Skip to content

Add standalone modular composition inspection - #42

Draft
Sheshiyer wants to merge 59 commits into
mainfrom
codex/standalone-composition-20261005
Draft

Sheshiyer wants to merge 59 commits into
mainfrom
codex/standalone-composition-20261005

Conversation

@Sheshiyer

@Sheshiyer Sheshiyer commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Temperance Engine needs a reusable composition and routing core that works without Cambium or Superset. This change adds standalone composition/lifecycle contracts, redacted banner/island projections, Git identity and Hands context, explicit TRIVECTOR evidence and diagnostic selection, and reusable bounded MCP transport/file primitives. Constellation is retired; declarations, observations and dependencies cannot reintroduce it.

Binary gates and active limitations precede pins. Legacy remaining-quota fractions remain separate from v4.1 window headroom and hazard. Half-open circuits require a probe reservation. Public router pins remain subject to circuit eligibility with truthful rejection receipts.

Portable Git lineage preserves original claim/replay references and deadlines. Git authority inspection has interactive and dedicated entrypoints; its three-file closure supports source-pinned private consumers. Context, fingerprints and process completion grant no execution, capacity, lease or semantic acceptance authority.

MCP stdio bounds frames, aggregate pending bytes/count, response encoding, backpressure and teardown. Closed transports cannot admit deferred handlers. Owner-file snapshots check regular descriptor size before allocation, bounded positional reads/growth and metadata/path continuity. Owners retain root confinement, synchronous deadlines and result-production obligations.

Validation:

  • 168 combined composition/Git/TRIVECTOR tests,920 assertions and TypeScript checks.
  • 8 authority CLI tests,92 assertions;18 public router tests,67 assertions.
  • 42 composition/run tests,167 assertions covering retirement and portable lineage.
  • 13 bounded stdio tests,46 assertions;9 owner-file tests,45 assertions and strict typecheck.
  • Independent source reviews passed after regression fixes.

This draft contains source and disposable fixture evidence. Installation, authenticated production claims/capacity reservations, native-client lifecycle acceptance, live calibration and independent plant canary/rollback/release remain separate. No activation, merge or deployment is included.

Standalone launch-budget source9c6010d adds a metadata-only standard-library primitive: private bounded records, verified retained creator birth/UID, irreversible durable reservation, nonce/file identity, downward-only four-launch and120-second lifetime ceilings, and lost-ack holds. Root18tests pass and independent review clear, including nested callers and nonblocking record/descriptor cleanup faults. No CLI adapter, installation, running-worker deadline, per-request inference cap, account/capacity or execution authority is established.

Audit532aa9 documents gate-first lexicographic TRIVECTOR selection and its remaining owner/task/accepted-result/domain/native-reservation joins. Existing32-entry packet bounds remain unchanged; no new math or scoring policy is introduced.

Launch-handle codec e5b8f93 adds a reusable metadata safety bootstrap over fixed FD3/FD4. Closed length-prefixed frames are bounded to16KiB, with strict UTF8/duplicate rejection, pipe-direction/nonblocking/CLOEXEC checks and finite ACK/confirmation EOF. Child reserves once, sends ACK and closes its return channel; owner validates ACK+EOF and retains the exact counter before confirmation. Both sides close transport descriptors before metadata-ready. Every receipt keeps execution, inference and capacity authorization false.

The original conservative invocation deadline is captured before helper creation and forwarded unchanged; exchange IO is limited to two seconds and remaining invocation time. Trusted synchronous reserve/retain callbacks are checked before/after but cannot be preempted or allocation-bounded. Missing/lost ACK, failed retention, partial/extra frames, cancellation and pre-confirmation expiry prevent readiness without refund, record recreation or disk-counter recovery. After confirmation delivery, owner uncertainty may leave the child ready; no retroactive zero-current-launch claim is made. Same-UID cooperation is not authenticated ancestry.

Codec15 focused fixtures pass, root independently reran15 and source/doc review is clear. Final combined launch-budget/codec33 tests pass. Actual inert nested fixtures retain the original creator/nonce/counter and prove fixture FD closure before an inert child; these are source proofs, not native tasklist/seat/wire joins. Adapter inheritance, full running-process/request/token budgets, native account/capacity, installed adoption and independent plant acceptance remain open.

Optional standalone organ guard source

Published the reviewed exact containment guard from Noesis b57931b as package/organ-guard, with its relative descriptor topology, closed provenance and a generic prose-only descriptor transform. All numerical policy values remain unchanged: 160 MiB, 120 seconds, 24 active descendants, and bounded retained identity inventory. The package has no Noesis/Cambium runtime dependency and is excluded from the default installer/router inventory.

Verification: seven focused standalone fixture cases, six pass and one successful-inert-CLI case held/skipped because actual host pressure was elevated. Root independently reproduced that result; no retry or pressure override occurred. Exact guard SHA-256 is 289643f5955ec243564728bf952e36e768cc8cb20430aa3d64766a4b674ab478; descriptor numerical/structural parity and independent source review cleared. This is optional source capability, not installation, activation, successful native CLI acceptance, callback delivery, provider/capacity authorization or sustained OOM acceptance. Darwin/Linux capture, synchronous syscall, observed lineage and cleanup grace limits remain documented.

Bounded model-worker capture bootstrap

Published57d7cee adds a standalone three-stream private collector for event stdout, diagnostic stderr and an owner-created final FIFO. Fixed limits are64KiB event frames,4MiB events,1MiB diagnostics,256KiB final and5MiB aggregate, checked before retention. It uses one retained deadline and at most250ms drain inside it. Trusted terminal observation must independently establish final-write completion, including empty output; FIFO EOF cannot supply process status. Held outcomes discard payloads and keep all execution, resource, inference and replay authority false.

Verification:20 inert fixtures pass; root independently reran20 in0.512s, AST/diff checks and independent source review cleared. Regressions cover overflow, partialEOF, missing/delayed writers, cancellation, descriptor replacement, independent cleanup failure and late deadline completion. Source SHA-256 is7b53673aebc8b0c29340fd29b9b83241f7cb97f6c1eac374da6431022cadfbc2.

This is framing/private-byte capture only, not Codex protocol proof or native Build acceptance. It does not spawn/terminate models, contain worker RSS/physical footprint, join the launch budget/ACK handshake or install a wire adapter. Same-UID/pathname cooperation and synchronous nonpreemption remain limits; actual binary FIFO compatibility is unverified. Official Codex0.147 terminal backfill and Plan fallback prevent universal final-text reconstruction from streamed agent messages, so future integration retains the exact final sink instead.

Explicit optional organ guard source installation

Added isolated COPY profile organ-guard with --only organ-guard.source, destination TEMPERANCE_STATE/optional/organ-guard. Default/minimal selected steps and prior outcomes are unchanged; the new skipped outcome/global inventory digest truthfully differ. The frozen6195142 source tree remains exact. Runtime Python version/ABI/command execution and native/capacity/semantic acceptance remain held; no actual installation or activation occurred.

The owning generator now supports scoped merges and v2 per-record revision/tree provenance, reconstructing retained declarations from their original commits before trust. All pre-existing lock records and expectation declarations remain exact. Unselected fragment bytes are preserved, including custom whitespace. Legacy v1 result revision/tree fields remain compatible; mixed v2 emits no false common anchor. Scoped generator check passes; full checkout check remains held on existing router.governed-runtime drift, deliberately not repinned.

Verification:57 tests187 assertions, strict package TypeScript and whitespace checks pass. Disposable lifecycle fixtures prove source copy/hash/mode, existing journal rollback and drift/symlink holds. Independent review cleared the final delta. Root separately verified exact public guard inert completion under normal point pressure with cleanup true and semantic false; this is no sustained canary or native organ/provider acceptance. All operational native/capacity/sustained-memory gates remain open.

Deliberate default router COPY consistency

Reconciled only router.governed-runtime against reviewed published e07 source: exactly routing-policy.ts and its test hashes change for the already-published cc6/3ac circuit safety fix. All file paths/modes and18 other record anchors, including optional organ619, remain unchanged. The owning generator and compiled lock now make full unscoped19-record source checking pass for the published checkout. Default/minimal selected steps and outcomes remain identical; the global inventory digest changes truthfully.

Verification:77 tests481 assertions, strict package TypeScript and independent review pass; root independently reproduced the suite and full inventory check. Disposable default router/backup-helper COPY dependency-closure fixtures prove dry-run, every copied hash/mode, journal rollback, sentinel preservation and zero runtime invocation. This is source-copy consistency, not whole mixed-profile installation, native activation, provider/capacity acceptance, policy recalibration or sustained memory proof. No root adoption occurred.

Runtime dependency contract alignment and pure protocol bootstrap

Published df32a40dfdcc15b85133aefe6ed5d2d72cd70e43 aligns fragment/lock requires with a closed, bounded 32-declaration validator. Binary declarations reject options, paths, injection syntax, non-ASCII and trailing line breaks; HTTP tokens are recognized metadata but held before resolution or probes pending a separate endpoint/HEAD/redirect/deadline/cancellation contract. Selected executor declarations are detached before awaits, optional binary skips and explicit/scoped holds remain, and no existing record gains requirements. Focused verification passed 68 tests/451 assertions and strict package TypeScript, with independent/root review.

No COPY record owns these installer-source files. The existing unscoped generator check passed all 19 retained provenance anchors against head 4cc321d20c7642a9cc77e9169b147993f78162c4; no unrelated expectations or anchors were repinned.

Published 4cc321d20c7642a9cc77e9169b147993f78162c4 adds the pure conservative Codex 0.147 app-server protocol profile: bounded decoding, resolved parameter/thread/session/turn correlation, one submission with permanent lost-response holds, full available-history readback and typed Plan fallback. Fifteen inert fixtures passed; independent source review confirmed retained session correlation. Unsupported notifications and server requests hold. The initial permission profile is read-only and is not a Build permission or native Hands join. Opaque history and text-only summary comparison do not prove full action schemas or zero effects.

