Rocko-authored, Filbert-reviewed inspector (r6 manifest a4a44930...) with full review/build/verdict evidence under docs/plans/reviews. 43/0 selftests, oracle zero-disagreement, foundation checker PASS. Owner A9 acceptance recorded separately.
4.3 KiB
Synthetic inspector code-review and owner-demo gates
Coordinator: darkwing. Code writer: rocko. Independent reviewer: filbert. Task: FI-ROCKO-3. Status: checklist prepared; no code candidate received or approved. Charter identity: 19b6721128a627a2032ffdb95ece2d50abe69a8f6d521e9eff8bbdaff22798b6. This is verification preparation under the authorized build, not another specification.
Candidate admission
- Receive exact path list, file hashes, integration HEAD and test receipts.
- Verify charter/note/schema identities and compare every changed path with the approved allowlist. Preserve Dewey's changes; never blanket-stage or reset.
- Inspect source and test commands before executing the new code. No native/sync, credential, live-state or network experiments. A temporary HOME alone is not an OS sandbox; apply the charter's explicit bounded-evidence qualifications.
- Freeze a content-hash manifest for the full code/fixture/test candidate. Do not call moving work independently reviewed. Recheck Filbert's assignment compatibility and non-authorship before the full review request.
Required review evidence by acceptance group
| Group | Evidence required, not just a green aggregate |
|---|---|
| A1 | Coherent positive read and assigned-change previews; exact text/JSON outputs, disclaimers, no physical change |
| A2 | Missing workspace registration and cross-project selection refusals; no fallback or unrelated payload output |
| A3 | Named first-failure results for duplicate/reference/ownership/revision/cycle fixtures; detector and CLI coverage distinct |
| A4 | All mandatory ceilings and optional restrictions; role/issuer/delegated-operation narrowing; no cross-assignment union |
| A5 | Strict parser and separate schema/profile corpus: duplicate keys, numeric tokens, type/null/bounds/Unicode/calendar/path cases |
| A6 | Static import/I/O inspection, descriptor checks, fixture/observed-root inventory comparison, no ambient bootstrap or live lookup |
| A7 | Both requester contexts and intent/delegation checks; direct-assumption limits; original selection preserved; allowed reassignment unreachable |
| A8 | Every output/exit class including pre-validation and I/O errors; body-free diagnostics, escaped terminal data, stable ordering |
Oracle verification must be mandatory, version-recorded and pinned to the accepted schema/checker. Missing dependency is a blocker, never a skip. Compare schema shape validity separately from profile/unsupported-kind/graph/admission outcomes.
Run the foundation checker and all five repository suites against the measured integration candidate, reporting unrelated concurrent changes separately. Existing charter-review shape probes are not code tests. No raw test counts substitute for coverage of the named failure paths. Finite tests do not prove complete schema conformance, absence of all reads, containment, authentic delegation or crash safety.
Independent verdict
Filbert must receive the exact candidate manifest, source baseline, charter/note hashes, writer receipts and this checklist. He returns an independent verdict with findings, actual commands/results and untested limits. Darkwing reconciles findings; Rocko alone fixes owned code, then a newly hashed candidate is re-reviewed. Neither writer nor coordinator substitutes for the independent verdict.
Owner demo (A9), only after verified code
Use only the delivered coherent synthetic examples and actual verified CLI syntax:
- Show the selected agent/project/workspace and a permitted read preview.
- Show an assigned file-change permission preview; demonstrate no file was changed.
- Select the unregistered workspace and show a refusal without fallback.
- Preview cross-lane reassignment: the original assignment remains selected and even fully supplied mock declarations cannot produce a real change or allowed result.
- Ask Jason whether the selection/refusal display and no-live-effects disclaimer are clear, and whether he accepts this increment. Record his answer separately.
Do not invent demo commands before the writer returns the implemented interface. No dependent live-registry/runtime increment starts before Jason's acceptance. No push, migration or issue closure follows automatically. Shared-index/commit coordination remains separate from code delivery and reviewer approval.