Skip to content

Harden Critique Ledger finite-canary recovery - #322

Draft
peteromallet wants to merge 100 commits into
mainfrom
fix/critique-recovery-cloud-observation-preflight-20260802
Draft

Harden Critique Ledger finite-canary recovery#322
peteromallet wants to merge 100 commits into
mainfrom
fix/critique-recovery-cloud-observation-preflight-20260802

Conversation

@peteromallet

Copy link
Copy Markdown
Owner

What changed

  • adds the bounded, zero-recovery Critique Ledger finite-canary launch path
  • isolates model phases under UID/GID 65532 with zero capabilities, no-new-privileges, strict scratch/resource limits, exact output-inode custody, and per-phase receipts
  • adds typed host capacity, workspace transition/reseal, fence, mount, model-evidence, custody, and completion validation
  • separates two consumed operational substrates from fifteen explicitly deferred F1/F2 obligations
  • adds an executable, no-network built-image structural smoke with synthetic credentials and durable success/failure evidence

Why

The prior Critique Ledger run stalled at gated, repeatedly notified the operator, and could not launch a durable diagnostic because resident delegation provenance was missing. The recovery path must prove one finite init → plan → critique → gate(PROCEED) → finalize run without enabling the failed fixer, residents, watchdogs, retries, or notifications.

Validation

  • focused zero-recovery suite: 80 passed, 1 expected platform skip
  • shared-chain regression slice: 456 passed
  • earlier full cloud suite on the A4 boundary: 2,468 passed, 1 expected skip
  • independent A5/B5 source/custody audit: pass
  • independent exact-pair review: conditional pass; only live capacity/fence/built-image smoke gates remain

Release state

Draft until the exact production image passes the committed offline structural smoke on the cloud host, the bounded live canary finalizes and stops, custody receipts/tags are pushed, and fresh-clone verification succeeds.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant