Files
stack/docs/plans/reviews/2026-09-06_foundation-map-filbert-verdict.md
jason.woltje 8ebddd6f93 feat(foundation): offline synthetic scope/permission inspector (FI-FILBERT-8 APPROVED r6)
Rocko-authored, Filbert-reviewed inspector (r6 manifest
a4a44930...) with full review/build/verdict evidence under
docs/plans/reviews. 43/0 selftests, oracle zero-disagreement,
foundation checker PASS. Owner A9 acceptance recorded separately.
2026-09-07 14:06:35 -05:00

18 KiB

FM-FILBERT-1 — independent written-map verdict

Reviewer: filbert. Follow-up owner: darkwing. Date: 2026-09-06.

Admission and verdict

APPROVED for the bounded written technical map at the exact identities below. No blocking technical-map defect found. This is not full Archify acceptance, owner acceptance, phase advancement, an implementation charter, or a runtime verdict.

I did not author/co-author this candidate in my available session history. My current instructions contain no competing personal owner-authorized assignment. FM-FILBERT-1-C1 resolved my earlier mistaken use of the source baseline's historical CURRENT.md as current task authority. That admission blocker and the resulting incomplete NOT APPROVED are superseded by this completed review, not erased. Mapping-commit CURRENT.md:8-25 records the later review gate; Jason's separately communicated authorization admits only this bounded review.

  • Mapping commit: 7345f330fc6bfae5aa1d896c78cfb7cbe62efbae
  • Source/plan baseline: d4696d09eb1b5dcf1028f30db2cd63735f51cb16
  • Foundation parent: 44f257cb06484feda3412d9382e3587393796353
  • Map: docs/plans/2026-09-06_foundation-technical-map.md SHA-256 772f9e61cb9fb7a31ce8187b12cdf1c4a5fb714ad517a9c12928901171a37db1
  • Handoff: docs/plans/2026-09-06_foundation-map-handoff.md SHA-256 1fd1a89f982a31bb9db21b852df78be954323aa1668ab9752be34de853ee4999

Both document hashes matched independent computation from git show. All 69 handoff input hashes matched the source baseline. The mapping commit's parent is the source baseline, whose parent is the foundation parent. The mapping commit changes only map, handoff and CURRENT. All nine inspected legacy source files are byte-identical to 69d1bb3 and to the isolated baseline export.

Numbered findings and limits

  1. Informational / confirmed — legacy launch is not managed admission. Locations: map launch/mount/context trace tables; baseline compose.yaml:38-43, scripts/agent.sh:121-138,181-199, src/run-agent.sh:37-41, src/load-contracts.sh:40-41,68-97, adapters/pi/adapter.sh:29-44,81-96. Evidence: broad writable data-root mount, shared SOUL/mission/prompt destinations, fixed .partial, blanket user Markdown discovery, directory-nonempty continuation, and native/print invocation are present. These support the proposed replacement boundaries; a named workspace is not isolation. Required correction: none. Limit: no race reproduction, engine discovery measurement or containment test.

  2. Informational / confirmed — evidence and lifecycle reuse is correctly narrow. Locations: map evidence/lifecycle tables and ordering constraints; baseline scripts/mosaic-task.mjs:295-302,442-466,548-641, scripts/reset.sh:16-48. Evidence: exclusive-create writes lack fsync in the helper; retry starts a new run without reconciliation; prune deletes before appending its receipt and treats directory-read exceptions as an empty inventory; reset lacks foundation claim/reference protection. Map preserves useful conventions without calling them crash durability or recovery. Required correction: none. Limit: static ordering inspection is not a measured crash/failure-injection result.

  3. Informational / confirmed — policy, packaging and process privilege remain distinct. Locations: map component/placement matrices and integrated ownership section; baseline ROADMAP:127-166, #55 layout plan, candidate README sections 2-3/6, RUNTIME sections 1/4/7. Pure calculation belongs to proposed packages/config; publication and process authority do not. CLI presentation does not own policy. Runtime/adapter logic has one proposed packages/agent owner, with only unavoidable retained src shims. Current extensions/** and generated .pi installation do not replace the future packages/* decision. A shared package is explicitly not a shared process privilege grant. Required correction: none. #55's historical native-test/reviewer receipts were read as reports, not independently rerun or recertified here; Dewey's current work is excluded.

