Overseer Handover — Knowtation
Living relay for Knowtation-owned work. Paste the NEXT SESSION block into a fresh chat to resume without prior history.
Authority split (changed 2026-07-26). This file is no longer a thin pointer. Knowtation now
has the Overseer Kit installed and owns its own security/authorization board
(docs/ROADMAP.md). Cross-repo product order still lives on the Scooling board
(~/scooling/docs/OVERSEER-HANDOVER.md + ~/scooling/docs/ROADMAP.md). When the two disagree about
product sequencing, Scooling wins. When they disagree about Knowtation's own authorization
behavior, this board wins.
Why this changed: the independent Pass 2 security audit
(~/scooling/docs/PRE-BUILD-SECURITY-AUDIT-FINDINGS-PASS2.md, verdict findings) put 7 of 11
code-level findings in Knowtation. Knowtation was doing the highest-risk work with no governed
roadmap, no freeze review, and no build-verification gate.
NEXT SESSION — FLOW-WRITE-LIVE-SMOKE §FWL.9 (RELAY → scooling FLOW-WRITE-LIVE-SMOKE Operator)
Date: 2026-07-29
Model: Operator (product order — paste on Scooling, not here)
Branch (Knowtation): Muse/main @ KN #278 land — admission ready. Prod
FLOW_AUTHORING_WRITES still unset until SMOKE needs Hub side (Operator).
Why this is a RELAY (not product PRIMARY): Product sequencing is owned by Scooling.
FLOW-WRITE-LIVE-HOSTED / form-guard / draft-500 are DONE + landed (SC #224–#226).
Knowtation’s previous PRIMARY paste (HOSTED Thinking→Auto) was stale — do not re-run it.
K13 workspace was dogfood-only and never on Muse/main; Scooling restored
.overseer/workspace.yaml so ok workspace check-next can catch this class of drift.
THE ONE NEXT STEP — Model: Operator (RELAY → Scooling product_order)
Open ~/scooling/docs/OVERSEER-HANDOVER.md and paste that PRIMARY fence
(§FWL.9 signed-in SMOKE). Do not start FLOW-WRITE-LIVE-HOSTED again.
FLOW-WRITE-LIVE-SMOKE §FWL.9 — Operator
Model: Operator + Auto
Repo: ~/scooling
Step: FLOW-WRITE-LIVE-SMOKE
Authority: relay
Wait for Netlify production publish of SC #226 if needed, then:
https://scooling.netlify.app/flows — sign in, personal scope, policy checked,
intent+title → draft→hosted_flow_saved. Confirm KN proposal source:flow +
scooling.flow: external_ref.
Env already SET (SCOOLING_FLOW_AUTHORING_WRITE + SCOOLING_FLOW_HOSTED_LIVE).
Do NOT flip capture/run/automatable/projection/Delegation.
Do NOT add KNOWTATION_HUB_TOKEN / SCOOLING_FLOW_HUB_TOKEN.
Hard stops: no feature→GitHub-main; no Delegation write env.
Prior session — Knowtation PRODUCT RELAY refresh (2026-07-29)
Synced to Scooling PRIMARY tip_hash sha256:38c2305e… after draft-500 land SC #226.
SD-21 land-hygiene + scooling-stack workspace restore recorded on Scooling board.
Prior session — Scooling L-SEAMa freeze pass; Knowtation relay was stale
Date: 2026-07-27 · Model: Thinking (Scooling) → governance fix (this board)
Scooling L-SEAMa completed freeze-review pass and advanced its PRIMARY to L-SEAMb Auto.
This Knowtation handover still showed the old Thinking paste (L-SEAM C1–C4). That was not
an Overseer Kit install failure — the kit does not cross-update consumer handovers. Fix:
regenerate this NEXT block to relay L-SEAMb Auto.
Prior session — governance sync: Overseer verified; NEXT → C1–C4 Thinking
Date: 2026-07-27 · Model: Auto
Operator asked to confirm Overseer live and point NEXT at C1–C4. Verified both repos with
ok status --json / verify-overseer-live.sh. Live HTTP: api.knowtation.store/health →
{"ok":true}; canister /vaults without gateway auth → 403 GATEWAY_AUTH_REQUIRED.
Browser MCP: knowtation.store/ landing loads (Sign in Google/GitHub visible). Production
CORS still advertises X-User-Id — expected until SEC-SEAM-1b deploys (not merged).
Prior session — SEC-SEAM-1b Auto build + BV pass
Date: 2026-07-27 · Model: Auto (build) → thinking-high (BV)
Implemented S1–S10 against the cleared freeze: five mint stamps (type:'session'),
resolveActorTokenClass / isSessionBoundActor, seam classification via apply-path predicates
(S3.0; seven conditions incl. flow/flow_capture), personalSelfApplyRefusalReason + S6.2 HTTP
seam codes on both approve gates, S10 empty parser module, CORS X-User-Id advertisement removed,
PROPOSAL-LIFECYCLE S7/S8. Seven-tier 33/33. BV round 1 = pass. T1–T5 unexecuted. No merge.
Prior session — SEC-SEAM-1a rounds 4–7: D5 = A, freeze CLEARED
Date: 2026-07-27 · Model: Thinking
Operator selected D5 = A after a grounded recommendation from lib/flow/** (forgeability
executed). Fixed V1–V11, then W1–W5 / X1–X2 / Y1 through freeze-review-loop. Round-7 independent
reviewer = pass. Mechanical gate pass; stamp retained only after semantic clearance.
Opened roadmap row SEC-SEAM-MEDIA (D2). T1–T5 unexecuted. No merge.
