Rocko-authored, Filbert-reviewed inspector (r6 manifest a4a44930...) with full review/build/verdict evidence under docs/plans/reviews. 43/0 selftests, oracle zero-disagreement, foundation checker PASS. Owner A9 acceptance recorded separately.
224 lines
18 KiB
Markdown
224 lines
18 KiB
Markdown
# FM-FILBERT-1 — independent written-map verdict
|
|
|
|
Reviewer: filbert. Follow-up owner: darkwing. Date: 2026-09-06.
|
|
|
|
## Admission and verdict
|
|
|
|
**APPROVED for the bounded written technical map at the exact identities below.**
|
|
No blocking technical-map defect found. This is not full Archify acceptance,
|
|
owner acceptance, phase advancement, an implementation charter, or a runtime verdict.
|
|
|
|
I did not author/co-author this candidate in my available session history. My
|
|
current instructions contain no competing personal owner-authorized assignment.
|
|
FM-FILBERT-1-C1 resolved my earlier mistaken use of the source baseline's historical
|
|
CURRENT.md as current task authority. That admission blocker and the resulting
|
|
incomplete NOT APPROVED are superseded by this completed review, not erased.
|
|
Mapping-commit CURRENT.md:8-25 records the later review gate; Jason's separately
|
|
communicated authorization admits only this bounded review.
|
|
|
|
- Mapping commit: `7345f330fc6bfae5aa1d896c78cfb7cbe62efbae`
|
|
- Source/plan baseline: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`
|
|
- Foundation parent: `44f257cb06484feda3412d9382e3587393796353`
|
|
- Map: `docs/plans/2026-09-06_foundation-technical-map.md`
|
|
SHA-256 `772f9e61cb9fb7a31ce8187b12cdf1c4a5fb714ad517a9c12928901171a37db1`
|
|
- Handoff: `docs/plans/2026-09-06_foundation-map-handoff.md`
|
|
SHA-256 `1fd1a89f982a31bb9db21b852df78be954323aa1668ab9752be34de853ee4999`
|
|
|
|
Both document hashes matched independent computation from `git show`. All 69
|
|
handoff input hashes matched the source baseline. The mapping commit's parent is
|
|
the source baseline, whose parent is the foundation parent. The mapping commit
|
|
changes only map, handoff and CURRENT. All nine inspected legacy source files
|
|
are byte-identical to 69d1bb3 and to the isolated baseline export.
|
|
|
|
## Numbered findings and limits
|
|
|
|
1. **Informational / confirmed — legacy launch is not managed admission.**
|
|
Locations: map launch/mount/context trace tables; baseline `compose.yaml:38-43`,
|
|
`scripts/agent.sh:121-138,181-199`, `src/run-agent.sh:37-41`,
|
|
`src/load-contracts.sh:40-41,68-97`, `adapters/pi/adapter.sh:29-44,81-96`.
|
|
Evidence: broad writable data-root mount, shared SOUL/mission/prompt destinations,
|
|
fixed `.partial`, blanket user Markdown discovery, directory-nonempty continuation,
|
|
and native/print invocation are present. These support the proposed replacement
|
|
boundaries; a named workspace is not isolation. Required correction: none.
|
|
Limit: no race reproduction, engine discovery measurement or containment test.
|
|
|
|
2. **Informational / confirmed — evidence and lifecycle reuse is correctly narrow.**
|
|
Locations: map evidence/lifecycle tables and ordering constraints; baseline
|
|
`scripts/mosaic-task.mjs:295-302,442-466,548-641`, `scripts/reset.sh:16-48`.
|
|
Evidence: exclusive-create writes lack fsync in the helper; retry starts a new
|
|
run without reconciliation; prune deletes before appending its receipt and
|
|
treats directory-read exceptions as an empty inventory; reset lacks foundation
|
|
claim/reference protection. Map preserves useful conventions without calling
|
|
them crash durability or recovery. Required correction: none. Limit: static
|
|
ordering inspection is not a measured crash/failure-injection result.
|
|
|
|
3. **Informational / confirmed — policy, packaging and process privilege remain distinct.**
|
|
Locations: map component/placement matrices and integrated ownership section;
|
|
baseline ROADMAP:127-166, #55 layout plan, candidate README sections 2-3/6,
|
|
RUNTIME sections 1/4/7. Pure calculation belongs to proposed packages/config;
|
|
publication and process authority do not. CLI presentation does not own policy.
|
|
Runtime/adapter logic has one proposed packages/agent owner, with only unavoidable
|
|
retained src shims. Current extensions/** and generated .pi installation do not
|
|
replace the future packages/* decision. A shared package is explicitly not a
|
|
shared process privilege grant. Required correction: none. #55's historical
|
|
native-test/reviewer receipts were read as reports, not independently rerun or
|
|
recertified here; Dewey's current work is excluded.
