From 5e4aa48496293fb46210f3c2e31a84f7182be9af Mon Sep 17 00:00:00 2001 From: XVVH Date: Wed, 15 Jul 2026 16:25:10 -0400 Subject: [PATCH] Substrate theory v2: five-stance adversarial panel, synthesis, amendments applied MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Panel (GPT 5.6 Sol xhigh, one stance per discipline; outputs preserved verbatim in docs/substrate-theory-analysis/) plus a fresh-context synthesis with steelman rulings. v2 applies the amendment list: C8 (staging recipe) struck — hardlink aliasing destroys retained-tree evidence AND violates A27.1, found independently by two stances; C11 (agent-OS category) struck on three-stance convergence; C1/C2/C3/C4/ C5/C6/C7/C9/C10/C12 refined with struck text preserved inline per the ADR norm; C13 added (behavior/judgment, the completeness gap); falsifiers re-ranked — F2' (delegation-frontier instrumentation, currently untestable pre-ratchet) on top, F7/F8 new, F4 demoted to a C5 scope condition. scripts/check-doc-hygiene gains a directory exemption for the verbatim external-review artifacts (quoted foreign-repo URLs false-positive as local doc refs); evidence files stay byte-identical; self-test unchanged and green. Co-Authored-By: Claude Fable 5 --- .../Stance 1 - GPT 5.6 Sol Xhigh.md | 18 + .../Stance 2 - GPT 5.6 Sol Xhigh.md | 35 ++ .../Stance 3 - GPT 5.6 Sol Xhigh.md | 91 +++ .../Stance 4 - GPT 5.6 Sol Xhigh.md | 92 +++ .../Stance 5 Verdict - GPT 5.6 Sol Xhigh.md | 92 +++ .../Synthesis - Claude Fable 5.md | 214 +++++++ docs/substrate-theory.md | 561 ++++++++++-------- scripts/check-doc-hygiene | 5 + 8 files changed, 872 insertions(+), 236 deletions(-) create mode 100644 docs/substrate-theory-analysis/Stance 1 - GPT 5.6 Sol Xhigh.md create mode 100644 docs/substrate-theory-analysis/Stance 2 - GPT 5.6 Sol Xhigh.md create mode 100644 docs/substrate-theory-analysis/Stance 3 - GPT 5.6 Sol Xhigh.md create mode 100644 docs/substrate-theory-analysis/Stance 4 - GPT 5.6 Sol Xhigh.md create mode 100644 docs/substrate-theory-analysis/Stance 5 Verdict - GPT 5.6 Sol Xhigh.md create mode 100644 docs/substrate-theory-analysis/Synthesis - Claude Fable 5.md diff --git a/docs/substrate-theory-analysis/Stance 1 - GPT 5.6 Sol Xhigh.md b/docs/substrate-theory-analysis/Stance 1 - GPT 5.6 Sol Xhigh.md new file mode 100644 index 0000000..678a586 --- /dev/null +++ b/docs/substrate-theory-analysis/Stance 1 - GPT 5.6 Sol Xhigh.md @@ -0,0 +1,18 @@ +## PART A + +| claim | verdict (AGREE / REFINE / REFUTE) | strongest counterargument you considered (mandatory even for AGREE) | your argument, with citations | +|---|---|---|---| +| C1 | **REFUTE** | Indirect prompt injection does place a privileged intermediary under adversarial influence. Capability and information-flow controls can break the resulting exploit chain even when the model remains compromised; CaMeL and the EchoLeak incident make that analogy operational. | The analogy is useful; the claimed identity is false. Hardy’s compiler held authority from **two sources**—its invoker and its own home-files licence—and applied its own authority to a filename designated by the invoker. The note inaccurately reduces this to “a program acting with its caller’s ambient authority.” Hardy’s remedy combined designation with the authority conveyed for that designation. By contrast, an injected agent can obey an adversarial instruction while selecting an action and target wholly inside authority legitimately granted by the user: the defect is instruction-provenance/control integrity, not necessarily authority-designation confusion. Ocap then bounds damage but does not cure the compromised decision. CaMeL confirms the distinction by employing two mechanisms: trusted-query control-flow extraction so untrusted data cannot steer the program, and capabilities to prevent unauthorized data flows. [Hardy, “The Confused Deputy”](https://people.cs.vt.edu/~kafura/cs6204/Readings/ConfusedDeputy.pdf); [Miller, *Robust Composition*, designation and authority](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf); [Debenedetti et al., “Defeating Prompt Injections by Design”](https://arxiv.org/abs/2503.18813); [EchoLeak case study](https://ojs.aaai.org/index.php/AAAI-SS/article/view/36899). Replace C1 with: **“Prompt injection can create a confused-deputy-shaped exploit chain; capability discipline bounds its effects, while trusted control/data separation addresses the injection itself.”** | +| C2 | **REFINE** | The exact ASF loop may be novel. KeyKOS/EROS checkpoints provide crash recovery, not user-directed semantic undo; sagas provide compensation, not authority; caretakers and membranes revoke access but do not make grants contingent on recovery evidence or a behavior hash. | “Ocap has no undo” and “the tradition never had to face behavior-specific trust” are historically indefensible. KeyKOS and EROS deliberately combined pure capabilities with system-wide consistent checkpoints, copy-on-write state, restart, and transaction support—although EROS correctly warned that a committed bad checkpoint could not itself be undone. Sagas paired committed steps with compensating transactions; Ken composed state checkpoints and message recovery across independently developed components. The behavior claim also ignores KeyKOS factories, EROS constructors certifying properties of created processes, E’s AST-inspecting auditors and behavior-dependent reliance analysis, and authorization based on attested program properties in Nexus. None is identical to ASF’s pin, but they destroy the claimed absence of ancestry. [KeyKOS nanokernel](https://pdos.csail.mit.edu/6.828/2010/readings/keykos.pdf); [Shapiro et al., “EROS: a Fast Capability System”](https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/Eros.pdf); [Garcia-Molina and Salem, “Sagas”](https://doi.org/10.1145/38713.38742); [Yoo et al., “Composable Reliability for Asynchronous Systems”](https://www.usenix.org/conference/atc12/technical-sessions/presentation/yoo); [Miller, auditors and behavioral authority analysis](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf); [Sirer et al., “Logical Attestation”](https://research.google/pubs/logical-attestation-an-authorization-architecture-for-trustworthy-computing/). The defensible novelty claim is narrower: **recoverability evidence, human ratification, and domain-scoped behavior-version invalidation are joined in one authority-accrual loop.** | +| F6 | **REFINE** | Ocap never promised to infer natural-language intent. A system can remain meaningfully capability-based even if semantic decisions require a judge: Capsicum, for example, mechanically restricts reachable namespaces and operations while leaving application correctness elsewhere. The presence of residual judgment therefore does not by itself reduce capability enforcement to marketing. | F6 identifies the right threat but is not presently falsifiable: “interesting,” “coarser,” and “marketing” have no measurement rule or rejection threshold. Pre-register an ablation: assume the worker always follows the injection; label prohibited effects before execution; disable judge and human intervention; then report deterministic prevention, severity-weighted loss prevented, false denials, and task completion. Partition cases into (1) attacker-designated targets outside caller-conveyed authority, (2) targets inside a coarse grant but contrary to intent, and (3) prohibited information flows. In a strict Hardy case, a proper capability interface should reject the unauthorized designation at resolution; if ASF merely accepts a separately supplied target and tests it against `known_contacts`, globs, or budgets, only category 1’s out-of-set subset is stopped. Macaroons themselves are explicitly bearer authorization credentials, while Miller distinguishes cryptographic capability protocols from the object-capability model and says cryptography alone enforces weaker properties. [Capsicum](https://www.usenix.org/event/sec10/tech/full_papers/Watson.pdf); [Macaroons](https://research.google/pubs/macaroons-cookies-with-contextual-caveats-for-decentralized-authorization-in-the-cloud/); [Miller, “Only Connectivity Begets Connectivity” and limits of cryptographic enforcement](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf). F6 should fail C1’s ocap-centrality thesis if, after ratchet convergence, deterministic controls do not clear a predeclared coverage threshold without unacceptable false denial; the threshold must be chosen before observing results. | + +## PART B + +1. **high — The note launders three different meanings of “capability.”** An object capability is an unforgeable reference that simultaneously designates an object and conveys authority to invoke it; its graph supports “only connectivity begets connectivity” and local reasoning about composition. A macaroon is explicitly a bearer authorization credential. ASF’s [Capability schema](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:152) authorizes a holder through a central broker while the request separately supplies tool, action, path, recipient, and target. That provides valuable unforgeability, attenuation, expiry, credential custody, and revocation, but it does not by itself recover ocap’s designation-authority identity or reference-topology arguments. Miller expressly limits his object-capability model to operating systems and programming languages, excluding cryptographic capability protocols from the same theorem set. The note needs a property-by-property inheritance table; until then, “capability-inspired broker with attenuated credentials” is the accurate name. [Miller](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf); [Macaroons](https://research.google/pubs/macaroons-cookies-with-contextual-caveats-for-decentralized-authorization-in-the-cloud/). + +2. **high — “Consequence bound” is not yet one theoretical quantity.** Exact rollback of owned bytes, crash-consistent restart, approximate SaaS reconstruction, a saga compensation, deletion of a still-unread message, and an apology after a human-visible message are not points on an established common scale. Sagas promise compensating actions that *amend* partial execution, not restoration of the prior world; EROS checkpoints preserve a consistent state, not a correct one. ASF itself admits that mirror compensation is partial and that fidelity grades remain unschematized in the [brief](/Users/josh/dev/Coppice/docs/agent-state-fabric-brief.md:191) and [spec](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:149). Until the ratchet consumes a declared fidelity measure and excludes irreversible/socially observed outcomes, “recoverability evidence compiles into authority” can launder cheap compensations into broad grants. [Sagas](https://doi.org/10.1145/38713.38742); [EROS](https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/Eros.pdf). + +3. **medium — C10 presents a typological list as a genealogy and then derives a monocausal history from it.** KeyKOS → EROS is a documented implementation lineage. Capsicum is an incremental UNIX retrofit; seL4 descends from the independent L3/L4 microkernel lineage. Their shared use of capabilities does not establish “KeyKOS → EROS → Capsicum → seL4 → Fuchsia,” nor does it show that all “lost to compatibility economics.” KeyKOS ran production workloads, L4-family kernels achieved large commercial deployments, and Capsicum was explicitly designed to preserve UNIX compatibility. Recast the sequence as several independent capability adaptations and treat compatibility cost as one tested factor, not the tradition’s settled cause of defeat. [EROS history](https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/Eros.pdf); [Capsicum](https://www.usenix.org/event/sec10/tech/full_papers/Watson.pdf); [Elphinstone and Heiser, “From L3 to seL4”](https://trustworthy.systems/publications/nictaabstracts/Elphinstone_Heiser_13.abstract). + +I would delete C1 outright: its identity claim is false even though a weaker analogy is useful. +I would bet on C2, narrowed to ASF’s evidence-coupled ratification loop rather than consequence bounding or behavior-aware authority in general. diff --git a/docs/substrate-theory-analysis/Stance 2 - GPT 5.6 Sol Xhigh.md b/docs/substrate-theory-analysis/Stance 2 - GPT 5.6 Sol Xhigh.md new file mode 100644 index 0000000..1c866db --- /dev/null +++ b/docs/substrate-theory-analysis/Stance 2 - GPT 5.6 Sol Xhigh.md @@ -0,0 +1,35 @@ +## PART A + +| claim | verdict | strongest counterargument considered | argument, with citations | +|---|---|---|---| +| C3 | REFUTE | Read literally as a statement about the portable POSIX API, uid is the principal most applications see; SELinux labels and Landlock domains are Linux-specific, and neither is a durable cross-host delegation identity. | That defense saves only a trivial POSIX claim, not “the kernel offers no boundary.” Linux tasks have MAC security contexts under SELinux, Smack, and AppArmor; Landlock creates unprivileged, inherited, monotonically restricted security domains; and credentials carry thread-, process-, and session-specific keyrings. These are finer-than-uid security contexts, although keyrings are authority containers and user namespaces are credential scopes rather than principals. The defensible replacement is: “Linux lacks one stable, authenticated, application-addressable manifest-instance identity consumed uniformly by mediation, broker authentication, and audit.” That narrowing preserves the need for W-4, but destroys C3’s causal claim that uid explains most hard problems. Those problems arise because the current deployment has configured no boundary, exactly as [P7 says](/Users/josh/dev/Coppice/docs/posture-assumptions.md:134), not because Linux cannot express one. [Linux LSM process contexts](https://docs.kernel.org/next/userspace-api/lsm.html), [Landlock domains](https://docs.kernel.org/security/landlock.html), [kernel keyrings](https://docs.kernel.org/6.3/security/keys/core.html). | +| C4 | REFUTE | OCI deployments often do begin with a broadly privileged host process, then remove capabilities, syscalls, mounts, and devices; profile-attachment omissions are a real fail-open class. | “Subtractive” is not a property of the container ecosystem. Smack and SELinux are explicit-allow MAC systems; AppArmor profiles are task-centered; Landlock defines handled accesses with deny-by-default behavior and only permits further restriction; seccomp can default-kill and explicitly allow. Conversely, a capability system can fail open by issuing an over-broad capability or mistranslating an application concept. Cgroups are mostly resource governance, not an authority model, and kernel documentation explicitly says seccomp is not a sandbox. The surviving insight is an object-model mismatch: ASF caveats speak recipients, budgets, behavior versions, and reversibility, while kernel controls speak tasks, inodes, sockets, and syscalls. The compiler boundary is dangerous, but not because one side is inherently subtractive. [Smack rules](https://docs.kernel.org/admin-guide/LSM/Smack.html), [AppArmor task profiles](https://docs.kernel.org/admin-guide/LSM/apparmor.html), [Landlock](https://docs.kernel.org/6.8/userspace-api/landlock.html), [seccomp’s stated limits](https://docs.kernel.org/6.2/userspace-api/seccomp_filter.html). | +| C5 | REFUTE | No existing facility combines a durable manifest identifier, monotonic spawn attenuation, whole-kernel mediation, audit attribution, broker peer authentication, revocation, and fleet lifecycle. A unified abstraction would be useful. | Useful abstraction does not imply necessary kernel work. A trusted launcher can verify the manifest, create a per-manifest cgroup or microVM, attach an SELinux/AppArmor/BPF-LSM label, apply Landlock and seccomp before exec, keep the broker in a different label/uid/VM, and bind broker requests to the peer label, cgroup, pidfd, or vsock endpoint. What breaks today is portability, policy cardinality, privileged policy loading, incomplete object coverage, inherited file descriptors, and the impossibility of expressing high-level caveats in kernel object terms. Those require a policy compiler and broker; they do not demonstrate a missing principal primitive. More decisively, distinct principals do not make A27 T2 “dissolve”: two differently labeled principals still race if both are authorized to write the same namespace. Only exclusion or mediated topology removes that race, which is precisely [A27’s existing answer](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:222). [BPF LSM](https://docs.kernel.org/next/bpf/prog_lsm.html), [LSM stacking approximation](https://docs.kernel.org/6.2/security/lsm.html), [Landlock’s stackable restrictions](https://docs.kernel.org/6.8/userspace-api/landlock.html). | +| C11 | REFINE | Talos and Bottlerocket are reasonably called operating systems even though their novelty is composition, lifecycle, and defaults rather than a new kernel. ASF could make an equally real single-purpose system image. | As an appliance or reference guest image, C11 is credible. As a theoretical OS delta, it is currently a rebrand. Firecracker already supplies a one-microVM-per-process hardware boundary and a host control plane; Kata already boots an agent with the workload and supports guest-agent policy. “Fabric daemon near PID 1, policy-compiled guest, host-side approval, broker-only I/O” is Firecracker/Kata plus an ASF control plane. The actual delta must be stated as manifest-bound launch attestation, broker-only capability I/O, branch-root lifecycle, and signed trace integration. Those are valuable ASF semantics, but none is a new OS mechanism. Call it an “ASF agent appliance” unless the note can name an invariant unavailable to a conventional microVM runtime and policy engine. [Firecracker design](https://github.com/firecracker-microvm/firecracker/blob/main/docs/design.md), [Firecracker production isolation](https://github.com/firecracker-microvm/firecracker/blob/main/docs/prod-host-setup.md), [Kata architecture and agent policy](https://github.com/kata-containers/kata-containers/blob/main/docs/design/architecture/README.md). | +| F4 | REFINE | TPM-backed measured boot, remote attestation, and signed manifests can let each host authenticate the code and policy it enforces; distributed identity can remain a separate control-plane concern without invalidating local kernel enforcement. | Correct—and that proves F4 is not a falsifier of local enforcement. Kernel enforcement helps after admission: it prevents a locally confined task from impersonating another manifest or exceeding compiled policy. It cannot determine whether the admitted manifest is current, whether a revoke was truncated, whether two cloned homes are spending the same one-use authority, or which fork is canonical. Those require a fabric trust root, external freshness anchor, and cross-host lease/reservation protocol. The problem does not recur “inside the kernel”; it remains above the kernel at policy admission. ASF already acknowledges this in [§6.2’s external monotonic anchor](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:313). F4 should become a mandatory scope condition for C5, not a contingent falsifier. | + +## PART B + +1. **[high] Principal identity is neither necessary nor sufficient to close T2.** + + C5’s strongest downstream claim is false. Giving publisher P and agent A different labels merely lets policy distinguish them. If both retain write authority to the store, A can still race P’s prepare/rename window. If policy denies A that authority, the race was closed by exclusion topology—not by principalhood. Conversely, separate uids, SELinux domains, cgroups, or microVMs can supply that topology without a new manifest principal. The note should strike “T2 dissolves by construction” at [C5](/Users/josh/dev/Coppice/docs/substrate-theory.md:90); it contradicts A27’s correct statement that T2 is topology’s problem. + +2. **[high] C5 and C11 undercut each other unless the scheduling unit is specified.** + + If one delegation manifest gets one microVM, the microVM identity, host cgroup, and vsock endpoint already constitute the locally enforceable principal; the proposed kernel patch has no job. If several manifests coexist inside one guest, per-task LSM identity becomes relevant, but C11’s microVM boundary no longer separates those delegates. The note must choose and state its unit: manifest-per-VM, agent-per-VM with multiple manifests, or a persistent agent guest spanning delegations. The “20% kernel work” estimate is otherwise numerology. + +3. **[high] The secure-attention analogy is conceptually apt but operationally romantic—and it conceals an internal contradiction.** + + Linux’s own documentation says its SAK is not a true C2 secure-attention mechanism; it kills processes associated with a virtual console rather than creating a modern desktop trusted path. Polkit delegates authentication UI to an agent in the graphical user session, registered for that session and effective uid. Wayland reduces ambient cross-client input access, but a legitimately granted Remote Desktop, accessibility, shell, or HID capability can still operate the same human surface. The repository’s own [SI-23](/Users/josh/dev/Coppice/docs/spec-issues.md:1124) correctly says W-4 cannot fix that case because the synthetic input arrives through an authorized door. A distinct manifest principal cannot distinguish “human clicked approve” from “authorized actuation clicked approve”; C2 needs independent user presence or an independent channel. [Linux SAK limitations](https://docs.kernel.org/security/sak.html), [polkit session-agent architecture](https://polkit.pages.freedesktop.org/polkit/polkit.8.html), [legitimate portal-mediated remote input](https://flatpak.github.io/xdg-desktop-portal/docs/doc-org.freedesktop.portal.RemoteDesktop.html). + +4. **[high] F4 understates the cross-host failure mode: cloning breaks consumption, not merely identity.** + + Clone a home after a capability and one-use approval are valid, then start it on hosts A and B. Both kernels can authenticate the same manifest and perfectly enforce the same local policy while each consumes the supposedly single use. A signed manifest establishes provenance, not freshness, uniqueness, or serialization. Preventing this requires A23’s external head plus a cross-host writer lease and durable authority reservation; TPM/IMA attestation can prove what each host loaded but cannot choose the canonical host or reconcile a partition. Kernel principal enforcement remains useful local defense, but contributes nothing to the distributed decision unless the admission protocol supplies current global truth. + +5. **[medium] The theory’s viable Linux thesis is narrower and stronger than its current one.** + + Linux already has enough subject labels and isolation mechanisms to prototype manifest-scoped enforcement. What it lacks is a standard binding among a signed delegation record, a locally unforgeable workload handle, a compiler-produced enforcement profile, broker peer authentication, and audit evidence. That is primarily a runtime protocol and policy-compiler problem. A future kernel facility might make the binding cheaper or more uniform, but the note has not shown a security property that only such a facility can provide. + +The one claim I would delete outright is C5, because its central conclusions—new kernel principal, T2 disappearing, and approval becoming memory-protection-like—do not follow from principal separation. + +The claim I would bet on is C11’s engineering core, narrowed to a manifest-attested ASF microVM appliance rather than marketed as a new operating-system category. diff --git a/docs/substrate-theory-analysis/Stance 3 - GPT 5.6 Sol Xhigh.md b/docs/substrate-theory-analysis/Stance 3 - GPT 5.6 Sol Xhigh.md new file mode 100644 index 0000000..b68bbb5 --- /dev/null +++ b/docs/substrate-theory-analysis/Stance 3 - GPT 5.6 Sol Xhigh.md @@ -0,0 +1,91 @@ +C7 and C8 are refuted as written. The central failure is hardlink aliasing: family 3 works only if the retained generation is immutable, and the proposed recipe does not produce an immutable generation. + +## Strongest findings + +1. **High — hardlinks erase the publication boundary.** The [staging recipe](/Users/josh/dev/Coppice/docs/substrate-theory.md:151) gives the outgoing and incoming trees names for the same inode. + + - A pre-swap in-place edit to an “unchanged” file mutates both trees, so it cannot be localized to the retained generation. + - A post-swap edit through the new live path mutates the retained evidence. + - Comparing retained against live finds equality; comparing retained against the prepared root can detect something changed only by scanning a path that was supposedly unchanged, and cannot tell which side of the swap the edit occurred on. + - Editors using temp-file-plus-rename break the alias on one side, while in-place writers preserve it. Correctness therefore depends on application save style. + + This is not the acknowledged descriptor tax: it affects an ordinary pathname opened after publication. The invariant must be “no writable inode is shared across generations.” That requires reflinked independent inodes, a real CoW snapshot, or full copies—not hardlinks. + +2. **High — `O(changed)` requires precisely the write-boundary mechanism C8 claims to avoid.** On raw POSIX: + + - Constructing the hardlink tree already requires enumerating and linking approximately `N` entries. + - Discovering edits at unknown paths in the retained tree requires either an `O(N)` walk or a complete change journal/watcher history. The latter is family-2 detection under another name. + - A one-operation directory rename containing `M` descendants requires `O(M)` namespace work because directories cannot be hardlinked. + - File↔directory transitions require examining the affected path-state union. Calling that `O(changed)` is true only if “changed” counts every affected descendant, not logical operations. + + Thus the bound can hold for a Merkle-indexed/native-snapshot substrate with a reliable mutation log. It does not hold for the claimed portable POSIX floor. + +3. **High — root exchange is hostile to watchers.** Linux inotify watches objects, not future occupants of a pathname. After exchanging the watched root, recursive watches remain associated with the outgoing directory objects; the newly staged directories are unwatched until the consumer rebuilds its watch set. Linux also documents rename pairing as inherently racy and recursive watch construction as expensive for large trees. [inotify documentation](https://man7.org/linux/man-pages/man7/inotify.7.html) + + On macOS, Apple explicitly requires a full-tree rescan when a watched root is moved or renamed. An exchange-rename therefore makes the external observation cost `O(N)` per publication for a conforming WatchRoot consumer. [Apple FSEvents guide](https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/FSEvents_ProgGuide/UsingtheFSEventsFramework/UsingtheFSEventsFramework.html) + + Syncthing’s documented rescan checks every existing entry’s metadata and rehashes entries whose metadata changed. It also retains periodic full scans because watcher delivery is not complete. [Syncthing synchronization documentation](https://docs.syncthing.net/users/syncing.html) + + I cannot substantiate a universal Syncthing/Dropbox delete-and-recreate conflict storm without black-box tests. The defensible finding is the dichotomy: rebuild/rescan at `O(N)`, or risk missing live changes. + +4. **High — “NFS-safe” conflates server atomicity with client coherence.** NFS RENAME is atomic at the server, but client LOOKUP and directory caches may retain the old symlink binding. Linux defaults permit directory attributes to remain cached for up to 60 seconds; NFS itself explicitly provides weaker cache coherence than a cluster filesystem. [Linux NFS documentation](https://man7.org/linux/man-pages/man5/nfs.5.html) + + NFSv4.1 directory delegations can provide synchronous recall, but they are optional and not always granted. Without one, different clients can resolve old and new targets concurrently, and a stale client can continue pathname-based writes into the retained generation after the nominal swap. [RFC 8881](https://www.rfc-editor.org/rfc/rfc8881.html) + + “NFS-safe” is defensible only as “server-atomic, no missing-name interval.” It is not a single globally visible transition. The profile needs cache/delegation requirements, a stale-resolution bound, and a retention/reconciliation grace period. + +## Claim verdicts + +| Item | Verdict | Reason | +|---|---|---| +| C6 | **Refute as worded** | WALs are an orthogonal crash-recovery mechanism; leases, delegations, and oplocks are revocable exclusion/coherence. Neither is a clean fourth family. More importantly, mature systems compose families: Git combines expected-old validation, locking, and atomic rename; MVCC combines version retention with locks or validation; LSM systems combine WAL, serialization, and manifest indirection. The examples do not establish an exhaustive or disjoint taxonomy. | +| C7 | **Refute** | Retention is sound only when the retained generation cannot change. Hardlinks, stale NFS resolution, and open handles violate that prerequisite and blur the claimed temporal cut. | +| C8 | **Refute as written** | The property-first framing is good, but the hardlink recipe, “NFS-safe” binding, “nearly free” cost, and unconditional `O(changed)` bound fail. | +| C9 | **Refine** | This is not one ladder. CoW improves retention cost; namespace primitives determine publication atomicity; leases/watchers determine observer coherence; mediation determines attribution. A CoW filesystem does not automatically retarget mounted paths, open handles, or watchers, nor make a multi-store swap atomic. This should be a profile matrix, not a monotonic substrate ladder. | +| F3 | **Valid but non-operational** | It needs explicit variables and thresholds. Under root-watcher rescans, the crossover arrives at surprisingly small sparse-change ratios. | + +## F3 crossover + +Let: + +- `N` = total entries +- `K` = entries targeted per publication +- `p` = publications per unit time +- `s` = full-scan throughput in entries/second +- `d` = family-2 validation cost per targeted entry +- `q` = fraction of publications causing a full watcher/sync rescan + +For native CoW, giving family 3 every advantage: + +``` +family 2: T₂ ≈ p K d +family 3: T₃ ≥ p q N / s +``` + +Family 3 loses when: + +``` +N / K > s d / q +``` + +Illustrative—not measured—values of `s = 50,000 entries/s` and `d = 100 µs` give: + +- If every root swap causes a scan (`q = 1`), family 3 loses when `N > 5K`, meaning less than 20% of the tree changes. +- If only 1% cause a scan, it loses when `N > 500K`. + +For `N = 1,000,000`, `K = 100`, and 12 publications/hour: + +``` +family 2: 10 ms/publication ≈ 0.12 s/hour +family 3: 20 s/publication ≈ 240 s/hour +``` + +That lower bound excludes staging, reconciliation, hashing, retained-byte growth, network metadata, and conflict copies. On the portable hardlink-tree implementation, add `O(N)` link/tree-construction work regardless of watcher behavior. + +F3 should therefore measure full scans, metadata operations, bytes rehashed, conflict copies, network traffic, retained unique bytes, and stale-client duration across inotify, FSEvents, NFS mount profiles, Syncthing, and Dropbox. Until that matrix exists, “nearly free” is unsupported rather than merely vulnerable to future falsification. + +::code-comment{title="[P1] Hardlinks invalidate retained-state evidence" body="Unchanged entries in the two generations name the same inode. In-place writes before or after the swap mutate both generations, so the outgoing tree is neither immutable evidence nor a stable temporal boundary. This also makes reconciliation dependent on writer save style. Family 3 requires independent writable inodes—reflinks, snapshots, or copies—not hardlinks." file="/Users/josh/dev/Coppice/docs/substrate-theory.md" start=151 end=154 priority=1} + +::code-comment{title="[P1] O(changed) assumes a complete mutation oracle" body="A raw retained POSIX tree cannot be proven unchanged at unknown paths without an O(tree) walk or a complete mutation log. Watchers can overflow and root exchange invalidates their object/path mapping; directory renames and topology changes can also touch an entire subtree despite being one logical operation. State the bound only for profiles supplying an immutable indexed generation plus reliable change enumeration." file="/Users/josh/dev/Coppice/docs/substrate-theory.md" start=155 end=157 priority=1} + +::code-comment{title="[P1] NFS atomicity is not client coherence" body="Rename-over-symlink is atomic at the NFS server, but cached LOOKUP and directory state can leave clients resolving the old target for tens of seconds under ordinary mount settings. Directory delegations can improve this but are optional. Label this server-atomic/eventually-visible and specify the cache/delegation and retention-grace profile instead of calling it NFS-safe." file="/Users/josh/dev/Coppice/docs/substrate-theory.md" start=147 end=150 priority=1} diff --git a/docs/substrate-theory-analysis/Stance 4 - GPT 5.6 Sol Xhigh.md b/docs/substrate-theory-analysis/Stance 4 - GPT 5.6 Sol Xhigh.md new file mode 100644 index 0000000..f66ae66 --- /dev/null +++ b/docs/substrate-theory-analysis/Stance 4 - GPT 5.6 Sol Xhigh.md @@ -0,0 +1,92 @@ +Verdict: **REQUEST CHANGES.** The core strategic error is conflating technical replaceability with adoption, and format survival with value capture. F2 is currently not falsifiable by the dogfood program. + +| Item | Verdict | Strongest attack | +|---|---|---| +| [C10](/Users/josh/dev/Coppice/docs/substrate-theory.md:178) | **Refute** | The boundary has a legacy constituency: today’s bash-first harnesses, arbitrary subprocesses, credential conventions, filesystem layouts, and network assumptions. A microVM can preserve POSIX, but a broker-only door cannot preserve ambient authority without ecosystem adoption. | +| [C12](/Users/josh/dev/Coppice/docs/substrate-theory.md:204) | **Refute strategic inference** | OCI proves formats can survive their authors. It does not prove their authors capture the resulting value. Docker’s history is at least as much a warning as a precedent. | +| [F1](/Users/josh/dev/Coppice/docs/substrate-theory.md:235) | **Refine** | It tests semantic impossibility when economic refusal is enough to kill C10. The boundary can be replaceable yet remain owned by labs and clouds. | +| [F2](/Users/josh/dev/Coppice/docs/substrate-theory.md:239) | **Currently untestable** | Dogfooding measures denial false positives, while standing grants cannot yet be widened. “The user did not widen” is therefore mechanically predetermined. | +| [F5](/Users/josh/dev/Coppice/docs/substrate-theory.md:250) | **Refute as stale/misspecified** | Vertically integrated substrates already exist. They do not need proprietary edge protocols: vendors can embrace MCP/A2A while keeping identity, policy, history, and enforcement proprietary. | +| [C11](/Users/josh/dev/Coppice/docs/substrate-theory.md:190) | **Refine** | Before manifest-as-principal, this is an appliance built on existing microVM and policy machinery, not a separately purchasable OS category. The note has not identified its buyer. | + +## C10/F1 — harness gravity is boundary loyalty + +OpenAI’s own Windows sandbox work is almost a direct falsification of C10’s economic premise: it found AppContainer’s capability model the wrong shape because Codex must drive shells, Git, Python, package managers, and arbitrary binaries. Anthropic likewise preserved bash and arbitrary subprocesses, adding transparent filesystem and network mediation around them. These are not merely tools “inside” the boundary; their assumptions define what the boundary must transparently reproduce. [OpenAI’s Windows sandbox analysis](https://openai.com/index/building-codex-windows-sandbox/), [Anthropic’s sandbox architecture](https://www.anthropic.com/engineering/claude-code-sandboxing). + +Who must adopt ASF’s stronger boundary: + +- **Labs and runtime operators** must bind launches to manifests, force external effects through the broker, and make their native approval/history systems subordinate to portable records. They want safer autonomy and enterprise sales, but have a contrary incentive against portable trust that weakens their control. +- **Tool and CLI authors** must expose structured action, target, reversibility, and credential semantics rather than rely on raw shell/network access. Their incentive is distribution, but MCP gateways already offer it with less schema burden. +- **Enterprise platform teams** must map IAM/Entra identities, secrets, audit, and incident procedures onto manifests. Their switching costs are substantial, and their incumbent vendor will offer a bundled mapping first. +- **Developers** must accept that some familiar shell workflows cannot receive ambient credentials or unrestricted network access. Fewer prompts are valuable; broken automation is not. + +A better F1 is: + +> If representative coding, research, and SaaS workflows cannot run through the broker without raw ambient credentials, unclassified shell effects, or routine bypass—and integrated vendor sandboxes deliver acceptable autonomy without manifest semantics—then the ASF boundary has lost economically even if it remains technically implementable. + +The current vault-only dogfood, which forbids shell on the agent surface, cannot test this. + +## C12 — OCI supports portability, not capture + +Docker donated an already dominant technology: the OCI announcement cited more than 500 million image downloads and 40,000 public projects before neutralization. Distribution created the standard; kernel-friendly schema design did not create distribution. [OCI’s 2015 announcement](https://opencontainers.org/posts/announcements/2015-06-20-industry-leaders-unite-to-create-project-for-open-container-standard/). + +Docker Hub also had a stronger accumulation story than ASF currently claims: publishers, consumers, official images, automation, namespaces, and millions of searchable artifacts. Yet cloud-attached registries and orchestrators could capture workloads while consuming the same format. Docker later sold its enterprise platform business to Mirantis. [Docker Hub](https://hub.docker.com/search), [Mirantis acquisition announcement](https://www.globenewswire.com/news-release/2019/11/13/1946550/0/en/Mirantis-Acquires-Docker-Enterprise-Platform-Business.html). + +The trust ledger is weaker as a network asset: + +- Records are private, user-specific, domain-scoped, and behavior-version-specific. +- Another customer’s history does not improve mine. +- Exportability deliberately lets the accumulated history leave with the customer. +- If independent runtimes can verify it, hosting becomes more substitutable, not less. + +That is excellent trust architecture and poor evidence of a moat. A real accumulating asset would need something like relying-party recognition, portable tool attestations, insurer/auditor acceptance, cross-vendor reputation verification, or uniquely calibrated risk infrastructure. “Hosted storage plus UX” is bundleable by the clouds. + +C12 should therefore say: **formats are the distribution and neutrality strategy; they are not the value-capture strategy.** The latter needs a separate claim and falsifier. + +## F5 — the vertical race has already started + +The credible field is: + +| Candidate | Existing position | Format incentive | +|---|---|---| +| **Microsoft** | MXC supplies OS-enforced agent containment, local/Entra agent identity, Agent 365 governance, and Foundry hosting. | Open MCP/A2A for ecosystem ingress; retain authority and telemetry in Entra, Intune, Purview, Agent 365, and Foundry. [Windows agent platform](https://developer.microsoft.com/en-us/windows/agentic) | +| **AWS** | AgentCore already combines per-session microVMs, workload identity, gateway, policy, credential custody, memory, and tracing. | Support any framework/model plus MCP/A2A while making IAM, Cedar, ARNs, and AgentCore the authoritative control plane. [AgentCore Runtime](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agents-tools-runtime.html) | +| **Google** | Vertex Agent Engine combines managed runtime, sessions, memory, code execution, observability, and per-agent identity. | Promote open A2A/ADK while retaining Google IAM, gateway, runtime state, and Cloud telemetry. [Agent Engine](https://cloud.google.com/vertex-ai/generative-ai/docs/reasoning-engine/overview), [Agent Identity](https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/agent-identity-overview) | +| **OpenAI** | Codex already spans local/cloud sandboxes, approvals, network policy, and agent-native telemetry. | Support portable tools while keeping task history, approval policy, and execution controls attached to Codex. [Codex deployment controls](https://openai.com/index/running-codex-safely/) | +| **Anthropic** | Claude Code has sandboxed bash, credential proxies, permissions, checkpoints, and MCP distribution. | Keep MCP neutral while retaining Claude-specific history, checkpoint, and permission semantics. [Claude sandboxing](https://www.anthropic.com/engineering/claude-code-sandboxing) | +| **Apple** | Xcode hosts multiple agents through MCP/ACP; Apple controls the OS sandbox and App Intents action surface. | Open agent ingress, proprietary OS authority and app-action semantics. [Xcode agent integration](https://www.apple.com/newsroom/2026/06/apple-aids-app-development-with-new-intelligence-frameworks-and-advanced-tools/) | +| **Red Hat / Canonical / NVIDIA** | Kagenti AgentRuntime/AuthBridge and OpenShell-on-Ubuntu are already forming a Linux-native alternative. | Likely allies for neutral formats, but may standardize on Kubernetes, SPIFFE, OCI, and OpenShell and treat ASF as redundant. [Red Hat AgentRuntime](https://developers.redhat.com/articles/2026/04/14/deploying-agents-red-hat-ai-openclaw), [Ubuntu OpenShell](https://canonical.com/blog/nvidia-openshell-ubuntu-announcement) | + +Thus F5’s “before a vertical substrate ships” window is closed. The remaining window is roughly **6–12 months to enter the neutral authority/governance standards conversation**, not several years to invent a standalone format. MCP already reports over 10,000 public servers, and A2A has broad cloud adoption; those are the channels with distribution gravity. [MCP’s foundation donation](https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation), [A2A adoption](https://www.linuxfoundation.org/press/a2a-protocol-surpasses-150-organizations-lands-in-major-cloud-platforms-and-sees-enterprise-production-use-in-first-year). + +A testable replacement for F5: + +> If by 2027-06-30 fewer than two independent runtimes natively emit ASF records, fewer than two independent gates authorize from them, or no external relying party accepts portable trust across vendor boundaries, ASF has not accumulated format network effects. Export adapters and nominal schema support do not count. + +## F2 — a 90-day disconfirming observation + +Current dogfooding cannot test F2. Its primary metric is denial false-positive rate, not delegated authority, and every grant remains session-scoped until the ratchet exists. [Current metrics](/Users/josh/dev/Coppice/docs/dogfooding.md:116), [standing grants unavailable](/Users/josh/dev/Coppice/docs/dogfooding.md:165). + +A minimally observable 90-day test would: + +1. Pre-register three recurring workflow families and a delegation-frontier vector: path/action scope, grant duration, unattended runtime, auto-promotion, and approvals per successful operation. +2. Record the operator’s actual maximum grant for the next run before histories accrue. +3. Accumulate at least three clean runs and one successful forced restore per family. +4. Present the evidence and offer the least-general standing grant covering those runs. +5. Collect at least 24 actual accept/narrow/reject decisions, keeping behavior version and task family fixed. + +Operational disconfirmation is: after clean histories and demonstrated recovery, the median frontier does not widen on any dimension, approval burden does not fall, and offers are repeatedly rejected for risks that recovery does not address—exfiltration, correctness, social consequences, or accountability. + +That falsifies the loop for the design-center operator. It does **not** establish causality or generalize to a market; that would require a staged or randomized multi-user rollout. The note should distinguish those two claims. + +## C11’s buyer + +Before manifest-as-principal, nobody plausibly buys an “agent OS” as such: + +- The solo operator buys an application or managed service. +- Labs and hyperscalers build the runtime because it is strategically controlling. +- Enterprise platform teams buy a certified control plane or appliance, but already possess VM/container pipelines, IAM, policy, secrets, observability, and incident tooling. + +The switching cost from Firecracker-plus-policy is therefore not the guest image. It is migration of identities, policy, credential flows, network controls, logs, compliance evidence, deployment pipelines, and operational ownership. Firecracker already provides the microVM isolation boundary and explicitly leaves egress filtering to the host, making ASF a plausible control-plane addition without runtime replacement. [Firecracker design](https://github.com/firecracker-microvm/firecracker/blob/main/docs/design.md). + +C11 is defensible only as **an ASF reference appliance or W-4 backend**. Its unique buying reason must be coherent cross-store recovery plus portable trust; without that demonstrated advantage, “agent-runtime OS” is packaging around an already commoditizing stack. diff --git a/docs/substrate-theory-analysis/Stance 5 Verdict - GPT 5.6 Sol Xhigh.md b/docs/substrate-theory-analysis/Stance 5 Verdict - GPT 5.6 Sol Xhigh.md new file mode 100644 index 0000000..d691ad2 --- /dev/null +++ b/docs/substrate-theory-analysis/Stance 5 Verdict - GPT 5.6 Sol Xhigh.md @@ -0,0 +1,92 @@ +Editorial verdict: major rewrite. The note’s best idea is retention-at-swap, but it prematurely presents an open SI-40 alternative as settled and then specifies a hardlink-based staging recipe that conflicts with the normative staged-bytes rule. That is exactly the epistemic failure the note says it exists to prevent. + +I did not assess the external historical claims; this review is confined to argumentative economy, internal consistency, and fidelity to the grounding documents. + +## Part A — C1–C12 + +| Claim | Role | Verdict | One-line justification | +|---|---|---|---| +| C1 | Supporting | MERGE | The confused-deputy lineage is useful setup for C2, but “the attack is unchanged” and the historical catalogue do no independent argumentative work. | +| C2 | Load-bearing | KEEP | This is the note’s actual theoretical thesis, but it must distinguish the brief’s aspirational consequence→authority coupling from what §7 currently specifies. | +| C3 | Supporting | MERGE | Same-uid weakness is a premise of C5; “this single fact generates most problems” is monocausal decoration that erases distinct trust-root, actuation, and policy failures. | +| C4 | Supporting | MERGE | The userspace-adapter tension belongs inside C5, while the additive/subtractive binary and “every enforcement claim” overstate A27’s specifically T2-scoped containment dependency. | +| C5 | Load-bearing | KEEP | Manifest-scoped execution is the indispensable OS bridge, but it does not by itself dissolve T2 or solve approval-surface reachability. | +| C6 | Supporting | MERGE | The taxonomy only scaffolds C7; “exactly three” is undefended, and detection remains necessary inside the purported indirection solution. | +| C7 | Load-bearing | KEEP | Retention rather than an earlier snapshot is the sharpest mechanism insight, but its descriptor residual defeats the unqualified “attributed, never lost” conclusion. | +| C8 | Decorative/speculative | MERGE | Keep the property/profile distinction in C7; remove the syscall recipe, cost claims, and registration behavior, which are unratified protocol work. | +| C9 | Supporting | MERGE | The substrate ladder usefully qualifies C7, but its branch-platform and hosted-infrastructure assertions are examples, not another claim. | +| C10 | Load-bearing | KEEP | Boundary compatibility economics is the necessary premise for the OS endgame and has a recognizable falsifier in F1. | +| C11 | Decorative/actionable | DELETE | It is an agent-OS roadmap disguised as a limit case and materially expands W-4 while claiming not to. | +| C12 | Load-bearing | KEEP | Portable formats provide the strategic bridge from current fabric to possible OS enforcement, provided this is framed as option value rather than prediction or design mandate. | + +## The five-claim note + +The survivors should be rewritten as: + +1. **C1+C2 — Authority, consequence, and epistemic compilation.** Prompted delegation inherits the confused-deputy structure; ASF adds state-based consequence bounds, behavior-scoped evidence, and human-ratified compilation rather than merely another capability syntax. + +2. **C3+C4+C5 — The substrate mismatch.** Current same-uid hosts do not natively express a delegation manifest as an execution principal, so W-4 emulates that boundary; manifest-as-principal is a hypothetical end state, not a solution to unresolved approval and actuation semantics. + +3. **C6+C7+C8+C9 — The publication property.** In open-world shared state, substrate-assisted publication is useful only when an atomic namespace transition retains the outgoing generation long enough to capture and attribute divergence; implementations must state weaker profiles honestly. No recipe belongs here while SI-40 remains open. + +4. **C10 — The compatibility wedge.** Agent workloads can retain POSIX inside the toolbox while replacing the trust boundary around it, making capability-oriented execution economically more plausible than earlier general-purpose capability systems. + +5. **C12 — Format option value.** Substrate-independent, enforceable manifest/capability/trace semantics could survive into a future runtime or OS, but this creates an option rather than a roadmap. + +What is lost: the historical name parade, the “exactly three families” flourish, the filesystem recipe, the hosted-substrate ladder, and the agent-OS mock-up. None is necessary to the inference. The SI-40 design material belongs in SI-40; the OS mock-up belongs in a separately labeled horizon memo. + +## F1–F6 ranked by bite + +| Rank | Falsifier | Assessment | Visible consequence | +|---:|---|---|---| +| 1 | F2 | **Real, but under-instrumented.** It attacks the central coupling claim through observable user behavior. | Remove consequence→authority from C2 and stop claiming recoverability is the product’s authority engine; “just backup” still overstates the result because the broker survives. | +| 2 | F6 | **Potentially devastating, not yet operational.** “Interesting decisions” can be redefined forever. | If repeated consequential work does not migrate from judge/human decisions into mechanical rules, recenter the theory on judgment rather than ocap. | +| 3 | F1 | **Real.** It kills the trust-boundary replacement thesis rather than merely weakening an implementation. | Treat W-4’s POSIX adapter as the permanent architecture and delete the OS-endgame claim. | +| 4 | F3 | **Real but local.** “Blow up” needs explicit latency, space-amplification, and churn thresholds. | Demote atomic-retention profiles or reintroduce boundary detection for affected stores; C2/C10/C12 remain intact. | +| 5 | F5 | **Performative.** A proprietary first mover changes commercial timing but does not falsify format durability or the Docker/OCI analogy. | At most it changes strategy and urgency, not the architectural claim. | +| 6 | F4 | **Not a falsifier.** Cross-host principals needing a trust root is an unsurprising boundary condition, not a refutation of a local execution principal. | Move it to “open weaknesses”; no stated claim necessarily changes. | + +To make F6 real: define a cohort of repeated workflows and a threshold for the fraction of consequential decisions still requiring judge/human intervention after ratification opportunities. To make F3 real: name the product budget beyond which the profile changes. + +## §5’s fence is not credible + +The status paragraph says nothing here is actionable, but the body repeatedly uses imperative or implementation-selecting language: + +- “The bindings form a ladder discovered at store registration and recorded ledger-visibly…” ([C8](/Users/josh/dev/Coppice/docs/substrate-theory.md:142)) +- “Staging recipe: unchanged entries hardlink from live … changed entries reflink from CAS…” ([C8](/Users/josh/dev/Coppice/docs/substrate-theory.md:151)) +- “Design discipline that follows today: W-4’s emulation interface should be designed as if it were the future kernel interface…” ([C11](/Users/josh/dev/Coppice/docs/substrate-theory.md:200)) +- “The endgame corollary: design the manifest, caveat, and trace schemas so that a kernel could enforce them…” ([C12](/Users/josh/dev/Coppice/docs/substrate-theory.md:204)) + +The third quotation is unambiguously a current work item. The first two specify a new registration protocol and publication implementation. The last imposes a schema design criterion. + +More seriously, “What works: the atomic swap” selects SI-40’s substrate-assisted arm even though SI-40 calls preservation/refusal the leading candidate and says substrate-assisted preservation should be evaluated only when a trigger fires ([SI-40](/Users/josh/dev/Coppice/docs/spec-issues.md:74), [substrate alternative](/Users/josh/dev/Coppice/docs/spec-issues.md:91)). A disclaimer cannot neutralize imperative prose. Either remove those prescriptions or file and cross-reference the corresponding SI/W/P items. + +## Grounding conflicts + +The strongest conflicts are: + +1. **C8 violates A27.1.** Hardlinking unchanged entries from the mutable live tree means an in-place edit can mutate the prepared incoming generation after verification. That conflicts with the requirement that forward images be immutable CAS-derived plans and that commit be a pure function of already-trusted bytes ([A24](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:218), [A27.1](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:223)). “Edits ride through” is precisely the forbidden mutation of the planned after-root. + +2. **C7 claims more than its own residual permits.** It says “Nothing falls between” and “‘Attributed, never lost’ achieved by construction,” then admits an open descriptor can write into the retained generation after the swap. Unless reconciliation establishes a closing point against such writers, that write can miss capture and attribution. The residual refutes the preceding guarantee rather than merely taxing it. + +3. **C8’s floor is not a profile of its stated property.** The property requires “one atomic namespace transition,” but the “universal floor” is explicitly a non-atomic two-rename protocol. That is a different, weaker property and must be labeled as such. + +4. **C5 silently resolves SI-23.** Saying manifest-as-principal makes the approval surface memory-protected assumes the reference monitor already understands actuation reach and qualifying approval surfaces. SI-23 explicitly says W-4 containment does not solve legitimate granted actuation reaching that surface ([SI-23](/Users/josh/dev/Coppice/docs/spec-issues.md:1124)). Principal separation is necessary but not sufficient. + +5. **C11 expands W-4 while denying expansion.** W-4 currently specifies attestation plus “a container/microVM whose only door is the proxy” ([roadmap](/Users/josh/dev/Coppice/docs/roadmap.md:373)). PID-1 adjacency, subvolume branches, caveat compilation, eBPF trace integration, and a kernel patch series are materially new scope. + +6. **C2 overstates its §7 citation.** The brief does say “Reversal earns authority” ([brief](/Users/josh/dev/Coppice/docs/agent-state-fabric-brief.md:135)), but normative §7 constructs rules from k approved examples and records raw behavior-scoped counters; it does not require recoverability evidence before widening authority ([StandingRule](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:339), [TrustRecord](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:364)). The note promotes a product aspiration into the fabric’s “theoretical identity” without acknowledging the specification gap. + +## The missing claim + +The behavior/judge silence is a gap, not a legitimate scope fence. + +C2 introduces behavior pinning as “the third leg,” then defines the triple as “authority bound, consequence bound, evidence-coupled”—behavior disappears from its own enumeration. Meanwhile the note claims to explain ASF’s theoretical basis as a whole, not merely filesystem publication. F6 itself concedes that the judge may determine whether the ocap framing is substance or marketing. + +The missing claim should be something like: + +> **C13 — Behavior is the unit of earned trust, and judgment is the compilation boundary.** Mechanical capabilities decide only stable, auditable predicates; a capability-less judge handles residual ambiguity, human ratification is the sole transition from judgment to standing authority, and evidence remains valid only for the behavior version that produced it. The loop succeeds only if repeated judgment shrinks into mechanical rules without losing behavior provenance. + +Its falsifier is direct: if behavior-version changes do not predict materially different outcomes, or if repeated judge work does not shrink through ratification, the behavior lineage and judge are ceremonial rather than load-bearing. + +Without that claim, this is a strong storage-and-capability horizon note mislabeled as ASF’s theoretical basis. diff --git a/docs/substrate-theory-analysis/Synthesis - Claude Fable 5.md b/docs/substrate-theory-analysis/Synthesis - Claude Fable 5.md new file mode 100644 index 0000000..4f71e59 --- /dev/null +++ b/docs/substrate-theory-analysis/Synthesis - Claude Fable 5.md @@ -0,0 +1,214 @@ +# Synthesis: five-stance adversarial review of `docs/substrate-theory.md` + +*Fresh-context synthesis (Claude Fable 5), 2026-07-15. Method: cross-matrix → +steelman rulings on convergent refutations → amendment list → survival +report. Reviewer citations verified at source before ruling: SI-40's +candidate ordering, A27.1's staged-bytes rule, §7's StandingRule/TrustRecord, +SI-23's self-satisfiable-approval finding, and A27's T2 determination. Every +reviewer citation checked was accurate.* + +--- + +## 1. Cross-matrix + +| Claim | S1 (ocap historian) | S2 (kernel/security) | S3 (storage) | S4 (strategist) | S5 (editor) | Classification of the REFUTE/REFINE content | +|---|---|---|---|---|---|---| +| C1 | **REFUTE** (identity claim false; analogy useful) | — | — | — | MERGE (setup only; "attack is unchanged" does no work) | **Stance-dependent** (S1's lens) but decisive on merits; S5 semi-converges on demotion | +| C2 | **REFINE** ("ocap has no undo" historically indefensible; narrow to the joined loop) + B2 (consequence bound not one quantity) | — | — | — | KEEP, but must separate brief aspiration from §7 spec (grounding conflict #6) | **Convergent demotion on two independent axes**: S1 attacks the history, S5 attacks the internal grounding | +| C3 | — | **REFUTE** (Linux has finer-than-uid subjects; real gap = no manifest-instance identity; problems are P7's unconfigured boundary) | — | — | MERGE ("single fact generates most problems" is monocausal decoration) | **Convergent** on the monocausal causal claim | +| C4 | — | **REFUTE** (subtractive/additive not an ecosystem property; surviving insight = object-model mismatch) | — | — | MERGE (binary and "every enforcement claim" overstate A27's T2-scoped dependency) | **Convergent** on the binary; the adapter-danger conclusion not contested | +| C5 | — | **REFUTE** (T2 does not dissolve; launcher over existing mechanisms suffices; B2 scheduling unit; B3 SI-23) | — | — | KEEP as load-bearing, but "does not dissolve T2 or solve approval-surface reachability" (conflict #4: silently resolves SI-23) | **Convergent** on both downstream conclusions; S2's B2 (scheduling unit) and B4 (clone/consumption) are **singletons, live** | +| C6 | — | — | **REFUTE as worded** (not exhaustive/disjoint; mature systems compose families) | — | MERGE ("exactly three" undefended; detection persists inside indirection) | **Convergent** | +| C7 | — | — | **REFUTE** (hardlink aliasing blurs the temporal cut; correctness depends on editor save style) | — | KEEP core, but residual refutes "nothing falls between" (conflict #2); note pre-selects SI-40's arm | **Convergent** on the by-construction absolutism; S5's SI-40 fence breach is a **decisive singleton** (§2.7) | +| C8 | — | — | **REFUTE as written** (hardlinks; O(changed) needs a mutation oracle; watcher O(N); "NFS-safe" false) | — | MERGE (recipe is unratified protocol work; conflict #1: violates A27.1; conflict #3: floor is not a profile of the property) | **Convergent and decisive** — two stances kill the recipe from independent directions (fs semantics; spec conformance) | +| C9 | — | — | **REFINE** (four independent axes, not one ladder) | — | MERGE (examples, not a claim) | **Convergent** refinement | +| C10 | B3: genealogy typological, monocausal (medium) | — | — | **REFUTE** (boundary has a harness-convention constituency; adoption economics) | KEEP (necessary premise, falsifiable via F1) | **Convergent demotion** on two axes (history: S1; economics: S4); technical core uncontested | +| C11 | — | **REFINE** (Firecracker/Kata + control plane; name the unique invariant or call it an appliance) | — | **REFINE** (no buyer; defensible only as reference appliance / W-4 backend) | **DELETE** (roadmap disguised as limit case; expands W-4 while denying it; fence breach) | **Convergent ×3** — the strongest convergence in the set | +| C12 | — | — | — | **REFUTE strategic inference** (OCI proves survival, not capture; distribution, not design, made the format canonical) | KEEP (as option value, not prediction; the "corollary" is imperative — fence breach) | **Stance-dependent** but the inference-refutation is decisive; S5 converges on the fence problem | +| F1 | — | — | — | **REFINE** (tests semantic impossibility; economic refusal suffices; replacement supplied) | Rank 3, real | **Convergent** on operationalization | +| F2 | — | — | — | **Currently untestable** (dogfood measures denial FPs; widening mechanically impossible pre-ratchet; 90-day protocol supplied) | Rank 1, real but under-instrumented | **Convergent**: top falsifier, not yet operational | +| F3 | — | — | **Valid but non-operational** (crossover model; "nearly free" *currently unsupported*, burden reversed) | — | Rank 4, real but local, needs thresholds | **Convergent** on operationalization; S3's burden-reversal is the sharper form | +| F4 | — | **REFINE** (not a falsifier; problem stays *above* the kernel at policy admission; B4: cloning breaks consumption, not just identity) | — | — | Rank 6, not a falsifier; move to open weaknesses | **Convergent demotion**; S2's B4 upgrade is a **singleton, live** | +| F5 | — | — | — | **REFUTE as stale** (vertical substrates already shipped; vendors embrace MCP/A2A while keeping authority proprietary; dated replacement supplied) | Rank 5, performative | **Convergent demotion**; S4's mechanism (open protocol, proprietary authority) is the decisive part | +| F6 | **REFINE** (right threat, unfalsifiable as written; pre-registered ablation supplied) | — | — | — | Rank 2, potentially devastating, not operational; shrinkage metric supplied | **Convergent** on operationalization | + +**Part B singletons not lens-dismissible (live):** S1-B1 (three meanings of +"capability" laundered — ocap reference vs macaroon credential vs ASF broker +grant); S1-B2 (consequence bound is not one quantity — fidelity laundering); +S2-B2 (C5/C11 jointly never name the unit of isolation); S2-B4 (cloned homes +double-spend one-use authority — attestation proves provenance, not freshness +or uniqueness); S3 watcher finding (root exchange makes conforming observers +pay O(N) per publication); S5's §5-fence audit and the missing behavior/ +judgment claim (C13). + +--- + +## 2. Steelman rulings on the convergent refutations + +**2.1 C5's downstream dissolutions (S2 + S5) — STANDS.** +Steelman: under manifest-as-principal, "same-uid writer" is definitionally +gone — T2 *as named* dissolves, and the kernel can now express the exclusion +topology as first-class policy rather than emulation. Ruling: the steelman +concedes the point. The race class survives wherever two principals both +hold write authority to one namespace; what removes it is exclusion topology +— A27's *existing, ratified* answer. Principals make topology +kernel-expressible; they do not make it unnecessary. The approval-surface +sentence fails harder: SI-23's documented failure mode is synthetic input +arriving *through a legitimate actuation grant*, which principal separation +cannot distinguish from a human — the note contradicts an OPEN SI. Both +sentences struck. + +**2.2 C8's staging recipe (S3 + S5) — STANDS, decisively.** +Steelman: hardlinking unchanged entries is a deliberate T3-friendliness +feature, and reconciliation could diff against the prepare-time CAS image, +so retained-tree immutability is not required. Ruling: fails twice. (a) With +shared inodes an in-place edit mutates *both* generations — a diff cannot +tell which side of the swap the edit landed on; attribution fails, and +correctness becomes a function of editor save style. (b) "Edits ride +through" is verbatim the mutation A27.1 forbids — commit installing bytes +sourced from mutable live storage after prepare-time verification. The +cleanest kill in the set: two reviewers who never met, one from filesystem +semantics, one from spec conformance, converged on the same defect. + +**2.3 C11 as an OS category (S2 + S4 + S5) — STANDS.** +Steelman: C11 is framed as a horizon, and Talos/Bottlerocket show +composition alone can constitute an OS category. Ruling: three independent +failures survive. S2: every named component is Firecracker/Kata plus an ASF +control plane; no invariant named that a conventional microVM runtime plus +policy engine cannot provide. S4: no buyer for the category as such. S5 +(verified): W-4 specifies attestation plus a microVM whose only door is the +proxy; PID-1 adjacency, subvolume branches, caveat compilation, eBPF +integration, and a patch series are materially new scope — and "design +discipline that follows today" is a present-tense work item inside a note +whose §5 promises there are none. Struck; the engineering core survives one +sentence. + +**2.4 C7's "attributed, never lost, by construction" (S3 + S5) — PARTIALLY +STANDS.** The mechanism insight survives fully — including the +snapshot-at-a-point refutation, now with three independent derivations. But +"nothing falls between" is contradicted by the note's own descriptor +residual, and S3 adds two more boundary crossings (shared inodes; NFS +clients resolving the old target for tens of seconds under default caching). +The guarantee must be scoped to a profile; "by construction," unqualified, +is struck. + +**2.5 C4's additive/subtractive binary (S2 + S5) — PARTIALLY STANDS.** +The steelman saves the deployed-ecosystem observation (and notes Landlock +defaults open for *unhandled* access categories — the fail-open-on-unknown- +dimension shape ASF forbids), but not the essentialist binary: Smack/SELinux +are explicit-allow; seccomp can default-kill; capability systems fail open +via over-broad grants. S2's object-model-mismatch replacement is stronger +for the note: it locates the danger at the compiler without a false +dichotomy to defend. Refined, not struck. (S2's "REFUTE" verdict overstates +its own finding.) + +**2.6 C3's monocausal uid claim (S2 + S5) — PARTIALLY STANDS.** +Steelman: the portable floor includes Darwin — the actual dogfood host — +where S2's counter-arsenal does not exist. Ruling: blunts the REFUTE to a +refine, but S2's causal correction stands: the listed problems arise because +the current posture configures *no* boundary (P7), and the trust-root and +actuation problems are not uid-shaped. S2's replacement sentence adopted, +Darwin caveat restored. + +**2.7 The §5 fence breach and SI-40 arm pre-selection (S5 alone) — STANDS; +a decisive singleton that outranks convergence.** Verified fact, not +judgment: SI-40 names per-entry capture-or-refuse the leading candidate and +files substrate-assisted retention as a deployment-floor option; the note's +C7 declares "What works: the atomic swap." A theory note that quietly +pre-resolves an open SI's design contest is precisely the failure its own §5 +promises to prevent. Every C7/C8 amendment carries explicit non-selection +language as a consequence. + +**2.8 C10's economics (S4 + S1-B3) — PARTIALLY STANDS.** +The technical claim survives on the refuter's own exhibits (vendors shipping +non-POSIX sandbox boundaries confirms replaceability). What falls is the +inference: the boundary has a constituency after all — harness conventions +define what any boundary must transparently reproduce, and the +boundary-builders' incentives oppose portable manifest semantics. S1's +genealogy correction also stands. + +**2.9 C6, C9, F1, F2, F3, F4, F5, F6 — STAND as refinements** (folded into +§3). Reviewer errors named: S3's C6 "REFUTE" lands on the exclusivity +flourish; the trichotomy survives as an outcome partition at the write +boundary (WALs are orthogonal crash recovery). S5's F4 assessment slightly +understates S2-B4 (clone double-spend), which forces a scope sentence into +C5. + +**2.10 C12's strategic inference (S4) — PARTIALLY STANDS.** +The option-value core survives; the causal comfort does not. OCI's record +shows pre-donation distribution dominance made the format canonical — design +quality was not the causal variable, and the precedent's author exited the +value. S4's trust-ledger-as-weak-network-asset finding is correct but is a +finding against the *brief*, carried here as an honesty label. + +--- + +## 3. Amendment list + +Applied to `docs/substrate-theory.md` v2 — KEEP / REFINE (replacement +written out) / STRIKE (refutation preserved inline): C1 refined (analogy +kept, identity struck; S1-B1 credential-vs-ocap label added); C2 refined +(narrowed to the joined loop, with the §7-gap and fidelity-laundering +honesty labels); C3 refined (S2's manifest-instance-identity sentence + +Darwin caveat); C4 refined (object-model mismatch replaces the binary); C5 +refined (diagnosis kept; both dissolutions struck; unit-of-isolation and +clone/double-spend scope conditions added; "20% kernel work" withdrawn); C6 +refined (outcome partition, not exclusive choice); C7 refined +(profile-scoped guarantee; SI-40 non-selection paragraph added); **C8 +STRUCK** (five refutations preserved; property/profile sentence relocated to +C7); C9 refined (four-axis profile matrix; rollback corollary kept — +untouched by any reviewer); C10 refined (harness-gravity replacement; +genealogy corrected); **C11 STRUCK** (three refutations preserved; appliance +one-liner survives under C10); C12 refined (option value, never capture); +**C13 ADDED** (behavior as the unit of earned trust; judgment as the +compilation boundary). + +Falsifiers, re-ranked: **F2′** (top; S4's 90-day pre-registered +delegation-frontier protocol — currently untestable, and instrumenting it is +the note's single legitimately actionable item), **F6′** (S1's ablation + +S5's shrinkage metric), **F8** (new: behavior lineage/judge ceremonial if +version changes don't predict outcomes or judge work doesn't shrink), +**F1′** (economic form), **F7** (new: fidelity laundering), **F3′** (burden +reversed: "nearly free" is unsupported until the measurement matrix exists), +**F5′** (dated replacement: two independent runtimes emitting ASF records by +2027-06-30), **F4** demoted to C5's scope condition. + +--- + +## 4. What the theory survived + +- **C7's mechanism core**: the most hostile technical reviewer destroyed the + recipe and kept the property. Retention-at-swap beats snapshot-at-a-point, + with three independent derivations of the latter's refutation. +- **C2's narrowed loop**: the historian found ancestry for every leg + individually and then bet on the conjunction. Close to the strongest + support a priority claim can get. +- **C5's diagnosis (not its remedy)**: S2 refuted the kernel-work conclusion + and volunteered that the narrower thesis is stronger. +- **C10's technical half, on the refuter's own exhibits.** +- **The note's own protocol**: numbered claims produced genuine cross-stance + convergence (the hardlink kill arrived twice, independently), and the one + thing convergence could not catch — the SI-40 fence breach — was caught by + the one stance assigned to check grounding. + +The pattern: the survivors are the parts written closest to ratified work; +the casualties are the parts written from analogy. The theory is strongest +where it touches the code and weakest where it romanticizes — a usable +editing rule for every future horizon note. + +## 5. What it cannot survive + +One question decides whether this note is a theory or an ornament: **does +demonstrated recoverability, presented as evidence, actually cause the +design-center operator to widen standing authority — and does the widened +authority displace judge and human intervention rather than accumulate +beside it?** (F2′ and F8, jointly.) If yes, the triple joined by +ratification is a real theoretical object and the substrate/format claims +are its logistics. If no, the ocap lineage is marketing, the ratchet is +decoration on a well-built broker-plus-backup, and the OS endgame is a +distro in search of a reason. The uncomfortable finding: the current dogfood +*cannot observe the answer* — it measures denial false-positives while +standing grants do not yet exist, so "users did not widen" is mechanically +predetermined. Instrumenting F2′ before histories accrue is the single +actionable item this note generates, and by its own §5 it must enter as an +ordinary filing, never by citation to this synthesis. diff --git a/docs/substrate-theory.md b/docs/substrate-theory.md index 7207360..2ffc7c6 100644 --- a/docs/substrate-theory.md +++ b/docs/substrate-theory.md @@ -1,271 +1,360 @@ # Substrate theory — ASF's theoretical basis and the operating-system endgame -**Status: THEORY NOTE — exploratory, non-normative.** Nothing here is +**Status: THEORY NOTE — exploratory, non-normative. v2.** Nothing here is spec, roadmap, or a work item; nothing here authorizes implementation. -Anything actionable that emerges from this document enters the system -the ordinary way — an SI, W, or P filing judged on its own merits — -never by citation to this note. Provenance: the 2026-07-15 side-session -thought experiment split off from the SI-32/SI-40 ratification cycle -(operator + agent), written down so the reasoning can be attacked -rather than remembered. Claims are numbered **C1–C12** so critique can -cite them; the intended review protocol is the house battery shape — -fresh-context readers returning a row-per-claim verdict table -(agree / refute / refine, with the argument), never prose-only -impressions. A refuted claim gets corrected or struck here with the -refutation preserved, in the ADR tradition. +Anything actionable that emerges from this document enters the system the +ordinary way — an SI, W, or P filing judged on its own merits — never by +citation to this note. Provenance: drafted 2026-07-15 in the side-session +thought experiment split off from the SI-32/SI-40 ratification cycle; +**amended to v2 the same day** after a five-stance adversarial panel +(GPT 5.6 Sol, xhigh reasoning; one stance per discipline) and a +fresh-context synthesis with steelman rulings — all outputs preserved in +`docs/substrate-theory-analysis/`. Per the house ADR norm, refuted text is +struck but preserved inline with its refutation; the panel's convergent +kills were C8 (the staging recipe — refuted independently from filesystem +semantics and from A27.1 conformance) and C11 (the agent-OS category — +refuted by three stances). Claims are numbered **C1–C13** so critique can +cite them. -Grounding documents: `docs/agent-state-fabric-brief.md` (the product -thesis this note must not contradict), `docs/asf-schema-spec.md` (A27 -§5.3 — the storage adversary model; §5.4–§5.5 — authority as event- -derived views; §7 — rules and trust records), `docs/spec-issues.md` -(SI-32, SI-40), `docs/posture-assumptions.md` (P7, P29, the gate -vocabulary). +Grounding documents: `docs/agent-state-fabric-brief.md` (the product thesis +this note must not contradict), `docs/asf-schema-spec.md` (A27 §5.3 — the +storage adversary model; §5.4–§5.5 — authority as event-derived views; §7 — +rules and trust records), `docs/spec-issues.md` (SI-32, SI-40, SI-23), +`docs/posture-assumptions.md` (P7, P29, the gate vocabulary). --- ## 1. What problem this architecture is actually an instance of -**C1 — Prompt injection is the confused deputy problem, restated for -LLMs.** The founding document of capability theory is Hardy's "The -Confused Deputy" (1988): a program acting with its *caller's* ambient -authority is steered by its *input* into actions the caller never -intended. Replace Hardy's compiler with an agent reading a poisoned -webpage, and the billing file with everything the user's session token -can touch: the attack is unchanged. Forty years of object-capability -work (KeyKOS, EROS, the E language, Miller's *Robust Composition*; -credential form: Google's macaroons, 2014, the direct ancestor of the -§5 caveat grammar) built the answer — no ambient authority; rights are -explicit, attenuable, and travel with the request — and never found a -mainstream workload that would pay the compatibility cost. C1's -consequence: ASF is not a reaction to this year's agent-safety -discourse; it is the object-capability tradition applied to delegation, -arriving with the workload that finally demands it. +**C1 — Prompt injection is a confused-deputy-SHAPED exploit chain; +capability discipline bounds it but does not cure it.** *(v2: the v1 +identity claim — struck: "the attack is unchanged" — was refuted by the +panel's historian: Hardy's deputy held authority from two sources and +misapplied its own authority to a caller-designated name, a +designation/authority confusion that capability discipline fully cures. An +injected agent can select action and target wholly inside authority +legitimately granted by the user — the defect is instruction provenance, +which authority bounds contain but cannot cure; CaMeL-style defenses need +both control-flow integrity and capabilities precisely because they answer +different halves.)* The refined claim: prompt injection produces a +confused-deputy-shaped chain — a privileged intermediary steered by its +input — and the object-capability tradition (Hardy 1988; KeyKOS, EROS, E, +Miller's *Robust Composition*; credential form: macaroons, the direct +ancestor of the §5 caveat grammar) supplies the blast-radius answer the +agent workload finally demands. Standing label (panel S1-B1): ASF's +capability is a broker-evaluated attenuated credential in the macaroon +lineage, **not** an ocap reference — designation and authority arrive +separately — so no ocap composition theorem may be invoked without a +property-by-property inheritance table, which is owed and does not yet +exist. -**C2 — ASF's addition to the ocap tradition is consequence, not -authority.** Object capabilities bound what *can happen*. They say -nothing about what what-happened *costs* — ocap has no undo. ASF's -synthesis is to pair the authority bound (capabilities + caveats) with -a consequence bound (content-addressed snapshots + coherent revert + -reversibility classes), and then couple them: evidence that outcomes -were recoverable compiles — through human ratification — into wider -standing authority (§7, the ratchets). The third leg, behavior-version -pinning (trust is evidence about a *specific* behavior; mutation drops -grants to escalation), addresses something the ocap tradition never had -to face, because its subjects were programs-as-artifacts, not evolving -learners. The brief claims the pinning as novel; this note claims the -*triple* — authority bound, consequence bound, evidence-coupled — as -the theoretical identity of the fabric. +**C2 — ASF's contribution is the joined loop, not any single leg.** *(v2: +struck: "ocap has no undo" and "something the ocap tradition never had to +face" — refuted: KeyKOS/EROS shipped system-wide consistent checkpoints; +sagas paired committed steps with compensations; Ken composed recovery +across components; KeyKOS factories, EROS constructors, E's auditors, and +Nexus logical attestation are all behavior-conditioned authority.)* The +defensible claim: the novelty is the **conjunction** — recoverability +evidence, human ratification, and domain-scoped behavior-version +invalidation joined into one authority-accrual loop. Two honesty labels +bind it: (a) the coupling is today the brief's design intent ("reversal +earns authority"), **not yet the spec** — §7's ratchet consumes k ≥ 3 +approved examples and raw counters, and nothing gates widening on a +recoverability-fidelity measure (the known-open fidelity-grades problem, +sharpened: until the ratchet consumes a declared fidelity grade, cheap +compensations can launder into broad grants — F7); (b) "consequence" is not +yet one theoretical quantity — byte-exact restore, saga compensation, and +post-hoc apology sit on no common scale. ## 2. The substrate anchoring -**C3 — POSIX's finest durable principal is the uid, and this single -fact generates most of the fabric's hard security problems.** Read -A27's tier model through this lens. T2 ("no sequence of pathname checks -can win; the honest answer is OS-enforced exclusion") exists because -once two processes share a uid, the kernel offers no boundary between -them: every pathname race, hardlink pre-plant, descriptor survival, and -"the approval socket is reachable by granted hands" (P7, P5) is -downstream of the kernel being unable to say *this process acts under -manifest X, that one under manifest Y*. The same fact shapes the -dogfooding hygiene rules (two surfaces by convention), the T1 trust-root -residual (keys readable by anything wearing the uid), and W-4's whole -reason to exist. +**C3 — The substrate gap is a missing manifest-instance identity, not a +missing fine-grained subject.** *(v2: struck: "this single fact [the uid] +generates most of the fabric's hard security problems" — refuted as a +causal claim: Linux offers finer-than-uid subjects (LSM labels, Landlock +domains, keyrings); the listed problems arise because the current posture +configures no boundary at all (P7), and the trust-root and actuation +problems are not uid-shaped.)* The refined claim, with the portability +caveat: what no substrate offers — and on the portable floor including +Darwin, where the Linux LSM arsenal does not exist, the uid really is the +only durable principal — is **one stable, authenticated, +application-addressable manifest-instance identity consumed uniformly by +mediation, broker peer-authentication, and audit**. That absence is why W-4 +must *emulate* the boundary rather than merely configure it. -**C4 — The container ecosystem is subtractive security; the caveat -grammar is additive; the adapter between them is where the failure -modes live.** Namespaces, chroot, seccomp, cgroups, Landlock: each -starts from a process born with full ambient authority and carves -pieces away. Subtractive security fails open by construction — the -recurring container CVE is "we forgot to carve away X." Capability -discipline is the additive inverse — born with nothing, handed specific -rights — and fails closed by construction. ASF's authority model is -additive (unknown dimensions fail closed; attenuation is subset-only), -but it runs on a subtractive substrate, so every enforcement claim -bottoms out in an emulation layer (deny rules today, W-4 containment -at graduation) whose job is to fake an additive boundary out of -subtractive parts. A27.4's standing sentence — "holds under COOP; -requires W-4 containment at G-ADVERSARIAL" — is the honest label on -that adapter. +**C4 — The dangerous seam is an object-model mismatch, and the compiler is +where fail-open lives.** *(v2: struck: the additive/subtractive binary as +an essence claim ("subtractive fails open by construction; additive fails +closed by construction") — refuted: Smack/SELinux are explicit-allow, +seccomp can default-kill, and capability systems fail open via over-broad +grants. Preserved counter-note: the deployed container stack's +forgot-to-carve CVE pattern is real, and Landlock's handled-access design +defaults open for unhandled categories — the fail-open-on-unknown-dimension +shape ASF forbids.)* The refined claim: caveats speak recipients, budgets, +reversibility, and behavior versions; kernel controls speak tasks, inodes, +sockets, and syscalls. The compiler between those vocabularies is where +fail-open-by-omission lives, and A27.4's standing sentence is the honest +label on that adapter. -**C5 — Manifest-as-principal is the kernel-shaped hole.** The one -genuinely missing operating-system concept, reduced from the "AI-native -OS" intuition: processes born bound to a delegation manifest, with -authority attenuating at spawn, the uid demoted to an accounting -detail, and the reference monitor evaluating caveats instead of mode -bits. Under manifest-as-principal, A27's T2 tier dissolves *by -construction* (there is no "same principal" between agent and broker to -race within), C2's approval surface is enforced the way memory -protection is, and "the agent never holds the real key" stops being an -architectural achievement and becomes how the machine works. Nearly -everything else the intuition wants already ships as parts: CoW state -(btrfs/ZFS/overlayfs; composefs + fs-verity is a content-addressed, -integrity-verified store as a mount type), additive scoping primitives -(Landlock, 5.13+), measured behavior (IMA/EVM, dm-verity), ambient -tracing (eBPF, auditd), and even C2's ancestor — the secure attention -key, the unfakeable-dialog invariant shipped since Windows NT (1993). -The distro is ~80% assembly; the principal is the ~20% that is real -kernel work. +**C5 — Manifest-as-principal is the missing unifying binding — a diagnosis, +not a remedy.** *(v2: struck: "A27's T2 tier dissolves by construction" — +refuted: two manifest principals authorized to write one namespace still +race; the race closes by exclusion topology, which is A27's existing, +ratified answer — principals make topology kernel-expressible, never +unnecessary. Also struck: "C2's approval surface is enforced the way memory +protection is" — refuted via open SI-23: a self-satisfiable approval +arrives through a legitimate actuation grant, and principal separation +cannot distinguish granted synthetic input from a human; this note may not +silently resolve an open SI. The v1 "20% real kernel work" figure is +withdrawn: no security property has been named that only a new kernel +principal provides — a trusted launcher over existing mechanisms suffices +for local enforcement.)* The surviving claim: a signed delegation record +bound to a locally unforgeable workload identity, consumed uniformly by +mediation, broker authentication, and audit, is the abstraction W-4 +emulates and a future substrate could make native. Two scope conditions +bind it: (a) the unit of isolation must be named — manifest-per-microVM +leaves a kernel principal jobless, while multi-manifest guests forfeit the +VM boundary between delegates; (b) cross-host identity stays **above** the +kernel at policy admission — attestation proves provenance, never freshness +or uniqueness, and cloned homes can each spend a one-use authority absent +A23's external head plus a writer lease (this absorbs v1's F4, demoted from +falsifier to scope condition). ## 3. Publication theory (what the SI-40 exploration generalized) -**C6 — For publication into a substrate with unmediated concurrent -writers, the solution space is exactly three families.** (1) -*Exclusion*: lock writers out during publish — foreclosed for -shared-state stores because unmediated human access is the product -thesis (brief §2; D32-4). (2) *Detection at the write boundary*: -per-entry compare-and-capture — race-narrowing forever, protocol-heavy; -it fights the substrate. (3) *Indirection*: never overwrite in place; -publish as one atomic namespace transition; retain the superseded -state. Every mature storage system chose family 3 (MVCC, git's -immutable objects + atomic ref update, LSM trees, CoW filesystems, -symlink-flip deploys). +**C6 — At the write boundary, outcomes partition three ways; real systems +compose them.** *(v2: struck: "the solution space is exactly three +families" and the implication that mature systems chose family 3 +exclusively — refuted: git composes expected-old validation, locking, and +atomic rename; MVCC composes retention with locks or validation; WALs are +orthogonal crash recovery.)* The refined claim: a concurrent write is +either **excluded**, **detected and handled**, or **redirected** so it +lands somewhere well-defined — design axes, not exclusive choices. The +load-bearing content is D32-4: exclusion is foreclosed for shared-state +stores, so the remaining design space is detection, redirection, or their +composition. -**C7 — The load-bearing mechanism in family 3 is retention, not -snapshotting — and the snapshot-at-a-point variant is refuted.** A -snapshot taken at any fixed point (gate-lock acquisition, apply start) -cannot preserve an edit that postdates it, and the SI-40 edit postdates -the prepare check by definition; the snapshot captures exactly the -state that was never in danger. (This variant was independently refuted -by this exploration's first pass and by external review of the SI-40 -filing — the convergence is recorded because the wrong variant is the -intuitive one.) What works: the atomic swap makes every concurrent -edit's fate *well-defined* — before the swap it lands in the retained -outgoing state (kept, diffed, CAS-ingested, attributed); after, it is -ordinary drift on the new live state. Nothing falls between, because -there is no between. "Attributed, never lost" achieved by construction -rather than by detection. The residual is the descriptor tax: an open -fd can still write into retained/unlinked state post-swap — a loss mode -the in-place design already carries today, socially mitigated by -editors' own file-changed detection, removable only by families 1 or -full mediation. +**C7 — Retention, not snapshotting, is the load-bearing mechanism — as a +profile, not a construction.** The core survives the panel intact: a +snapshot taken at any fixed point cannot preserve an edit that postdates it, +and the SI-40 edit postdates the prepare check by definition (this +refutation now has three independent derivations: this note's first pass, +the SI-40 external review, and the panel's storage stance). What works is +retention of the outgoing generation at swap time, followed by diff, CAS +ingestion, and attribution. *(v2: struck: "Nothing falls between, because +there is no between" and "'attributed, never lost' achieved by +construction" — refuted by the note's own residual plus two more boundary +crossings: an open descriptor writes into retained state post-swap; shared +inodes make an edit unattributable to a side of the swap; NFS clients under +default caching resolve the old target for tens of seconds.)* The refined +guarantee: **under an aliasing-free staging (independent inodes) on a +locally coherent filesystem**, the atomic swap makes every +pathname-addressed concurrent edit's fate well-defined — before the swap it +lands in the retained generation (kept, diffed, ingested, attributed); +after, it is ordinary drift on live state. The guarantee is a profile; +descriptors, shared inodes, and stale remote caches each cross it and each +must carry its own labeled residual. Publication guarantees generally are +**properties with per-substrate profiles, never primitives**; any concrete +staging recipe or registration protocol is SI-40/W-lane work, and none +appears in this note. -**C8 — Publication guarantees should be stated as properties with -per-substrate profiles, never as primitives.** The property: *one -atomic namespace transition; superseded state retained until diffed, -captured, and attributed*. The bindings form a ladder discovered at -store registration and recorded ledger-visibly (the durable-commit -profile pattern): exchange-rename (Linux `renameat2(RENAME_EXCHANGE)`, -2014 — ext4/btrfs/xfs/tmpfs; Darwin `renamex_np(RENAME_SWAP)` is the -later port), symlink-flip (pure POSIX, NFS-safe), journaled two-rename -(universal floor; non-atomic but fail-visible and recoverable through -the existing recovery grammar). Staging recipe: unchanged entries -hardlink from live (inode/mtime preservation; edits ride through); -changed entries reflink from CAS (`FICLONE`/`clonefile` — independent -inodes, so no writable path into the CAS; plain copy as floor). -Retention under this recipe is nearly free (unique bytes ≈ old versions -of changed entries, already CAS-resident from prepare) and -reconciliation is O(changed), not O(tree). +**Non-selection notice (v2, added after the panel's fence audit):** this +note does not select SI-40's remedy. SI-40's leading candidate is per-entry +capture-or-refuse; retention-at-swap is the filed deployment-floor +alternative, evaluated against it when a trigger fires. This section is the +theory of why the retention family is coherent — not a verdict between the +arms, which belongs to the SI's own ratification. -**C9 — Substrates grade up, and the local POSIX directory is the -floor, not the model.** The same store contract degrades or dissolves -by substrate: raw POSIX dir (families 2/3 emulated in userspace) → CoW -filesystem (family 3 native; hosted infrastructure can simply provision -it — zero-friction constrains the *user's* machine, not the product's -cloud) → branch-native platform (Tier-2 stores publish through the -platform's own atomic branch operation; the SI-40 window mostly does -not exist there) → fabric-served view (every write mediated and -attributed; T3 dissolves). The last rung is deliberately not taken for -user machines: it is the closed-world assumption wearing a mount point, -and brief §2 bets the market on its negation. Corollary, double-edged: -hosted CoW infrastructure also makes *whole-home rollback* a -one-command accident — the exact coherent-suffix-regression case A27 -assigns to the external anchor — so the same substrate that solves -publication sharpens the case that layer-2 anchoring is a hard -G-PRODUCTION requirement. +**C8 — STRUCK (v2).** The v1 staging recipe — unchanged entries hardlinked +from live, changed entries reflinked from CAS, exchange-rename / +symlink-flip / journaled two-rename ladder, O(changed) reconciliation, +"NFS-safe," "nearly free" — is struck in its entirety. *(Refutations +preserved: (1) hardlinking unchanged entries from the mutable live tree +shares writable inodes across generations — an in-place edit mutates both +trees, cannot be attributed to a side of the swap, and makes correctness a +function of editor save style; worse, it is verbatim the mutation A27.1 +forbids — commit installing bytes sourced from mutable storage after +prepare-time verification — so the recipe contradicted a normative clause +ratified the same week, found independently by the storage stance and the +editor stance. (2) O(changed) reconciliation presumes a complete mutation +oracle; on the portable floor, proving a retained POSIX tree unchanged at +unknown paths costs an O(tree) walk or a change journal — family-2 +detection under another name — and the hardlink farm itself costs O(N) to +build. (3) Root exchange is hostile to observers: inotify watches objects, +not future occupants of a pathname; FSEvents requires a full-tree rescan on +a moved root; a conforming watcher or sync daemon pays O(N) per +publication. (4) "NFS-safe" conflated server atomicity with client +coherence — default attribute caching lets clients resolve the old target +for up to ~60s. (5) The journaled two-rename "universal floor" is not a +profile of the stated atomic property but a weaker property that must be +labeled as such.)* The one surviving sentence is relocated into C7 above. +Consequence worth stating plainly: on raw local POSIX with watchers and +sync daemons present, the panel's crossover analysis shows per-entry +detection — SI-40's filed leading candidate — can beat retention-at-swap at +surprisingly small change ratios; the side thread's preference for the swap +arm was over-fitted to CoW-native substrates. -## 4. The endgame ladder and why the timing is not romantic +**C9 — Substrates grade on four independent axes, not one ladder.** *(v2: +the monotonic ladder is refined away: retention cost, namespace atomicity, +observer coherence, and mediation/attribution are independent — a CoW +filesystem buys retention, not watcher retargeting or multi-store +atomicity.)* The refined claim: publication capability is a **profile +matrix** discovered per store; hosted infrastructure can provision rungs on +some axes (real CoW datasets — zero-friction constrains the user's laptop, +not the product's cloud) while leaving others at the portable floor. Kept +unamended, untouched by any reviewer: the double edge — hosted CoW +infrastructure also makes whole-home rollback a one-command accident, the +exact coherent-suffix-regression case D32-2 assigns to A23 layer 2, so the +same substrate that eases publication sharpens the case that the external +anchor is a hard G-PRODUCTION requirement. -**C10 — Agent fleets are the first workload class in decades with no -POSIX loyalty at the trust boundary.** Capability operating systems -(KeyKOS → EROS → Capsicum → seL4 → Fuchsia) lost to compatibility -economics, not to refutation: nobody rewrites the world's software for -a better security model. Agents change the economics selectively: the -*trust boundary* around an agent has no legacy-software constituency, -even though the agent's *toolbox inside* the boundary remains -POSIX-hungry (today's agents live in bash). So the claim is refined, -not naive: POSIX survives indefinitely as the toolbox inside the -sandbox; it is replaceable as the boundary *around* it. That is exactly -the shape of a microVM whose only door is the broker. +## 4. The endgame, demoted to its defensible core -**C11 — The buildable near-term form is a single-purpose agent-runtime -OS, and it is W-4's limit case.** Not a desktop distro for humans; the -Talos/Bottlerocket pattern ("the Kubernetes OS," "the container OS") -applied to delegation: the image an agent's microVM boots — fabric -daemon adjacent to PID 1, every workload manifest-scoped, branches as -subvolumes, Landlock/cgroup profiles compiled from caveats, eBPF trace -feeding the signed substrate, approval surfaces on the host side of the -VM boundary. No new kernel; one patch series (the principal) at most, -assembly otherwise. This is not a departure from the roadmap; it is -W-4 containment matured until the sandbox profile *is* the boot image. -Design discipline that follows today: W-4's emulation interface should -be designed as if it were the future kernel interface, because on this -path it becomes one. +**C10 — The trust boundary is technically replaceable; its constituency +moved rather than vanished.** *(v2: struck: "no POSIX loyalty at the trust +boundary" as an absence-of-constituency claim — refuted: harness +conventions (bash-first tooling, ambient credentials, network assumptions) +define what any boundary must transparently reproduce, and the vendor +sandbox work confirms it; also struck: the KeyKOS→EROS→Capsicum→seL4→ +Fuchsia arrow-chain and "lost to compatibility economics" as settled +history — a typological list, not a genealogy; compatibility cost is one +tested factor.)* The refined claim: agent trust boundaries are already +being rebuilt without POSIX semantics — the boundary is *technically* +replaceable, confirmed by the refuting stance's own exhibits — but the +constituency now lives in harness conventions and in the +boundary-builders themselves, whose incentives oppose portable trust. For +this workload, the compatibility cost that defeated general-purpose +capability systems is an adapter-engineering cost, not a rewrite-the-world +cost; whether the neutral adapter or the vertically integrated one wins is +F1′'s economic question, not a semantic one. The near-term composition is a +manifest-attested ASF microVM appliance built from existing parts; whether +W-4's emulation interface should anticipate a future kernel interface is a +question to file through the ordinary channel, not a discipline this note +may impose. -**C12 — The strategic precedent is Docker/OCI: name the unit, ship the -format; formats outlive assemblers.** Docker invented almost no kernel -mechanism (namespaces 2002–2013, cgroups 2007); it named the container, -shipped an image format, and the format — donated to neutral -governance — outlived Docker's market position. The brief's §9 strategy -(open formats, donate the spec, monetize the runtime) already chose -this side. The endgame corollary: design the manifest, caveat, and -trace schemas so that a kernel *could* enforce them — substrate-free -semantics, posture-bound implementations — and the fabric's formats -become the candidate wire format of whatever agent-OS eventually -exists, whoever builds it. The house discipline already trends this -way (properties with profiles; T2 answered by topology, not syscalls); -this claim just names why it matters beyond tidiness. +**C11 — STRUCK (v2).** The v1 "agent-runtime OS" claim is struck. *(Refuted +by three independent stances: every named component is Firecracker/Kata +plus an ASF control plane, with no invariant a conventional microVM runtime +and policy engine cannot supply; no buyer exists for the category as such — +the purchasable object is a control plane or appliance; and the claim +materially expanded roadmap W-4's specified scope while its "design +discipline that follows today" sentence was a present-tense work item +inside a note whose §5 forbids them.)* What survives is the appliance +one-liner now housed under C10. + +**C12 — Formats are option value — a neutrality-and-distribution strategy, +never a value-capture strategy.** *(v2: struck: the implication that +kernel-enforceable schema design positions the formats to become the +standard, and the imperative "design the schemas so that a kernel could +enforce them" — refuted/fenced: OCI proves formats can outlive their +assemblers, not that authors capture value; Docker donated an +already-dominant format — distribution, not design quality, made it +canonical — and later exited the business; the imperative was a schema +design criterion this note has no authority to issue.)* The refined claim: +substrate-free semantics with posture-bound implementations remain the +house discipline for the fabric's own reasons; the option this creates — +that the formats could survive into whoever's runtime wins — is real but +modest, and value capture requires its own claim and falsifier, which this +note deliberately does not supply. Honesty label carried from the panel: +the trust ledger is a weak *network* asset as currently conceived (private, +user-scoped, deliberately exportable — another customer's history does not +improve mine); that observation indicts nothing here but presses on the +brief's §9 moat story. + +**C13 — Behavior is the unit of earned trust, and judgment is the +compilation boundary.** *(v2: added — the panel's completeness stance found +the note enumerated a "triple" in which behavior did not appear, while +claiming to state ASF's theoretical basis.)* Mechanical capabilities decide +only stable, auditable predicates; a capability-less judge handles residual +ambiguity; human ratification is the sole transition from judgment to +standing authority; and evidence remains valid only for the behavior +version that produced it. The loop succeeds only if repeated judgment +demonstrably shrinks into mechanical rules without losing behavior +provenance — if it does not, the behavior lineage and judge are ceremonial, +and this note is a storage-and-capability theory mislabeled as a theory of +trust (F8). ## 5. What this theory does NOT license -Stated to keep the note honest and the critique aimed: +Stated to keep the note honest and the critique aimed — and rewritten in v2 +after the panel showed the v1 fence was breached by its own body text +(imperative "design disciplines," a staging recipe, and a silent +pre-selection of SI-40's arm — all removed above): - It does not reprioritize anything. The current queue (dogfooding, the - ratchet, W-15a) is where the product lives; this note is a horizon, - not a backlog. A theory note that quietly becomes a roadmap is the - spiral this project just corrected. -- It does not weaken the open-world bet. C5/C11 describe substrates the - product may *provision*; they never justify requiring one from a - user's laptop. -- It does not claim the fabric needs an OS to be valuable. The wedge - thesis (userspace proxy, drop-in, vendor-free) is unchanged; the - ladder is one-directional option value. + ratchet, W-15a) is where the product lives; this note is a horizon, not a + backlog. +- It does not weaken the open-world bet. C9's hosted-substrate observations + describe what the product may *provision*; they never justify requiring + anything from a user's laptop. +- It does not claim the fabric needs an OS to be valuable, and after the + panel it no longer claims an OS category at all. +- It selects no SI-40 arm, imposes no schema criterion, and issues no + design discipline. The single actionable item the review cycle surfaced — + instrumenting F2′ before histories accrue — enters through an ordinary + W-1/W-3 filing or not at all. -## 6. Falsifiers and open weaknesses (attack here first) +## 6. Falsifiers, re-ranked by the panel (attack here first) -- **F1 (vs C10):** if agent *authority* patterns turn out to require - deep POSIX semantics at the boundary (not just inside it) — e.g., - tool ecosystems that structurally resist brokered mediation — the - boundary-replaceability claim fails and the adapter (C4) is permanent. -- **F2 (vs C2):** if consequence-bounding does not actually compile - into delegation confidence — i.e., dogfooding shows users do not - widen authority even with clean recoverable histories — the coupling - thesis is decoration and the product is "just backup." -- **F3 (vs C6/C8):** if reconciliation costs blow up on real stores - (huge vaults, high churn, sync-daemon interference), family 3's - "nearly free" claim degrades and family 2 re-enters. -- **F4 (vs C5):** manifest-as-principal may reintroduce the identity - problem one level down: cross-host principals need a trust root, and - the anchor problem (spec §6.2 layer 2) recurs inside the kernel - boundary rather than being solved by it. -- **F5 (vs C12):** the formats-win analogy fails if a hyperscaler ships - a vertically integrated agent-OS with proprietary formats *before* - neutral formats accumulate network effects — the brief's timing risk, - restated at the substrate layer. -- **F6 (vs C1/C2):** the ocap framing may flatter the design: caveat - grammars are coarser than ocap's object granularity, and the judge/ - escalation layer is an admission that mechanical authority alone - cannot express intent. If the interesting delegation decisions all - land in the judgment layer, the capability lineage is marketing, not - mechanism. +- **F2′ (vs C2 — rank 1).** Currently *untestable*: the dogfood measures + denial false-positives while standing grants cannot yet widen, so "users + did not widen" is mechanically predetermined. Operational form (panel + S4): pre-register recurring workflow families and a delegation-frontier + vector (scope, duration, unattended runtime, auto-promotion, approvals + per success); record the operator's maximum grant before histories + accrue; accumulate ≥3 clean runs plus one forced restore per family; + offer least-general standing grants; collect ≥24 accept/narrow/reject + decisions at fixed behavior version. Disconfirmation: the frontier widens + on no dimension and rejections cite risks recovery does not address. + Falsifies for the design-center operator; market claims need a staged + rollout. +- **F6′ (vs C1/C2/C13 — rank 2).** Two pre-registered arms: an *ablation* + (assume the worker obeys every injection; disable judge and human; + measure deterministic prevention across attacker-designated targets + outside conveyed authority, targets inside a coarse grant but against + intent, and prohibited flows — threshold chosen before results) and a + *shrinkage* metric (over a fixed workflow cohort, the fraction of + consequential decisions still requiring judge/human after ratification + opportunities must fall). +- **F8 (vs C13 — rank 3, new).** If behavior-version changes do not predict + materially different outcomes, or repeated judge work does not shrink + through ratification, the behavior lineage and judge are ceremonial. +- **F1′ (vs C10 — rank 4).** Economic form: if representative + coding/research/SaaS workflows cannot run through the broker without + ambient credentials, unclassified shell effects, or routine bypass — + while integrated vendor sandboxes deliver acceptable autonomy without + manifest semantics — the ASF boundary has lost economically even though + technically implementable. +- **F7 (vs C2 — rank 5, new).** If the ratchet widens standing grants on + compensation evidence a declared fidelity grade would have excluded, the + coupling is laundering, not learning — regardless of whether users widen. +- **F3′ (vs C7/C9 — rank 6, burden reversed).** "Cheap retention" is + *unsupported* until measured: full scans triggered, metadata ops, bytes + rehashed, conflict copies, retained unique bytes, stale-client duration — + across inotify, FSEvents, NFS profiles, Syncthing, Dropbox. The panel's + crossover model says watcher rescans dominate at small change ratios. +- **F5′ (vs C12 — rank 7, re-dated).** The verticals already shipped and + embrace MCP/A2A while keeping identity, policy, and history proprietary. + Replacement trigger: if by 2027-06-30 fewer than two independent runtimes + natively emit ASF records, fewer than two independent gates authorize + from them, or no external relying party accepts portable trust across + vendor boundaries, the format bet has failed; export adapters and nominal + schema support do not count. +- **F4 — demoted (v2).** Not a falsifier; recast as C5's scope condition + (b): admission-time freshness, uniqueness, and canonical-fork selection — + including the cloned-home double-spend — live above the kernel, at A23's + anchor plus a writer lease. ## 7. Reading lineage -Hardy, "The Confused Deputy" (1988) · Miller, *Robust Composition* -(2006) and the E language · KeyKOS / EROS · Watson et al., Capsicum -(USENIX Security 2010) · seL4 (verified capability microkernel) · -Fuchsia/Zircon (handles, no ambient authority) · Birgisson et al., -"Macaroons" (NDSS 2014) · Landlock (Linux 5.13) · IMA/EVM, dm-verity, -fs-verity, composefs · NixOS / ostree (immutable, generation-based -system state) · Talos, Bottlerocket (single-purpose OS pattern) · -`renameat2(2)` / `renamex_np(2)` · Firecracker (microVM isolation) · -OCI (the format-outlives-assembler precedent). +Hardy, "The Confused Deputy" (1988) · Miller, *Robust Composition* (2006) +and the E language · KeyKOS / EROS (checkpointing capability systems) · +Watson et al., Capsicum (USENIX Security 2010) · seL4 · Fuchsia/Zircon · +Birgisson et al., "Macaroons" (NDSS 2014) · Garcia-Molina & Salem, "Sagas" +(1987) · Yoo et al., Ken/composable reliability (USENIX ATC 2012) · Sirer +et al., logical attestation (Nexus) · Debenedetti et al., CaMeL — +"Defeating Prompt Injections by Design" (2025) · Landlock (Linux 5.13) · +IMA/EVM, dm-verity, fs-verity, composefs · NixOS / ostree · Talos, +Bottlerocket · `renameat2(2)` / `renamex_np(2)` · Firecracker · OCI (the +format-outlives-assembler precedent, read in v2 as a warning as much as a +precedent). diff --git a/scripts/check-doc-hygiene b/scripts/check-doc-hygiene index bdc4cd4..8dae6e2 100755 --- a/scripts/check-doc-hygiene +++ b/scripts/check-doc-hygiene @@ -52,9 +52,14 @@ run_checks() { # boundary rule it orders *future* work and names planned or # unmerged-branch artifacts (e.g. a doc recovered on an unmerged # branch). Every other doc describes current state and is enforced. + # docs/substrate-theory-analysis/ is exempt for the same class of + # reason: it holds verbatim external-review artifacts (evidence, + # never edited), whose quoted URLs can contain foreign-repo paths + # like blob/main/docs/design.md that false-positive as local refs. # ADR-number refs are enforced everywhere, roadmap included. case "$rel" in docs/roadmap.md) ;; + docs/substrate-theory-analysis/*) ;; *) grep -noE 'docs/[A-Za-z0-9._/-]+\.md' "$f" 2>/dev/null \ | while IFS=: read -r ln ref; do