Files
stack/docs/plans/reviews/2026-09-06_foundation-map-filbert-verdict.md
T
jason.woltje 8ebddd6f93 feat(foundation): offline synthetic scope/permission inspector (FI-FILBERT-8 APPROVED r6)
Rocko-authored, Filbert-reviewed inspector (r6 manifest
a4a44930...) with full review/build/verdict evidence under
docs/plans/reviews. 43/0 selftests, oracle zero-disagreement,
foundation checker PASS. Owner A9 acceptance recorded separately.
2026-09-07 14:06:35 -05:00

224 lines
18 KiB
Markdown

# FM-FILBERT-1 — independent written-map verdict
Reviewer: filbert. Follow-up owner: darkwing. Date: 2026-09-06.
## Admission and verdict
**APPROVED for the bounded written technical map at the exact identities below.**
No blocking technical-map defect found. This is not full Archify acceptance,
owner acceptance, phase advancement, an implementation charter, or a runtime verdict.
I did not author/co-author this candidate in my available session history. My
current instructions contain no competing personal owner-authorized assignment.
FM-FILBERT-1-C1 resolved my earlier mistaken use of the source baseline's historical
CURRENT.md as current task authority. That admission blocker and the resulting
incomplete NOT APPROVED are superseded by this completed review, not erased.
Mapping-commit CURRENT.md:8-25 records the later review gate; Jason's separately
communicated authorization admits only this bounded review.
- Mapping commit: `7345f330fc6bfae5aa1d896c78cfb7cbe62efbae`
- Source/plan baseline: `d4696d09eb1b5dcf1028f30db2cd63735f51cb16`
- Foundation parent: `44f257cb06484feda3412d9382e3587393796353`
- Map: `docs/plans/2026-09-06_foundation-technical-map.md`
SHA-256 `772f9e61cb9fb7a31ce8187b12cdf1c4a5fb714ad517a9c12928901171a37db1`
- Handoff: `docs/plans/2026-09-06_foundation-map-handoff.md`
SHA-256 `1fd1a89f982a31bb9db21b852df78be954323aa1668ab9752be34de853ee4999`
Both document hashes matched independent computation from `git show`. All 69
handoff input hashes matched the source baseline. The mapping commit's parent is
the source baseline, whose parent is the foundation parent. The mapping commit
changes only map, handoff and CURRENT. All nine inspected legacy source files
are byte-identical to 69d1bb3 and to the isolated baseline export.
## Numbered findings and limits
1. **Informational / confirmed — legacy launch is not managed admission.**
Locations: map launch/mount/context trace tables; baseline `compose.yaml:38-43`,
`scripts/agent.sh:121-138,181-199`, `src/run-agent.sh:37-41`,
`src/load-contracts.sh:40-41,68-97`, `adapters/pi/adapter.sh:29-44,81-96`.
Evidence: broad writable data-root mount, shared SOUL/mission/prompt destinations,
fixed `.partial`, blanket user Markdown discovery, directory-nonempty continuation,
and native/print invocation are present. These support the proposed replacement
boundaries; a named workspace is not isolation. Required correction: none.
Limit: no race reproduction, engine discovery measurement or containment test.
2. **Informational / confirmed — evidence and lifecycle reuse is correctly narrow.**
Locations: map evidence/lifecycle tables and ordering constraints; baseline
`scripts/mosaic-task.mjs:295-302,442-466,548-641`, `scripts/reset.sh:16-48`.
Evidence: exclusive-create writes lack fsync in the helper; retry starts a new
run without reconciliation; prune deletes before appending its receipt and
treats directory-read exceptions as an empty inventory; reset lacks foundation
claim/reference protection. Map preserves useful conventions without calling
them crash durability or recovery. Required correction: none. Limit: static
ordering inspection is not a measured crash/failure-injection result.
3. **Informational / confirmed — policy, packaging and process privilege remain distinct.**
Locations: map component/placement matrices and integrated ownership section;
baseline ROADMAP:127-166, #55 layout plan, candidate README sections 2-3/6,
RUNTIME sections 1/4/7. Pure calculation belongs to proposed packages/config;
publication and process authority do not. CLI presentation does not own policy.