These are source contracts, not installed/native compatibility, account capacity, inference or activation evidence. Full subprocess capture, lifetime/resource policy, retained launch acknowledgment handoff, final binary FIFO compatibility and usable guarded Build remain separate proof requirements. All existing independent product/plant, optional module and source/installed/runtime distinctions remain intact.

Pure worker observation policy, phase one

Published 9646696f7213604b9271f80cc87be5349bec6565 adds closed trusted policy/retained-owner/process DTOs and injected observation folding. Eleven inert fixtures passed, with independent source review and root rerun. Original nonce, post-ACK counter and deadline are detached and retained; deadlines never renew, first kernel-start metadata is preserved, and clock/birth/usage drift or late callbacks hold. Receipts remain redacted with all authority, containment and cleanup flags false.

The calibration profile's ten-second and independent 128 MiB RSS/physical-footprint ceilings are proposed and unmeasured. Active-descendant zero and inventory ceilings are declarations, not implemented inventory enforcement. Build policy is absent and held. No actual native syscall, process spawn, model request, configuration change or installation occurred. Trusted observer labels and DTOs do not prove ACK authenticity, native ABI, parent-child relationships, account capacity, resource containment or cleanup. Full native capture/lifetime/resource/ACK/protocol joins remain open; synchronous callbacks cannot be preempted.

Injected stopped-bootstrap bookkeeping, phase two

Published a2325c3a93fd0d084721db8c5ac0a50dcb4f68b8 adds the injected bootstrap state machine with thirteen inert source fixtures, independent review and root rerun. It retains the original owner deadline and consumed launch slot, checks declared creator/child identity before injected release, and requires parent-channel closure first. A fixed 500 ms normal cleanup reserve precedes admission and release; normal cleanup retains the original deadline. Expired cleanup has a separate once-only best-effort allowance and always remains held/unverified. Exception classification uses bounded exact exception arguments without invoking exception string formatting.

This unit opens no actual descriptors, creates no process, performs no native syscalls and requests no model. Fixed FD5/FD6 roles and byte ceilings are declarations awaiting transport enforcement. Trusted injected callbacks and process DTOs do not establish native stopped-before-exec, ACK authentication, capacity, containment or cleanup proof; synchronous callbacks cannot be preempted. All authority and acceptance flags remain false. The dedicated native metadata backend is superseded by the separately scoped source evidence below; native worker acceptance remains open.

Dedicated native observation metadata backend

Published c6510d37b707bd2ea7605da8d8ecbe1ddf56ac47 adds the bounded Darwin direct-process metadata backend. Fourteen fixtures passed with root rerun and independent review, including current-process-only ABI metadata. Fixed BSD/task/rusage layouts and exact native returns are checked; original deadlines precede library loading and remain checked around synchronous native calls. Retained PID birth/kernel-start metadata cannot be overwritten, and target retention is bounded. Loader/setup failures have finite redacted diagnostics.

The own-process fixture establishes current ABI viability only. This backend launches no worker or native CLI, requests no provider, and supplies no resource enforcement, cleanup or capacity acceptance. Pressure is observed metadata, never launch admission. Trusted expected process DTOs are not authenticated owner authority; synchronous native calls remain nonpreemptible. Full inventory, stopped-child/bootstrap transport, launch acknowledgment, model protocol/capture, resource enforcement and cleanup joins remain open. All authority and acceptance flags remain false. The inventory and organ issuance-closure plans remain pending root review.

Bounded native inventory and pure coordination

Published 58136712e3cf4b472e897756f937fa3e8fe08f5a adds bounded Darwin UID metadata capture and immutable lifetime inventory. Fixed 4097 PID slots detect snapshots above 4096 rows before expansion; exact task-all metadata and same-birth zombie validation reject uncertainty. Lifetime tracking retains identities without overwrite or pruning, uses a linear parent traversal, and admits at most one bounded cleanup frame after freezing. Malformed frames and uncertainty remain sticky holds, including through cleanup, with the original finite reason preserved. Mocked fixtures and a bounded current-host metadata snapshot support metadata intake only, not worker enforcement or capacity.

Published c39afcc4f7c18c5edecab73e7d1218973d694db7 adds pure explicit-step coordination. Ten inert fixtures passed, with independent/root review. The original retained owner ACK/counter/deadline is a trusted precondition; no reserve, create or retry API is supplied. Declared stopped resource observation precedes parent-channel closure, reobservation and once-only injected release. Every nonblocking capture step is preceded by resource observation; late 50 ms polling/callbacks and the 256-step ceiling hold. The original deadline retains its 500 ms normal cleanup reserve; emergency cleanup is once-only, held and unverified.

These remain source-only contracts. Fixed descriptor roles, injected native/resource observations and capture terminal acknowledgments are declarations, not actual stopped-before-exec, FD ownership, model completion, resource enforcement or reaping evidence. No native worker, signal, provider request, installation or activation occurred. Build policy remains absent; all execution, inference, capacity, containment, cleanup, pre-effect and replay flags remain false. Native adapter planning and its original ACK/deadline, periodic resource checks, finite capture and birth-safe reap joins remain pending.

Nonblocking capture-step source seam

Published 26518d830ad42c9b01162750eb460425afb8da82 adds injected zero-wait three-stream capture steps, with twelve inert fixtures, independent review and root rerun. Each step requests at most three reads of at most 16 KiB, probing remaining limits before retention. Stream/frame/aggregate ceilings remain fixed; retained descriptor identities are checked around reads and closure. Trusted exit-zero plus explicit final-write acknowledgement precedes final-keeper closure and a 250 ms drain inside the original deadline. Prewriter final EOF cannot complete a capture.

Cleanup attempts independent original identities once, preserves replacements, and discards held private payloads even when a late failure occurs after descriptors were already closed. The nonempty late-close regression verifies disposal and failed coordination projection. Caps are immutable; late polling/callbacks and post-copy deadlines hold. The existing blocking collector remains unchanged.

This is source/mock evidence only: it supplies no actual descriptor reads, stopped child, native writer, model request, resource enforcement, capacity or verified cleanup. Adapter callbacks and terminal/final-write metadata are trusted assertions, not native compatibility or authority. Historical plan packets and the stopped-adapter plan remain proposals; actual original-owner ACK, direct-parent identity, finite FD5 status-to-stop, bounded FD6 confirmation-to-release, resource polling and birth-safe reap joins remain open. No installation, activation or Build acceptance follows.

Mocked stopped-control protocol source

Published 445d41578d660a8115075471f9f899e6cf596e46 adds the pure injected stopped-control protocol and its reviewed stage plan. Ten inert fixtures passed with root rerun and independent review. FD5 models exactly one bounded status frame plus EOF before independent stopped-state observation. FD6 models a fixed 69-byte control record derived from retained nonce/counter/original signed64 deadline and child identity, with bounded exact birth encoding. A single write-return count, parent-writer closure and fresh identity/pressure/resource observation precede injected continuation; partial writes and uncertainty hold without retry.

Receipts distinguish the parsed trusted owner-slot precondition from owner_ack_observed, which starts false and becomes true only after exact trusted callback validation. Neither proves actual reservation, authenticated issuance or native launch-codec execution. Full control delivery may become child-observable after continuation; later uncertainty cannot establish that no payload ran. Held status bytes are discarded.

This stage opens no actual FD, launches no child, performs no native observation or signal and calls no provider. Actual original-owner FD3/FD4 ACK retention, direct-parent native identity, child FD6 decoding/EOF closure, resource enforcement, cleanup/reaping and final-write ACK remain separate missing joins. Build policy, capacity, execution and native acceptance remain held; all authority flags are false. The next nonblocking FD-adapter work remains a plan requiring separate review, not accepted implementation. No installation or activation is included.

Capture descriptor adapter, source/mock verification

Published 3ec5f1a8196871f7636d05d8857c2b4e567c4c48 adds the capture descriptor OS-boundary source and reviewed plan. Thirteen mocked fixtures passed with root rerun and independent review, including in-process use of the actual CaptureStep with injected syscalls. Four independently discovered original descriptor identities survive peer admission failure. Access modes and flags are retained and rechecked around nonblocking/CLOEXEC changes and bounded zero-wait reads. Replacements hold without closing the new identity.

Adapter-owned teardown covers at most four unique transferred descriptors with one identity query and one close attempt each, recorded before closure and never retried after failure or expiry. Independent peer cleanup continues; failed closure cannot become successful on repetition. Outer capture identity checks are additional and are not included in that four-query bound. Held private-byte disposal remains independently enforced by CaptureStep.

This is source/mock evidence only: no actual descriptor, FIFO, child, provider or native worker test occurred. Check/set/recheck is not atomic CLOEXEC installation or FD-table exclusion; synchronous syscalls are not preemptible and same-UID ownership races remain explicit. Original launch ACK, stopped-child control, resource/inventory enforcement, real producer final-write acknowledgment, signals/reap, native compatibility and Build capacity remain open. No installation or activation is included. The separately scoped named-FIFO point below supersedes this proposal; native worker acceptance remains open.

Bounded named-FIFO point and manual RSS diagnostic

Published 8781f3fe5e03d8e38646b24a4714161fe889e00e adds the separately approved current-process named-FIFO point fixture. One point passed in 0.004s: three valid distinct reader identities, zero invalid identity components, eight immediately verified EBADF closures, four adapter teardown attempts, 48 synthetic bytes, and cleanup_unknown=false. This verifies only the private named-FIFO capture topology in the current process. Two earlier anonymous-pipe points remain held with an unproven cause and cleanup uncertainty; production identity checks were not weakened. No child, model, native CLI or organ ran.

Published 2ab9a7ad42c2de54e8074ba440062021f9a4e569 adds an explicit manual-once RSS/pressure diagnostic with ten mocked fixtures, independent source review and root rerun. Two bounded source pins are attested before detached loading; one retained two-second deadline and 4096-row ceiling cover the metadata query. Default invocation and import do not query. No scheduler, service, retry, provider lookup or process action is registered.

