From f9fa8793f029e790792eded74355cfb24efc612f Mon Sep 17 00:00:00 2001 From: POWERFULMOVES <142271328+POWERFULMOVES@users.noreply.github.com> Date: Fri, 28 Aug 2026 12:31:33 -0400 Subject: [PATCH 1/2] docs(agnote): claim review-gate topology lane Branch protection's required-approval gate has a measured 0% pass rate and 100% bypass rate (20/20 merged PRs, #2782-#2806, 0 approvals, author=POWERFULMOVES) because every PR in this fleet is authored by the same account and GitHub forbids self-approval. Files one CLAIM in the register scoping investigation + a design-doc proposal, signed via the pmoves-chit-sign skill. Co-Authored-By: Claude Sonnet 5 --- pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md b/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md index f8118d37b9..c82538e10a 100644 --- a/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md +++ b/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md @@ -2321,3 +2321,7 @@ b8cea26c8\ that added it to the top-level equired\ array). (2) PMOVES-pinokio PR - `2026-08-28T16:20:00Z` CLAIM `SPARK-KIMI (Crush)` scope: **A0 wrapper hardening + provider-key/OTEL reach-in + MiniMax verifier refresh + a0-plugins fork-sync assessment.** Operator-directed. Branch `fix/a0-wrapper-timeout-health` off fresh `origin/main`. Deliverables: (1) wrapper PR — `AGENT_ZERO_MESSAGE_TIMEOUT` config (kill the hardcoded 60s at services/agent-zero/main.py:280), health-probe verb fix for the POST-only connector `capabilities` route, healthz 503 when inner is down (green-while-dead fix); (2) OTEL reach-in — `OTEL_*` traces env is in the secrets manifest/tier-llm but measured ABSENT from both the agent-zero and archon containers (verified via docker exec env) — wire into compose for both services; (3) rebuild + recreate A0 so provider keys (Z_AI/MINIMAX/OPENAI present post-funnel) and OTEL land in-container, verify connector path; (4) init `Pmoves-MiniMax-Provider-Verifier` submodule (16 submodules uninitialized on primary) and run the verifier to refresh MiniMax model suits; (5) `PMOVES-a0-plugins` fork drift: upstream `agent0ai/a0-plugins` pushed 2026-08-28, fork diverged behind 3 / ahead 146 — assess/sync per fleet-fork-sync; (6) dispatch A0 (connector, a0-archon-bridge skill) to review the wrapper patch. Three-body: delivery=SPARK-KIMI (Crush), control=DARKXSIDE + operator, memory=this trail. agent_signature: `ACK::SPARK-KIMI::A0-WRAPPER-HARDENING-CLAIM::2026-08-28`. + +- `2026-08-28T16:40:00Z` CLAIM `B850-CLAUDE (Knuckles)` scope: **Review-gate topology: `main`'s required PR-approval gate has a measured 0% pass rate and a 100% bypass rate, because every PR in this fleet is authored by the same `POWERFULMOVES` account and GitHub forbids self-approval.** Branch `docs/review-gate-topology`, operator-directed (they read the finding and said "this needs to be addressed"). Measured via `gh api repos/POWERFULMOVES/PMOVES.AI/branches/main/protection`: `required_approving_review_count=1`, `require_code_owner_reviews=true`, `enforce_admins.enabled=false`. Measured via `gh pr list --state merged --limit 20 --json number,author,reviews`: **20 of 20 merged PRs (#2782-#2806) carry 0 approvals, author=POWERFULMOVES** — a required gate this fleet's single-account topology cannot satisfy, bypassed every time through `ADMIN_REVIEW_BYPASS` (pmoves/mk/preflight.mk:311-312). Why it matters: the bypass firing on every merge carries no signal distinguishing "bypassed because one account holds all agents" from "bypassed because nobody reviewed this" — the second is the 2026-08-23 failure class the node-steward role exists to prevent. The fleet's real review discipline (Three-Body separation, an independent Control Body, this register's claim/release trail) is sound and lives entirely outside branch protection, which cannot see it. **Scope: investigation + proposal only.** Deliverable is a design doc under pmoves/docs/operations/ laying out options — a machine-checkable Control-Body attestation as a required status check; per-agent GitHub App/bot identities so approvals become genuine; CODEOWNERS restructuring; or accepting the bypass and making it auditable by requiring it to name the reviewing body — with what each breaks. **Explicitly out of scope, nothing altered in this lane:** branch protection settings, new accounts, removing the bypass. **Identity note surfaced while signing this trail:** this node's `pmoves/config/agent_registry.yaml` key is `claude_b850`, but `make sign-trail AGENT=claude_b850` resolves under a fallback presentation (`claude_b850` is not registered in `pmoves/config/agent_signatures.yaml` — warn + fallback glyph/color, no signing_card_id), while `make sign-trail AGENT=b850-claude` resolves cleanly (card `...036`, matching this register's prior signed entries) — the signing roster carries the hyphenated form the registry key doesn't. A smaller instance of the same "identity the machine cannot resolve" shape as the topic itself. **Three-body:** delivery=a delegated delivery-agent (not yet assigned), control=independent review, memory=this trail (Memory Body, `claude_b850` / `b850-claude`). CHIT trail **signed** via `b850-claude`, `hmac: FewPTdETk9oq2w2gPjaUTPmWWK2Olz86XoK7W+1cPHc=`, kid `chit-signing-v01`, card `...036`. `agent_signature: CLAIM::B850-CLAUDE::REVIEW-GATE-TOPOLOGY::Opus-5::2026-08-28`. + + From 95bc271479beb79c0f093758b6c93fb5ce3f8dd0 Mon Sep 17 00:00:00 2001 From: POWERFULMOVES <142271328+POWERFULMOVES@users.noreply.github.com> Date: Fri, 28 Aug 2026 12:51:56 -0400 Subject: [PATCH 2/2] docs(agnote): add the TTL, and retract a mechanism claim I could not support Two Codex findings on #2810, both correct. P1 -- no TTL. AGENTS.md requires branch + scope + TTL and this row carried branch and scope. Added, as an explicit instant. Noted without deflection that the same omission was caught on #2809 an hour earlier, which makes this the second instance in one session of the very convention whose 7% compliance rate that PR documented. P2 -- the row asserted all 20 merges were "bypassed every time through ADMIN_REVIEW_BYPASS". That was not measured. What was measured is that no approving review existed on any of them; the bypass PATH was inferred from knowing the path this session used, and then written as if checked. This is the inferring-a-referent-and-treating-it-as-checked failure recorded as this identity's most frequent one, committed inside a claim about governance being asserted rather than verified. Narrowed to the demonstrated claim, and the attempt to support the stronger one is itself the better finding: * ADMIN_REVIEW_BYPASS is confirmed for exactly one merge, #2806, run here * mergedBy is POWERFULMOVES on all of them -- an account, not a path * gh run list --workflow=pr-closeout.yml returns ZERO runs So the guarded, fail-closed target left no trace for any of the 20. There is no audit trail separating "merged through pr-closeout with a named reviewing body" from "merged by any other admin path". A bypass that cannot be distinguished from a different bypass cannot be made auditable by requiring it to name the reviewing body -- the record has to exist before it can carry a name. That constraint lands on this lane's own deliverable and would have been discovered late, during design, rather than now. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01FkwiW3VY1xWmahTAtVioxz --- pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md b/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md index c82538e10a..d032ecf800 100644 --- a/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md +++ b/pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md @@ -2322,6 +2322,6 @@ b8cea26c8\ that added it to the top-level equired\ array). (2) PMOVES-pinokio PR -- `2026-08-28T16:40:00Z` CLAIM `B850-CLAUDE (Knuckles)` scope: **Review-gate topology: `main`'s required PR-approval gate has a measured 0% pass rate and a 100% bypass rate, because every PR in this fleet is authored by the same `POWERFULMOVES` account and GitHub forbids self-approval.** Branch `docs/review-gate-topology`, operator-directed (they read the finding and said "this needs to be addressed"). Measured via `gh api repos/POWERFULMOVES/PMOVES.AI/branches/main/protection`: `required_approving_review_count=1`, `require_code_owner_reviews=true`, `enforce_admins.enabled=false`. Measured via `gh pr list --state merged --limit 20 --json number,author,reviews`: **20 of 20 merged PRs (#2782-#2806) carry 0 approvals, author=POWERFULMOVES** — a required gate this fleet's single-account topology cannot satisfy, bypassed every time through `ADMIN_REVIEW_BYPASS` (pmoves/mk/preflight.mk:311-312). Why it matters: the bypass firing on every merge carries no signal distinguishing "bypassed because one account holds all agents" from "bypassed because nobody reviewed this" — the second is the 2026-08-23 failure class the node-steward role exists to prevent. The fleet's real review discipline (Three-Body separation, an independent Control Body, this register's claim/release trail) is sound and lives entirely outside branch protection, which cannot see it. **Scope: investigation + proposal only.