Agent-Sudo went live on both hosts tonight (005c214 in the boilerplates repo). This
records what "done" actually means and what is left, since dedicated time on this ends
today and the rest has to run via background agents.
Corrects the goal: tier 4 is human-only BY DESIGN (D-CB7) — the daemon unit env holds
SUDO_MD_VERIFY_ENFORCE, so a system that can restart its own daemon can disarm its own
gate. "Handling tier 4" means refusing it, which is done and verified. Real remaining
scope is tiers 1-3.
Records the measured Incus asymmetry (server-01 has it, primary does not), which makes
tier 2 on primary an open design question rather than a task; the tier-1 scoped-undo
defect (app.py:244 hardcodes tier 3 while REQUIRES_UNDO_TIERS is (1,3)); and the
per-host-values-in-a-shared-tracked-file bug class that bit twice in one directory.
secrets-proxy is deliberately scoped as investigate-then-plan: it exited gracefully and
nobody knows why, so S1 answers that before anyone writes S2.
Refs #128, #146, #149, #150, #173, #191, projects id=187.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- agent_sudo_design_decisions.md: D-CB5 (3 tier-3 fails / 15min sliding / per-host),
D-CB6 (append-only breaker log, state always replayed — tamper-EVIDENT beats
tamper-PROOF when the daemon is root), D-CB7 (Set B host_override in code),
D-CB8 (which tier-4 sources latch), D-CB9 (trip escalation). Each with rationale,
rejected alternatives, and accepted costs.
- agent_prompts.md: add the P3-WIRING prompt. Flags a real NAME COLLISION — the
existing "P3" section is the OLD P3 (Vault AppRole + Timeshift + evaluator, done
as #142); P3 was redefined after D-CB1-D-CB9 were locked. Running the old one
would redo finished work. Today's inline agent prompts were never persisted, which
is why this one is.
- context.md: P3 code complete but UNDEPLOYED — the server-01 tier-0 breaker.log hole
is open in production until DEPLOY_RUNBOOK.md runs. Two verified deploy blockers
(Dockerfile never COPYs circuit_breaker.py/security/; compose has no
/var/lib/agent-sudo mount => breaker resettable by docker restart, the exact D-CB6
bypass). Both were invisible to an 85/85-green suite.
- context.md: MEMORY_DIR answered — do NOT repoint embed_memory_dir.py; its
claude_memories table has no reader. Recall corpus now includes design docs;
context.md stays excluded until #192 prunes it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- constrained_autonomy_design_decisions.md: D1-D8 locked (hybrid hook
classifier + Agent-Sudo daemon executor, structural classification with
unknown->sandbox, fail-closed, Hermes recovery ladder) + EXECUTION ORDER
with CA-P1a inserted as zero-dependency item 0
- agent_prompts.md shared block: replace "TIER-2 IS BROKEN" with the
corrected root cause (old primary bridge's NTFY endpoint was unreachable;
tier-2 works when the bridge reaches ntfy + user is attended)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- P0 build prompt now does Part A (command_audit schema) + Part B
(read-only audit of all P1-P5 assumptions) + Part C (remediate safe
findings = all of P1: Incus install, host inventories, build-sandbox.sh,
both sandbox mirrors)
- Golden Rule: only remediate read-only or server-01-sandbox findings;
tier-2/manual-auth or prod-touching → batched, never blocked
- Ends with a BUILD READINESS wrap-up so the focused build starts at P2
- P1 section retained as canonical contract reference, marked folded-in
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>