RF — TFW_20260830-114238_ASSISTED15: Neutral Assisted 1.5 Product and Maintenance Bridge¶
Date: 2026-08-30 Author: saubakirov via Codex Executor Status: 🟢 RF — Complete Parent HL: HL-TFW_20260830-114238_ASSISTED15 TS: TS — TFW_20260830-114238_ASSISTED15
1. What Was Done¶
New Files¶
| File | Description |
|---|---|
editions/02-assisted/{VERSION,CHANGELOG.md} |
Exact public Assisted 1.5 authority and public-only history |
editions/02-assisted/.agents/skills/{tfw-plan,tfw-handoff,tfw-review,tfw-update,tfw-identity}/ |
Five complete manual/autonomous role contracts and metadata |
editions/02-assisted/.agents/skills/tfw-identity/scripts/tfw_identity.py |
Cross-platform fail-closed profiles, resolution, machine-local binding and V7–V8 matrix |
editions/ASSISTED_MAINTENANCE.md |
Public/core-overlay maintenance contract and both-direction route |
editions/maintenance/{assisted_maintenance.py,release-manifest.json,maintenance-policy.json} |
Canonical release boundary, deterministic authority policy, gated P2/reverse implementation and V1–V12 entry point |
editions/02-assisted/шаблоны/{заметка.md,план_работы.md,документ_A4.md,презентация.html,build_a4.py,theme.css} |
Complete neutral Russian worked examples and offline A4 builder |
editions/02-assisted/шаблоны/{overlay/theme.css,assets/tfw-mark.svg} |
Restricted six-property customization overlay and neutral shape-only mark |
workspace/2026/TFW_20260830-114238_ASSISTED15/evidence/ |
Actual Windows, P2/reverse/P6, blocked-network render, visual and deterministic verification package |
Modified Files¶
| File | Changes |
|---|---|
editions/README.md |
Assisted selection now states 1.5 lifecycle, standalone boundary and capability limits accurately |
editions/02-assisted/{AGENTS.md,README.md,PROJECT.md,MIGRATION.md} |
Neutral 1.5 service contract, onboarding, uninitialized project and migration behavior |
editions/02-assisted/{people/README.md,knowledge/INDEX.md} |
Empty participant/knowledge navigation with no shipped project or organization state |
Deleted Files¶
| File | Reason |
|---|---|
editions/02-assisted/.codex/hooks.json |
Exact known stock lifecycle-hook registration retired |
editions/02-assisted/.codex/hooks/tfw-hook.ps1 |
Exact known stock PowerShell hook retired |
editions/02-assisted/.codex/hooks/tfw-hook.sh |
Exact known stock shell hook retired |
Product commits are local: 957c70f (complete product), c6f1b0f (expanded identity matrix), ca1ef26 (offline render pagination/readability), b37f7a3 (D1–D7 safety correction), and afef18a (D9–D10 stable-lock and first-access-order correction). No push or tag occurred.
2. Key Decisions¶
- The public product contains universal behavior, not field payload. Field mechanisms informed lifecycle, identity, templates and maintenance constraints; organization facts, people, branding, paths and private history were excluded.
- The frozen topology is authoritative: maintainer tooling lives at
editions/maintenance/witheditions/ASSISTED_MAINTENANCE.md; the copied02-assistedstarter remains independently usable through complete manual contracts. - Forward and reverse maintenance are intentionally asymmetric. P2 first proves an exact regenerated release payload, carries the self-excluded manifest as a separate release record, pins every operation/staging ancestry, and acquires one stable private target-keyed OS lock before operation-directory creation, baseline capture, staging or product writes. Reverse accepts only closed terminal+journal provenance and creates one exactly approved candidate outside every protected root. The mixed field tree stays P6 read-only.
