Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions docs/adr/0018-declarative-workflow-state-machine.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,10 @@ The tension: does re-introducing workflow definitions reverse ADR-0006? The reso

## Implementation note (2026-05-31) — inert inputs-file navigator Write grant (Codex P0 r3331024136, resolved-by-design)

> Active end-state (this implementation note only): `plugin/governance/security-policy.md` ("Inert Inputs-File Navigator Pattern"). The declarative-state-machine decision in this ADR still governs; this note's claims about the inputs-file pattern are superseded.

**Superseded by `plugin/governance/security-policy.md` (Inert Inputs-File Navigator Pattern), 2026-09-25 (#369).** The 2026-09-25 amendment at the end of this ADR states, item by item, which of this note's claims are corrected and which live source owns each subject. This note states no current value; read the section named above for what the pattern claims today. The original note is retained for history.

Codex P0 r3331024136 flagged the unrestricted `Write` grant on the two engine navigator skills (`hivemind:init-run-ledger`, `hivemind:record-state-result`) as an over-broad capability. The resolution is **documented-accept plus defense-in-depth**, NOT grant removal. Removing the grant was REJECTED: it reopens the command-substitution injection class this PR closed — the navigators MUST author a file with the Write tool so the committed engine script can read untrusted fields with `jq` into inert `"$var"` variables (bash does not re-evaluate command substitution from variable contents). Splicing those values into shell/jq source instead would re-admit the exact injection class.

The **inert inputs-file navigator pattern** that makes the single Write grant sound:
Expand Down Expand Up @@ -101,3 +105,15 @@ Decision 2 (§A format-follows-consumer) states: "No file is read by both `jq` a
**No migration.** The manifest is ephemeral gitignored runtime state (`manifest_version` bumped 2→3). The plugin is unreleased at 2.20.0; there are no persisted cross-version manifests to migrate. Writer and reader move together in this PR.

This amendment is APPEND-ONLY. The original Decision, Consequences, and all prior amendments stand. Status remains accepted.

## Amendment — 2026-09-25 (the 2026-05-31 inert inputs-file note and the 2026-06-01 transport amendment are corrected to pointer form; every dated literal in this ADR's notes and amendments is a snapshot, not authority; #369)

This amendment corrects four claims carried by the 2026-05-31 inert inputs-file navigator Write-grant implementation note above and by the 2026-06-01 transport amendment. Each item names the superseded claim and the live source that owns its subject. No item restates a current value, because a restated value is the defect being corrected: this ADR is append-only, so any value written here is frozen at its date while the source keeps moving. Item 5 states the standing rule that closes that whole class. This amendment does not edit the Decision, the Consequences, or any prior implementation note or amendment.

1. **Item 2's "Inert content" claim is WITHDRAWN as an over-claim.** That item asserts the inputs-file content "is never interpreted as a path, Bash, or instruction." The absolute reaches past the transport to what a consumer does with a field after reading it, which this note's soundness argument never established. What the pattern claims today, and the exact scope of that claim, is stated in one place only: `plugin/governance/security-policy.md` ("Inert Inputs-File Navigator Pattern"). Read that section, not item 2. "Inert" survives here as the pattern's NAME.
2. **Item 1's "Single fixed-path inputs file" transport claim is SUPERSEDED.** The per-navigator transport paths it names, and the invariant a transport path must satisfy, are owned by `plugin/governance/security-policy.md` ("Inert Inputs-File Navigator Pattern"). This ADR states neither.
3. **Item 3's "All three pipeline navigators" no longer describes the covered set.** The covered set is enumerated authoritatively in exactly one place — `plugin/governance/security-policy.md` ("Inert Inputs-File Navigator Pattern") — and is expected to keep changing. This ADR does not track it and asserts no membership or count; a reader takes the current members from that section.
4. **The `spawn-brood` singleton-transport exemption recorded in the 2026-06-01 amendment above is SUPERSEDED.** That amendment exempts `spawn-brood`'s inputs file from the per-invocation-uniqueness requirement on a serialization argument; the exemption no longer stands. What `spawn-brood`'s transport is today, and why, is stated in `plugin/governance/security-policy.md` ("Inert Inputs-File Navigator Pattern"); the brood state layout and manifest schema that transport depends on are owned by ADR-0021 and `plugin/references/brood-ledger-model.md`.
5. **Everything DATED in this ADR is a snapshot, not authority — this rule closes the class items 1-4 enumerate.** Items 1-4 each retire one stale claim, and that enumeration structurally cannot keep up: this ADR is append-only, so every note freezes the world as of its own date while the sources it describes keep moving. The standing rule, which needs no future amendment: every filesystem path, schema or format version number, count, membership list, and named mechanism that ANY implementation note or amendment of this ADR states as a value is dated as of THAT note's date and carries no authority today. A pointer that only names which live document owns a subject — such as the pointers in items 1-4 and at the end of this item — is not such a value and is exempt: it states no value, only where the current value lives. A reader takes the current value from the live source, never from this file. This holds for every note and amendment above without exception, the 2026-06-01 brood-manifest amendment included. Live sources by subject — inputs-file transport, its path invariant, and its covered set: `plugin/governance/security-policy.md` ("Inert Inputs-File Navigator Pattern"); brood state layout and manifest schema: ADR-0021 and `plugin/references/brood-ledger-model.md`. A future divergence of this kind is corrected THERE and needs no further amendment here.

This amendment is APPEND-ONLY. The original Decision, Consequences, and all prior implementation notes and amendments stand. Status remains accepted.
Loading