Prior session — SEC-SEAM-1a round 3: D1–D4 ratified, N1 closed, loop blocked at round 3
Date: 2026-07-27 · Model: Thinking
Opened by refusing to treat the paste-ready prompt as a ratification. That prompt said "fix N1 per D4 option A", but it was written by the round-2 session itself, so acting on it would have been an authoring session clearing its own escalation — the defect that reverted SEC-KN-4a §12.1. Stopped, asked, and recorded four verbatim operator selections in freeze §12.1 before editing any rule.
Then fixed all 18 round-2 findings, verifying every citation against source first and correcting two of the reviewer's own (N15 was inverted — the audit row is stale, not the justification; N18's line number was off by one). Rewrote S3 around D4 = A: classification now calls the same predicate the apply hook calls, with S3.0 forbidding any hand-written seam list. Reproduced the N1 evasion and its fix by executing the predicates.
Round-3 independent review (thinking-high, fresh) = blocked, 11 findings, but it confirmed
15 of 18 round-2 fixes and confirmed N1 is closed by construction. Its three sharpest findings
disprove claims round 3 had asserted — see the NEXT block for V1/V2/V3. Loop halted for the operator
per the skill's security-and-blocked hard stops rather than attempting a fourth self-directed
round.
Prior session — SEC-SEAM-1a freeze authored, loop blocked at round 2
Date: 2026-07-26 · Model: Thinking
Wrote the freeze (frozen inputs: ROADMAP, this file, Pass 2 P3, Scooling ROADMAP L-SEAM,
SEC-KN-4 freeze, PROPOSAL-LIFECYCLE). Verified against source rather than assumed: gateway JWT mint
sites, X-Actor-Id being server-set and client-injection blocked, task_meta absent from
canister proposal records while frontmatter is serialized, and Scooling's three transports
(taskWriteHubTransport, mediaWriteHubTransport, delegationHubTransport) all sending the shared
env token while hostedReviewWriteBack sends the learner's own session JWT — the contrast that makes
P3 real. Round 1 = blocked (14 findings, all fixed). Round 2 = blocked (18 findings, none fixed;
round 1's F3 and F13 fixes did not hold). Loop halted per
.cursor/skills/freeze-review-loop/SKILL.md:28-36 because N1 escalates security and changes design.
Prior session — SEC-KN-6 BV round 1 = pass
Date: 2026-07-26 · Model: Auto (build) → thinking-high (BV)
P14: constantTimeTextEqual (OR-of-XOR, full scan) replaces got == expected in both
gatewayAuthorized and operatorExportAuthorized. Seven-tier 18/18; Motoko compile
verified; SEC-KN-1 still 19/19. T1–T4 not executed.
ARCHIVED SESSION — SEC-KN-6 build prompt
Date: 2026-07-26 Model: Auto
SEC-KN-5 is DONE (BV round 1 = pass on feat/sec-kn-5-delegation-ttl-viewer-mint).
Next: P14 constant-time secret compare in Motoko gateway auth.
Branch: open feat/sec-kn-6-constant-time-secret-compare (or continue on a feature branch). Muse feature-branch only.
SEC-KN-6 — Auto: constant-time gateway auth secret compare.
Model: Auto.
Read docs/ROADMAP.md (SEC-KN-6 row) + docs/OVERSEER-HANDOVER.md.
P14: replace `==` after length check in hub/icp/src/hub/main.mo:919-939
(gateway auth + operator export) with a constant-time compare.
Seven-tier tests + security regression vs pre-fix; /build-verification-review before DONE.
T1–T4 remain unexecuted. No merge to main. No canister deploy.
Prior session — SEC-KN-5 BV round 1 = pass
Date: 2026-07-26 · Model: Auto (build) → thinking-high (BV)
P12: readVaultDelegationPolicy clamps max_ttl_seconds to MAX_TTL_SECONDS (86400).
P13: self-hosted grant mint is requireRole('admin') only. Seven-tier + security
regressions green (26/26 with route file; related delegation 64/64).
T1–T4 not executed.
ARCHIVED SESSION — SEC-KN-5 build prompt
Date: 2026-07-26 Model: Auto
SEC-KN-3a is DONE (BV round 1 = pass on feat/sec-kn-4a-delegation-principal-binding-freeze).
Next: P12 clamp vault-policy max_ttl_seconds + P13 restrict self-hosted grant mint to admin.
Branch: open feat/sec-kn-5-delegation-ttl-viewer-mint (or continue on current feature branch). Muse feature-branch only.
SEC-KN-5 — Auto: clamp policy TTL + block viewer grant mint.
Model: Auto.
Read docs/ROADMAP.md (SEC-KN-5 row) + docs/OVERSEER-HANDOVER.md.
P12: clamp vault policy max_ttl_seconds to MAX_TTL_SECONDS (86400) in
lib/agent/delegation.mjs — currently accepts any value > 0, silently widening SD-10.
P13: restrict self-hosted grant mint to admin — hub/server.mjs currently allows viewer.
Seven-tier tests + security regression vs pre-fix; /build-verification-review before DONE.
T1–T4 remain unexecuted. No merge to main.
Prior session — SEC-KN-3a BV round 1 = pass
Date: 2026-07-26 · Model: Auto (build) → thinking-high (BV)
Refreshed 4 stale resolveHostedActorRole source-shape assertions; isolated billing-repair DB
(no replica gate — false diagnosis). RBAC trio + SEC-KN-3 + billing-repair 82/82.
T1–T4 not executed.
ARCHIVED SESSION — SEC-KN-3a build prompt
Date: 2026-07-26 Model: Auto
SEC-KN-4b is DONE (BV round 2 = pass on feat/sec-kn-4a-delegation-principal-binding-freeze).
Next: fix the 4 stale resolveHostedActorRole source-shape assertions left by SEC-KN-3 so the full
suite can go green again (blocks frozen §7.2 DoD for later SEC phases). Also decide whether
test/gateway-admin-billing-repair.test.mjs should gate behind a replica-available guard.