- Identity persistence requires the bounded
operational-local-v1proof at operation time. The full namespace chain is pinned after creation and private owner/ACL state is positively reprobed before any registry or lock existence/type/read access, with every registry read kept inside that validated live lock. Ambiguous profiles, permissive ACLs, namespace substitution, unsafe storage, live lock, reparse/root drift or invalid state returns no participant and zero persistent writes; session-only use remains complete. - Template customization is a versioned restricted interface: one six-property
:rootoverlay and one neutral shape-only local SVG. Offline builder defaults stay relative to the copied template directory and reject escaping/external/active resources. - The research/source aggregate digest distinction is documented rather than normalized away: the complete 29 per-file rows match, while PowerShell culture sort and Python code-point sort produce different aggregate digests. Two initial fail-closed aborts occurred before fixtures, then the same-row proof authorized resumption without changing source authority.
3. Acceptance Criteria¶
- [x] AC-1 — complete uninitialized standalone 1.5, exact version/history and frozen product boundary
- [x] AC-2 — exact regenerated payload equality, portable acyclic manifest/policy and exact hook retirement
- [x] AC-3 — pinned source/target/operation/stage ancestry, stable target-keyed lock, immutable preflight, create-once partial and linked recovery
- [x] AC-4 — complete five-skill lifecycle/manual baseline and recorded seven-scenario role reuse table; same-Reviewer full re-review is the next lifecycle gate
- [x] AC-5 — installed state, customization, unknown paths and separate Full namespace preserved
- [x] AC-6 — closed-provenance, confined candidate-only reverse projection and non-mutating P6 field treatment
- [x] AC-7 — fail-closed identity semantics, surname/collision matrix and zero-write fallback
- [x] AC-8 — operation-time Windows ACL/owner proof before first access, full namespace pin, live OS lock, reparse/substitution defense and honest limits
- [x] AC-9 — complete neutral Russian templates, restricted TI1, header-free blocked-network renders and 20 replacement inspections
- [x] AC-10 — product-wide agreement and zero downstream/company residue
- [x] AC-11 — shipped V1–V12 matrix repeated deterministically with task schema validation
- [x] AC-12 — both isolated maintenance directions, identical field pre/post rows and no publication; explicit Reviewer acceptance is the next lifecycle gate
4. Verification¶
- Release integrity:
verify-releasepassed twice with manifestf09603aa…c66eaand policy2caf8bba…d64b07; omitted/extra/self/nonregular hostile payload cases reject. - Complete shipped verification:
self-test --source-root editionspassed twice with V1–V12 alltrue. Its retained REAL two-process fixture proves one stable lock key for the same target, blocks the loser before operation-directory creation with zero target/product writes, and allows a different target to proceed independently. - Identity: full V7–V8 matrix passed twice with all 25 checks true; actual Windows private ACL and complete created namespace chain were proven. Instrumentation proves reprobe precedes the first registry read, and namespace substitution before that first read causes zero substituted reads and zero registry writes. Project-root, live-lock, junction/reparse, permissive-ACL and other namespace-substitution cases stayed zero-write. The documented
--organization-rolecommand ran from a clean copy and createdivanov. - Templates: static attack/self-test passed twice; four stock/custom outputs rendered with network resolution blocked and print headers disabled, parsed as 3+3+5+5 pages, and all 16 page images plus four single-shot full captures were visually inspected. Every
.pnghas PNG bytes and no stitch overlap. - Actual directions: populated P2 reached verifiable 1.5 with exact manifest carry and protected bytes unchanged; a clean target served as the next source. Injected partial/recovery history remained immutable. Closed reverse provenance produced byte-identical candidates, while fake-report and public-root attacks wrote nothing.
- Source: 29-row inventory is equal across PowerShell/Python and pre/post; both documented aggregate digests are stable.
- Boundary: product is exactly 35 paths / 4,035 changed lines; private-token scan has zero hits;
git diff --checkpassed. The post-commit run enumerated all 20 Assisted commits through terminal evidence640fad5with zero forbidden-path hits and found it in no remote-tracking ref or tag. This attestation-only follow-up is exact-path staged to RF/EV/log/attestation/summary only; concurrent forbidden paths are separately enumerated as external dirty/commits and were neither staged nor modified here. - Task traces: project and task closed-schema checks pass.
- Reproducibility: the corrected evidence runner repeated twice with identical summary SHA-256
4b24de24…5cc0c.