Runtime/adapter logic has one proposed packages/agent owner, with only unavoidable
retained src shims. Current extensions/** and generated .pi installation do not
replace the future packages/* decision. A shared package is explicitly not a
shared process privilege grant. Required correction: none. #55's historical
native-test/reviewer receipts were read as reports, not independently rerun or
recertified here; Dewey's current work is excluded.
4. **Informational / confirmed with implementation limits — the inspector is appropriately bounded.**
Locations: map recommended-increment section and cross-lane scenario; candidate
REVIEW first-increment proposal, README sections 2-3/8, RUNTIME sections 2/5.
Coherent synthetic graph, explicit selection, required policy refusal,
least-privilege intersection, no assignment-union grants, deterministic preview,
no live writes and owner test gate are stated. The cross-lane case preserves the
original assignment unless a properly authorized, recorded change within owner
intent is reconciled. A message does not itself confer delegation or acceptance.
Required correction: none for this recommendation. A later charter must specify
executable graph/operation inputs and tests for those rules; the current small
model is not a real graph resolver, authenticator or reassignment implementation.
5. **Informational / review limit — source flags and reported external behavior are not runtime proof.**
Locations: map adapter row, authority/coordination history and owner-reported
cross-lane scenario; handoff collaboration section. I confirm adapter flags and
command construction, not the pinned engine's complete discovery, exact-session,
fork-preservation or security behavior. Future reuse remains conditional on the
admission tests already required by the plan. Collaboration delivery, native
acceptance and the separate-environment incident are reported context, not
independently observed facts in this review. Required correction: none; preserve
those qualifications in downstream maps and charters. No external incident
diagnosis or investigation was performed.
## Request-item dispositions
| Item | Disposition | Independent basis |
|---|---|---|
| 1. Source/plan boundaries, hops, reuse and gaps | Confirmed at the written map's explicitly limited inventory level | All direct source-locator rows opened in the committed baseline; dispositions below. New responsibilities are proposals, not repository-wide absence claims. |
| 2. R1-R34 meaning | Confirmed as responsibility mapping, not a replacement specification | Each requirement checked against the foundation table, owner interview and accepted phase-2 rules; per-R dispositions below. |
| 3. Policy/effects, package/process, source/install, single owners | Confirmed | Placement matrix and integrated qualifications agree with ROADMAP, #55 and RUNTIME trust boundaries. |
| 4. Synthetic inspector | Confirmed as a recommendation | Seven core acceptance cases plus cross-lane case preserve the no-live-grants boundary; execution and enforcement unimplemented. |
| 5. Identity/commit distinction | Confirmed mechanically | Exact map/handoff hashes, 69 input hashes, both parent links and nine legacy identities verified. |
| 6. Independent checks | Passed within stated limits | Contract checker, config suite, syntax and mapping whitespace checks below; no native/synchronization/security suites claimed. |
## Direct source-row dispositions
Every row is **confirmed as a static source finding and justified reuse/change
recommendation**, subject to findings 1-5. No row is certified as external runtime
behavior. Paths/lines here resolve at d4696d09.
| Map source row | Verified meaning / disposition |
|---|---|
| agent.sh:78-130 | Reads seat defaults, copies canonical SOUL to shared agent path, conditionally writes seat record. Reuse identity concept; change snapshot materialization. |
| agent.sh:132-170 | Global agent session default and role-tool narrowing. Replace scoped selection; retain narrowing principle only. |
| agent.sh:181-199 | Shared mission copy, name-default workspace, Compose TUI launch. Change orchestration and inputs. |
| adapter.sh:23-50 | cwd, fork/persistent/ephemeral flags and nonempty-directory `-c`; explicit tools/no-tools. Exact scoped binding remains new. |
| adapter.sh:63-96 | Native/print modes and explicit suppression/provider/model/prompt arguments. New mediated gateway remains required; engine behavior not exercised. |
| mosaic-task.mjs:252-273,670-676 | Closed role keys, filename identity, known unique tools, network enum and emitted metadata. Not network enforcement or scope RBAC. |
| mosaic-task.mjs:362-378 | Requested task tools intersect mission tools when both exist; empty intersection is tool-free. Absent task tools can inherit mission tools: this is narrower legacy semantics, not the new full policy resolver. |
| mosaic-task.mjs:295-325 | Exclusive-create snapshots/helper, no fsync in helper. Reuse intent, replace durable publisher. |
| mosaic-task.mjs:442-466 | Final response/provenance/process result fields, followed by writeOnce. Not invocation-level managed audit. |
| compose.yaml:38-43 | Writable whole-root mount and separate read-only auth mount. New managed isolation/credential boundary needed. |
| run-agent.sh:20-41 | Adapter path checks and shared generated prompt before dispatch. Retain dispatch validation, change context publication. |
| load-contracts.sh:18-58 | Required governance sources, optional seat SOUL and fixed staging file. Snapshot/publication changes warranted. |
| load-contracts.sh:68-77,81-98 | Blanket user Markdown selection precedes mission, contrary to header order. Replace discovery with authorized classified selection. |
| reset.sh:16-48 | Configured target, symlink/realpath/marker checks, recursive delete; no claim/reference/receipt integration. |
| mosaic-task.mjs:548-595 | Retry redirects relative mission references to snapshot and replays as a new run. Not uncertainty recovery. |
| mosaic-task.mjs:598-641 | Count-based preview/apply, caught directory errors, delete then receipt. Protected retention requires changes. |
| mosaic-config.mjs:39-61,76-174 | MOSAIC_CONFIG override, strict shape/file/root validation and lstat errors treated as missing. Sole-config reconciliation is explicitly required, not silently approved. |
| mosaic-config.mjs:194-239 | Exclusive bootstrap creation, existing-config validation and quoted env output. Synthetic inspector must not invoke bootstrap/live resolution. |
| auth.sh:19-96 | Config-backed account reporting; status parses credential JSON and parser diagnostics. Static source read only; no redaction guarantee or credential read performed by reviewer. |
| agent.sh:28-64 | Named auth account refusal checks and mount-source export; no project-selection parser. Future #50 binding must replace flat selection. |
The nine files were read completely. Plan inputs read: foundation requirements,
workspace/schema interview, phase-2 contract, candidate README/REVIEW/RUNTIME,
ROADMAP, #55 layout, #54 native-development plan and #50 auth/provider registry.
Also read candidate check.py and semantic-model.py, extension/.pi READMEs,
Containerfile and adapter contract. The 69-entry identity audit is a byte audit,
not a claim of independent line-by-line review of every extension/schema fixture.
The schema/fixture inventory was additionally consumed by the author checker.
## R1-R34 semantic dispositions
C = confirmed responsibility allocation and planned gap, not implemented behavior.
The map's concise index is read with its named accepted-plan input; it does not
need to restate every normative clause to be a faithful responsibility map.
| Requirement | Disposition and meaning checked |
|---|---|
| R1 | C — reusable definition retained; execution-specific identity binding changes. |
| R2 | C — project registration and bounded delegation require new resolver, not tool names. |
| R3 | C — exactly one project parent, explicit workspace membership; dependencies do not grant access. |
| R4 | C — one identity across scopes with distinct scoped sessions, replacing global default. |
| R5 | C — explicit agent/project/workspace selection, not cwd or seat-name inference. |
| R6 | C — reusable instructions, selected scoped work context and authorized snapshots. |
| R7 | C — exact Resume/Fresh/genuine-first-use distinction; damaged history is not first use. |
| R8 | C — assignment-only Abandon and explicit authorized prerequisite/selection transitions. |
| R9 | C — authorized human/service launch and recovery from checked work records. |
| R10 | C — claim key is scoped, not session-only; tuning/budgets/scaling are not implemented by the map. |
| R11 | C — shared client operations/work truth; no separate interface task list. |
| R12 | C — explicit scoped messaging, no identity-based conversation mixing; cross-lane text is not authority. |
| R13 | C — whole-root mount is not containment; actual enforcement remains a proof gate. |
| R14 | C — legacy provenance is useful but lacks trusted classified per-action evidence. |
| R15 | C — owner phase/user-test gates retained; independent written approval is not owner acceptance. |
| R16 | C — canonical SOUL retained, current approved launch revision snapshotted; no silent live reload. |
| R17 | C — comparable base hash and cross-interface notices are new, distinct from full launch identity. |