Branch: continue on feat/sec-kn-4a-delegation-principal-binding-freeze or open
feat/sec-kn-3a-rbac-assertion-refresh — either is fine; keep Muse feature-branch only.
SEC-KN-3a — Auto: refresh stale resolveHostedActorRole source-shape assertions.
Model: Auto.
Read docs/ROADMAP.md (SEC-KN-3a row) + docs/OVERSEER-HANDOVER.md.
Failing files: test/proposal-approve-rbac-fix-{data-integrity,security,unit}.test.mjs
(4 failures). They assert a pre-SEC-KN-3 shape of resolveHostedActorRole in
hub/gateway/server.mjs. Update assertions to match the post-SEC-KN-3 scope-capped
implementation; do not weaken SEC-KN-3's security properties.
Also: decide whether test/gateway-admin-billing-repair.test.mjs should skip/gate when
no canister replica is available (it hangs plain npm test).
Seven-tier not required if this is assertion-only hygiene; still run the three RBAC
files + sec-kn-3 suite green, then /build-verification-review before DONE.
T1–T4 remain unexecuted. No merge to main.
Prior session — SEC-KN-4b BV round 2 = pass
Date: 2026-07-26 · Model: thinking-high
BV round 2 re-verified BV1–BV4, R1–R9, tests 31/31, migration exit 0, Motoko compile verified.
One new MINOR (R5 docs :245) fixed in-session. SEC-KN-4b marked DONE. T1–T4 not executed.
ARCHIVED SESSION — SEC-KN-4b build prompt
Date: 2026-07-26 Model: Auto
SEC-KN-4a freeze is ratified. The P4 contract is in
docs/SEC-KN-4-DELEGATION-PRINCIPAL-BINDING-FREEZE.md (frozen: true), the mechanical gate passes,
two independent review rounds ran, and the operator ratified both escalated decisions on
2026-07-26 — recorded verbatim in freeze §12.1:
- D1 (
security) — RATIFIED, fail closed. The canister must never fall back toX-User-IdwhenX-Actor-Idis absent.X-User-IdiseffectiveCanisterUid, i.e. the workspace owner (hub/bridge/delegation-routes.mjs:68;hub/bridge/server.mjs:698-736), so a fallback would write the owner's derived principal into a consent the owner never authored — the same bug shape the fix exists to close. Store""and let apply refuseDELEGATION_AUTHOR_UNVERIFIED. - D2 (
irreversible) — RATIFIED, one-shot hook. Addingcreated_bymakes the upgrade hook non-identity (Migration.mo:8), so a repeat deploy either fails compatibility or resets every author to"". Exactly one release may carry it; the next release restores identity — roadmap rowSEC-KN-4c, freeze gate T4, to be scheduled in the same operator session as the T1 upgrade.
Freeze review = pass (round 3, 2026-07-26, recorded in freeze §11): C1–C8 all pass, nothing open
in an escalating category, implementable with zero design decisions left open. Both preconditions
are met — the freeze is CLEARED for the 4b code build. Still not authorized: T1 canister upgrade,
T2 any merge, T3 gate flip, T4 identity restore.
Design decision the build must respect:
the principal is re-derived from the server-recorded proposal author, never from the
authenticated actor at apply (freeze §3.1). Code on
feat/sec-kn-4a-delegation-principal-binding-freeze. Not merged to main.
SEC-KN-4b — Auto: build P4 principal binding at apply + proposal authorship.
Model: Auto. PRECONDITIONS (both already met as of 2026-07-26 — re-verify, do not assume):
freeze §12.1 records the operator's D1/D2 selection, and freeze §11 shows a round-3 `pass`.
If either is missing, STOP and ask — never ratify on the operator's behalf (round 2 blocked
exactly that). Ratification covers the CODE build only: no canister deploy, no merge, no gate flip.
Read first (the freeze is ground truth — do NOT redesign):
- docs/SEC-KN-4-DELEGATION-PRINCIPAL-BINDING-FREEZE.md (R1-R9, R2.1 check order, §5 scope,
§6 test matrix, §8 Tier-3 gates, §12 decisions)
- docs/ROADMAP.md (SEC build queue) and docs/OVERSEER-HANDOVER.md (this file)
Do (implement exactly R1-R9; nothing outside freeze §5):
1) R1 canister authorship: add created_by to Migration.ProposalRecord; pin
StableStorageV5/V6/V7 AND the two historical row maps (Migration.mo:233, :268) to
ProposalRecordV7; add _proposalV7ToCurrent setting created_by = "" plus the
TODO(SEC-KN-4c) identity-restore marker on the hook; in main.mo proposal create set
created_by from X-Actor-Id ONLY — no X-User-Id fallback, no truncation (store "" when
absent/empty/over 128), never from the JSON body; emit it in both GET serializers;
extend scripts/verify-canister-migration.mjs.
2) R2 + R2.1 precheckApprovedDelegationProposal(dataDir, proposal, { author }) — author
REQUIRED, fail closed (DELEGATION_AUTHOR_UNVERIFIED), checks in the frozen order.
Wire all call sites listed in R2 (hub/server.mjs:3072 proposed_by;
lib/agent/delegation-hosted-proposal.mjs:299 created_by; three test fixtures on
TEST_USER_ID).
3) R3/R4 re-derive principal_ref / owner_ref from the author; refuse on mismatch AND
overwrite with the derived value. R5 reject org_ref: in delegation paths (apply + mint).
4) R6 drop ownerRef from the identity propose input. R7 add checkDelegationGate to apply.
R8 lock no-cross-partition apply by test. R9 keep delegation out of self-apply.
5) Seven-tier tests in test/sec-kn-4-delegation-principal-binding.test.mjs per freeze §6,
including the security regression that PASSES the attack against a body-trusted replica
and refuses it against the fixed code, plus the R1.5 anti-regression (empty created_by
must never bind to the partition owner). npm test green; npm run
canister:verify-migration exit 0. If dfx build does not resolve locally, record the
compile UNVERIFIED — do not claim it passed.
6) Update ROADMAP + this handover; Muse commit on a feature branch.
Do NOT: deploy or upgrade the canister, merge to main, flip the delegation gate, widen
self-apply, or "fix" the audit-append principal (freeze §2.1 — already grant-bound).
If a frozen rule cannot be implemented as written, STOP and return to Thinking.
Governance gates (§KH1.9 — mandatory; silence is not pass):
- [x] Freeze review — round 3 = **pass**; operator ratified §12 D1/D2 (freeze §12.1). Re-verify.
- [ ] Build verification — /build-verification-review must be pass before DONE.
- [ ] Governance sync — ROADMAP + this file in the closing Muse commit (SD-17).
- [ ] Verify claims — ok -C ~/knowtation status --json (initialized, kit_version, footprint ok).
Knowtation-owned findings (from Pass 2)
| ID | Sev | Finding | Primary citation |
|---|---|---|---|
| P1 | CRITICAL-conditional | gatewayAuthorized fails open on empty secret; identity from raw X-User-Id |
hub/icp/src/hub/main.mo:930-939, :153-158, :1017, :1149 — fixed in tree (SEC-KN-1); canister upgrade pending Tier 3 |
| P2 | MAJOR | Client-supplied evaluation_status: "passed" / evaluated_by persisted verbatim outside the fingerprint class |
lib/hub-proposal-create-augment.mjs — fixed in tree (SEC-KN-2) |
| P4 | MAJOR | Delegation apply trusts proposal.body.principal_ref; no created_by on the record → approval mints a grant for an attacker-named principal |
lib/agent/delegation.mjs:837-878, :1013; Migration.mo:154-184 — fixed in tree (SEC-KN-4b); not live until T1 |
| P6 | MAJOR | mcp_access tokens get admin-allowlist role lookup, contradicting access-token-authz.mjs; agent tokens also satisfy the self-apply human-review predicate |
hub/gateway/server.mjs + access-token-authz.mjs + hub-proposal-personal-self-apply.mjs — fixed in tree (SEC-KN-3); stale assertion hygiene SEC-KN-3a DONE |
| P12 | MINOR | Vault policy max_ttl_seconds accepted with no ceiling → silently widens SD-10's 24h cap |
lib/agent/delegation.mjs:124-136 with :996-1003 — fixed in tree (SEC-KN-5) |
| P13 | MINOR | Self-hosted viewer may mint delegation grants (runtime bearer authority) |
hub/server.mjs:1872,1912 — fixed in tree (SEC-KN-5); mint is admin only |
| P14 | INFO | Non-constant-time secret comparison | main.mo:919-939 — fixed in tree (SEC-KN-6); canister upgrade pending Tier 3 |
| P3 | MAJOR (shared) | Task/media/delegation proposals arrive with a shared service token, not a learner session — no ownership proof for self-apply | Scooling src/adapters/taskWriteHubTransport.ts:210,298 and siblings |
What Pass 2 found CLEAN in Knowtation (do not re-litigate): PROXY_HEADER_ALLOWLIST never
forwards client authorization or cookie to the canister; no secret appears in logs, errors, or
results; principal_ref is hashed before it reaches a result; delegation TTL is server-clamped
(default 3600s, max 86400s) with no client-supplied expiry accepted; JWT role claims are not
trusted (role is re-derived from sub); AIR attestation is fail-open and does not weaken the write
gate; canister proposals are partitioned by effective user id with no gateway-path IDOR.
Governance gates checklist
- [x] Overseer Kit installed — 2026-07-26,
initialized: true,kit_version: 0.1.0,footprint_self_integrity: ok,muse_sync: synced - [x] SEC-KN-0 — canister gateway auth secret verified SET (2026-07-26 live probe) — DONE
- [x] SEC-KN-1 — P1 fail-closed + security-tier regression test (Auto) — DONE (code; canister upgrade pending Tier 3)
- [x] SEC-KN-2 — P2 server-only evaluation fields (Auto) — DONE (code on
feat/sec-kn-2-server-only-evaluation) - [x] SEC-KN-3 — P6
mcp_accessrole cap + no self-apply for agent tokens (Auto) — DONE (code onfeat/sec-kn-3-mcp-access-role-cap) - [x] SEC-KN-4a — DONE — P4 spec frozen; three review rounds (1 blocked → 8 amended; 2 confirmed all hold, blocked on self-ratification; 3
pass); D1/D2 RATIFIED by operator 2026-07-26 (docs/SEC-KN-4-DELEGATION-PRINCIPAL-BINDING-FREEZE.md§11, §12.1) - [x] SEC-KN-4b — P4 build against the frozen spec (Auto) — DONE (BV round 2 =
pass; code on branch; not merged) - [ ] SEC-KN-4c — restore the migration hook to identity after the T1 canister upgrade (Operator + Auto)
- [x] SEC-KN-3a — 4 stale RBAC source-shape assertions + billing-repair isolation (Auto) — DONE (BV round 1 =
pass) - [x] SEC-KN-5 — P12 clamp policy TTL + P13
viewercannot mint (Auto) — DONE (BV round 1 =pass) - [x] SEC-KN-6 — P14 constant-time compare (Auto) — DONE (BV round 1 =
pass) - [x] SEC-SEAM-1 — P3 session-bound identity for task/media/delegation/flow writes (Thinking → Auto) — DONE (1a freeze CLEARED round 7; 1b BV round 1 =
pass; code onfeat/sec-seam-1-session-bound-writes; not merged) - [ ] SEC-SEAM-MEDIA — hosted media proposal surface (Thinking → Auto) — TODO (post–SEC-SEAM-1b; D2 = A)
- [ ] KN-b — FINISH-COMPLETE-APPLY self-apply policy — BLOCKED on SEC-SEAM-1 consumer C1–C4 + T1 + the Scooling freeze
Status (Knowtation product)
| API | api.knowtation.store live |
| MCP public | https://mcp.knowtation.store/mcp |
| Durable agent auth | MCP OAuth durable refresh + Hub Connect cloud agent (RFC 8628) shipped on main (KN #271). Public recipes: AGENT-INTEGRATION.md § Always-on cloud agents. Device routes require the persistent MCP gateway deploy. |
| Calendar 1D | LIVE (gate on) |
| Overseer Kit | Live (2026-07-26) — see deviation note below |
Verified snapshot (what exists now)
| Area | State |
|---|---|
| Overseer Kit | initialized: true, lock.kit_version: 0.1.0, footprint_self_integrity: ok, muse_sync: synced, substrate: healthy — re-verified 2026-07-27 via ok -C ~/knowtation status --json |
| Footprint deviation (intentional) | ok status --check-footprint → footprint_integrity: mismatch. Cause: MUSE-BRIDGE-WORKFLOW.md and scripts/muse-bridge-deploy.sh were restored to Knowtation's live versions (sha256 ef8a50b5… and fcc17c36…) after init --force overwrote them with kit templates. Knowtation's bridge script is 10,004 bytes and is the live deploy path; the kit template is 3,842 bytes and is not a substitute. Do not "repair" these two files. Recorded in .overseer/config.yaml → kit.notes. |
| Canister gateway auth secret | SET (2026-07-26) — hub rsovz-byaaa-aaaaa-qgira-cai; GET /vaults without X-Gateway-Auth → 403 GATEWAY_AUTH_REQUIRED. operator_status does not exist on canister. |
| SEC-KN-1 fail-closed (source) | Landed on feature branch — empty secret DENIES in Motoko; health exposes gateway_auth_configured. Not live on canister until Tier 3 upgrade. |
| SEC-KN-2 server-only eval (source) | Landed on feature branch — create augment strips client evaluation fields; E1 uses server audit only. Not merged to main. |
| SEC-KN-3 mcp_access role cap (source) | Landed on feature branch — scope-capped role; no allowlist elevation; agent tokens barred from self-apply. Not merged to main. |
| SEC-KN-4 P4 (delegation principal) | DONE on feature branch (BV round 2 = pass). R1–R9 on feat/sec-kn-4a-delegation-principal-binding-freeze: canister created_by, author-bound apply, gate on apply path, org_ref: rejected on both refs for every kind; seven-tier tests 31/31; Motoko compile VERIFIED; canister:verify-migration exit 0. Not live until T1 canister upgrade installs created_by (hosted apply refuses fail-closed until then). Repeat deploy after T1 is refused (M0216) until T4. |
| SEC-KN-3a (RBAC assertion refresh) | DONE on feature branch (BV round 1 = pass). Four stale source-shape assertions updated to post-SEC-KN-3 shape (single verify + isMcpAccess + roleFromVerifiedAccessPayload fallback). Billing-repair: not replica-gated; isolated via KNOWTATION_BILLING_DB_PATH. RBAC trio + SEC-KN-3 + billing-repair 82/82. Not merged to main. |
| SEC-KN-5 (P12 TTL clamp + P13 admin mint) | DONE on feature branch (BV round 1 = pass). readVaultDelegationPolicy clamps to MAX_TTL_SECONDS; self-hosted grant mint is requireRole('admin') only. Seven-tier test/sec-kn-5-delegation-ttl-viewer-mint.test.mjs + route assertion 26/26; related delegation 64/64. Not merged to main. |
| SEC-KN-6 (P14 constant-time compare) | DONE on feature branch (BV round 1 = pass). constantTimeTextEqual (OR-of-XOR full scan) replaces got == expected in gatewayAuthorized and operatorExportAuthorized. JS mirror updated. Seven-tier 18/18; SEC-KN-1 still 19/19; Motoko compile VERIFIED. Not live on canister until Tier 3 upgrade. Not merged to main. |
| SEC-SEAM-1 (P3 session-bound identity) | DONE on feature branch (BV round 1 = pass). Five mint stamps; seam classify via apply-path predicates (incl. flow/flow_capture); named refusal codes; S10 empty; CORS advertisement removed. Seven-tier 33/33. Not merged to main. T1–T5 unexecuted. Consumer L-SEAMa freeze pass on Scooling; remaining load is Scooling L-SEAMb Auto (C1–C4 impl). |
| Knowtation Netlify env | Site knowtation-gateway (api.knowtation.store, id 3123cc84-…): CANISTER_AUTH_SECRET present, SESSION_SECRET present, HUB_ADMIN_USER_IDS present, HUB_EVALUATOR_MAY_APPROVE absent (fail-safe). |
MCP host / gateway SESSION_SECRET sharing |
UNVERIFIED — determines P6 exploitability today |
Hard stops
- Never
git push origin main— GitHubmainonly via amuse-mirror → mainPR after a Tier 3 Musemainmerge - Never merge to Muse
mainwithout operator authorization (Tier 3) - Never claim a runtime/security state without running the check in the same session
- Delegation intents are never eligible for personal self-apply (P4) — this is not a tuning knob
- Do not re-sync
MUSE-BRIDGE-WORKFLOW.md/scripts/muse-bridge-deploy.shfrom the kit
Change log
| Date | Event |
|---|---|
| 2026-07-27 | Relay fix — NEXT → Scooling L-SEAMb Auto. Scooling L-SEAMa freeze-review pass had already advanced ~/scooling/docs/OVERSEER-HANDOVER.md to L-SEAMb Auto; this Knowtation relay still showed the old Thinking paste. Not a kit outage — the kit does not cross-update consumer handovers. Regenerated this NEXT to relay L-SEAMb. Archived SEC-KN-5/6 prompts below are history, not competing PRIMARYs. |
