Rocko-authored, Filbert-reviewed inspector (r6 manifest a4a44930...) with full review/build/verdict evidence under docs/plans/reviews. 43/0 selftests, oracle zero-disagreement, foundation checker PASS. Owner A9 acceptance recorded separately.
312 lines
20 KiB
Markdown
312 lines
20 KiB
Markdown
# FI-FILBERT-6 — independent CODE verdict: NOT APPROVED
|
||
|
||
Reviewer: filbert. Author: rocko. Coordinator/follow-up: darkwing.
|
||
Date: 2026-09-06. Authority: the exact FI-FILBERT-6 request under Jason's authorization.
|
||
|
||
No competing assignment is known. I have not authored the implementation. This is
|
||
review of the full frozen inspector candidate, not just the regex correction.
|
||
The supplied tests pass, but independent adversarial CLI witnesses expose failures
|
||
of reference completeness, work-access narrowing, revision handling and specified
|
||
first-failure ordering. No real permission grant or runtime exploit is claimed.
|
||
|
||
## 1. Exact subject and admission
|
||
|
||
| Input | SHA-256 / commit |
|
||
|---|---|
|
||
| `2026-09-06_foundation-inspector-rocko-build-manifest-r3.json` | `3c2253b6c9f31e448c77aaac53977d41baecfb30e15845dcfffd8dc694428547` |
|
||
| `2026-09-06_foundation-inspector-rocko-build-r3.md` | `ec0444c94c9caf16472fdba1ff3fbc767dffd1a798b9a2da837598c9f4b25508` |
|
||
| Charter candidate 3 | `19b6721128a627a2032ffdb95ece2d50abe69a8f6d521e9eff8bbdaff22798b6` |
|
||
| Incorporated feasibility r2, §§5–13 subject to overrides | `f2f47fcfe22dca79f10f885b83d87a2f846fdb560425a4e20705c40ce4a123e1` |
|
||
| Pattern/profile addendum | `afe2980be2f91e701dae5af3018831ac5c300474f52bcc06e740ce5b5cc68ca5` |
|
||
| Addendum verdict | `03c979b77cc6b03b6685ba51ed1ce24c3f1d7b274ce8f772263a103670050da7` |
|
||
| `records.schema.json` | `05774aaf6943cb69c113e39ff1c29676a2a230ca7bf665c50dbcaa8049672af6` |
|
||
| `check.py` | `82564a7d3200afcdda0850a9454cac6e6cd6a76687d2162c13cf214d7eac4607` |
|
||
| Source/schema baseline | `d4696d09eb1b5dcf1028f30db2cd63735f51cb16` |
|
||
| Accepted map | `7345f330fc6bfae5aa1d896c78cfb7cbe62efbae` |
|
||
| Measured integration HEAD | `9a5fbdbda74b16adf488fe28138b2ba69ea5e669` |
|
||
|
||
Report/manifest paths above are under `docs/plans/reviews/`. Code is uncommitted;
|
||
HEAD alone is not its identity. I independently verified all 294 distinct regular
|
||
files, modes, sizes, hashes, the exact implementation allowlist with no extras,
|
||
all six aggregates and every pinned input before execution. Source baseline
|
||
package bytes were exported from the committed baseline, not mutable extensions.
|
||
|
||
Final recheck at **2026-09-06T21:49:22Z** verified the same identities in both the
|
||
shared tree and isolated export, and the same HEAD. No candidate drift found.
|
||
The all-candidate aggregate is
|
||
`e5f9039cf4614e8acc3f6c6a71f0a03dbc1c29002703029180d1ccef5757979c`.
|
||
|
||
## 2. Numbered findings and required dispositions
|
||
|
||
All source locations below refer to the frozen `scripts/foundation/resolve.mjs`
|
||
(SHA-256 `eaa4a419618328915cd470ba192a88b8d313ee8fa48f600289ffe39df15280b2`)
|
||
unless another file is named. Witnesses use copies of the frozen demos; no shared
|
||
fixture was edited. `B` means `fixtures/demo/demo-file-change-src.json`; `P` means
|
||
`fixtures/demo/demo-change-w1.json`, under `scripts/foundation/`.
|
||
|
||
### F1 — BLOCKING / high: referenced declarations are incompletely enforced
|
||
|
||
Locations: `checkStructuralReferences`, lines 1043–1083; `computeContext`,
|
||
1324–1347 and 1403–1407; declaration helpers at 1213 onward.
|
||
Contract: charter §3 and incorporated r2 §6.2 require exact registry-reference
|
||
resolution and declared authorization inputs; charter §§7/10.4 preserve the
|
||
special admission-stage missing-declaration exits.
|
||
|
||
Two independent witnesses:
|
||
|
||
- From B, remove registry declarations whose registry is `harness`, `settings`
|
||
or `context-content`, leaving the agent's references intact. Actual: **exit 0,
|
||
allowed**. These references are shape-checked but never resolved.
|
||
- From B, set `task-w1-dep.authorizationRef` to the undeclared, well-formed UUID
|
||
`00000000-0000-4000-8000-000000000099`. Actual: **exit 0, allowed**. The dependency
|
||
is consulted and its accepted status used, but its authorization is not checked.
|
||
Required result is a missing-state refusal, not an allowed preview; the
|
||
authorization case has the charter's exit-3 admission exception.
|
||
|
||
Required correction: enforce the applicable exact declaration checks, including
|
||
consulted dependencies, without turning missing declarations into unrestricted
|
||
facts or swallowing their documented admission exits. Add independent negatives
|
||
for absence and mismatched references, not just missing policy ceilings.
|
||
|
||
### F2 — BLOCKING / high: task-only contexts evade required `work.read`
|
||
|
||
Locations: `computeContext` lines 1354–1356, 1385–1417;
|
||
`checkWorkAccess` lines 1426–1434.
|
||
Contract: charter §10.2 requires work.read for consulted task references within
|
||
the supported workspace/project relation, in the full applicable intersection.
|
||
|
||
- From B, clear the selected task's `missionRef` and `dependencies`. Set execution
|
||
restrictions to operations `["file.change"]`, readPaths `[]`, writePaths
|
||
`[{"root":"workspace","path":null}]`, network `none`, endpointRefs `[]`.
|
||
Actual: **exit 0, allowed**, despite consulting the assigned task without
|
||
work.read. The boolean `consultedWork` is set only for missions/dependencies,
|
||
not the task bound by the assignment.
|
||
- From P, clear every task's mission/dependency references and set both requester
|
||
execution restrictions to operations `["assignment.change"]`, empty paths,
|
||
network `none`, no endpoints. Actual: **exit 3, unresolved /
|
||
runtime-reconciliation-required**, rather than consulted-work-not-readable.
|
||
`checkWorkAccess` similarly conditions work.read on the task having other refs.
|
||
|
||
Required correction: distinguish genuinely taskless reads from calculations
|
||
which consult a task. Require work.read for the latter, including proposal
|
||
subject/target work, even when that task has no mission or dependency.
|
||
|
||
### F3 — BLOCKING / high: proposal issuer narrowing does not recheck work access
|
||
|
||
Locations: `evaluateProposal`, lines 1504–1535 and 1555–1563.
|
||
Contract: charter §10.1 says the explicit delegation issuer's restrictions
|
||
additionally narrow the requester calculations in **both** scopes; §10.2 requires
|
||
work.read in that full intersection.
|
||
|
||
From P, change only `delegationInputs[0].issuerCeiling.operations` to
|
||
`["assignment.change"]`. Its delegated operation remains within the issuer ceiling,
|
||
but the resulting intersection excludes work.read. Original subject work includes
|
||
mission/dependency references, so this case does not depend on F2's task-only edge.
|
||
Actual: **exit 3, unresolved / runtime-reconciliation-required**.
|
||
|
||
The code checks work access before applying the issuer, then checks only
|
||
assignment.change against the narrowed layers. Required correction: enforce all
|
||
applicable access conditions against the issuer-narrowed contexts, with coherent
|
||
negative coverage in both scopes. An unresolved preview must not falsely claim
|
||
that all modeled checks passed.