| R18 | C — single-owner mission/parent graph and exact references, not duplicated project truth. |
| R19 | C — bounded within-plan decomposition and authorized non-author acceptance; coordinator title is insufficient. |
| R20 | C — taskless permitted read/chat is distinct from recorded assigned changes. |
| R21 | C — active conflict plus explicitly authorized connection, not automatic attach/replacement. |
| R22 | C — transcript visibility/handoff is separate from work-record read and automatic context loading. |
| R23 | C — revoke affected scope, stop/fence and reconcile effects; independent other-scope authority survives. |
| R24 | C — one controller, separately authorized observers and explicit generation-fenced transfer. |
| R25 | C — controlled Fresh replacement requires stopping/safety evidence, not timeout/idle alone. |
| R26 | C — non-destructive authorized investigation, no blind replay or invented success. |
| R27 | C — audit failure closes affected admission; preauthorized fail-safe stop is not unaudited recovery. |
| R28 | C — classified relevant user context replaces blanket global Markdown discovery. |
| R29 | C — retirement/reopen preserves evidence, distinct from deletion and protected retention. |
| R30 | C — reviewed legacy adoption preserves originals; no inferred membership. |
| R31 | C — current approved intent pauses affected work for reconciliation; messages cannot silently retask it. |
| R32 | C — standard nonhierarchical scope roles narrow reviewed ceilings, not redefine identity. |
| R33 | C — invocation evidence plus actually enforced limits; no claim to enumerate every internal effect. |
| R34 | C — Mosaic-controlled client with Pi behind the single reviewed adapter; no native parity waiver of safety. |
Owner-intent/reassignment was checked particularly against R8/R19/R23/R31/R32,
README reference/permission/lifecycle rules and RUNTIME assignment/message rules.
Independent acceptance uses actual author provenance and current reviewer authority,
not a fresh session of the same author or a message saying approved. The small
synthetic model cannot prove that enforcement; the map does not claim it does.
## Independent test receipts
Measured 2026-09-06 around 08:01 UTC. Isolated source export:
`/tmp/fm-filbert-1.6Acnih`, created with
`git archive d4696d09eb1b5dcf1028f30db2cd63735f51cb16 | tar -x -C <export>`.
No shared-tree checkout/reset, dependency install or live runtime was used.
1. Python/subprocess `git show <commit>:<path>` plus `hashlib.sha256`:
both candidate hashes matched; 69/69 inventory matched; 9/9 legacy files matched
69d1bb3 and the export. `git rev-list --parents -n 1` confirmed both parent links.
2. From export, with clean environment, temporary HOME and bytecode writes disabled:
`/home/jwoltje/.pyenv/versions/3.12.8/bin/python3 docs/plans/foundation-v1-candidate/check.py`.
**Exit 0:** 38 command shapes, 38 record shapes, 16 paths, 7 restricted-domain hash
vectors, 155 runtime/artifact shapes, 35 synthetic model cases; 5+5 deliberately
shape-valid semantic forgeries remain shape-valid. Python 3.12.8/jsonschema 4.26.0.
Initial attempt using `env -i PATH=/usr/bin:/bin ... python3` failed exit 1 because
that interpreter lacked jsonschema. No dependency was installed; the existing
explicit interpreter above supplied the documented dependency for the successful run.
3. From export: `env -i PATH=/usr/bin:/bin HOME=/tmp/fm-filbert-1.6Acnih-review-home bash scripts/test-config.sh`.
**Exit 0: 24 passed, 0 failed.** Suite uses its own temporary synthetic config/data.
4. `bash -n` for scripts/agent.sh, auth.sh, reset.sh; `sh -n` for
adapters/pi/adapter.sh, src/run-agent.sh, src/load-contracts.sh;
`node --check` for scripts/mosaic-config.mjs and scripts/mosaic-task.mjs.
**All exit 0.** Observed default Node v26.8.1; syntax checking is not pinned-runtime testing.
5. `git diff-tree --check 7345f330^ 7345f330`: **exit 0**.
No test-task full suite, release/conductor/auth runtime suites, verify.sh, Docker,
native extension, sync/package, renderer, browser, process-stopping, sandbox,
credential separation, crash-durability or full JCS/Unicode enforcement tests ran.
In particular the author checker is independently executed author test code, not
an independent implementation of its validator and not proof of real authorization.
No architecture JSON/HTML, render receipt or visual preview was supplied or accepted.
Only this offered verdict path was written in the repository. No shared logs,
CURRENT, source, policies, installations, commits or pushes were changed. No
credential contents, live worker state or separate ~/.mosaic environment were read.
No implementation or automatic next increment is authorized by this verdict.