# Queue as data — adversarial review, round 6 Verdict: **approve** the plan. Rocko, 2026-09-26. Verified target SHA-256 before reading: `282fabbb8969510ae9e139a12082421ca3ffc395a90a800d936cc47abf6ab67a`. This supersedes round-five target 889f2566 and answers report `3b031a707555960dc69cc274fef6c39c0d8c0ebad539a5e8ae0c0c2545f4177e`. Review covers the active specification, especially 8.11, 8.12, 8.5 and 8.9. No blocking findings remain from round five. 1. **G1 resolved — the freshness proof is now obtainable.** Pre-launch listings, command line and UTC start time exist before Pi starts. The later session/header audit no longer requires a file Pi has not created, nor a warm-up message or manual session seeding. The header is correctly outside the entry chain; null first parent and sequential later parents match the pinned SessionManager behavior reproduced in round five. Prefix restrictions and whole-file input audit still exclude ordinary resume, inherited summaries and branch coaching. Positive controls now complement the negative controls. The pre-instruction context hashes remain required; moving the session-file pin to cutoff does not waive those hashes. This is cooperative evidence with the previously accepted helper/context-edit limits, not independent proof against an actor rewriting all receipts. 2. **G2 resolved — activation is checked, not inferred from bytes.** The plan checks file type, ownership, executability, bytes and hooksPath at invocation and again before publication. The canary invokes Git's hook mechanism using an isolated index, checks both acceptance and the guard's specific refusal, and makes disabled/redirected hooks fail before publishing. 8.5 explicitly forbids later mode/config/environment overrides and honestly states the same-user limitation. Nothing here claims to prevent a seat deliberately bypassing the protocol after a check. Keeping that limit is appropriate for the accepted scope. Independent scratch-repository check of the stated canary returned: clean index 0; changed queue index 1 with the refusal line; nonexecutable hook 1 on the clean index; redirected hooksPath 1 on the clean index. The temporary repository was removed. This is validation of the mechanism, not of queue-commit.sh, which has not been built. 3. **Lead identity note resolved.** 8.9 explicitly expects jarvis from GET user when the lead posts, while retaining the lead as queue actor. Fake-transport positive and wrong-login cases include the sage mismatch. This closes the ambiguity without changing the authorized credential rule. No token was opened or live API request made in this review. Builder detail, nonblocking: step 1 currently lists the canary before the bullet that captures H, although the canary reads its temporary index from H. Capture H before constructing that canary, use that same H for the snapshot/base work, and retain expected-old-value publication. A concurrent HEAD change may cause a conservative refusal; it must never cause the script to silently adopt a new untested base. For the genesis canary, QUEUE.md is already a tracked queue entry even though queue.json is absent. The previous round's F2 coherent reads, F3 genesis/base procedure and F5 op-length bounds remain resolved. No new contradiction in the reviewed changes requires an owner ruling. Approval is for the design and its stated acceptance tests; implementation still needs the fault-injection, Git-race, transport and Gate G evidence specified in section 8. Only this report was written in the repository. No source/index edit, commit, push, live process change or credential access.