Full commands and outputs: evidence/assisted15-verification.log.
Review correction closure¶
| Finding | Closure | Primary evidence |
|---|---|---|
| D1 | Exact regenerated payload equality; omitted/extra/self/nonregular hostile cases reject | assisted15-fixture-results.json → maintenance.v1_v12.details.manifest_hostile |
| D2 | Manifest is a separately journaled release record; target verifies and clean target is reusable as source | maintenance/forward-journal.ndjson; fixture manifest_*, target_verified_release, next_source_ready |
| D3 | Source/target/operation/stage component chains pin; Windows junction ancestry rejects before writes | fixture operation_link_rejected; shipped V3 |
| D4 | Created identity namespace is fully pinned and private ACL/owner-proven; permissive ACL and substitution stay zero-write | identity-windows.json; shipped V8 |
| D5 | Reverse requires closed terminal+journal provenance, exact outside candidate root and pinned recheck; fake/public-root attacks reject | fixture reverse and v1_v12.details.reverse_hostile |
| D6 | Seven deterministic input/expected/observed role records pass; actual one-Coordinator/same-Executor/one-Reviewer lineage retained | fixture role_lineage and role_tabletop; review/verify.md |
| D7 | Skill/parser use --organization-role; documented clean-copy command executed and created ivanov |
identity-windows.json; boundary-summary.json |
| D8 | Header-free PDFs, true-PNG replacements, four single-shot full captures, 20/20 visual inspections, zero stitch overlap | templates/render-summary.json; replacement media |
| D9 | Stable private target-keyed lock is independent of operation directories; retained REAL two-process fixture proves same-target exclusion before writes and different-target independence | fixture maintenance.v1_v12.details.same_target_contention; shipped V3/V11 |
| D10 | Full namespace/ACL reprobe occurs before first registry/lock access; instrumented pre-read substitution records zero substituted reads and zero registry writes | identity-windows.json; shipped V8/V11 |
5. Evidence¶
Cognitive mode: Observational verification — evidence lives in the EV file, not inline.
See EV file for evidence details.
Evidence verdict: 11/12 VERIFIED, 1 DEFERRED, 0 BLOCKED, 0 N/A
The one deferred row represents the remaining lifecycle leg: the same independent Reviewer must rerun the complete contract on this corrected terminal RF/evidence. E4 lineage and scenario coverage were already accepted in review revision 2; all implementation, fixture, source and publication checks required for the terminal review are present and resolvable.
6. Observations (out-of-scope, not modified)¶
No observations.
7. Fact Candidates¶
| # | Category | Candidate | Source | Confidence |
|---|---|---|---|---|
| 1 | product | The public personal Assisted starter should ship reusable templates and universal workflow behavior, while organization knowledge remains in the real field application and is not copied into the starter. | User, task inception clarification | High |
| 2 | process | Future Assisted improvements must be able to move safely from public core to field application and, when generic, from field evidence back toward public core. | User, task objective | High |
8. Strategic Insights (Execution)¶
| # | Insight | Category | Source |
|---|---|---|---|
| S1 | A useful public methodology should promote the best repeatable mechanisms from real practice while excluding the practice's organization-specific state. This implies an explicit overlay boundary and reviewed candidate promotion, not a symmetric folder mirror. | product | User, distinction between personal template and real field application |
| S2 | Bidirectional evolution is trustworthy only when authority differs by direction: verified stock may move forward automatically under a closed baseline, while field discoveries move backward only as privacy-safe candidates for independent review. | process | User, requirement that later updates may move either way |
9. Diagrams¶
public Assisted release (manifest + policy)
│
│ P2: accepted prior + clean baseline + exact approval
▼
isolated/downstream Assisted core ─── preserves ──► work / people / knowledge / project / overlay
│
│ private append-only operation report
▼
closed public projection ──► generic candidate ──► independent review ──► future public decision
real mixed field tree ── P6 read-only inventory/digest only ──► candidate evidence
RF — TFW_20260830-114238_ASSISTED15: Neutral Assisted 1.5 Product and Maintenance Bridge | 2026-08-30