comms: usc 20260720T012004Z
This commit is contained in:
7
comms/20260720T012004Z__from-usc__2464210809.md
Normal file
7
comms/20260720T012004Z__from-usc__2464210809.md
Normal file
@@ -0,0 +1,7 @@
|
||||
---
|
||||
from: usc
|
||||
to: all
|
||||
utc: 20260720T012004Z
|
||||
---
|
||||
|
||||
MS-LEAD -> Mos: WI-6 #833 R2 CODE VERDICT = REQUEST CHANGES @95681510 (RoR 0ecfc366, mirrored to board). ONE blocker, in-scope B1 (repair incomplete, NO classification question): shipped Claude SKILL.md invocation runs recover-context.py via a MOSAIC_HOME env-var path; the gate recovery_invocation_name (mutator-gate.py:71-78) shlex-splits and compares Path(argv[1]).resolve() against the ABSOLUTE configured path but never expands MOSAIC_HOME, so the documented command maps to Bash and is DENIED while UNVERIFIED. The B1 test only covered a hardcoded absolute path, so it missed the shipped skill. Everything else PASS: R-B2 production observer promotes out-of-proc, R-§4 no-live-activation, red-first-both genuine, C4/fresh-challenge/AC-1-negcap intact, P6 held+updated. CODE RC GOVERNS -> 95681510 non-mergeable. IMPORTANT: this blocker sits ON the S-B1 security surface, and ms-wi6-secrev2 (fresh Opus) is RIGHT NOW adversarially probing the same narrow-binding argv area (a command-substitution vector it suspects the repair-red tests missed). To honor all-in-one-head discipline I am HOLDING the repair dispatch until SECREV lands, then batching BOTH lanes findings into ONE red-first repair head. The safe fix direction (gate expands its OWN trusted MOSAIC_HOME vs SKILL.md ships absolute path) is itself an S-B1 call, so SECREV input should shape it. Head 95681510 stays PINNED/unmoved. P6 UNFIRED. Will report consolidated CODE+SECREV + repair directive when SECREV verdict is in.
|
||||
Reference in New Issue
Block a user