| 2026-07-27 | Governance sync — Overseer re-verified; NEXT → Scooling L-SEAM C1–C4. ok -C ~/knowtation status --json: initialized: true, kit_version: 0.1.0, footprint_self_integrity: ok. Scooling verify-overseer-live.sh → live: true. Live HTTP api.knowtation.store/health → {"ok":true}; canister auth still SET (403 GATEWAY_AUTH_REQUIRED). Browser MCP confirmed knowtation.store/ landing loads. PRIMARY product next is consumer C1–C4 on the Scooling board (freeze §6). |
| 2026-07-27 | SEC-SEAM-1 DONE — BV round 1 = pass. S1–S10 on feat/sec-seam-1-session-bound-writes: five mint stamps (type:'session'), resolveActorTokenClass / isSessionBoundActor, seam classify via apply-path predicates (S3.0; seven conditions incl. flow/flow_capture), personalSelfApplyRefusalReason + S6.2 HTTP seam codes on both approve gates, S10 empty parser (lib/hub-self-apply-ineligible.mjs), CORS X-User-Id advertisement removed, PROPOSAL-LIFECYCLE S7/S8. Seven-tier 33/33 (test/sec-seam-1-session-bound-identity.test.mjs, sha256 bd57bfe8868175096589c4dac823586ddd6ce683066ccef92fdef65cfaedd361). T1–T5 unexecuted. No merge. NEXT = Scooling L-SEAM / SEC-SEAM-MEDIA Thinking / Operator Tier-3 merge (pick one). |
| 2026-07-27 | SEC-SEAM-1a CLEARED — round 7 = pass. Operator D5 = A (flow + flow_capture in S3.1). Fixed V1–V11 (V3 overlap executed; V1 machine-credential premise corrected; fifth mint issueLocalToken; S6.2 / S10 lib parser / seven S3.1 conditions). Loop cleared W1–W5 / X1–X2 / Y1. Independent clearance round-7. Mechanical gate pass; stamp retained after semantic clearance. Roadmap row SEC-SEAM-MEDIA opened (D2). NEXT = SEC-SEAM-1b Auto. T1–T5 unexecuted. No merge. |
| 2026-07-27 | SEC-SEAM-1a round 3 — D1–D4 RATIFIED, BLOCKER N1 closed, round-3 review = blocked (11 new findings). Session refused to read the handover's own paste-ready prompt ("fix N1 per D4 option A") as ratification — it was round-2's authorship, and acting on it would repeat the SEC-KN-4a self-ratification defect. Operator selections obtained and quoted verbatim in freeze §12.1: D1 = A (stamp type: 'session' at all mint sites; absent = legacy_session, propose-OK / self-apply-ineligible), D2 = A (media out of scope, roadmap row), D3 = start empty (S10 ships dormant), D4 = A (classification reuses the apply path's predicate). All 18 round-2 findings fixed; S3 rewritten with frozen anti-drift rule S3.0 — no hand-written seam field list may exist in built code — plus new ground truth G27–G31 and a full 14-step refusal precedence (S6.1). N1's evasion and its fix reproduced by execution. Round-3 independent reviewer (thinking-high, fresh) confirmed 15/18 round-2 fixes and that N1 is closed by construction, but returned blocked with 11 findings — incl. security V1 (a machine-credential mint path does exist: netlify/functions/consolidation-scheduler.mjs:72, which is the premise D3 was ratified on), V2 (fifth learner-session mint site hub/lib/local-auth.mjs:179), and V3 (S6.1's "no live behavior change" disproved by execution). Loop halted per the skill's security/blocked hard stops. New operator decision D5 (are Flow / Flow-capture seam surfaces? — apply-bearing and self-apply-gated at hub/server.mjs:3056/:3064, absent from the freeze). Mechanical ok review --freeze = pass, 0 findings; its auto-written review_stamp removed by hand every run since the semantic verdict is blocked. Muse branch feat/sec-seam-1-session-bound-writes (canonical, unchanged; git is parked on an unrelated stale branch and was not touched). SEC-SEAM-1b not started. T1–T5 unexecuted. No merge. |
| 2026-07-26 | SEC-KN-6 DONE — BV round 1 = pass. P14: Motoko constantTimeTextEqual (OR-of-XOR over every character; no early-exit ==) wired into both gatewayAuthorized and operatorExportAuthorized; JS mirror in lib/gateway-authorized.mjs. Seven-tier + security regressions vs length-then-== early-exit in test/sec-kn-6-constant-time-secret-compare.test.mjs (18/18, sha256 67db4bca…); SEC-KN-1 still 19/19; Motoko compile VERIFIED (env -i … NO_COLOR=1 TERM=dumb dfx build --check hub). Branch feat/sec-kn-6-constant-time-secret-compare. T1–T4 not executed. No canister deploy. NEXT = SEC-SEAM-1 (Thinking). |
| 2026-07-26 | SEC-KN-5 DONE — BV round 1 = pass. P12: readVaultDelegationPolicy clamps max_ttl_seconds via Math.min(..., MAX_TTL_SECONDS) so a vault policy of 604800 cannot widen SD-10. P13: self-hosted POST /api/v1/delegation/grants is requireRole('admin') only (consent propose stays viewer-inclusive). Seven-tier + security regressions vs unclamped legacy / viewer-inclusive mint in test/sec-kn-5-delegation-ttl-viewer-mint.test.mjs; route assertion updated. Evidence: SEC-KN-5 + route 26/26 (sha256 0f4a1219…), related delegation suites 64/64. Branch feat/sec-kn-5-delegation-ttl-viewer-mint. T1–T4 not executed. NEXT = SEC-KN-6. |