  4. Informational / confirmed with implementation limits — the inspector is appropriately bounded. Locations: map recommended-increment section and cross-lane scenario; candidate REVIEW first-increment proposal, README sections 2-3/8, RUNTIME sections 2/5. Coherent synthetic graph, explicit selection, required policy refusal, least-privilege intersection, no assignment-union grants, deterministic preview, no live writes and owner test gate are stated. The cross-lane case preserves the original assignment unless a properly authorized, recorded change within owner intent is reconciled. A message does not itself confer delegation or acceptance. Required correction: none for this recommendation. A later charter must specify executable graph/operation inputs and tests for those rules; the current small model is not a real graph resolver, authenticator or reassignment implementation.

  5. Informational / review limit — source flags and reported external behavior are not runtime proof. Locations: map adapter row, authority/coordination history and owner-reported cross-lane scenario; handoff collaboration section. I confirm adapter flags and command construction, not the pinned engine's complete discovery, exact-session, fork-preservation or security behavior. Future reuse remains conditional on the admission tests already required by the plan. Collaboration delivery, native acceptance and the separate-environment incident are reported context, not independently observed facts in this review. Required correction: none; preserve those qualifications in downstream maps and charters. No external incident diagnosis or investigation was performed.

Request-item dispositions

Item Disposition Independent basis
1. Source/plan boundaries, hops, reuse and gaps Confirmed at the written map's explicitly limited inventory level All direct source-locator rows opened in the committed baseline; dispositions below. New responsibilities are proposals, not repository-wide absence claims.
2. R1-R34 meaning Confirmed as responsibility mapping, not a replacement specification Each requirement checked against the foundation table, owner interview and accepted phase-2 rules; per-R dispositions below.
3. Policy/effects, package/process, source/install, single owners Confirmed Placement matrix and integrated qualifications agree with ROADMAP, #55 and RUNTIME trust boundaries.
4. Synthetic inspector Confirmed as a recommendation Seven core acceptance cases plus cross-lane case preserve the no-live-grants boundary; execution and enforcement unimplemented.
5. Identity/commit distinction Confirmed mechanically Exact map/handoff hashes, 69 input hashes, both parent links and nine legacy identities verified.
6. Independent checks Passed within stated limits Contract checker, config suite, syntax and mapping whitespace checks below; no native/synchronization/security suites claimed.

Direct source-row dispositions

Every row is confirmed as a static source finding and justified reuse/change recommendation, subject to findings 1-5. No row is certified as external runtime behavior. Paths/lines here resolve at d4696d09.

Map source row Verified meaning / disposition
agent.sh:78-130 Reads seat defaults, copies canonical SOUL to shared agent path, conditionally writes seat record. Reuse identity concept; change snapshot materialization.
agent.sh:132-170 Global agent session default and role-tool narrowing. Replace scoped selection; retain narrowing principle only.
agent.sh:181-199 Shared mission copy, name-default workspace, Compose TUI launch. Change orchestration and inputs.
adapter.sh:23-50 cwd, fork/persistent/ephemeral flags and nonempty-directory -c; explicit tools/no-tools. Exact scoped binding remains new.
adapter.sh:63-96 Native/print modes and explicit suppression/provider/model/prompt arguments. New mediated gateway remains required; engine behavior not exercised.
mosaic-task.mjs:252-273,670-676 Closed role keys, filename identity, known unique tools, network enum and emitted metadata. Not network enforcement or scope RBAC.
mosaic-task.mjs:362-378 Requested task tools intersect mission tools when both exist; empty intersection is tool-free. Absent task tools can inherit mission tools: this is narrower legacy semantics, not the new full policy resolver.
mosaic-task.mjs:295-325 Exclusive-create snapshots/helper, no fsync in helper. Reuse intent, replace durable publisher.
mosaic-task.mjs:442-466 Final response/provenance/process result fields, followed by writeOnce. Not invocation-level managed audit.
compose.yaml:38-43 Writable whole-root mount and separate read-only auth mount. New managed isolation/credential boundary needed.
run-agent.sh:20-41 Adapter path checks and shared generated prompt before dispatch. Retain dispatch validation, change context publication.
load-contracts.sh:18-58 Required governance sources, optional seat SOUL and fixed staging file. Snapshot/publication changes warranted.
load-contracts.sh:68-77,81-98 Blanket user Markdown selection precedes mission, contrary to header order. Replace discovery with authorized classified selection.
reset.sh:16-48 Configured target, symlink/realpath/marker checks, recursive delete; no claim/reference/receipt integration.
mosaic-task.mjs:548-595 Retry redirects relative mission references to snapshot and replays as a new run. Not uncertainty recovery.
mosaic-task.mjs:598-641 Count-based preview/apply, caught directory errors, delete then receipt. Protected retention requires changes.
mosaic-config.mjs:39-61,76-174 MOSAIC_CONFIG override, strict shape/file/root validation and lstat errors treated as missing. Sole-config reconciliation is explicitly required, not silently approved.
mosaic-config.mjs:194-239 Exclusive bootstrap creation, existing-config validation and quoted env output. Synthetic inspector must not invoke bootstrap/live resolution.
auth.sh:19-96 Config-backed account reporting; status parses credential JSON and parser diagnostics. Static source read only; no redaction guarantee or credential read performed by reviewer.
agent.sh:28-64 Named auth account refusal checks and mount-source export; no project-selection parser. Future #50 binding must replace flat selection.

The nine files were read completely. Plan inputs read: foundation requirements, workspace/schema interview, phase-2 contract, candidate README/REVIEW/RUNTIME, ROADMAP, #55 layout, #54 native-development plan and #50 auth/provider registry. Also read candidate check.py and semantic-model.py, extension/.pi READMEs, Containerfile and adapter contract. The 69-entry identity audit is a byte audit, not a claim of independent line-by-line review of every extension/schema fixture. The schema/fixture inventory was additionally consumed by the author checker.

R1-R34 semantic dispositions

C = confirmed responsibility allocation and planned gap, not implemented behavior. The map's concise index is read with its named accepted-plan input; it does not need to restate every normative clause to be a faithful responsibility map.

Requirement Disposition and meaning checked
R1 C — reusable definition retained; execution-specific identity binding changes.
R2 C — project registration and bounded delegation require new resolver, not tool names.
R3 C — exactly one project parent, explicit workspace membership; dependencies do not grant access.
R4 C — one identity across scopes with distinct scoped sessions, replacing global default.
R5 C — explicit agent/project/workspace selection, not cwd or seat-name inference.
R6 C — reusable instructions, selected scoped work context and authorized snapshots.
R7 C — exact Resume/Fresh/genuine-first-use distinction; damaged history is not first use.
R8 C — assignment-only Abandon and explicit authorized prerequisite/selection transitions.
R9 C — authorized human/service launch and recovery from checked work records.
R10 C — claim key is scoped, not session-only; tuning/budgets/scaling are not implemented by the map.
R11 C — shared client operations/work truth; no separate interface task list.
R12 C — explicit scoped messaging, no identity-based conversation mixing; cross-lane text is not authority.
R13 C — whole-root mount is not containment; actual enforcement remains a proof gate.
R14 C — legacy provenance is useful but lacks trusted classified per-action evidence.
R15 C — owner phase/user-test gates retained; independent written approval is not owner acceptance.
R16 C — canonical SOUL retained, current approved launch revision snapshotted; no silent live reload.
R17 C — comparable base hash and cross-interface notices are new, distinct from full launch identity.
R18 C — single-owner mission/parent graph and exact references, not duplicated project truth.
R19 C — bounded within-plan decomposition and authorized non-author acceptance; coordinator title is insufficient.
R20 C — taskless permitted read/chat is distinct from recorded assigned changes.
R21 C — active conflict plus explicitly authorized connection, not automatic attach/replacement.
R22 C — transcript visibility/handoff is separate from work-record read and automatic context loading.
R23 C — revoke affected scope, stop/fence and reconcile effects; independent other-scope authority survives.
R24 C — one controller, separately authorized observers and explicit generation-fenced transfer.
R25 C — controlled Fresh replacement requires stopping/safety evidence, not timeout/idle alone.
R26 C — non-destructive authorized investigation, no blind replay or invented success.
R27 C — audit failure closes affected admission; preauthorized fail-safe stop is not unaudited recovery.
R28 C — classified relevant user context replaces blanket global Markdown discovery.
R29 C — retirement/reopen preserves evidence, distinct from deletion and protected retention.
R30 C — reviewed legacy adoption preserves originals; no inferred membership.
R31 C — current approved intent pauses affected work for reconciliation; messages cannot silently retask it.
R32 C — standard nonhierarchical scope roles narrow reviewed ceilings, not redefine identity.
R33 C — invocation evidence plus actually enforced limits; no claim to enumerate every internal effect.
R34 C — Mosaic-controlled client with Pi behind the single reviewed adapter; no native parity waiver of safety.

