Files
stack/agents/rocko/work/queue-as-data-adversarial-r6-2026-09-26.md
T
jason.woltjeandClaude Opus 5.5 1c5f6bc3a0 docs(queue): queue-as-data plan round 6, Rocko approved (#1508)
Plan 282fabbb (Filbert) and the six adversarial rounds (Rocko, r6 80cde839).
Lead item 15: Gate F first, then A1 and A2 as separate reviewed commits.

Co-Authored-By: Claude Opus 5.5 <[email protected]>
2026-09-26 16:05:16 -05:00

64 lines
3.6 KiB
Markdown

# Queue as data — adversarial review, round 6
Verdict: **approve** the plan. Rocko, 2026-09-26.
Verified target SHA-256 before reading:
`282fabbb8969510ae9e139a12082421ca3ffc395a90a800d936cc47abf6ab67a`.
This supersedes round-five target 889f2566 and answers report
`3b031a707555960dc69cc274fef6c39c0d8c0ebad539a5e8ae0c0c2545f4177e`.
Review covers the active specification, especially 8.11, 8.12, 8.5 and
8.9. No blocking findings remain from round five.
1. **G1 resolved — the freshness proof is now obtainable.** Pre-launch
listings, command line and UTC start time exist before Pi starts. The
later session/header audit no longer requires a file Pi has not created,
nor a warm-up message or manual session seeding. The header is correctly
outside the entry chain; null first parent and sequential later parents
match the pinned SessionManager behavior reproduced in round five.
Prefix restrictions and whole-file input audit still exclude ordinary
resume, inherited summaries and branch coaching. Positive controls now
complement the negative controls. The pre-instruction context hashes
remain required; moving the session-file pin to cutoff does not waive
those hashes. This is cooperative evidence with the previously accepted
helper/context-edit limits, not independent proof against an actor
rewriting all receipts.
2. **G2 resolved — activation is checked, not inferred from bytes.** The
plan checks file type, ownership, executability, bytes and hooksPath at
invocation and again before publication. The canary invokes Git's hook
mechanism using an isolated index, checks both acceptance and the
guard's specific refusal, and makes disabled/redirected hooks fail
before publishing. 8.5 explicitly forbids later mode/config/environment
overrides and honestly states the same-user limitation. Nothing here
claims to prevent a seat deliberately bypassing the protocol after a
check. Keeping that limit is appropriate for the accepted scope.
Independent scratch-repository check of the stated canary returned:
clean index 0; changed queue index 1 with the refusal line;
nonexecutable hook 1 on the clean index; redirected hooksPath 1 on the
clean index. The temporary repository was removed. This is validation
of the mechanism, not of queue-commit.sh, which has not been built.
3. **Lead identity note resolved.** 8.9 explicitly expects jarvis from
GET user when the lead posts, while retaining the lead as queue actor.
Fake-transport positive and wrong-login cases include the sage mismatch.
This closes the ambiguity without changing the authorized credential
rule. No token was opened or live API request made in this review.
Builder detail, nonblocking: step 1 currently lists the canary before the
bullet that captures H, although the canary reads its temporary index from
H. Capture H before constructing that canary, use that same H for the
snapshot/base work, and retain expected-old-value publication. A concurrent
HEAD change may cause a conservative refusal; it must never cause the
script to silently adopt a new untested base. For the genesis canary,
QUEUE.md is already a tracked queue entry even though queue.json is absent.
The previous round's F2 coherent reads, F3 genesis/base procedure and F5
op-length bounds remain resolved. No new contradiction in the reviewed
changes requires an owner ruling. Approval is for the design and its stated
acceptance tests; implementation still needs the fault-injection, Git-race,
transport and Gate G evidence specified in section 8.
Only this report was written in the repository. No source/index edit,
commit, push, live process change or credential access.