| 2026-07-26 | SEC-KN-3a DONE — BV round 1 = pass. Refreshed 4 stale resolveHostedActorRole source-shape assertions (unit/security/data-integrity) to match SEC-KN-3: one entry jwt.verify, isMcpAccess return field, bridge fallback via roleFromVerifiedAccessPayload(bearerPayload), allowlist override gated by mayApplyAdminAllowlistOverride. SEC-KN-3 suite still green (security properties not weakened). Billing-repair decision: do not skip on canister replica — root cause was corrupt shared data/hosted_billing.json; billing-store.mjs now resolves path at call time from KNOWTATION_BILLING_DB_PATH / KNOWTATION_GATEWAY_DATA_DIR, and the repair test uses an isolated temp DB. Evidence: RBAC trio + SEC-KN-3 + billing-repair 82/82 (sha256 c587e459…). T1–T4 not executed. NEXT = SEC-KN-5. |
| 2026-07-26 | SEC-KN-4b DONE — BV round 2 = pass. Independent verifier re-checked BV1–BV4 and R1–R9 against the freeze: security regression still discriminates; R5 checks both refs + cross-kind test; performance read-count test green; R1.5 owner-never-persisted assertion real; Motoko compile verified via env -i PATH=… HOME=… NO_COLOR=1 TERM=dumb dfx build --check hub (plain NO_COLOR alone can still hit ColorOutOfRange); canister:verify-migration exit 0; SEC-KN-4 tests 31/31; related delegation suites 24/24. One new MINOR: freeze R5 required docs/AGENT-DELEGATION-V0-SPEC.md:245 to mark org_ref: reserved — it did not; amended in-session, then re-verified. SEC-KN-3a pre-existing proof strengthened: muse snapshot-diff from SEC-KN-3 tip → HEAD lists no hub/gateway/server.mjs and no proposal-approve-rbac-fix-*.test.mjs. T1–T4 not executed. NEXT = SEC-KN-3a. |
| 2026-07-26 | SEC-KN-4b build verification round 1 = findings (4 MINOR, nothing escalating) — all fixed; round 2 pending. The verifier confirmed the two things most likely to be faked: the security regression genuinely discriminates (precheckLegacyBodyTrusted is a branch-for-branch copy of the pre-fix function, accepts the attacker-named principal, and the test fails if the fix is reverted), and the "pre-existing" label on the failing suite is proven — the asserted-on source and the asserting test files are sha256-identical before and after the build commit, so the 4 real failures are stale resolveHostedActorRole assertions from SEC-KN-3, now tracked as SEC-KN-3a. Fixes: tautological assert.notEqual on two constants replaced with a real "owner principal never persisted" check; R5 now checks both principal_ref and owner_ref for every record kind (the literal frozen wording) with a cross-kind test; performance tier now asserts the "no extra filesystem read" clause; the non-green full suite is disclosed instead of omitted. Motoko compile VERIFIED — the dfx build panic was terminal-colour detection, and NO_COLOR=1 TERM=dumb dfx build --check hub succeeds, which also discharges the one static risk BV could not check (createdByFromRequest forward-referencing isAsciiSpace). Upgrade behaviour measured: first upgrade accepted (exit 0), repeat deploy refused with Compatibility error [M0216] — the freeze's hedge resolves to "no silent erasure, but un-upgradeable until T4", and R1.4 + gate T4 now carry the measurement. SEC-KN-4 tests 31/31; canister:verify-migration exit 0. T1–T4 not executed. |
| 2026-07-26 | SEC-KN-4b WIP (code) — R1–R9 built on feat/sec-kn-4a-delegation-principal-binding-freeze: canister created_by + V7 migration hook (TODO SEC-KN-4c), author-required precheckApprovedDelegationProposal, principal/owner re-derive, apply gate, org_ref: rejection, seven-tier test/sec-kn-4-delegation-principal-binding.test.mjs. canister:verify-migration exit 0. Awaiting /build-verification-review before DONE. T1–T4 not executed. |
| 2026-07-26 | SEC-KN-4a DONE — freeze review round 3 = pass. A third fresh reviewer re-derived every claim from source: all 5 round-2 findings resolved; the §12.1 ratification accepted as legitimate (a quoted operator selection, and the recorded option A matches what R1.5 and R1.4 + T4 actually say, with T1–T4 correctly excluded); RR6 confirmed accurate (the consent branch has no duplicate check and the hosted status === 'active' shortcut can never match a stored consent, which carries only revoked_at); created_by reaches precheck with no unlisted file; C1–C8 all pass; nothing open in an escalating category; implementable with zero design decisions left open. One MINOR fixed in place: R3(2) now reads "non-empty after trim" so a whitespace-only principal_ref cannot both refuse (R3) and apply (§6). Freeze CLEARED for the 4b code build only. |
| 2026-07-26 | SEC-KN-4a D1/D2 RATIFIED by operator — explicit selection received (both option A): D1 fail-closed author (no X-User-Id fallback, no truncation; apply refuses DELEGATION_AUTHOR_UNVERIFIED), D2 one-shot migration hook with mandatory identity-restore follow-up (SEC-KN-4c, freeze gate T4) scheduled in the same operator session as the T1 upgrade. Quoted verbatim in freeze §12.1, which also preserves the governance distinction that a general "proceed" is not a selection. Ratification covers the code build only — T1–T4 remain Tier 3 and unexecuted. Round-3 freeze review launched so clearance rests on a reviewer verdict rather than this session's judgement; SEC-KN-4b starts on pass. |
| 2026-07-26 | SEC-KN-4a freeze review round 2 = blocked (governance, not design) — a fresh independent reviewer re-derived every claim from source and confirmed all 8 round-1 amendments hold: Migration.mo:233/:268 are private with zero callers so the ProposalRecordV7 re-pin is type-correct and canister:verify-migration still passes; no userId(req) author fallback survives and PROXY_HEADER_ALLOWLIST (hub/gateway/server.mjs:1351-1356) blocks client injection of x-actor-id; the precheckApprovedDelegationProposal call-site list is exhaustive (5 callers + 1 source assertion); all 6 production validateChain callers pass requireGrant: true. The blocker was mine: §12.1 had recorded ratification of the escalated D1/D2 after a general "continue" instruction whose selection payload never arrived — flagged gates_tier3 and reverted to UNRATIFIED. Also amended: R2.1/§6 "malformed" wording that contradicted R3(2)'s mismatch refusal (a build session could have softened the loud-failure property), the data-integrity idempotency row scoped to agent_identity with the pre-existing consent duplicate-append recorded as RR6, and the repeat-deploy consequence restated as "fails compatibility or silently resets" since Motoko's actual behavior is not provable from this tree. ok review --freeze = pass. P4 remains open; SEC-KN-4b still not started. |
| 2026-07-26 | SEC-KN-4a BLOCKED (freeze written, review escalated) — P4 contract in docs/SEC-KN-4-DELEGATION-PRINCIPAL-BINDING-FREEZE.md (frozen: true) binds the delegation principal to the server-recorded proposal author (canister created_by from X-Actor-Id, self-hosted proposed_by), refuses on mismatch, rejects org_ref: authority refs in v0, gates the previously ungated apply path, and freezes the check order. New analysis beyond the audit: the org_ref: variant needs no secret knowledge (path A); exploit path C is persisted forgery but not reachable (all validateChain callers pass requireGrant: true); the audit-append principal is already grant-bound (lib/agent/delegation.mjs:613-615) so it stays out of scope. Round-1 independent review = blocked: 6 findings amended, 2 escalated to the operator (§12 D1 fail-open author fallback; D2 non-idempotent migration hook). ok review --freeze = pass. Branch feat/sec-kn-4a-delegation-principal-binding-freeze. NEXT = operator ratification, then SEC-KN-4b. |
| 2026-07-26 | SEC-KN-3 DONE (code) — mcp_access scope-capped role; never allowlist elevate; agent tokens never self-apply; seven-tier + security regression vs legacy inheritance; BV pass. Branch feat/sec-kn-3-mcp-access-role-cap. NEXT = SEC-KN-4 (Thinking first). |
| 2026-07-26 | SEC-KN-2 DONE (code) — strip client evaluation_status / evaluated_by / evaluated_at on create augment; E1 server-audit only; seven-tier + security regression vs forge-preserving legacy; BV pass. Branch feat/sec-kn-2-server-only-evaluation. NEXT = SEC-KN-3. |
| 2026-07-26 | SEC-KN-1 DONE (code) — gatewayAuthorized fail-closed; health gateway_auth_configured; seven-tier + security regression vs fail-open; BV pass. Branch feat/sec-kn-1-gateway-auth-fail-closed. Canister upgrade not deployed (Tier 3). |
| 2026-07-26 | SEC-KN-0 DONE — canister gateway auth secret verified SET via live HTTP probe (hub rsovz-byaaa-aaaaa-qgira-cai → 403 GATEWAY_AUTH_REQUIRED). Knowtation gateway env keys confirmed present. MCP/SESSION_SECRET share still UNVERIFIED. Cross-board: Scooling L-ENV (P7/P8/P9) also closed same day. |
| 2026-07-26 | Overseer Kit installed (init --regime muse+git-mirror --migrate --force, option A) on feat/overseer-kit-install. Existing docs/OVERSEER-HANDOVER.md preserved; docs/ROADMAP.md + docs/CROSS-REPO-COORDINATION.md seeded; live bridge assets restored over kit templates (known footprint deviation). Verified initialized: true. |
| 2026-07-26 | SEC queue opened from independent Pass 2 audit (~/scooling/docs/PRE-BUILD-SECURITY-AUDIT-FINDINGS-PASS2.md, verdict findings) — Knowtation owns P1, P2, P4, P6, P12, P13, P14 and shares P3. Scooling's FINISH-COMPLETE-APPLY-KN-b is NO-GO until SEC-KN-0 is verified and SEC-KN-2 ships. |
| 2026-07-13 | Docs hygiene: durable-auth freeze/evidence moved to local development/ (not public). |
| 2026-07-13 | Connect cloud agent + honesty UI merged — KN #271 |
| 2026-07-12 | Durable MCP OAuth refresh (strong store) merged — KN #270 |
Shared context (prepend to any phase prompt)
Knowtation is the canonical store and permission authority — notes, calendar, tasks, Flows, and the authorization decisions over them. Scooling is a consumer and stores nothing canonical. MuseHub enriches (version/provenance/social); it does not own.
Read first: docs/ROADMAP.md, this file, AGENTS.md, MUSE-BRIDGE-WORKFLOW.md,
docs/PROPOSAL-LIFECYCLE.md, docs/AGENT-DELEGATION-V0-SPEC.md, and
~/scooling/docs/PRE-BUILD-SECURITY-AUDIT-FINDINGS-PASS2.md for the SEC queue.
Tests: seven tiers (unit, integration, e2e, stress, data-integrity, performance, security) for new slices. Every SEC phase additionally needs a security-tier test that fails against the pre-fix code.
Governance: update both docs/ROADMAP.md and this file in the closing commit (SD-17). Muse
feature branch → (Tier 3) Muse main → muse-mirror PR only.
Model labeling: every NEXT block and paste-ready prompt must include Model: —
Thinking, Auto, Thinking → Auto, or Operator + Auto.