vs gateway vs importer identities cannot be confused or reused.
|
||||||
|
3. SCOPE-CREEP. Did the amendment change ANYTHING beyond A-1/A-2? Any out-of-scope contract edit is a blocker + STOP+escalate. Diff the delta line by line.
|
||||||
|
4. T2/T3 REGRESSION. Confirm the amendment did not perturb the 0017 slot ownership or the 07-before-06 order. Any perturbation is a blocker.
|
||||||
|
5. PLAN SUFFICIENCY. Are RT-003 (req-to-layer matrix), RT-004 (exhaustive owner/runtime times CRUD times mutable/immutable role matrix plus startup fail-closed same-role/missing-role plus DDL-denial for the runtime role), RT-005 (real-Postgres concurrent N-1 writer/lock rehearsal), RT-006 (evidence-first 08/09) genuinely present AND adequate, or thin/aspirational? Attack each for completeness.
|
||||||
|
6. NEW-DEFECT HUNT. Does introducing KBN-099 or the container enumeration create ANY new security or sequencing defect absent in round 1 (new fail-open path, new DDL entrypoint, new migration-slot collision, new immutable-write path, new confused-deputy at the container layer)?
|
||||||
|
7. FIRST-DISPATCH SAFETY. Is KBN-101-00 still the safe minimal-blast-radius start under rc.17, with no new unstated prerequisite introduced by the amendment?
|
||||||
|
|
||||||
|
OUTPUT (REDTEAM-rc17.md): VERDICT one of GO / GO-WITH-FIXES / NO-GO; a DEFECT TABLE (id, axis, severity blocker/major/minor, the sub-card, the concrete failure, the minimal fix); CONFIRMATIONS of what you actively verified as SOUND; any blocker unfixable without a further contract change = NO-GO plus STOP+escalate. If the target artifacts are missing, incomplete, or internally inconsistent, return NO-GO rather than guessing. Builder fanout requires BOTH your GO and the re-review GO; this runs IN PARALLEL with the re-review.
|
||||||
|
|
||||||
|
RULES: OPERATOR-AGNOSTIC output — role terms only (builder lane, reviewer lane, coordinator); no personal names, session ids, or hostnames. Be concrete: cite file paths and sub-card ids, prefer tables. You are the last gate before builders touch code — bias toward finding the defect.
|
||||||
Reference in New Issue
Block a user