One separately authorized, hash-verified manual point completed with pressure elevated before and after: 672 current-UID rows, all live, RSS sum 14147371008 bytes and maximum 745897984 bytes. Only closed redacted counts/decimal aggregates were returned; no process identities, names, arguments, environment or account data were projected. All execution, capacity, cleanup, causal, sustained and native-worker acceptance flags remain false. No repeat or process action followed.

RSS may double-count shared pages and omits compressed/kernel/swap and other-UID memory. This changing point observation neither identifies the pressure cause nor rebuts elevated pressure, authorizes a kill/restart, calibrates paid-worker capacity, or closes sustained/native acceptance. Original launch ACK, stopped-child transport, full resource enforcement, semantic CLI evidence, cleanup/reaping and independent plant canaries remain open. No installation, activation or merge is included.

Status/release endpoint boundary, source/mock evidence

Published ef22b9e683100df0c2039b0752f0574e111f323f adds the owner-side status/release descriptor boundary and reviewed plan. Thirteen mocked fixtures passed with root rerun and independent review, integrating the actual stopped protocol through injected syscall/callback seams. Independently retained endpoint identities, flags and access modes bound zero-wait status reads, EOF reader closure, pipe atomic-bound checking and the exact retained 69-byte control write. Writer closure and a fresh retained-token observation precede injected continuation.

Write and continuation attempts are sticky before their callbacks. Partial writes, uncertain returns, exceptions and lost acknowledgments cannot cause repetition; fresh observations cannot reset continuation. Two-endpoint teardown remains once-only with finite identity/close attempts, replacement protection and truthful closure failures. Child FD5/FD6 roles remain distinct from internal owner endpoint numbers; no unrelated descriptor remapping occurs.

Verification remains mocked: no actual status/release FD, child, native stopped observation, SIGCONT, provider or model ran. Owner ACK and resource callbacks are trusted seams, not actual reservation, authentication or resource enforcement. Original launch-codec ACK, native direct-parent identity, child control decoding, reaping/cleanup and Build/account capacity remain open. The earlier named-FIFO capture point proves only its current-process capture topology; both anonymous-pipe holds and the manual RSS point's noncausal limitations remain intact. The separately reviewed and authorized status/release point below supersedes this proposal; no worker/canary acceptance or installation follows.

Current-process status/release named-FIFO point

Published 47884987661263f2f92862cfd9e33275287f19f8 adds the separately approved status/release point fixture and reviewed plan. One point passed against exact test source 74fe5406eff7a195a43bfefe6c32df1ee456e82eff9522e0d104de697ed364cb: 216 synthetic bytes, seven bounded protocol steps, one injected continuation callback, five close attempts and five immediate EBADF verifications, two adapter-owned attempts, cleanup_unknown=false and scoped basis-module registration restored. The original 1.5-second assertion passed. No repeat was performed.

The fixture executes three bounded, attested detached source snapshots without an unbounded loader reread or global import patch. It proves only current-process named-FIFO I/O, framing/EOF, fixed control bytes, and closure for this exact point. Creator/child identities, original-owner ACK, stopped/resource evidence and continuation are synthetic trusted callbacks. No child, native PID query, signal, provider, model, real reservation or authenticated issuance occurred.

Operational criteria remain open: actual original launch-budget/codec ownership join, native fixed-FD inheritance and stopped-before-payload execution, resource enforcement, final model/CLI semantics, reaping/cleanup, account capacity and sustained independent plant canaries. Earlier anonymous-pipe holds remain unproven; the RSS point remains noncausal metadata. No installation, activation, merge or usable guarded Build acceptance follows.

Pure original-owner pre-reserved codec profile

Published b3d2fef557a025172b14010e5e6f5eb82b0fd27a adds the pure injected pre-reserved profile, with sixteen fixtures, independent review and root rerun. Reservation intent precedes exactly one injected counter0-to1 reservation; its validated receipt is retained before injected creation. The child codec callback supplies that retained receipt once, without a second budget mutation. The trusted bridge matches actual codec MappingProxy callback shapes and the owner’s single-argument retain callback, preserving its None return after validated ACK/EOF placement.

Original creator context and deadlines are retained. Invocation and exchange ceilings are checked against the original creation anchor, not renewed remaining time. Closed keys and scalar types precede set/hash operations; the bridge enforces a running 16KiB encoding estimate before copying. That estimate specifically describes literal-Unicode UTF8 JSON with ensure_ascii=False, not default ASCII-escaped serialization. Source SHA-256 remains 70fd7f58a110237a87a3f9038325609365e69121183dba342dc7fc63a7979f6b; the contract carries this encoding clarification.

All evidence remains pure/injected: no actual budget record, private FD, native creator verification, child or model was used. Codec-owned proxy backing and ACK/EOF callback placement are trusted preconditions, not authentication. Lost/late reservation, creation, supplier or ACK outcomes hold without retry, refund, new nonce or disk-counter recovery. The profile counts a designated payload launch, not every bootstrap process or model turn. Actual private pre-reservation transfer, owner/codec joins, native stopped/resource/capture/reap enforcement and usable guarded Build remain open; all execution, capacity and inference flags stay false. No installation or activation follows.

