Skip to content

Add falsification-first control loop and evidence-bound Guardian patch sessions - #1

Open
Question86 wants to merge 20 commits into
v3from
v3-axiom-atlas-loop
Open

Question86 wants to merge 20 commits into
v3from
v3-axiom-atlas-loop

Conversation

@Question86

@Question86 Question86 commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

This branch contains the falsification-first Werkfaden operating method and the deterministic Guardian v2 implementation that enforces the supported investigation-to-mutation path.

Core loop:

Human problem -> hypothesis -> Falsifier 1 -> Falsifier 2 -> map -> counterprobe -> exact source -> prove -> patch session (TX1..TXn) -> verified heartbeat -> fresh run -> return to top

Architecture changes:

  • adds START_HERE_AGENT, the Memory verification protocol, the hypothesis-to-patch contract, and the AXIOM semantic Runtime atlas;
  • makes Memory verification temporal: guard-enter <STATE> returns exact state-relevant canonical Memory passages before the state action; completion consumes the same state ticket;
  • validates semantic and structural falsifiers as fresh/session-bound evidence instead of opaque strings;
  • state-gates supported KAIROS source escalation so source permits/search cannot become an early discovery shortcut;
  • replaces the v1 single-TX Guardian with one proven patch session that may own TX1..TXn, with rolling package identity and available/consumed scope;
  • moves Guardian enforcement below the Workshop CLI into the public WorkshopEngine lease/state boundary, covering direct supported Python mutation calls;
  • applies the same patch-session boundary to normal transactions, auxiliary document transactions, static source-set transactions, and C-family header-authority migrations;
  • validates actual prepared mutation scope and exact-source edit windows before live apply;
  • binds patch completion to real POSTCHECK_VERIFIED transactions and the exact verified Workshop heartbeat;
  • closes a Guardian only from a content-bound fresh-run receipt tied to the final package, heartbeat, state ticket, executor, artifacts, active-criterion problem evidence, and configured validation receipts;
  • adds session locking, atomic state replacement, hash-chained Guardian history, bounded crash reconciliation, and canonical Workshop-control-plane enforcement;
  • retains the structurally superseded v1 Guardian/engine/CLI/search-policy sources under quarantine/ as non-supported audit history rather than deleting them.

Audit/remediation rationale is recorded in workshop/GUARDIAN_AUDIT_REMEDIATION.md.

Important boundary: Guardian v2 closes the supported application-level mutation/source-escalation paths. It is not an OS sandbox. A process with unrestricted filesystem/database write rights can still bypass application code; that remains owned by the Workshop ACL/service-identity boundary and a later native-tool hook.

No FTS ranking/scoring changes are introduced. Graph resolves structure, search resolves governed questions, and source-search resolves exact bytes.

Validation on current head:

  • compileall: PASS
  • full KAIROS harness: 148/148 PASS
  • full Kickstart: 34/34 PASS
  • full Workshop: 31/31 PASS
  • universal intake gate: PASS

The v3 final-seal regression census is updated to 213 (= 148 + 34 + 31).

Copy link
Copy Markdown
Owner Author

Guardian update: this branch now includes an opt-in deterministic pre-mutation gate for the normal Workshop checkout path. With guardian_required=true (or WERKFADEN_GUARDIAN_REQUIRED=1 for a temporary test), coding checkout is refused until a Guardian ledger has traversed HYPOTHESIS -> FALSIFIER_1 -> FALSIFIER_2 -> MAP -> COUNTERPROBE -> EXACT_SOURCE -> PROVE in order. Every state requires canonical-Memory references; EXACT_SOURCE additionally requires a real VERIFIED KAIROS SIR_... receipt; PROVE freezes exact source scope; guarded checkout must match that scope exactly and is the only transition into PATCH. WORKSHOP -> HEARTBEAT -> FRESH_RUN closes the ledger after mutation. See workshop/GUARDIAN.md. This is workflow enforcement, not a hostile-process sandbox: direct OS-level bypass still belongs to a later hook/ACL boundary.

@Question86 Question86 changed the title Bind falsification-first investigation loop and AXIOM semantic runtime atlas Add falsification-first control loop and evidence-bound Guardian patch sessions Sep 16, 2026

Copy link
Copy Markdown
Owner Author

Guardian v2 remediation is now on the branch.

Architecture changes are recorded in workshop/GUARDIAN_AUDIT_REMEDIATION.md. The important replacement is structural, not a patch around v1: PATCH is now a persistent evidence-bound patch session that can own TX1..TXn, with rolling package identity, available/consumed scope, one active TX, state-ticketed Memory preflight, typed receipt validation, engine-level mutation enforcement, and real postcheck/heartbeat/fresh-run closure. The superseded v1 engine/Guardian/CLI/search-policy sources are retained under quarantine/ and are no longer supported public surfaces.

Current CI on head 1d0bcf7f411630586104c8d6f420662bce8ac41a:

  • compileall: PASS
  • full KAIROS harness: 148/148 PASS
  • full Kickstart: 34/34 PASS
  • full Workshop: 31/31 PASS
  • universal intake gate: PASS

The v3 final-seal census has therefore been updated to 148 + 34 + 31 = 213 tests.

Remaining explicit boundary: Guardian v2 closes the supported application-level Workshop/KAIROS source-escalation paths. It is not an OS sandbox. A process with unrestricted filesystem/database write rights can still bypass Python-level enforcement; that remains owned by SECURITY_BOUNDARY.md, the service-identity/ACL deployment, and the later native-tool hook. The branch does not claim otherwise.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant