16 KiB
Review Checklist Standing Archive
This file is the durable archive for STANDING DISCLOSURES and STANDING NOTES
attached to items in docs/CHECKLISTS.md (today: Repo Commit Checklist
item 21, capability_regression). They were moved here so the live checklist
stays small enough to load in every review pack without losing the record.
These entries remain BINDING on every reviewer — triad, scope, and advisory. Each records an owner-accepted removal, narrowing, or replacement path. Do not re-raise anything recorded here as a new undisclosed removal/narrowing finding; when a diff touches a surface an entry covers, judge it against the entry's stated bounds instead. The archive is append-only: corrections land as new superseding entries, not edits to old ones.
Item 21 (capability_regression) — standing disclosures
Standing disclosure (v6.80.0), do not re-raise as an undisclosed removal: the audited owner-opt-in DEGRADED ADVISORY scope review was REMOVED as a capability, together with OUROBOROS_SCOPE_REVIEW_DEGRADED. By owner decision the frozen gateway surface of OUROBOROS_SCOPE_REVIEW_FLOOR is NOT removed: the endpoint, contract field, route, merge-skip, web client and all three self-lowering guards stay, the stored value is preserved, and every write is answered with an explicit deprecation notice — the key is simply ENFORCEMENT-INERT (nothing consults it, no getter exists). Whether the P3 blocking scope review applies is decided solely by the owner-only OUROBOROS_CONTEXT_MODE, read as the owner-selected value through config.get_owner_context_mode; persistent system auto-Low and settings-time model downgrades are retired, so only the owner endpoint authors stored Low. The REPLACEMENT PATH for an install with no ≥1M-context reviewer (fully local, GigaChat-only, single small provider) is the low context mode: whole-repository scope review is then declaredly NOT performed, every skipped commit records a typed scope_review status="skipped_low_context_mode" evidence row, and the diff-reviewer triad still blocks in every mode. Since the BIBLE P3 retrieving-scope amendment, low is no longer the only ADMITTED replacement path: the owner may instead declare a RETRIEVING scope reviewer (reads the surface itself through read-only tools; owner-selected per scope slot; context window established by sourced Capability Evidence at ≥200K tokens; every such review records a typed durable row naming the mode; opened artifacts recorded as forensic, non-certifying evidence) as a second, owner-declared AGENTIC DELIVERY of the same authoritative review — not a degraded fallback, in BIBLE P3's own words, once its four bounds hold. That mode is IMPLEMENTED — with its fourth BIBLE bound DISCLOSED AS UNIMPLEMENTED rather than claimed: the artifacts a session opened are not recorded, because the host cannot see them and no upstream Claudexor read-event capability exists yet, so the coverage manifest states that coverage is the session's own retrieval and is not host-attested. What IS implemented: the scope fan-out delivers an agent_session row through the review-execution seam, scope_review_session gates its blocking authority on SOURCED ≥200K window evidence (stale or unsourced evidence downgrades the row to a typed session_advisory whose findings are advisory AND which BLOCKS the commit for want of an authoritative verdict — the same shape as a sub-floor api row; returning a non-blocking row there made the P3 gate fail OPEN on an all-retrieving panel), the ≥200K floor is REACHABLE through the same owner-capability-ack the api slot uses (the scope-slot save offers session rows their ack against the session floor, fingerprinted under the agent_session provider rather than a guessed one), and every such review records a typed durable row naming the mode. Two costs are accepted explicitly by the owner: in low the whole-repository architectural review is lost even when a genuine ≥1M reviewer IS configured (the coupling is a POLICY choice, not a technical limit), and no partial-coverage reviewer remains that could be mistaken for the gate. The replacement path is REACHABLE: during the one compatibility window OUROBOROS_CONTEXT_MODE_AUTO_LOW=false is an inert owner-provenance tombstone, bare env Low remains owner Max, /api/state.context_mode_auto_low is the frozen literal false, and scope-slot changes still surface the pinned reviewer's needs_ack through the existing owner-capability-ack flow. Also disclosed: review-pack sizing is deliberately conservative — the review reducer takes the DENSEST still-fresh witnessed density times its safety factor and never sizes below the Claude-derived 1.65 cold floor (or the independent absolute-margin bound), so a lighter measured tokenizer does NOT earn a larger review pack; the cap may loosen back toward that floor only after the supporting dense witness expires, never because lighter traffic refreshed or evicted an unsupported maximum. Main-context density is the separate liberal reducer (newest fresh exact-route witness, then newest exact-model witness, then neutral 1.0) and is not floored. A stale stored degraded key is inert (every consumer iterates SETTINGS_DEFAULTS) and never fails settings validation. Since v6.87.44 blocking scope authority is a property of sourced, non-stale ≥1M Capability Evidence for the slot's route — the designated default carries no name-based authority and is probed (metadata-only, rate-limited by the evidence TTL, v6.87.45) like any pin; the no-evidence 1M sentinel only SIZES prompts and never signs a blocking verdict. The floor guard also became PRECISE rather than weaker, by INVERTED polarity: reaching the key or the owner endpoint is blocked unless the whole command line is demonstrably read-only inspection (per-segment command-head allowlist), so a pure grep OUROBOROS_SCOPE_REVIEW_FLOOR data/settings.json read is no longer blocked while an interpreter or HTTP client naming the endpoint is refused whatever verb spelling it carries.
Standing disclosure (v6.89.0), do not re-raise as an undisclosed narrowing: the light-mode interpreter write fence is INVERTED — an inline invocation is refused unless python's AST proves it cannot write into the repo. The narrowing is bounded to what the owner approved: a non-python inline invocation that names the repo by an ABSOLUTE path, or by a ./- or ../-prefixed relative one, is refused even for reading. One that does not name the repo in one of those spellings still runs, whatever it writes elsewhere — the resolved-cwd test is python-only, because the DEFAULT shell cwd is the repository and applying it to every family refused ordinary node -e / ruby -e work outright. Measured, a PLAIN relative spelling does not count as naming the repo: EMBEDDED_RELATIVE_PATH_RE anchors on .//../, so node -e "…('ouroboros/safety.py')" names the repo to a reader but not to the scan and RUNS — for a write as much as for a read. Disclosed, not closed: widening the regex would be a strengthening. drive, user_files and advanced/pro are untouched: the non-python read-vs-write refinement was rolled back to the public head, which leaves a KNOWN write hole there (node -e "require('fs').writeFileSync('<drive>/logs/chat.jsonl','')" runs) — disclosed, not closed, under the owner's standing direction that protection may be weakened but not strengthened. Measured, that drive hole covers the NODE and PHP families in EVERY spelling: node, nodejs, node18, php and php8.3 all reach another task's drive path unblocked (the versioned spellings blocked at the public head and no longer do; the unversioned ones were already open). It does NOT extend to ruby or perl — both are LIGHT_SHELL_WRITER_COMMANDS members, so ruby, ruby3.2, perl and perl5.38 are still caught by the conservative full-mention scan on the earlier writer-command branch. One narrowing does ride with the inversion and is deliberate: python inline code is now inspected on run_command, not only on run_script. Three gaps are DISCLOSED rather than detected, and must not be re-raised as findings to fix. (a) No invariant ties the AST walker to the write-indicator regex: <mod>.open(p,"w") (io/codecs/gzip/bz2/lzma) counts as a write to the regex while the walker reads argument 0 as the MODE and can answer "no targets", which the fence reads as a proven read; measured, that truncates a repo source file. (b) Aliased writers escape the walker's vocabulary (import shutil as sh, from shutil import copy, getattr(os,"replace")). (c) The fence is a light-mode convenience boundary against the agent's own mistakes, not a containment boundary against a determined writer.
Standing disclosure (Q4=A sandbox unwind, owner decision 2026-08-08), do not re-raise as an undisclosed widening or narrowing: the argv-text blanket GIT_VIA_SHELL_BLOCKED default lane was deliberately replaced by the target-aware git_shell_policy.external_workspace_git_violation resolver for ALL non-workspace shell lanes. Mutating git is free outside the Ouroboros runtime in every runtime mode including light and direct chat; read-only git is allowed even at runtime targets (the v4.5.1/f14baf8f false-block line); only mutating git that targets the system repo / data drives (bidirectional, casefold, symlink-resolved containment) is refused, with commit_reviewed as the remedy; acting self_worktree children keep the strict read-only git policy, and the allowed_resources.network fence and gh repo create/delete/gh auth blocks are unchanged. Disclosed residuals, not defects to fix: git launched through a transparent wrapper (nice/xargs) or from interpreter code is not classified by the deterministic guard (the pre-flip text classifier never saw the interpreter form either; the LLM safety layer and the light post-exec system-repo dirtiness tripwire remain), and -c alias/config indirection is not parsed. Completing that unwind, two composition rules are also standing and disclosed: git init <dir> / git clone <url> <dir> are judged by their DESTINATION rather than the cwd (the default lane's cwd IS the system repo, so the cwd verdict was a blanket false block; the destination is the last path-shaped operand with init/clone's own value-taking flags consumed; with no destination the cwd remains the target; --flag=<path> retargets stay checked by the flag's documented type while non-path flag values like -b feature/x are never resolved as paths; relative candidates are canonicalized like absolute ones), and in external-workspace mode the runtime/secret READ guard exempts commands proven read-only git in EVERY segment (is_readonly_git_command) — all-or-nothing, so a compound that merely starts with git still meets the full guard, and WRITE-aware, so a read-only subcommand carrying the diff --output=<file> option (which truncates the file) or --no-index (which reads arbitrary host files) does not ride the exemption; --output targets are containment-judged at the FILE, and only with those rules does "the credential surface is unchanged" hold.
Standing note for item 21 (2026-08-15), do not re-raise as a missing successor class: the delegated-coding target class lost in the D10 migration — editing one exact non-Git installed skill payload — is restored through delegate_start(subagent_id=..., prompt=..., root="skill_payload", bucket=..., skill_name=...) (private standalone snapshot, explicit parent CAS apply, review goes stale), with a golden registry-level test pinning it.
SUPERSEDING entry (campaign owner decision Q10=A, v7.0 ABI window; batch #9 item 6=A), read this instead of the v6.80.0 floor clause above: By the campaign owner decision Q10=A (v7.0) the OUROBOROS_SCOPE_REVIEW_FLOOR gateway surface (key, endpoint, contract field, route, merge-skip, web client, self-lowering guards) IS removed in 7.0 — this supersedes the v6.80.0 standing disclosure above; the key is retired via RETIRED_SETTING_KEYS (a stored value is stripped on load). This is an INTENTIONAL, disclosed capability removal, not an accident to re-raise. Everything else the v6.80.0 entry records is unchanged and still binding: scope-review applicability is decided solely by the owner-only OUROBOROS_CONTEXT_MODE, low and the owner-declared RETRIEVING scope reviewer remain the two admitted replacement paths, and the accepted costs stand. One clause of that entry narrows with the removal: the INVERTED-polarity read-carve it describes for "the key or the owner endpoint" survives family-wide as _owner_control_mention_blocks (a provably read-only inspection reaches any owner-control key or endpoint; an interpreter or HTTP client naming one is refused whatever verb spelling it carries), while the floor-SPECIFIC detector was retired together with its setting. The grep OUROBOROS_SCOPE_REVIEW_FLOOR data/settings.json example in that clause therefore names a setting that no longer exists; the carve it illustrates does.
Standing disclosure (owner decision 2026-09-14, #884), do not re-raise as an undisclosed removal: the semantic duplicate-task gate on schedule_subagent admission (supervisor/events_schedule_task.py::_find_duplicate_task, a light-model judge that rejected a child as rejected_duplicate for resembling an active task) is REMOVED. Admission keeps exact task-id fencing, the per-root active-child cap, the hard cap, depth caps and cost ceilings; the parent decides what to spawn and receives task_id, objective and subagent_id for every child. Byte-identical siblings (multi-model cross-checks, majority votes) are admitted by design. The rejected_duplicate status constant and its projections remain for old task records only. Residual risk, disclosed: a parent re-queued after a mid-wave crash may pay a wave twice, bounded by the cap and the per-tree ceiling.
SUPERSEDING entry (owner decisions 2026-09-17 and 2026-09-18, retrieval-review contribution), read this instead of the retrieving-scope clauses of the v6.80.0 and v7.0 entries above: whole-repository scope review is delivered by RETRIEVAL on every scope row: an api_chat row runs the native inspection episode, an agent_session row runs the delegated session. The assembled scope packet, Generated Scope Atlas admission ladder and its overflow terminals, the ≥1M packed and ≥200K retrieving authority floors, their owner-capability-ack UI, the session_advisory downgrade and the scope cold-floor clause are intentionally removed. Window metadata sizes sends only. Scope runs in every context mode; the skipped_low_context_mode row and low-mode coupling are intentionally removed. Packed deep self-review and its pack-unfit refusal are also removed; every deep-review row retrieves. The required-source manifest, exact paged subject/preimages and recorded read coverage remain evidence for the reviewer and author. By the owner's explicit refinement, coverage is DIAGNOSTIC on ALL routes: incomplete or unobserved reads never remove an answered reviewer from quorum, block a commit, relabel its substantive verdict or automatically buy a repeat review. Native receipts attest delivered ranges; harness-journal ranges are weaker inferences and unknown extents stay unknown, including ordinary Cursor file reads. The agent decides whether a specific gap warrants further work. Existing substantive-finding enforcement, missing-response handling and exact-candidate binding remain applicable.
The same owner-approved governance tiers also narrow the tool-less triad packet: core rules remain inline, while relevant DEVELOPMENT/DESIGN material and ARCHITECTURE sections fit the shared inline share; the remaining sources are named as navigation metadata, without claiming that a packet recipient has reading tools. This intentional change replaces whole-book inlining and must not be re-raised as an undisclosed removal.