- agent_sudo_design_decisions.md: D-CB5 (3 tier-3 fails / 15min sliding / per-host),
D-CB6 (append-only breaker log, state always replayed — tamper-EVIDENT beats
tamper-PROOF when the daemon is root), D-CB7 (Set B host_override in code),
D-CB8 (which tier-4 sources latch), D-CB9 (trip escalation). Each with rationale,
rejected alternatives, and accepted costs.
- agent_prompts.md: add the P3-WIRING prompt. Flags a real NAME COLLISION — the
existing "P3" section is the OLD P3 (Vault AppRole + Timeshift + evaluator, done
as #142); P3 was redefined after D-CB1-D-CB9 were locked. Running the old one
would redo finished work. Today's inline agent prompts were never persisted, which
is why this one is.
- context.md: P3 code complete but UNDEPLOYED — the server-01 tier-0 breaker.log hole
is open in production until DEPLOY_RUNBOOK.md runs. Two verified deploy blockers
(Dockerfile never COPYs circuit_breaker.py/security/; compose has no
/var/lib/agent-sudo mount => breaker resettable by docker restart, the exact D-CB6
bypass). Both were invisible to an 85/85-green suite.
- context.md: MEMORY_DIR answered — do NOT repoint embed_memory_dir.py; its
claude_memories table has no reader. Recall corpus now includes design docs;
context.md stays excluded until #192 prunes it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- constrained_autonomy_design_decisions.md: D1-D8 locked (hybrid hook
classifier + Agent-Sudo daemon executor, structural classification with
unknown->sandbox, fail-closed, Hermes recovery ladder) + EXECUTION ORDER
with CA-P1a inserted as zero-dependency item 0
- agent_prompts.md shared block: replace "TIER-2 IS BROKEN" with the
corrected root cause (old primary bridge's NTFY endpoint was unreachable;
tier-2 works when the bridge reaches ntfy + user is attended)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- P0 build prompt now does Part A (command_audit schema) + Part B
(read-only audit of all P1-P5 assumptions) + Part C (remediate safe
findings = all of P1: Incus install, host inventories, build-sandbox.sh,
both sandbox mirrors)
- Golden Rule: only remediate read-only or server-01-sandbox findings;
tier-2/manual-auth or prod-touching → batched, never blocked
- Ends with a BUILD READINESS wrap-up so the focused build starts at P2
- P1 section retained as canonical contract reference, marked folded-in
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>