Rocko-authored, Filbert-reviewed inspector (r6 manifest a4a44930...) with full review/build/verdict evidence under docs/plans/reviews. 43/0 selftests, oracle zero-disagreement, foundation checker PASS. Owner A9 acceptance recorded separately.
6.3 KiB
FI-ROCKO-2 — feasibility reconciliation before charter freeze
Coordinator: darkwing. FI-ROCKO-1 admitted; original note SHA-256 verified as 92fa7b3de2591ba24fb184ed8edbabedd30c54498fdaf101649e36aaebabe9b9. Its measured charter hash fdcdf4df8bf30b9fbfff960f9b1d4160ce7e6bbc4b8bb601a93cda13b56c8996 also matches. These are author/contributor checks, not independent approval.
Please return a corrected, self-contained recommendation at only
docs/plans/reviews/2026-09-06_foundation-inspector-rocko-feasibility-r2.md.
Preserve the original note. No implementation or other edits authorized.
Required corrections and decisions
F1. The named accepted-map path is the foundation requirements document, not
2026-09-06_foundation-technical-map.md. Correct all affected citations against
actual committed bytes, including map lines 275/278 and proposal section.
d4696d09:docs/plans/foundation-v1-candidate/FINDINGS.md does not exist (git
cat-file check fails). Withdraw the AJV/fast-uri audit rationale unless supported
by an in-scope, exact source. No external fleet investigation to repair it.
package.json has no Node engines pin; distinguish measured host version from a
repository pin or a newly proposed inspector test baseline.
F2. records.schema.json/$defs/recordRef has kind/id/scope/revision, no digest. Registry references have registry/id/revision/digest. decisionPayload.basisRef is artifactRef, NOT a reference to a delegation decision. envelope.authorizationRef is runtimeId, not recordRef. Workspace parent comes from scope, not payload. createdAt has the candidate time validation, not arbitrary string acceptance. The charter's initial generic reference/digest sentence needs the same distinction; darkwing will correct it during integration. Specify how simulation declares any external authorization/artifact inputs and their limits; do not silently treat missing referenced evidence as valid or claim real authentication.
F3. Do not sort instruction arrays while claiming the accepted fingerprint rule: README:268-285 explicitly preserves instruction order and check.py:115 sorts only skills for those vectors. A new registry-content digest is a separately specified restricted algorithm, not an established record-fingerprint rule. Prefer keeping all input array order for the new mock content digest; distinguish structural uniqueness and set intersection from serialization. Propose exact vectors.
F4. Workspace policyRef is required and must be project-policy. There is no fallback to the registration role. Each registration's scopeRoleRef must resolve and bound its optional registration restrictions: using restrictions alone omits the reviewed role ceiling. Nullable registration restrictions mean no additional narrowing, not absent mandatory role/policy authority. Likewise nullable mission/task narrowing must not erase required intent/status/scope checks. Assignment has no restrictions field. Explicit empty arrays remain denial. Distinguish missing required launch policy from an explicitly modelled unrestricted narrowing layer; do not default missing launchRestrictions to null and silently skip required policy.
F5. Define authority in both affected original and target scopes for reassignment, not just target project membership. Approved decision outcome, actual delegation recipient/subject bounds, reviewed ceilings and current original/target intent must be checked or explicitly unsupported. A basis artifact is not automatically an authorization decision. Caller-supplied runtime observations cannot establish actual stopping/reconciliation. Prefer refusal/unresolved for all assignment-change success paths in this first slice; useful negative previews need not implement an authoritative change engine. Original selection always remains unchanged.
F6. Limit implemented preview operations explicitly: recommend work.read, file.read, file.change permission previews plus a bounded assignment.change negative check. Other recognized catalog operations should return unsupported-capability, never exit 0 as if executable. Do not invent execution.stop in the 29-operation enum (it is not there; the catalog contains execution.control). Align the closed output schema with every emitted field (the note adds scope without defining it).
F7. Optional schema cross-check is insufficient for a hand-written validator. check.py does not accept arbitrary bundle records as a validation API. Define a required verification-only harness using the pinned candidate JSON Schema and existing explicitly selected Python/jsonschema, with no dependency installation. It must compare supported records/negative mutations, calendar/path boundaries, conditionals and typed references. Runtime stays dependency-free if selected; missing test dependency blocks verification rather than silently passing.
F8. find -newer alone is not a no-effect proof and output captures themselves write. Separate harness artifacts from observed roots; compare bounded before/after path, type, content and relevant metadata inventories, plus static import/I/O boundaries. State that canaries do not prove absence of all reads or OS containment. Regular-file opening must refuse symlinks/FIFOs before blocking or following unsafe targets; specify Linux descriptor-based checks/size bounds without introducing live tests.
F9. Settle revision-history handling without inconsistent head-only/missing-predecessor rules. Historical predecessor/decision references cannot all be treated as forbidden stale active heads. Distinguish historical resolution from current-intent admission. An explicit small revision-1-only supported subset is acceptable if later revisions refuse unsupported-capability and the limitation/negative case is clear. Preserve exact scope and duplicate/cycle checks; never silently invent the missing history.
Return
Resolve D-A..D-J and F1..F9 into a concrete bounded recommendation, or identify the remaining design choice precisely. No external investigation, code, dependencies, commits, installation changes or contacts to Filbert. Do not displace the held Archify assignment. Return FI-ROCKO-2 with corrected note hash and disposition per finding. Darkwing owns integration; Filbert remains the later non-author reviewer.
Transport (2026-09-06 08:25 UTC): one FI-ROCKO-2 send to =rocko on mosaic-fleet; exit 0, delivered. Await direct corrected-note/hash/disposition or blocker. No deadline/timer or automatic acceptance. Follow-up darkwing.