Retained pre-reservation codec point — fixture scope only

Published 4bb9e3f24d6a7c15d9968624d839f93fd2428c60 adds the bounded current-process private launch-budget/codec fixture and its reviewed planning receipts. Six default inert mocks cover descriptor ownership, close uncertainty, and the actual codec readonly byte-view write contract. The test remains opt-in; ordinary discovery does not perform the point.

The first separately authorized point at source c5a9420 held before any wire bytes because the fixture rejected the codec's readonly memoryview. Its historical result remains preserved: one failure, 0.019 seconds, zero wire bytes, five close attempts and five immediate EBADF checks, no surviving thread, and cleanup uncertainty false. The source/mock correction was independently reviewed before a separately authorized new point.

The corrected single point at source 3731f41b1857b1d60ad00d08e92df4e2e0871e8b860ffd87eadaef50ba74cb65 passed in 0.018 seconds: one actual private budget creation and retained response, one irreversible reservation and retained response, one injected creation marker, one retained ACK, and two metadata-ready codec roles. Three writes carried 1,006 attempted/written/read bytes under the shared 16 KiB ceiling. Five owned close attempts were followed by five immediate EBADF checks; cleanup uncertainty and surviving-thread flags were false, and scoped module entries were restored.

This is a same-process metadata fixture using two private FIFOs and one daemon thread, with the original 1.5-second deadline retained. The creation marker does not launch a worker. All execution, inference, capacity, and native-authentication flags remain false. Synchronous syscalls are not preemptible; an unjoined thread would hold with cleanup unknown. There is no installed adapter, model/provider call, native worker, reservation authentication, resource enforcement, or operational acceptance, and no counter reread, refund, recreation, or replay recovery after uncertainty.

Pure pre-reserved bootstrap context codec

Published afd65f5d119ec73fee9cb322bc53f7ed24e27ebc adds the independently reviewed pure context encoder/decoder and framing contract, with 12 inert fixtures also rerun by the root reviewer. The payload ceiling is 16 KiB; lexical depth 3, node count 128, and bounded integer tokens are checked before full JSON parsing. Closed context, creator, receipt, and existing handle shapes correlate original creation counter 0 with retained reservation counter 1. Signed 64-bit original anchors retain the 120-second invocation ceiling and 2-second point/exchange ceilings. Recursive duplicate keys, incomplete/extra frames, stale or backward supplied times, and repeated consumption hold; private buffers clear and successful decoded mappings are immutable.

This source opens no descriptors, creates no process, reads no clock callback, and performs no budget mutation. Proposed child-role FD7 is a future transport contract, not an implemented channel. Caller-provided time and EOF remain trusted assertions; same-UID cooperative context possession is not native identity or issuer authentication. Existing ACK fields are unchanged and contain no child token. Independently retained native child birth/direct-parent/resource evidence before confirmation, actual FD topology and collision handling, supervisor memory accounting, and parent-loss/orphan containment remain held. A SIGSTOP child cannot self-expire through a suspended timer. All execution, inference, and capacity flags remain false; no native bootstrap, model/provider, installation, or operational acceptance follows.

Pure fixed descriptor action planner

Published a2c2d85156aedb9105c9f7c7ab493f7411a632f8 adds the independently reviewed pure descriptor action planner, with 10 mock fixtures also rerun by the root reviewer. Closed bounded metadata describes 12 original descriptors and six distinct lifted stages, for an explicit 18-owned-FD peak. Eight ordered DUP2 actions map fixed null metadata to targets 0–2 and the five child roles to 3–7; known originals/stages outside those targets close once afterward. A mock FD table verifies original-target collisions preserve lifted sources. Returned actions are detached immutable metadata, with no parent FD-table mutation.

No descriptor, fcntl, native ABI, clock, process, reservation, or spawn operation is performed by this source. Reported CLOEXEC_DEFAULT remains advisory: unknown inherited-FD closure and actual native readiness are false regardless of that boolean. Actual fixed null-device identity and native capability verification remain future owner operations. All execution, inference, and capacity flags remain false.

The reviewed production direction keeps v1 contracts unchanged and requires a future versioned original-creator/supervisor/direct-parent owner chain. Both supervisor and worker OS launches must be explicitly accounted through two retained reservations on the same original budget before any creation; no second nonce, refund, counter recovery, or fabricated ACK identity is accepted. That typed join, proposed separate unmeasured supervisor/worker resource policies, conditional parent-loss containment, actual spawn, and native worker acceptance remain held. This publication is source/mock planning evidence only and performs no installation or activation.

Pure retained versioned owner chain

Published 122cd0eaf9ab86647e60bc6f053f94ddcebda9ff adds the independently reviewed pure injected v2 owner-chain retention helper, with 16 pure fixtures also rerun by the root reviewer. Existing v1 contracts remain unchanged. The helper requires two reported reservation responses on the same original nonce and limit 2, ordered expected counter 0→1 for supervisor and 1→2 for worker before either creation callback. Intent is retained before each callback; lost, late, malformed, or changed responses hold permanently without retry, refund, counter recovery, or a new nonce. Original 120-second invocation and 2-second exchange anchors remain bounded.

