Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions docs/substrate-theory-analysis/Stance 1 - GPT 5.6 Sol Xhigh.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
## PART A

| claim | verdict (AGREE / REFINE / REFUTE) | strongest counterargument you considered (mandatory even for AGREE) | your argument, with citations |
|---|---|---|---|
| C1 | **REFUTE** | Indirect prompt injection does place a privileged intermediary under adversarial influence. Capability and information-flow controls can break the resulting exploit chain even when the model remains compromised; CaMeL and the EchoLeak incident make that analogy operational. | The analogy is useful; the claimed identity is false. Hardy’s compiler held authority from **two sources**—its invoker and its own home-files licence—and applied its own authority to a filename designated by the invoker. The note inaccurately reduces this to “a program acting with its caller’s ambient authority.” Hardy’s remedy combined designation with the authority conveyed for that designation. By contrast, an injected agent can obey an adversarial instruction while selecting an action and target wholly inside authority legitimately granted by the user: the defect is instruction-provenance/control integrity, not necessarily authority-designation confusion. Ocap then bounds damage but does not cure the compromised decision. CaMeL confirms the distinction by employing two mechanisms: trusted-query control-flow extraction so untrusted data cannot steer the program, and capabilities to prevent unauthorized data flows. [Hardy, “The Confused Deputy”](https://people.cs.vt.edu/~kafura/cs6204/Readings/ConfusedDeputy.pdf); [Miller, *Robust Composition*, designation and authority](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf); [Debenedetti et al., “Defeating Prompt Injections by Design”](https://arxiv.org/abs/2503.18813); [EchoLeak case study](https://ojs.aaai.org/index.php/AAAI-SS/article/view/36899). Replace C1 with: **“Prompt injection can create a confused-deputy-shaped exploit chain; capability discipline bounds its effects, while trusted control/data separation addresses the injection itself.”** |
| C2 | **REFINE** | The exact ASF loop may be novel. KeyKOS/EROS checkpoints provide crash recovery, not user-directed semantic undo; sagas provide compensation, not authority; caretakers and membranes revoke access but do not make grants contingent on recovery evidence or a behavior hash. | “Ocap has no undo” and “the tradition never had to face behavior-specific trust” are historically indefensible. KeyKOS and EROS deliberately combined pure capabilities with system-wide consistent checkpoints, copy-on-write state, restart, and transaction support—although EROS correctly warned that a committed bad checkpoint could not itself be undone. Sagas paired committed steps with compensating transactions; Ken composed state checkpoints and message recovery across independently developed components. The behavior claim also ignores KeyKOS factories, EROS constructors certifying properties of created processes, E’s AST-inspecting auditors and behavior-dependent reliance analysis, and authorization based on attested program properties in Nexus. None is identical to ASF’s pin, but they destroy the claimed absence of ancestry. [KeyKOS nanokernel](https://pdos.csail.mit.edu/6.828/2010/readings/keykos.pdf); [Shapiro et al., “EROS: a Fast Capability System”](https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/Eros.pdf); [Garcia-Molina and Salem, “Sagas”](https://doi.org/10.1145/38713.38742); [Yoo et al., “Composable Reliability for Asynchronous Systems”](https://www.usenix.org/conference/atc12/technical-sessions/presentation/yoo); [Miller, auditors and behavioral authority analysis](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf); [Sirer et al., “Logical Attestation”](https://research.google/pubs/logical-attestation-an-authorization-architecture-for-trustworthy-computing/). The defensible novelty claim is narrower: **recoverability evidence, human ratification, and domain-scoped behavior-version invalidation are joined in one authority-accrual loop.** |
| F6 | **REFINE** | Ocap never promised to infer natural-language intent. A system can remain meaningfully capability-based even if semantic decisions require a judge: Capsicum, for example, mechanically restricts reachable namespaces and operations while leaving application correctness elsewhere. The presence of residual judgment therefore does not by itself reduce capability enforcement to marketing. | F6 identifies the right threat but is not presently falsifiable: “interesting,” “coarser,” and “marketing” have no measurement rule or rejection threshold. Pre-register an ablation: assume the worker always follows the injection; label prohibited effects before execution; disable judge and human intervention; then report deterministic prevention, severity-weighted loss prevented, false denials, and task completion. Partition cases into (1) attacker-designated targets outside caller-conveyed authority, (2) targets inside a coarse grant but contrary to intent, and (3) prohibited information flows. In a strict Hardy case, a proper capability interface should reject the unauthorized designation at resolution; if ASF merely accepts a separately supplied target and tests it against `known_contacts`, globs, or budgets, only category 1’s out-of-set subset is stopped. Macaroons themselves are explicitly bearer authorization credentials, while Miller distinguishes cryptographic capability protocols from the object-capability model and says cryptography alone enforces weaker properties. [Capsicum](https://www.usenix.org/event/sec10/tech/full_papers/Watson.pdf); [Macaroons](https://research.google/pubs/macaroons-cookies-with-contextual-caveats-for-decentralized-authorization-in-the-cloud/); [Miller, “Only Connectivity Begets Connectivity” and limits of cryptographic enforcement](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf). F6 should fail C1’s ocap-centrality thesis if, after ratchet convergence, deterministic controls do not clear a predeclared coverage threshold without unacceptable false denial; the threshold must be chosen before observing results. |

## PART B

1. **high — The note launders three different meanings of “capability.”** An object capability is an unforgeable reference that simultaneously designates an object and conveys authority to invoke it; its graph supports “only connectivity begets connectivity” and local reasoning about composition. A macaroon is explicitly a bearer authorization credential. ASF’s [Capability schema](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:152) authorizes a holder through a central broker while the request separately supplies tool, action, path, recipient, and target. That provides valuable unforgeability, attenuation, expiry, credential custody, and revocation, but it does not by itself recover ocap’s designation-authority identity or reference-topology arguments. Miller expressly limits his object-capability model to operating systems and programming languages, excluding cryptographic capability protocols from the same theorem set. The note needs a property-by-property inheritance table; until then, “capability-inspired broker with attenuated credentials” is the accurate name. [Miller](https://jscholarship.library.jhu.edu/bitstream/handle/1774.2/873/markm-thesis.pdf); [Macaroons](https://research.google/pubs/macaroons-cookies-with-contextual-caveats-for-decentralized-authorization-in-the-cloud/).

2. **high — “Consequence bound” is not yet one theoretical quantity.** Exact rollback of owned bytes, crash-consistent restart, approximate SaaS reconstruction, a saga compensation, deletion of a still-unread message, and an apology after a human-visible message are not points on an established common scale. Sagas promise compensating actions that *amend* partial execution, not restoration of the prior world; EROS checkpoints preserve a consistent state, not a correct one. ASF itself admits that mirror compensation is partial and that fidelity grades remain unschematized in the [brief](/Users/josh/dev/Coppice/docs/agent-state-fabric-brief.md:191) and [spec](/Users/josh/dev/Coppice/docs/asf-schema-spec.md:149). Until the ratchet consumes a declared fidelity measure and excludes irreversible/socially observed outcomes, “recoverability evidence compiles into authority” can launder cheap compensations into broad grants. [Sagas](https://doi.org/10.1145/38713.38742); [EROS](https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/Eros.pdf).

3. **medium — C10 presents a typological list as a genealogy and then derives a monocausal history from it.** KeyKOS → EROS is a documented implementation lineage. Capsicum is an incremental UNIX retrofit; seL4 descends from the independent L3/L4 microkernel lineage. Their shared use of capabilities does not establish “KeyKOS → EROS → Capsicum → seL4 → Fuchsia,” nor does it show that all “lost to compatibility economics.” KeyKOS ran production workloads, L4-family kernels achieved large commercial deployments, and Capsicum was explicitly designed to preserve UNIX compatibility. Recast the sequence as several independent capability adaptations and treat compatibility cost as one tested factor, not the tradition’s settled cause of defeat. [EROS history](https://www.princeton.edu/~rblee/ELE572Papers/Fall04Readings/Eros.pdf); [Capsicum](https://www.usenix.org/event/sec10/tech/full_papers/Watson.pdf); [Elphinstone and Heiser, “From L3 to seL4”](https://trustworthy.systems/publications/nictaabstracts/Elphinstone_Heiser_13.abstract).

I would delete C1 outright: its identity claim is false even though a weaker analogy is useful.
I would bet on C2, narrowed to ASF’s evidence-coupled ratification loop rather than consequence bounding or behavior-aware authority in general.
Loading