** Deliverable is a design doc under pmoves/docs/operations/ laying out options — a machine-checkable Control-Body attestation as a required status check; per-agent GitHub App/bot identities so approvals become genuine; CODEOWNERS restructuring; or accepting the bypass and making it auditable by requiring it to name the reviewing body — with what each breaks. **Explicitly out of scope, nothing altered in this lane:** branch protection settings, new accounts, removing the bypass. **Identity note surfaced while signing this trail:** this node's `pmoves/config/agent_registry.yaml` key is `claude_b850`, but `make sign-trail AGENT=claude_b850` resolves under a fallback presentation (`claude_b850` is not registered in `pmoves/config/agent_signatures.yaml` — warn + fallback glyph/color, no signing_card_id), while `make sign-trail AGENT=b850-claude` resolves cleanly (card `...036`, matching this register's prior signed entries) — the signing roster carries the hyphenated form the registry key doesn't. A smaller instance of the same "identity the machine cannot resolve" shape as the topic itself. **Three-body:** delivery=a delegated delivery-agent (not yet assigned), control=independent review, memory=this trail (Memory Body, `claude_b850` / `b850-claude`). CHIT trail **signed** via `b850-claude`, `hmac: FewPTdETk9oq2w2gPjaUTPmWWK2Olz86XoK7W+1cPHc=`, kid `chit-signing-v01`, card `...036`. `agent_signature: CLAIM::B850-CLAUDE::REVIEW-GATE-TOPOLOGY::Opus-5::2026-08-28`. +- `2026-08-28T16:40:00Z` CLAIM `B850-CLAUDE (Knuckles)` scope: **Review-gate topology: `main`'s required PR-approval gate has a measured 0% pass rate and a 100% bypass rate, because every PR in this fleet is authored by the same `POWERFULMOVES` account and GitHub forbids self-approval.** Branch `docs/review-gate-topology`, TTL 72h (expires `2026-08-31T16:40:00Z`), operator-directed (they read the finding and said "this needs to be addressed"). Measured via `gh api repos/POWERFULMOVES/PMOVES.AI/branches/main/protection`: `required_approving_review_count=1`, `require_code_owner_reviews=true`, `enforce_admins.enabled=false`. Measured via `gh pr list --state merged --limit 20 --json number,author,reviews`: **20 of 20 merged PRs (#2782-#2806) carry 0 approvals, author=POWERFULMOVES** — a required gate this fleet's single-account topology cannot satisfy, and which was therefore satisfied by something other than a review on every one of those merges. **Correction, per Codex P2 on this PR — the earlier draft over-claimed and the retraction matters more than the claim did:** `gh pr list --json number,author,reviews` establishes that no approving review existed; it does NOT establish *which* bypass path each merge took. `ADMIN_REVIEW_BYPASS` (`pmoves/mk/preflight.mk:311-312`) is confirmed for exactly ONE merge - #2806, run by this session. For the other 19 the mechanism is **undetermined**: `mergedBy` is `POWERFULMOVES` on all of them (an account, not a path), and `gh run list --workflow=pr-closeout.yml` returns **zero runs**, so the guarded target left no trace for any of them. **That inability is a stronger finding than the one it replaces, and it lands inside this lane's own subject**: there is no audit trail distinguishing 'merged through the fail-closed guarded target with a named reviewing body' from 'merged by any other admin path'. A bypass that cannot be told apart from a different bypass cannot be made auditable by naming it; the record has to exist first. Why it matters: the bypass firing on every merge carries no signal distinguishing "bypassed because one account holds all agents" from "bypassed because nobody reviewed this" — the second is the 2026-08-23 failure class the node-steward role exists to prevent. The fleet's real review discipline (Three-Body separation, an independent Control Body, this register's claim/release trail) is sound and lives entirely outside branch protection, which cannot see it. **Scope: investigation + proposal only.** Deliverable is a design doc under pmoves/docs/operations/ laying out options — a machine-checkable Control-Body attestation as a required status check; per-agent GitHub App/bot identities so approvals become genuine; CODEOWNERS restructuring; or accepting the bypass and making it auditable by requiring it to name the reviewing body — with what each breaks. **Explicitly out of scope, nothing altered in this lane:** branch protection settings, new accounts, removing the bypass. **Identity note surfaced while signing this trail:** this node's `pmoves/config/agent_registry.yaml` key is `claude_b850`, but `make sign-trail AGENT=claude_b850` resolves under a fallback presentation (`claude_b850` is not registered in `pmoves/config/agent_signatures.yaml` — warn + fallback glyph/color, no signing_card_id), while `make sign-trail AGENT=b850-claude` resolves cleanly (card `...036`, matching this register's prior signed entries) — the signing roster carries the hyphenated form the registry key doesn't. A smaller instance of the same "identity the machine cannot resolve" shape as the topic itself. **Three-body:** delivery=a delegated delivery-agent (not yet assigned), control=independent review, memory=this trail (Memory Body, `claude_b850` / `b850-claude`). CHIT trail **signed** via `b850-claude`, `hmac: FewPTdETk9oq2w2gPjaUTPmWWK2Olz86XoK7W+1cPHc=`, kid `chit-signing-v01`, card `...036`. `agent_signature: CLAIM::B850-CLAUDE::REVIEW-GATE-TOPOLOGY::Opus-5::2026-08-28`.