Original creator, reported supervisor/direct parent, and reported worker tokens remain distinct and immutable. Kernel-start continuity is an opaque reported token, without an invented time unit. The first bounded returned creation candidate is retained before relationship, post-callback clock, or owner-observation checks. A valid-shaped wrong-parent/UID/PID candidate remains available as private metadata with admission false and a sticky hold; malformed or lost responses do not invent a token. Candidate retention never supplies native cleanup authority.

This is pure retention/state evidence using trusted injected callbacks and bounded closed DTOs; there is no actual budget mutation, process creation, native identity query, signal, descriptor transport, or resource enforcement. All native authentication, native cleanup authority, execution, inference, and capacity flags remain false. Future typed private context transfer, actual owner-chain observations, POSIX spawn ABI/capability, conditional parent-loss containment, supervisor/worker memory accounting, and operational acceptance remain held. Synchronous injected callbacks are not preemptible; original clocks are checked around them. No installation or activation follows this source publication.

Pure spawn capability profile audit

Published audit source 3184318eeb440fd1239e638cbe3035ed87884c6e and plan wording correction 5c7a98cbfae8a673aec12fc07420a9e80048c3a5 add the independently reviewed pure/mock audit, with 11 pure fixtures also rerun by the root reviewer. Fixed three injected excerpts are capped at 64 KiB each, with a declared 256 KiB aggregate ceiling (three-source maximum 192 KiB); the report uses exactly nine fixed symbols and the original deadline of at most two seconds. Closed scalar checks, one-attempt retention, before/after callback clocks, and fixed redacted holds remain bounded.

This helper performs no filesystem source intake, library loading, real symbol resolution, audited target-function call, FD operation, or spawn. Its conservative literal SDK profile is not a C/TBD parser, authenticated source provenance, or complete prototype/ABI validation. Matching SDK/runtime version labels remain unproved; differing labels mean compatibility unknown, while explicit platform, architecture, or scalar mismatches hold. Reported symbols and Python flag exposure are advisory; native readiness, unknown inherited-FD closure, execution, inference, and capacity remain false.

Any real loader-only point needs separate source review and explicit authorization. Library loading/resolution itself involves native runtime activity, so only absence of audited target-function calls could be claimed. Actual native semantics, versioned actor contexts, owner-chain/FD joins, resource enforcement, parent-loss containment, model/Build use, installation and operational acceptance remain held. No actual loader point or activation is included in this publication.

Pure versioned private actor context codec

Published 317f9492847c687149153397ce19951079097c1f adds the reviewed v2 private actor context codec, contract and planning receipts. Fifteen pure source fixtures pass; the root independently reran all 15 and independent source review is clear. Supervisor role has 15 closed fields; worker role adds the retained supervisor token for 16. Both contexts carry the same original creator, create receipt 0, supervisor reservation 1 and worker reservation 2 on limit 2 before either creation, with unchanged original invocation/exchange anchors. Existing v1 files and HANDLE/ACK fields remain unchanged.

Decode compares against a separately supplied trusted expected context, retained as immutable top-level and nested snapshots. Bounded literal UTF8 escaped size precedes copying/serialization; payload is at most 16 KiB, with preparse depth 3, nodes 192, bounded integer tokens and recursive escaped-key duplicate rejection. Prefix intake retains at most four bytes before declared-length admission; excess payload is rejected before retention. EOF, cancellation, expiry, backward time, extra/partial/repeated frames and mismatch permanently hold with private wire buffers cleared. Redacted status contains no handles, paths, tokens or nonce, and all native authentication, native cleanup, execution, inference and capacity flags remain false.

This pure source implements no descriptor transport, actual reservation, clock callback, native identity query, process creation, signal, model/provider call or installation. FD7 capability ownership and independent native actor provenance remain future joins. Creation-candidate retention stays in the existing v2 owner-chain helper and supplies no cleanup authority here. Actual owner-chain/FD topology/CLOEXEC, supervisor resource accounting, parent-loss containment and native worker/Build acceptance remain held; a codec fixture pass does not activate any runtime.

Scoped current-process loader metadata point

Published 685186f9fb68fb2768644cba491d12d4e1d665c6 adds the reviewed loader-point source, contract and scoped planning receipts. Twelve default pure mocks pass with root and independent source review clear. Ordinary discovery performs no actual loading; the separately authorized root point used exact source da7a0ae552dee31eab5966b199138460f78227c9aa00bc8c45aae488f43b9683 once, without a reviewer or author rerun.

That current-process metadata point returned exit 0, nine of nine fixed callable symbol attributes available, Darwin arm64, 64-bit pointer and 16-bit short, and kernel release label 27.2.0. Source snapshot attestation matched, cleanup uncertainty was false, and original two-second deadline checks passed; no measured elapsed duration is claimed. A returned library handle is retained before late-return validation. Presence checks never invoke audited target functions, set argtypes, initialize attributes/actions, call spawn, or explicitly unload the library. Loading/resolution themselves involve native runtime activity.

The earlier 4i1 one-window source preparation remains a historical hold with zero of nine symbol declarations; no window hunting or claim of SDK/native incompatibility followed. The later loader point deliberately decouples symbol availability from that SDK gate. It establishes neither complete prototypes nor ABI/flag semantics, stopped behavior, unknown inherited-FD exclusion, source/SDK version compatibility, or worker readiness.

All native authentication, native readiness, unknown-FD closure, execution, inference and capacity flags remain false. No child/model/provider, reservation mutation, signal, actual spawn/attrs/actions, repeated probe, installation or activation occurred. Actual owner-chain/FD7/CLOEXEC/native resource/parent-loss and operational acceptance gates remain held; current-process symbol metadata does not close them.

Zero-child opaque ABI point (4vi/4ty)

Published d50fda1b8b123310e21c0491cb45539a4b22f65a retains the reviewed source/mock and separately root-authorized ONE current-process zero-child point at exact fa5f candidate: init2/candidate2/destroy2 verified, nativecalls9/ops5, masktrue, cleanup_unknownfalse/emergencyfalse. Original deadline checks passed; no elapsed claim. No spawn, child, current FD dup/close actions, model or repeated point occurred. Readiness, unknown-FD closure, native authentication, capacity, execution and inference remain false. All earlier held SDK-window and anonymous-pipe points and operational limits remain unchanged.

Synthetic bootstrap ordering (59j/52z)

Published 93c886a76f362550faf89e86a5e4ed8bdc4d4b9a adds reviewed source-only ordering evidence with15pure synthetic fixtures. Direct-owned-child scalar observations and native transitive inventory remain distinct; no actual FD, budget reservation, codec exchange, native join, worker/model operation or activation occurred. Prior source/point histories and all native, containment, cleanup, capacity and semantic acceptance holds remain unchanged.

Mock descriptor preparation (5k5)

Published 5617f1b5ec5b2e4dad9881bb6cb2c26ad244da85 adds reviewed source-only descriptor preparation with19mock fixtures independently checked at root and source review clear. The unchanged action planner retains18owned descriptors plus1diagnostic distinction. No actual FD, native attestation, budget/codec exchange, resource enforcement, process spawn or joined worker occurred. All prior scope and operational/native/cleanup/capacity acceptance holds remain unchanged.

Source continuation: the fixed source-owner wrapper published at b6fc56d adds ten mock fixtures, with root and independent review of source 5f0aa. It joins bounded attested source snapshots to the injected descriptor-preparation boundary. Actual source-owner FD intake, native attestation, launch-budget/codec/resource/spawn integration and operational acceptance remain open; no installation or native point ran in this unit.

Source continuation 65e9f92 adds the four-source descriptor bridge with ten mock fixtures and root/independent review of source 1e00. RealOps is defined but has not been executed: no actual source-owner descriptor point or native FD, budget, codec, resource or spawn join is accepted. All prior source and narrowly scoped point evidence above remains distinct from operational readiness.

Source-owner intake point fd74842: root ran the separately authorized read-only point once against exact entry source 9de2. It completed with 42,450 requested source bytes, four close intents, two transfers and four immediate EBADF observations; cleanup_unknown and emergency were false. This is bounded source-descriptor intake evidence, with no elapsed-time claim, repeated point, native worker, endpoint authentication, capacity or execution acceptance. All prior source-only and scoped point limits remain.

Source continuation 55cf7e3 adds the reader-first callback ownership wrapper with fourteen mock fixtures and root/independent review of source 3b0335/test b1a855. NativeOps remains absent: nonblocking/no-follow flag metadata is not native proof, and no actual endpoint point ran. The genuine owning-writer retained receipt/capability bridge is a separate pending contract; existing source and point evidence does not authenticate it.

Source continuation 23e0fc4 adds the owning retained launch-budget API, with 27 selected source fixtures verified by author/root and independent source review; two native fixtures were excluded. Same-instance exact opaque-handle continuity and full original record comparison precede irreversible reservation; final freshness after descriptor cleanup precedes handle publication. Existing CLI receipt nine-field contract remains unchanged. No writer point, Noesis source-pin migration, installation or actual adapter join ran. This cooperative capability does not authenticate native issuer delivery, FD/process admission, capacity or execution.

Source continuation ff55b97 adds the retained owning-API bridge to mocked descriptor preparation/wrapper: fifteen fixtures, root rerun and independent review of source 809d8ddc/test ce70bf9e. Fixtures use actual temporary-record create/reserve writes with injected synthetic birth/clock, retaining both owning results before the mocked eighteen-endpoint join. Lost second acknowledgment leaves counter two consumed and permits zero preparation or retry. Original creator continuity, fixed 2000ms same-clock anchors and opaque observer-only kernel token remain explicit. This is not an actual native writer or endpoint point, installation, native authentication, capacity or execution acceptance; the owning helper source remains unchanged.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant