patch feat/codex-live-finish-docs #1 / 3
aaronrene · 16 days ago · Aug 27, 2026 · Diff

RHF-b-KN0: delegation compatibility hardening for retail helper finish.

Bridge generic grant mint rejects session and legacy_session before catalog work; immutable agent_codex_retail catalog; marker-aware fail-closed authority reads. Seven-tier 17/17; BV pass. Deploy proof FINDINGS recorded (land follows).

sha256:96c3131c56eb39ada387b7a495169328ee08ff5d5fe8fa7198cd4968c9b5e52d sha
+61 ~41 −7 symbols
sha256:c1f4ac196c8ef6e2f426b8c1c5ac3ec332b2f846496e56d776d4da43d89410c1 snapshot
+61
symbols added
~41
symbols modified
−7
symbols removed
0
dead code introduced
Semantic Changes 109 symbols
+ Build verification — RHF-b-KN0 round 1 section Build verification — RHF-b-KN0 round 1 L1–47
+ Checklist section Checklist L19–41
+ Evidence section Evidence L34–41
+ table section table L36–40
+ table section table L21–33
+ Findings section Findings L13–19
+ table section table L15–18
+ Scope checked section Scope checked L8–13
+ Verdict rationale section Verdict rationale L41–47
+ RHF-b-KN0 deploy proof — hosted bridge session mint denial section RHF-b-KN0 deploy proof — hosted bridge session mint denial L1–65
+ Constraints honored section Constraints honored L57–62
+ Deploy gate section Deploy gate L11–22
+ table section table L13–21
+ Local code readiness (not a substitute for hosted PASS) section Local code readiness (not a substitute for hosted PASS) L34–42
+ table section table L36–41
+ NEXT section NEXT L62–65
+ Required probes (freeze: session + legacy_session → 403 before catalog work) section Required probes (freeze: session + legacy_session → 403 before catalog work) L22–34
+ table section table L26–31
+ Root cause section Root cause L42–47
+ Unblock (Operator — Tier 3 for land) section Unblock (Operator — Tier 3 for land) L47–57
+ computeDelegationAuthorityStateHash function function computeDelegationAuthorityStateHash L60–70
+ delegationAuthorityMarkerBlobKey function function delegationAuthorityMarkerBlobKey L26–28
+ delegationAuthorityMarkerFileName function function delegationAuthorityMarkerFileName L34–36
+ getEnvelopeStoredConsent function function getEnvelopeStoredConsent L348–354
+ getEnvelopeStoredGrant function function getEnvelopeStoredGrant L361–367
+ getEnvelopeStoredIdentity function function getEnvelopeStoredIdentity L335–341
+ isNonEmptyString function function isNonEmptyString L42–44
+ isSha256Prefixed function function isSha256Prefixed L50–52
+ readEnvelopeRaw function async_function readEnvelopeRaw L176–195
+ readMarkerRaw function async_function readMarkerRaw L146–165
+ resolveDelegationAuthorityReadMode function async_function resolveDelegationAuthorityReadMode L282–328
+ resolveDelegationAuthorityReadModeSync function function resolveDelegationAuthorityReadModeSync L221–280
+ validateDelegationAuthorityEnvelope function function validateDelegationAuthorityEnvelope L100–136
+ validateDelegationAuthorityMarker function function validateDelegationAuthorityMarker L77–92
+ getTrustedCatalogIdentity function function getTrustedCatalogIdentity L51–56
+ isReservedCatalogAgentId function function isReservedCatalogAgentId L43–45
+ listTrustedCatalogIdentities function function listTrustedCatalogIdentities L61–63
~ test/rhf-b-kn0-compatibility.test.mjs .mjs 10 symbols added
+ buildEnvelope function function buildEnvelope L106–122
+ delegationProposal function function delegationProposal L141–150
+ enableGate function function enableGate L59–63
+ legacyBridgeGrantMintWouldAcceptSession function function legacyBridgeGrantMintWouldAcceptSession L83–93
+ legacySessionToken function function legacySessionToken L69–71
+ mkDataDir function function mkDataDir L55–57
+ mockReq function function mockReq L99–104
+ serviceToken function function serviceToken L73–75
+ sessionToken function function sessionToken L65–67
+ writeMarkerAndEnvelope function function writeMarkerAndEnvelope L124–139
~ docs/OVERSEER-HANDOVER.md .md 11 symbols added, 7 symbols removed, 25 symbols modified
NEXT SESSION — RHF-b-KN0 compatibility hardening section NEXT SESSION — RHF-b-KN0 compatibility hardening L32–137
THE ONE NEXT STEP — Model: Auto section THE ONE NEXT STEP — Model: Auto L39–69
PRODUCT RELAY — RHF-b-KN0 (PRIMARY lives on the Scooling board) section PRODUCT RELAY — RHF-b-KN0 (PRIMARY lives on the Scooling board) L137–231
THE ONE NEXT STEP — product order — Model: Auto section THE ONE NEXT STEP — product order — Model: Auto L173–177
code variable variable code L150–172
table section table L144–147
Product-order relay (2026-08-27, RHF-a pass) section Product-order relay (2026-08-27, RHF-a pass) L18–32
+ NEXT SESSION — KN0 deploy proof re-run (then RHF-b-KN1) section NEXT SESSION — KN0 deploy proof re-run (then RHF-b-KN1) L37–192
+ Archived — RHF-b-KN0 paste block (completed) section Archived — RHF-b-KN0 paste block (completed) L99–124
+ Paste-ready prompt — RHF-b-KN1 (separate chat; blocked until deploy proof PASS) section Paste-ready prompt — RHF-b-KN1 (separate chat; blocked until deploy proof PASS) L67–84
+ code[text] variable variable code[text] L69–83
+ THE ONE NEXT STEP — Model: Operator section THE ONE NEXT STEP — Model: Operator L45–67
+ code[text] variable variable code[text] L51–66
+ This session — RHF-b-KN0 Auto DONE (2026-08-27) section This session — RHF-b-KN0 Auto DONE (2026-08-27) L91–99
+ This session — RHF-b-KN0 deploy proof Operator FINDINGS (2026-08-27) section This session — RHF-b-KN0 deploy proof Operator FINDINGS (2026-08-27) L84–91
+ PRODUCT RELAY — sequencing (Scooling board) section PRODUCT RELAY — sequencing (Scooling board) L192–258
+ table section table L198–203
+ Product-order relay (2026-08-27, KN0 deploy proof FINDINGS) section Product-order relay (2026-08-27, KN0 deploy proof FINDINGS) L18–37
~ hub/bridge/delegation-routes.mjs .mjs 1 symbol added, 1 symbol modified
+ humanSessionTokenFromReq function function humanSessionTokenFromReq L65–74

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:96c3131c56eb39ada387b7a495169328ee08ff5d5fe8fa7198cd4968c9b5e52d --body "your comment"