|
||
|
||
### F4 — BLOCKING / medium: cycle construction merges distinct historical revisions
|
||
|
||
Location: `checkCycles`, lines 1087–1109.
|
||
Contract: exact four-field references, contiguous history, and separate edge
|
||
relations in charter §3 / §10.4 and incorporated r2 §6.2–6.3.
|
||
|
||
The dependency graph keys tasks by identity **without revision** and unions edges
|
||
from every historical record. Independent witness:
|
||
|
||
- Keep B's revision-1 history: T1 (`task-w1`) depends on D1 (`task-w1-dep`).
|
||
- Add contiguous T2 with no dependencies, and D2 depending on T2.
|
||
- Add revision 2 of the selected assignment and the two relevant plan decisions;
|
||
bind the assignment/selection and plan subjects to the new exact revisions.
|
||
Each new record supersedes its own revision 1. All old references still exist.
|
||
|
||
All records pass the pinned schema/formats. Independent exact-reference DFS finds
|
||
**no cycle** in dependencies, mission parents or supersedes, and independently
|
||
asserts contiguous histories. The selected current task T2 has no dependencies.
|
||
Actual CLI: **exit 2, invalid-request / dependency-cycle** because the implementation
|
||
constructs the different graph T→D→T by discarding revision distinctions.
|
||
|
||
Required correction: do not infer cycles by unioning temporally distinct edges.
|
||
Preserve the approved exact-reference/history semantics and required cycle-before-
|
||
continuity precedence. If a stronger, identity-wide historical prohibition is
|
||
intended, obtain an explicit contract ruling instead of silently adding it.
|
||
|
||
### F5 — BLOCKING / medium: specified first-failure ordering is not preserved
|
||
|
||
Locations: `validateBundleShapeScoped`, approximately 719–733 (before Model's
|
||
record sort at 988); `evaluateProposal`, 1504–1541.
|
||
Contract: charter §10.4 requires stable kind/id/scope/revision/field ordering within
|
||
a stage, not inventory input order; §5 gives missing delegation plus message its
|
||
named rule after structural validation.
|
||
|
||
1. From B, set `agent-a.payload.status` to an invalid enum and add an unknown
|
||
`extra` field to `agent-b.payload`. Forward record inventory yields
|
||
**exit 2 / shape-enum-mismatch**. Reverse only the top-level record array:
|
||
**exit 2 / shape-unknown-field**. Both identities remain well-formed. Validation
|
||
returns the first array member's error before the later stable sorting applies.
|
||
2. From P, set delegationRef null, supply a synthetic message, and restrict original
|
||
requester execution to work.read only. Structural validation succeeds. Actual:
|
||
**exit 3 / operation-not-permitted**, proposal rule
|
||
`requester-lacks-original-scope-authority`, rather than `message-is-not-authority`.
|
||
The special message check is deferred until after requester admission.
|
||
|
||
Required correction: implement the frozen first-failure contract and add independent
|
||
multi-failure/permutation tests. If message precedence is meant differently, darkwing
|
||
must reconcile the explicit §5 exception; the writer must not guess an override.
|
||
|
||
### F6 — NONBLOCKING evidence improvement: writer inventories omit ownership
|
||
|
||
`cli.test.mjs:31–39` and `test-foundation.sh:123` inventory path/type/size/mode/
|
||
inode/mtime/content, but omit UID/GID despite charter §8 naming ownership.
|
||
My separate 15-run inventory includes UID/GID and passes (see §4), so this is not
|
||
an observed owner change or an additional code rejection. Preserve ownership
|
||
coverage in the maintained regression harness rather than relying on this review's
|
||
one-off receipt.
|
||
|
||
## 3. Acceptance and historical-finding dispositions
|
||
|
||
| Gate | Independent disposition |
|
||
|---|---|
|
||
| A1 | Positive text/JSON read and assigned-change demos pass exact-output tests; disclaimers present; bounded no-effect observation passes. Does not rescue F1/F2's additional false-positive cases. |
|
||
| A2 | Named missing-workspace-registration/cross-project fixtures pass; no fallback or unrelated payload emission observed. |
|
||
| A3 | Supplied duplicate/reference/ownership/revision/cycle negatives pass, including separate detector and CLI-precedence tests. **Not satisfied generally: F1/F4.** |
|
||
| A4 | Supplied role, mandatory policy, optional task/mission/execution, registration-delegation, path-prefix and no-assignment-union tests pass. **Not satisfied: F1–F3.** |
|
||
| A5 | Strict-parser, bounded canonical domain, separate pinned schema/profile oracle and production LF refusals pass the tested finite domains. |
|
||
| A6 | Static runtime import/I/O review and independent descriptor/non-effect tests pass within stated limits; see F6. No OS-containment claim. |
|
||
| A7 | No allowed reassignment branch found; original selection is preserved and supplied requester negatives pass. **Not satisfied: F2/F3 and F5's proposal ordering.** |
|
||
| A8 | Closed fields, exits 0/2/3/4, parser/I/O diagnostics, escaping and body-free outputs pass supplied tests. **Not fully satisfied: F5.** |
|
||
| Required integration verification | Foundation checker independently green. **Five repository suites not independently rerun; writer receipts only. Gate remains uncleared.** |
|
||
| A9 | Not performed; Jason's demo/acceptance remains separate and cannot proceed as an accepted-code gate from this verdict. |
|
||
|
||
Prior admission findings against the older candidates:
|
||
|
||
- **C1 closed for r3 identity.** The corrected message-demo digest is
|
||
`f1c6bd523cdff161e51da156fd00cfaa652d193f41541686548cf023378fd8ab`;
|
||
manifest and demo-copy equality verify. I do not independently attest the writer's
|
||
historical scratch timestamps or reconstruct authorship of the original typo.
|
||
- **C2 closed for the tested r3 corpus/profile implementation.** The actual Node
|
||
schema column agrees with pinned Python; no disagreement waiver or copied oracle
|
||
answer supplies the Node result. Strict production validation remains separate,
|
||
rejects rather than normalizes identities, and precedes graph admission.
|
||
Original four LF witnesses remain, as do the low-year calendar witnesses.
|
||
- **C3 closed.** Exactly the twelve charter result fields; process exit is separate.
|
||
Contract-derived assertions and spawned outputs pass, including pre-validation.
|
||
- **C4 closed as bounded evidence.** Before inventories are captured before runs
|
||
and compared afterwards, not regenerated as the expected baseline. My separate
|
||
ownership-inclusive observation confirms the measured result.
|
||
- **C5 closed.** Actual CLI requires O_RDONLY/O_NOFOLLOW/O_NONBLOCK, including the
|
||
valid zero-valued O_RDONLY; FIFO refusal passes. No O_CLOEXEC claim is made.
|
||
|
||
## 4. Independent commands, receipts and reproducibility
|
||
|
||
Isolated candidate export: `/tmp/fi-filbert-6.42ru903e`.
|
||
Separate harness/evidence root: `/tmp/fi-filbert-6.42ru903e-evidence`.
|
||
Source/test commands were inspected before execution. Candidate fixture generation
|
||
ran only into the suite's disposable scratch, never the shared frozen tree.
|
||
|
||
Measured toolchain: Node **v26.8.1**, Python **3.12.8**, jsonschema **4.26.0**.
|
||
The pinned low-year platform witness is `strftime('%Y', year 999) == '999'`.
|
||
|
||
From the isolated export, the following commands each exited **0**, under `env -i`
|
||
with PATH `/home/jwoltje/.pyenv/versions/3.12.8/bin:/usr/bin:/bin`, synthetic HOME
|
||
and TMPDIR beneath the evidence root, `PYTHONDONTWRITEBYTECODE=1`, `NO_COLOR=1`:
|
||
|
||
| Command | Actual result |
|
||
|---|---|
|
||
| `node --test scripts/foundation/` | 63 tests, 63 pass, 0 fail, 0 skipped |
|
||
| `python3 scripts/foundation/verify-schema.py` | 3 pins match; 38 pinned fixtures; 1539 corpus records; 519 agree-valid / 983 agree-invalid / **0 disagreements**; 27 parser-only; 10 unsupported-kind unassessed; 489 profile-valid / 30 profile-invalid among schema-valid records; 73 named probes verified |
|
||
| `bash scripts/test-foundation.sh` | 43 passed, 0 failed; scratch regeneration equality, suites/oracle, goldens, I/O and non-effect checks |
|
||
| `python3 docs/plans/foundation-v1-candidate/check.py` | Exit 0: command 38+5, records 38, paths 16, restricted fingerprints 7, runtime/artifact 155+5, synthetic semantic model 35; not runtime enforcement |
|
||
|
||
Additional independent harnesses in the evidence root:
|
||
|
||
- `python3 reproduce.py` and `python3 additional-probes.py`: exact CLI witnesses
|
||
described above, plus the allowed B positive control. Captured result JSON and
|
||
input hashes are in `witnesses/`; all CLI stderr was empty.
|
||
- `python3 witness-validation.py`: 390 record-shape checks across exploratory and
|
||
finding witnesses pass using the pinned schema and independently redeclared
|
||
checker formats. The intentional shape-order negatives are excluded. Also checks
|
||
exact graph acyclicity and complete histories for F4; exit 0.
|
||
- `python3 profile-probes.py`: **831** independently enumerated typed-identity
|
||
occurrences/probes across B/P and a non-null agent execution-ID control. Each
|
||
single-final-LF mutation gives exit 2, invalid-request/profile-pattern-mismatch,
|
||
with selection/operation/proposal/diagnostic all null. A multiline mission
|
||
objective remains allowed. This extends, not replaces, the supplied record oracle.
|
||
- `python3 non-effect.py`: 15 independent text/JSON, parser, missing-file,
|
||
final-symlink, FIFO and usage runs. All expected exits pass. **16 inventory
|
||
entries unchanged**, including path/type/size/mode/UID/GID/inode/mtime-ns and
|
||
content or symlink target, with fixture/home/cwd/data roots separated from logs.
|
||
Absolute Node executable, PATH `/nonexistent`, synthetic HOME/config canaries;
|
||
no canary output. Exit 0.
|
||
- `python3 recheck.py`: final shared-tree/export identities and HEAD pass, exit 0.
|
||
|
||
Selected evidence hashes (paths relative to the evidence root):
|
||
|
||
| Artifact | SHA-256 |
|
||
|---|---|
|
||
| `node-tests.log` | `36c59ae491eec2d97909912f3fe4141b44e6473f0640b2141c460e2089a8a1df` |
|
||
| `oracle.log` | `18774c031f6e2bea64c45112fc23e29984db4923a74b365eaafed912746481ad` |
|
||
| `selftest.log` | `fafe1f016eaa8d150119902f2bec5ca2a83a78ccaf06501dbc5db9e9b0979a05` |
|
||
| `foundation-check.log` | `42ddd578b4f2be0c0b7b5b78a95de3a94e7d372661f634eb6f5209aa55e0c60a` |
|
||
| `profile-probe-receipts.json` | `6c067bcd6c4d88482b410e4e91f228ae5ef293156670b32c13d88544bcba463a` |
|
||
| `witnesses/receipts.json` | `db77081d5f0acf6f9f2744c48ea208a5363a688ec363db19a8767c32ef02b773` |
|
||
| `witnesses/additional-receipts.json` | `04c3945df8de33e0ed7b44a760703c19cb9d1a27dcc1e31b5678be1d630a7df1` |
|
||
| `inventory-before.json` and `inventory-after.json` (identical) | `78d5da15db9f0ae1501f7a24dccb14208eb9ba8b80c6e96d243fb850daced47c` |
|
||
| `recheck.log` | `66a96b5d044180515a717551a26ec75adaa109d0765eeb3a74ef3081b43c7d37` |
|
||
|
||
Witness input SHA-256s, for exact reproduction/audit:
|
||
|
||
| Witness basename under `witnesses/` | SHA-256 |
|
||
|---|---|
|
||
| `missing-agent-registry-declarations.json` | `78efd6fb46960079423eacc5cc9f469f0856a945137b03808e64b98add50bf56` |
|
||
| `consulted-dependency-undeclared-authorization.json` | `cc78be2811d49e6d56d67a009cac532e559a901e9a960834f64121d154e75299` |
|
||
| `assigned-change-without-work-read.json` | `35ee45e648387b9a8b0aa81b201b4eff61eb5a15bdc6eea30ecbfacecae77bd9` |
|
||
| `proposal-task-only-contexts-without-work-read.json` | `e1a9cd887f1bc64a8abdd8a0a1326df21b1ac0406ead978d2e6fc26e4eb0d683` |
|
||
| `proposal-issuer-denies-work-read.json` | `34d1ed805d3d42098052be2b928404947bd2d3b7b4c1af0edd3ec344aaec88f2` |
|
||
| `acyclic-versioned-history-false-cycle.json` | `e3dd1cd34e24c4d9ba0354203b7754c9e045966f0503d28ae1912e4e89eb2d15` |
|
||
| `shape-order-forward.json` | `689f9aa9713e53d7b10f9a9e263d16a2ff7e83d3056060c37c79c4e30bd11d6c` |
|
||
| `shape-order-reversed.json` | `d14fca5e43632c3283f1bcda772f9940dcd234afdfa43fe19bf5faa336eff062` |
|
||
| `message-priority-after-structural-validation.json` | `9e2ec77b87fb99fa602876fb5ffd52bbcd2142a4f7224cf1cdf7ec223a89d6fe` |
|
||
|
||
Scratch paths are local, disposable evidence, not durable repository artifacts.
|
||
The mutation recipes above and the frozen demo identities permit reconstruction.
|
||
|
||
## 5. Limits, corrections and handoff
|
||
|
||
- The five legacy repository suites were **not independently rerun**. Their green
|
||
results remain Rocko's receipts. Inspection found Docker/live branches in legacy
|
||
task/release tests and git mutation fixtures in the conductor test; I did not
|
||
widen this already-failing review into those activities or invent a skip/stub
|
||
and call the integration gate green. That required gate still needs an explicitly
|
||
authorized, isolated, non-live verification run before approval.
|
||
- Exploratory scratch receipts also contain blocked-subject-task, unrelated
|
||
subject-task-intent and blocked-target-mission probes reaching unresolved.
|
||
**Correction to their provisional expected-from-contract labels and my early
|
||
progress wording:** these are not counted as established violations here.
|
||
§5 specifically names subject-assignment and target-task checks; I do not infer
|
||
an additional full subject/target L1–L9 calculation from those experiments.
|
||
- An exploratory Unicode probe agreed (both rejected U+13439); no Unicode
|
||
disagreement is claimed. Exhaustive comparison of the host Python/Node
|
||
Cc/Cf/Cs category sets found the same 2283 code points. This does not establish
|
||
general equivalence of their Unicode or schema implementations.
|
||
- Finite tests, static import review and unchanged inventories do not prove absence
|
||
of every read, complete schema equivalence, OS containment, authentic delegation,
|
||
crash safety, parent-path containment or resistance to same-size concurrent
|
||
input mutation. Only Node v26.8.1 was executed; no Node 22/24 portability claim.
|
||
- No shared implementation, fixture, charter, log, CURRENT or index edits; no
|
||
installation, staging/commit/checkout/reset/push, engine/network/native/sync or
|
||
live-data work. Synthetic canary files used by tests are not real credentials;
|
||
the operator's actual HOME/credentials/`~/.mosaic` were not investigated.
|
||
This verdict is the only repository write for FI-FILBERT-6.
|
||
|
||
**Return to darkwing:** reconcile F1–F5 with the frozen contract, let Rocko alone
|
||
make any authorized corrections, then supply a newly hashed frozen candidate and
|
||
complete verification receipts for independent re-review. No implementation,
|
||
reassignment, acceptance, owner demo, push, issue closure or next phase follows
|
||
automatically. No timer or deadline is set.
|