|
|
|
|
4. **Informational / confirmed with implementation limits — the inspector is appropriately bounded.**
|
|
Locations: map recommended-increment section and cross-lane scenario; candidate
|
|
REVIEW first-increment proposal, README sections 2-3/8, RUNTIME sections 2/5.
|
|
Coherent synthetic graph, explicit selection, required policy refusal,
|
|
least-privilege intersection, no assignment-union grants, deterministic preview,
|
|
no live writes and owner test gate are stated. The cross-lane case preserves the
|
|
original assignment unless a properly authorized, recorded change within owner
|
|
intent is reconciled. A message does not itself confer delegation or acceptance.
|
|
Required correction: none for this recommendation. A later charter must specify
|
|
executable graph/operation inputs and tests for those rules; the current small
|
|
model is not a real graph resolver, authenticator or reassignment implementation.
|
|
|
|
5. **Informational / review limit — source flags and reported external behavior are not runtime proof.**
|
|
Locations: map adapter row, authority/coordination history and owner-reported
|
|
cross-lane scenario; handoff collaboration section. I confirm adapter flags and
|
|
command construction, not the pinned engine's complete discovery, exact-session,
|
|
fork-preservation or security behavior. Future reuse remains conditional on the
|
|
admission tests already required by the plan. Collaboration delivery, native
|
|
acceptance and the separate-environment incident are reported context, not
|
|
independently observed facts in this review. Required correction: none; preserve
|
|
those qualifications in downstream maps and charters. No external incident
|
|
diagnosis or investigation was performed.
|
|
|
|
## Request-item dispositions
|
|
|
|
| Item | Disposition | Independent basis |
|
|
|---|---|---|
|
|
| 1. Source/plan boundaries, hops, reuse and gaps | Confirmed at the written map's explicitly limited inventory level | All direct source-locator rows opened in the committed baseline; dispositions below. New responsibilities are proposals, not repository-wide absence claims. |
|
|
| 2. R1-R34 meaning | Confirmed as responsibility mapping, not a replacement specification | Each requirement checked against the foundation table, owner interview and accepted phase-2 rules; per-R dispositions below. |
|
|
| 3. Policy/effects, package/process, source/install, single owners | Confirmed | Placement matrix and integrated qualifications agree with ROADMAP, #55 and RUNTIME trust boundaries. |
|
|
| 4. Synthetic inspector | Confirmed as a recommendation | Seven core acceptance cases plus cross-lane case preserve the no-live-grants boundary; execution and enforcement unimplemented. |
|
|
| 5. Identity/commit distinction | Confirmed mechanically | Exact map/handoff hashes, 69 input hashes, both parent links and nine legacy identities verified. |
|
|
| 6. Independent checks | Passed within stated limits | Contract checker, config suite, syntax and mapping whitespace checks below; no native/synchronization/security suites claimed. |
|
|
|
|
## Direct source-row dispositions
|
|
|
|
Every row is **confirmed as a static source finding and justified reuse/change
|
|
recommendation**, subject to findings 1-5. No row is certified as external runtime
|
|
behavior. Paths/lines here resolve at d4696d09.
|
|
|
|
| Map source row | Verified meaning / disposition |
|
|
|---|---|
|
|
| agent.sh:78-130 | Reads seat defaults, copies canonical SOUL to shared agent path, conditionally writes seat record. Reuse identity concept; change snapshot materialization. |
|
|
| agent.sh:132-170 | Global agent session default and role-tool narrowing. Replace scoped selection; retain narrowing principle only. |
|
|
| agent.sh:181-199 | Shared mission copy, name-default workspace, Compose TUI launch. Change orchestration and inputs. |
|
|
| adapter.sh:23-50 | cwd, fork/persistent/ephemeral flags and nonempty-directory `-c`; explicit tools/no-tools. Exact scoped binding remains new. |
|
|
| adapter.sh:63-96 | Native/print modes and explicit suppression/provider/model/prompt arguments. New mediated gateway remains required; engine behavior not exercised. |
|
|
| mosaic-task.mjs:252-273,670-676 | Closed role keys, filename identity, known unique tools, network enum and emitted metadata. Not network enforcement or scope RBAC. |
|
|
| mosaic-task.mjs:362-378 | Requested task tools intersect mission tools when both exist; empty intersection is tool-free. Absent task tools can inherit mission tools: this is narrower legacy semantics, not the new full policy resolver. |
|
|
| mosaic-task.mjs:295-325 | Exclusive-create snapshots/helper, no fsync in helper. Reuse intent, replace durable publisher. |
|
|
