Plan 282fabbb (Filbert) and the six adversarial rounds (Rocko, r6 80cde839). Lead item 15: Gate F first, then A1 and A2 as separate reviewed commits. Co-Authored-By: Claude Opus 5.5 <[email protected]>
64 lines
3.6 KiB
Markdown
64 lines
3.6 KiB
Markdown
# Queue as data — adversarial review, round 6
|
|
|
|
Verdict: **approve** the plan. Rocko, 2026-09-26.
|
|
|
|
Verified target SHA-256 before reading:
|
|
`282fabbb8969510ae9e139a12082421ca3ffc395a90a800d936cc47abf6ab67a`.
|
|
This supersedes round-five target 889f2566 and answers report
|
|
`3b031a707555960dc69cc274fef6c39c0d8c0ebad539a5e8ae0c0c2545f4177e`.
|
|
Review covers the active specification, especially 8.11, 8.12, 8.5 and
|
|
8.9. No blocking findings remain from round five.
|
|
|
|
1. **G1 resolved — the freshness proof is now obtainable.** Pre-launch
|
|
listings, command line and UTC start time exist before Pi starts. The
|
|
later session/header audit no longer requires a file Pi has not created,
|
|
nor a warm-up message or manual session seeding. The header is correctly
|
|
outside the entry chain; null first parent and sequential later parents
|
|
match the pinned SessionManager behavior reproduced in round five.
|
|
Prefix restrictions and whole-file input audit still exclude ordinary
|
|
resume, inherited summaries and branch coaching. Positive controls now
|
|
complement the negative controls. The pre-instruction context hashes
|
|
remain required; moving the session-file pin to cutoff does not waive
|
|
those hashes. This is cooperative evidence with the previously accepted
|
|
helper/context-edit limits, not independent proof against an actor
|
|
rewriting all receipts.
|
|
|
|
2. **G2 resolved — activation is checked, not inferred from bytes.** The
|
|
plan checks file type, ownership, executability, bytes and hooksPath at
|
|
invocation and again before publication. The canary invokes Git's hook
|
|
mechanism using an isolated index, checks both acceptance and the
|
|
guard's specific refusal, and makes disabled/redirected hooks fail
|
|
before publishing. 8.5 explicitly forbids later mode/config/environment
|
|
overrides and honestly states the same-user limitation. Nothing here
|
|
claims to prevent a seat deliberately bypassing the protocol after a
|
|
check. Keeping that limit is appropriate for the accepted scope.
|
|
|
|
Independent scratch-repository check of the stated canary returned:
|
|
clean index 0; changed queue index 1 with the refusal line;
|
|
nonexecutable hook 1 on the clean index; redirected hooksPath 1 on the
|
|
clean index. The temporary repository was removed. This is validation
|
|
of the mechanism, not of queue-commit.sh, which has not been built.
|
|
|
|
3. **Lead identity note resolved.** 8.9 explicitly expects jarvis from
|
|
GET user when the lead posts, while retaining the lead as queue actor.
|
|
Fake-transport positive and wrong-login cases include the sage mismatch.
|
|
This closes the ambiguity without changing the authorized credential
|
|
rule. No token was opened or live API request made in this review.
|
|
|
|
Builder detail, nonblocking: step 1 currently lists the canary before the
|
|
bullet that captures H, although the canary reads its temporary index from
|
|
H. Capture H before constructing that canary, use that same H for the
|
|
snapshot/base work, and retain expected-old-value publication. A concurrent
|
|
HEAD change may cause a conservative refusal; it must never cause the
|
|
script to silently adopt a new untested base. For the genesis canary,
|
|
QUEUE.md is already a tracked queue entry even though queue.json is absent.
|
|
|
|
The previous round's F2 coherent reads, F3 genesis/base procedure and F5
|
|
op-length bounds remain resolved. No new contradiction in the reviewed
|
|
changes requires an owner ruling. Approval is for the design and its stated
|
|
acceptance tests; implementation still needs the fault-injection, Git-race,
|
|
transport and Gate G evidence specified in section 8.
|
|
|
|
Only this report was written in the repository. No source/index edit,
|
|
commit, push, live process change or credential access.
|