Owner-intent/reassignment was checked particularly against R8/R19/R23/R31/R32, README reference/permission/lifecycle rules and RUNTIME assignment/message rules. Independent acceptance uses actual author provenance and current reviewer authority, not a fresh session of the same author or a message saying approved. The small synthetic model cannot prove that enforcement; the map does not claim it does.

Independent test receipts

Measured 2026-09-06 around 08:01 UTC. Isolated source export: /tmp/fm-filbert-1.6Acnih, created with git archive d4696d09eb1b5dcf1028f30db2cd63735f51cb16 | tar -x -C <export>. No shared-tree checkout/reset, dependency install or live runtime was used.

  1. Python/subprocess git show <commit>:<path> plus hashlib.sha256: both candidate hashes matched; 69/69 inventory matched; 9/9 legacy files matched 69d1bb3 and the export. git rev-list --parents -n 1 confirmed both parent links.
  2. From export, with clean environment, temporary HOME and bytecode writes disabled: /home/jwoltje/.pyenv/versions/3.12.8/bin/python3 docs/plans/foundation-v1-candidate/check.py. Exit 0: 38 command shapes, 38 record shapes, 16 paths, 7 restricted-domain hash vectors, 155 runtime/artifact shapes, 35 synthetic model cases; 5+5 deliberately shape-valid semantic forgeries remain shape-valid. Python 3.12.8/jsonschema 4.26.0. Initial attempt using env -i PATH=/usr/bin:/bin ... python3 failed exit 1 because that interpreter lacked jsonschema. No dependency was installed; the existing explicit interpreter above supplied the documented dependency for the successful run.
  3. From export: env -i PATH=/usr/bin:/bin HOME=/tmp/fm-filbert-1.6Acnih-review-home bash scripts/test-config.sh. Exit 0: 24 passed, 0 failed. Suite uses its own temporary synthetic config/data.
  4. bash -n for scripts/agent.sh, auth.sh, reset.sh; sh -n for adapters/pi/adapter.sh, src/run-agent.sh, src/load-contracts.sh; node --check for scripts/mosaic-config.mjs and scripts/mosaic-task.mjs. All exit 0. Observed default Node v26.8.1; syntax checking is not pinned-runtime testing.
  5. git diff-tree --check 7345f330^ 7345f330: exit 0.

No test-task full suite, release/conductor/auth runtime suites, verify.sh, Docker, native extension, sync/package, renderer, browser, process-stopping, sandbox, credential separation, crash-durability or full JCS/Unicode enforcement tests ran. In particular the author checker is independently executed author test code, not an independent implementation of its validator and not proof of real authorization. No architecture JSON/HTML, render receipt or visual preview was supplied or accepted.

Only this offered verdict path was written in the repository. No shared logs, CURRENT, source, policies, installations, commits or pushes were changed. No credential contents, live worker state or separate ~/.mosaic environment were read. No implementation or automatic next increment is authorized by this verdict.