| mosaic-task.mjs:442-466 | Final response/provenance/process result fields, followed by writeOnce. Not invocation-level managed audit. |
|
|
| compose.yaml:38-43 | Writable whole-root mount and separate read-only auth mount. New managed isolation/credential boundary needed. |
|
|
| run-agent.sh:20-41 | Adapter path checks and shared generated prompt before dispatch. Retain dispatch validation, change context publication. |
|
|
| load-contracts.sh:18-58 | Required governance sources, optional seat SOUL and fixed staging file. Snapshot/publication changes warranted. |
|
|
| load-contracts.sh:68-77,81-98 | Blanket user Markdown selection precedes mission, contrary to header order. Replace discovery with authorized classified selection. |
|
|
| reset.sh:16-48 | Configured target, symlink/realpath/marker checks, recursive delete; no claim/reference/receipt integration. |
|
|
| mosaic-task.mjs:548-595 | Retry redirects relative mission references to snapshot and replays as a new run. Not uncertainty recovery. |
|
|
| mosaic-task.mjs:598-641 | Count-based preview/apply, caught directory errors, delete then receipt. Protected retention requires changes. |
|
|
| mosaic-config.mjs:39-61,76-174 | MOSAIC_CONFIG override, strict shape/file/root validation and lstat errors treated as missing. Sole-config reconciliation is explicitly required, not silently approved. |
|
|
| mosaic-config.mjs:194-239 | Exclusive bootstrap creation, existing-config validation and quoted env output. Synthetic inspector must not invoke bootstrap/live resolution. |
|
|
| auth.sh:19-96 | Config-backed account reporting; status parses credential JSON and parser diagnostics. Static source read only; no redaction guarantee or credential read performed by reviewer. |
|
|
| agent.sh:28-64 | Named auth account refusal checks and mount-source export; no project-selection parser. Future #50 binding must replace flat selection. |
|
|
|
|
The nine files were read completely. Plan inputs read: foundation requirements,
|
|
workspace/schema interview, phase-2 contract, candidate README/REVIEW/RUNTIME,
|
|
ROADMAP, #55 layout, #54 native-development plan and #50 auth/provider registry.
|
|
Also read candidate check.py and semantic-model.py, extension/.pi READMEs,
|
|
Containerfile and adapter contract. The 69-entry identity audit is a byte audit,
|
|
not a claim of independent line-by-line review of every extension/schema fixture.
|
|
The schema/fixture inventory was additionally consumed by the author checker.
|
|
|
|
## R1-R34 semantic dispositions
|
|
|
|
C = confirmed responsibility allocation and planned gap, not implemented behavior.
|
|
The map's concise index is read with its named accepted-plan input; it does not
|
|
need to restate every normative clause to be a faithful responsibility map.
|
|
|
|
| Requirement | Disposition and meaning checked |
|
|
|---|---|
|
|
| R1 | C — reusable definition retained; execution-specific identity binding changes. |
|
|
| R2 | C — project registration and bounded delegation require new resolver, not tool names. |
|
|
| R3 | C — exactly one project parent, explicit workspace membership; dependencies do not grant access. |
|
|
| R4 | C — one identity across scopes with distinct scoped sessions, replacing global default. |
|
|
| R5 | C — explicit agent/project/workspace selection, not cwd or seat-name inference. |
|
|
| R6 | C — reusable instructions, selected scoped work context and authorized snapshots. |
|
|
| R7 | C — exact Resume/Fresh/genuine-first-use distinction; damaged history is not first use. |
|
|
| R8 | C — assignment-only Abandon and explicit authorized prerequisite/selection transitions. |
|
|
| R9 | C — authorized human/service launch and recovery from checked work records. |
|
|
| R10 | C — claim key is scoped, not session-only; tuning/budgets/scaling are not implemented by the map. |
|
|
| R11 | C — shared client operations/work truth; no separate interface task list. |
|
|
| R12 | C — explicit scoped messaging, no identity-based conversation mixing; cross-lane text is not authority. |
|
|
| R13 | C — whole-root mount is not containment; actual enforcement remains a proof gate. |
|
|
| R14 | C — legacy provenance is useful but lacks trusted classified per-action evidence. |
|
|
| R15 | C — owner phase/user-test gates retained; independent written approval is not owner acceptance. |
|
|
| R16 | C — canonical SOUL retained, current approved launch revision snapshotted; no silent live reload. |
|
|
| R17 | C — comparable base hash and cross-interface notices are new, distinct from full launch identity. |
|
|
| R18 | C — single-owner mission/parent graph and exact references, not duplicated project truth. |
|
|
| R19 | C — bounded within-plan decomposition and authorized non-author acceptance; coordinator title is insufficient. |
|
|
| R20 | C — taskless permitted read/chat is distinct from recorded assigned changes. |
|
|
| R21 | C — active conflict plus explicitly authorized connection, not automatic attach/replacement. |
|
|
| R22 | C — transcript visibility/handoff is separate from work-record read and automatic context loading. |
|
|
| R23 | C — revoke affected scope, stop/fence and reconcile effects; independent other-scope authority survives. |
|
|
| R24 | C — one controller, separately authorized observers and explicit generation-fenced transfer. |
|
|
| R25 | C — controlled Fresh replacement requires stopping/safety evidence, not timeout/idle alone. |
|
|
| R26 | C — non-destructive authorized investigation, no blind replay or invented success. |
|
|
| R27 | C — audit failure closes affected admission; preauthorized fail-safe stop is not unaudited recovery. |
|
|
| R28 | C — classified relevant user context replaces blanket global Markdown discovery. |
|
|
| R29 | C — retirement/reopen preserves evidence, distinct from deletion and protected retention. |
|
|
| R30 | C — reviewed legacy adoption preserves originals; no inferred membership. |
|
|
| R31 | C — current approved intent pauses affected work for reconciliation; messages cannot silently retask it. |
|
|
| R32 | C — standard nonhierarchical scope roles narrow reviewed ceilings, not redefine identity. |
|
|
| R33 | C — invocation evidence plus actually enforced limits; no claim to enumerate every internal effect. |
|
|
| R34 | C — Mosaic-controlled client with Pi behind the single reviewed adapter; no native parity waiver of safety. |
|
|
|
|
Owner-intent/reassignment was checked particularly against R8/R19/R23/R31/R32,
|
|
README reference/permission/lifecycle rules and RUNTIME assignment/message rules.
|
|
Independent acceptance uses actual author provenance and current reviewer authority,
|
|
not a fresh session of the same author or a message saying approved. The small
|
|
synthetic model cannot prove that enforcement; the map does not claim it does.
|
|
|
|
## Independent test receipts
|
|
|
|
Measured 2026-09-06 around 08:01 UTC. Isolated source export:
|
|
`/tmp/fm-filbert-1.6Acnih`, created with
|
|
`git archive d4696d09eb1b5dcf1028f30db2cd63735f51cb16 | tar -x -C <export>`.
|
|
No shared-tree checkout/reset, dependency install or live runtime was used.
|
|
|
|
1. Python/subprocess `git show <commit>:<path>` plus `hashlib.sha256`:
|
|
both candidate hashes matched; 69/69 inventory matched; 9/9 legacy files matched
|
|
69d1bb3 and the export. `git rev-list --parents -n 1` confirmed both parent links.
|
|
2. From export, with clean environment, temporary HOME and bytecode writes disabled:
|
|
`/home/jwoltje/.pyenv/versions/3.12.8/bin/python3 docs/plans/foundation-v1-candidate/check.py`.
|
|
**Exit 0:** 38 command shapes, 38 record shapes, 16 paths, 7 restricted-domain hash
|
|
vectors, 155 runtime/artifact shapes, 35 synthetic model cases; 5+5 deliberately
|
|
shape-valid semantic forgeries remain shape-valid. Python 3.12.8/jsonschema 4.26.0.
|
|
Initial attempt using `env -i PATH=/usr/bin:/bin ... python3` failed exit 1 because
|
|
that interpreter lacked jsonschema. No dependency was installed; the existing
|
|
explicit interpreter above supplied the documented dependency for the successful run.
|
|
3. From export: `env -i PATH=/usr/bin:/bin HOME=/tmp/fm-filbert-1.6Acnih-review-home bash scripts/test-config.sh`.
|
|
**Exit 0: 24 passed, 0 failed.** Suite uses its own temporary synthetic config/data.
|
|
4. `bash -n` for scripts/agent.sh, auth.sh, reset.sh; `sh -n` for
|
|
adapters/pi/adapter.sh, src/run-agent.sh, src/load-contracts.sh;
|
|
`node --check` for scripts/mosaic-config.mjs and scripts/mosaic-task.mjs.
|
|
**All exit 0.** Observed default Node v26.8.1; syntax checking is not pinned-runtime testing.
|
|
5. `git diff-tree --check 7345f330^ 7345f330`: **exit 0**.
|
|
|
|
No test-task full suite, release/conductor/auth runtime suites, verify.sh, Docker,
|
|
native extension, sync/package, renderer, browser, process-stopping, sandbox,
|
|
credential separation, crash-durability or full JCS/Unicode enforcement tests ran.
|
|
In particular the author checker is independently executed author test code, not
|
|
an independent implementation of its validator and not proof of real authorization.
|
|
No architecture JSON/HTML, render receipt or visual preview was supplied or accepted.
|
|
|
|
Only this offered verdict path was written in the repository. No shared logs,
|
|
CURRENT, source, policies, installations, commits or pushes were changed. No
|
|
credential contents, live worker state or separate ~/.mosaic environment were read.
|
|
No implementation or automatic next increment is authorized by this verdict.
|