Files
stack/docs/plans/reviews/2026-09-06_foundation-inspector-rocko-build-request.md
jason.woltje 8ebddd6f93 feat(foundation): offline synthetic scope/permission inspector (FI-FILBERT-8 APPROVED r6)
Rocko-authored, Filbert-reviewed inspector (r6 manifest
a4a44930...) with full review/build/verdict evidence under
docs/plans/reviews. 43/0 selftests, oracle zero-disagreement,
foundation checker PASS. Owner A9 acceptance recorded separately.
2026-09-07 14:06:35 -05:00

81 lines
4.6 KiB
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# FI-ROCKO-3 — authorized synthetic inspector build
Jason explicitly answered yes to Rocko building the offline synthetic inspector,
Filbert independently reviewing the code, and darkwing bringing an owner demo.
No push, live registration/permission changes, migration or fleet work authorized.
Requester/integration owner: darkwing. Sole implementation writer: rocko.
Independent reviewer: filbert (not yet dispatched to code review).
Issue: #53. Recheck current assignment compatibility; do not displace held owner work.
## Exact build contract
Repository: /home/jwoltje/src/mosaic-stack-dev-test
Charter: docs/plans/2026-09-06_foundation-inspector-charter.md, candidate 3
SHA-256 19b6721128a627a2032ffdb95ece2d50abe69a8f6d521e9eff8bbdaff22798b6
Incorporated r2 sections 513, overridden by charter (especially §10):
docs/plans/reviews/2026-09-06_foundation-inspector-rocko-feasibility-r2.md
SHA-256 f2f47fcfe22dca79f10f885b83d87a2f846fdb560425a4e20705c40ce4a123e1
Independent charter verdict: reviews/2026-09-06_foundation-inspector-filbert-verdict-r3.md
SHA-256 15f3d04cb74a7296be6a1a26f2c0907b9dd2b08fdd1eb0ef51c95c7a52ff0399
Source/schema baseline d4696d09eb1b5dcf1028f30db2cd63735f51cb16;
accepted map 7345f330fc6bfae5aa1d896c78cfb7cbe62efbae.
## Only authorized implementation paths
- scripts/foundation-inspect.mjs
- scripts/foundation/strict-json.mjs
- scripts/foundation/canonical.mjs
- scripts/foundation/resolve.mjs
- scripts/foundation/validate-record.mjs (test-only bridge)
- scripts/foundation/verify-schema.py (verification only)
- scripts/foundation/*.test.mjs
- scripts/foundation/fixtures/**
- scripts/test-foundation.sh
- Your build report only: docs/plans/reviews/2026-09-06_foundation-inspector-rocko-build.md
No edits to charter, incorporated notes, verdicts, CURRENT, shared logs, root/package
files, existing schemas, extension/native files, policies, runtime data or installations.
If another helper/path or specification decision is necessary, return a concrete
proposal rather than improvise outside the allowlist. Work only in these initially
unclaimed implementation paths; report any conflicting existing work before editing.
## Implementation and verification obligations
Implement the approved charter, not the superseded r1/r2 shorthand. Four supported
operations only; assignment.change has no allowed branch. All output is simulation-
labelled; no source of mock data becomes authenticated authority. Preserve exact
role/issuer/assignment/execution narrowing, supported-work scope, history/current
semantics, output privacy, closed shapes and lexical-versus-schema distinction.
Build coherent fixtures plus positive/negative tests for A1A8 and §§10.110.5.
Prepare simple commands for Jason's later A9 demo; do not claim owner acceptance.
Required verification: pinned schema/checker hashes; mandatory differential oracle
with existing explicit Python/jsonschema 4.26.0 (no installation or silent skip);
unit and isolated CLI/non-effect/privacy tests; syntax and diff checks; foundation
checker and all five repository suites. Report exact commands/toolchain/results.
Do not run native/sync tests against Dewey's installation. Use disposable synthetic
HOME/cwd/fixtures/data-root for new CLI tests. No credential, live-data or ~/.mosaic
reads/experiments, network access or engine launches. Tests may spawn test subprocesses;
the inspector must not. Do not report static flags or finite tests as sandbox proof.
## Shared Git and review handoff
Dewey owns the shared index per MS58-DW-1. NO staging, commit, checkout/reset or push.
Read-only git inspection is allowed. Other source changes may occur concurrently;
keep pinned contract inputs distinct from the measured integration HEAD.
Return FI-ROCKO-3 admission/blocker, then completion with exact changed-file list,
SHA-256 per file, baseline/integration HEAD, test receipts, A1A8 coverage, known
limitations and owner-demo commands. Freeze code/fixtures while Filbert reviews;
a delivered build is a review candidate, not accepted work. If blocked, report the
specific unmet gate; do not switch assignments or silently weaken tests.
Direct tagged reply is the return mechanism. Follow-up darkwing. No deadline or
automatic timer/approval. Implementation authorization does not authorize dependent
live-registry/runtime increments, source migration, issue closure or publication.
Transport (2026-09-06 17:02 UTC): FI-ROCKO-3 sent once to =rocko/mosaic-fleet;
exit 0, delivered. Await admission/blocker and then frozen build/test manifest.
FI-FILBERT-4 availability-only send to =filbert/default returned exit 2, unconfirmed.
No blind retry. Direct reply/manual steering is the return condition; no timer.