You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Perform an independent, adversarial, release-candidate-bound security and recovery review of the complete Daimon Matrix V0 implementation and private canary evidence. Reproduce the declared tests from a clean environment, add independent attack probes, restore canonical and encrypted state through separate drills, audit migration/rollback/adapter disablement, publish all findings and residual risks, obtain exact-head approval after fixes, and require an explicit human go/no-go decision before release.
This card is a gate, not a ceremonial checklist. Green CI, author self-report, prior component reviews, or a plausible threat model do not prove release readiness.
Blocked by
DM-055 Tribe runtime cutover is complete and its final provenance/no-history report plus pre-archive handoff plan are available; final source tagging/archive remains sequenced after release and is not a pre-release blocker.
DM-061 compatible species update and branching implementation is complete.
DM-071 consented external relationship/source canary is complete with participant-approved redacted evidence.
DM-072 reversible private CompAII canary is complete with human-approved redacted evidence.
DM-074 harness-adoption guide and synthetic fixtures are merged, so the audit reviews them rather than approving an older candidate.
DM-076 release-candidate preparation is merged and has frozen all release notes, manifests, build inputs, documentation and proposed artifact bytes on the exact default-branch candidate; publication remains gated by this review.
Every other V0 implementation/test/ops issue except the later publication and source-archive cards is closed or has a release-blocking disposition that does not defer required V0 behavior.
Keep status:blocked until all gates close. The candidate commit, package bytes, deployment/config template digests, dependency lock, and evidence set must then freeze for review; any code/schema/dependency/build/config change invalidates the approval and requires scoped re-review.
Independence and review protocol
Reviewer must not be the author of the candidate changes and must work read-only in a clean clone/worktree/environment from the exact candidate commit. Separate operator accounts are preferred; when GitHub identity is shared, the report must name the independent reviewer principal and explicit textual APPROVE/REQUEST_CHANGES verdict bound to the exact SHA.
Review the complete cumulative diff from the last independently approved release/baseline, not only the final fix commit. Read normative specs, issues/acceptance criteria, source, schemas, migrations, tests/vectors, CI/build/deployment/runbooks, and author review records—the latter last as self-report.
Reproduce commands and expected counts independently. Inspect what each test actually covers; a passing count, tautology, mocked shortcut, skipped capability, or synthetic-only assertion cannot support a broader claim.
Create independent adversarial probes and retain reproducible redacted scripts/fixtures/results. Do not use production secrets/private state or mutate live services.
Every finding has stable ID, severity, affected invariant/artifact/path, evidence/reproducer, exploit/failure impact, required fix or accepted rationale, owner, status, and exact resolving commit/re-review.
critical, high, or release-boundary medium findings block. A nonblocking residual risk requires explicit rationale, bounded exposure, mitigation/monitor, future issue and human acceptance; severity cannot be lowered merely to ship.
Fixes land under new signed claims/PRs and full relevant CI. The original reviewer verifies the exact new head and states whether each finding is closed; an approval of an older SHA never transfers.
Candidate and evidence manifest
Produce a closed content-addressed v0-security-review-manifest/v0 containing only public/redacted evidence:
Python/runtime/platform/dependency lock, SBOM/license/provenance, pinned CI actions/builders and reproducible-build environment;
list and immutable digest of every V0 issue, PR/claim/review, conformance corpus, required scenario registry, test command/report, canary/cutover/recovery report and residual-risk register;
public deployment topology/authority-role model and digests of private effective configurations—never paths, endpoints, keys, tokens, memory or member rosters;
For every trust boundary identify assets, authority it may and may not exercise, entry points, persistent state, replay/fork/high-water keys, confidentiality/classification, resource bounds, failure mode, recovery authority, and observable evidence.
Identity, custody, and presence review
Independently recompute me_id, content/key/certificate/genesis/control/revocation/acceptance IDs/hashes/signatures/domains/thresholds and strict JSON/JCS for fresh and checked-in vectors.
Verify root/recovery private keys remain offline/role-separated and never appear in body/adapter/Cluster/harness/provider/backup/log/build/process state. Keystore permissions/symlink/hardlink/path/TOCTOU, passphrase/KDF, atomic write/fsync, backup/restore and generic-signing absence are probed.
Exercise identity-wide lease sequence/predecessor/external receipt, expiry/clock rollback, event cutoff, competing active bodies, stale restore/reacquire, witness compromise, route union, and split-brain quarantine. No name/host/harness/Tribe/state snapshot can upgrade unverifiable identity/presence.
Prove distinct Codex/Hermes me_id values/roots in one /we and one active body maximum per identity. Shared inputs remain attributed, not shared autobiography.
Canonical artifacts, ledger, persistence, and cursors
Race the authenticated single-writer daemon with multiple processes/clients, request/idempotency conflicts, commit-before-response, crash/disk full/WAL/corruption/fsync failures, clock skew, transaction interruption and stale connections. Direct database writes/handles are not public protocol.
Verify canonical events/CAS are authority; projections/indexes/HMK/Wiki/queues/caches are rebuildable and cannot originate/correct/retract state. Forks quarantine; timestamps/arrival/order/hash never pick winners.
Disable each adapter/provider one at a time and all optional adapters together. Canonical state, high-waters, receipts and audit history remain readable/rebuildable; provider-owned projections may disappear but cannot delete or reinterpret ledger/CAS state. Re-enable/replacement rebuilds from immutable refs without duplicate effects.
Cryptography, messages, routes, and privacy
Independently implement/check RFC/JCS cryptographic preimages and every DM-011 key/ID/signature/HPKE/AEAD size/domain; probe all-zero/low-order/malformed keys, nonce/CEK reuse, wrong AAD/info/protected metadata, recipient/key/sender/disclosure substitution, ciphertext/tag/signature tampering and oracle behavior.
Same logical message/thread IDs survive fan-out/retry/reseal; delivery ID replay conflicts are separate from per-recipient semantic dedup. Direct/hub duplicates and ambiguous timeout ingest/effect once.
Forge/expand/swap /we, relationship, direct-reply and sealed recipient sets; test wrong route/body/key/cert/adapter, ACK-versus-intake confusion, terminal receipt conflict, expiry/transport classification, outbox after envelope expiry and crash recovery.
Route fallback happens only after typed unavailability, never authenticated crypto/policy/protocol rejection. Hub cannot decrypt/rewrap/expand or claim delivery. @localhost rejects remote/mixed audiences before any remote effect/key wrap.
Probe unauthorized .status/resolution/inbox/cursor/directory/route/grant/revocation errors and timing as membership/backlog/capability oracles. /everyone remains explicitly bounded/public/disabled by default.
Gateway/mirror escaping, length/chunking, allowlists, provenance, inbound attribution, token/log redaction and disabled-by-default state receive independent tests.
Membership, delegation, source, memory, birth, and species
/we: threshold/root acceptance, governance rotation possession, removal/replay, ambiguous alias pin, pending transition, unrepresentable policy, late sibling/fork, active-presence intersection, frozen resolution and no collective key/voice.
DM-016: forged cards/handshakes/grants/acceptances, subject/controller/relationship/resource/operation/classification mismatch, delegation attenuation/depth/birth limits, predecessor gaps/forks, expiry/closure/revocation/relinquishment, stale cache/partition, descendant resurrection and disclosure/roster oracles.
DM-017/030–036: category/author/context/derivation/lane predecessor, correction/retraction/fork, personal versus peer/source/tribal/species/incarnation boundary, policy determinism/stale plan, worker/model/reviewer/Librarian authority, projection overlap and final rendered artifact/secret scan.
Adapters, harnesses, Librarian, and Matrix↔Cluster
DM-018 manifests negotiate exact versions, retain accepted-version high-water, fail unknown/downgrade, enforce all false authority flags, content refs/idempotency, secret/path/DB exclusion, migration/export/apply/verify/commit/rollback monotonicity and no adapter-selected canonical authority.
Codex/Hermes effective config, isolated homes/profiles/sessions, prompt/role-prefix stability, native-memory policy, plugin/hook/tool/MCP allowlist and host-default fallback are reviewed. Kill/restart at every harness/daemon boundary and inspect open files/process/env/log/archive leakage.
Matrix↔Cluster controller authentication/delegation, genuine CAS, permanent monotonic fence, Matrix presence/fence dual admission, park/wake saga, failed wake successor, restored volume/HMK/profile/controller state, FakeSigner/placeholder rejection and no one-gate ACK/effect are independently exercised.
Binder/activation/migration TOCTOU: mutate manifest/content/policy/key/head/config between plan/verify/apply/exec/receipt; every effect revalidates exact bytes/high-waters immediately before commit and binds them atomically in its receipt.
Separate recovery drills
A. Ledger/CAS reconstruction
Build a synthetic but complete accepted V0 state through installed daemon interfaces: identities, /we, events/checkpoints, memory lanes, relationships/grants/revocation, source/species/application, messages/receipts/cursors and adapter evidence.
Stop services; preserve only canonical ledger/event/CAS bytes plus required public proofs and separately authorized keys. Remove/move every projection, index, cache, HMK/Wiki DB, route queue, adapter DB, runtime pointer and generated state from the isolated test root.
Install the exact candidate wheel cleanly and rebuild all projections through public recovery APIs. Compare canonical heads/hashes, effective state, exclusions, cursors and rendered approved public outcomes—not implementation DB bytes.
Corrupt/omit/reorder/fork canonical inputs and prove incomplete/quarantine/refusal without invented state or destructive repair. Repeat rebuild and compare deterministic digests.
B. Encrypted backup restoration
Independently create the supported encrypted backup from the same cutoff, binding format/version/KDF/AEAD/content manifest/checkpoint/high-waters and excluding ephemeral caches/secrets not intended for backup.
Restore into a fresh isolated owner-only target with no pre-existing state, using the documented key/recovery ceremony. Verify ciphertext tamper, wrong key/passphrase, truncation, rollback/stale backup, path/symlink/archive traversal, permission, partial write, disk-full and interrupted restore failures.
Revalidate every restored canonical byte/key role/head against current durable anti-rollback evidence before activation. A backup cannot resurrect revoked keys, removed members, stale leases/fences/grants, retracted memory or old runtime pointers.
Rebuild projections and compare to Drill A. Exercise disablement/restart and a new successor event after restore. Preserve a redacted proof of recovery; destroy only exact temporary test roots.
The drills prove different properties. A ledger rebuild is not proof that backup encryption/restore works, and a byte-restored DB is not proof of canonical reconstruction or current authority.
Migration, v0 containment, supply chain, and release artifacts
Verify Tribe v0 parser/listener/service/key/history/dual-write/downgrade remains absent and cannot be re-enabled by rollback/config/import. Matrix starts empty and rejects Tribe v0/v1 history/private-state import; DM-050 source provenance is not runtime/state migration.
Reproduce DM-018 storage/provider migrations and every rollback as forward successor state; no deleted receipt, regressed high-water, category/identity collapse or restored DB authority.
Confirm the DM-055 Tribe cutover report, proposed source-archive target/notice handoff and zero runtime dependency; current Matrix/CompAII review works without Tribe. Final source tagging/archive is sequenced after release and is not evidence for candidate safety.
Generate clean sdist/wheel/source archives twice in independent environments; compare allowed deterministic contents/hashes. Inspect generated metadata, schemas/vectors/docs/licenses/SBOM/provenance and entry points.
Scan Git history/current tree, archives, wheels, containers, fixtures, test reports, caches, logs, crash artifacts and canary/security evidence for secrets, private keys, credentials, endpoints, personal memory/prompts/reasoning, database/state snapshots and unsafe paths. A source-only scan is insufficient.
Findings, residual risk, and release decision
Publish SECURITY-REVIEW-V0.md (or equivalent reviewed report) plus machine-readable findings manifest. It includes scope/head, methodology, reproduced commands/counts, independent probes, coverage matrix, findings/evidence/fixes/reviews, recovery results, artifact digests, limitations and residual risks. Redact private canary/external participant data while retaining independently checkable public evidence.
APPROVE: exact candidate head/artifacts/config-template/evidence were reviewed; all blockers closed; every nonblocker recorded; reviewer explicitly recommends release subject to human approval.
After exact-head APPROVE, the human release owner reviews the full report/residual-risk register and records an explicit GO or NO-GO tied to the same manifest/candidate. Silence, issue closure, merge permission, or author intent is not approval. A GO authorizes only DM-075 publication/tagging of the already reviewed commit and bytes. Any candidate-affecting code, schema, dependency, build, configuration, fixture, documentation, release-metadata or artifact change reopens review.
Acceptance criteria
An independent reviewer binds scope and verdict to the exact immutable release-candidate SHA/artifacts/evidence and reproduces the full declared suite in a clean environment.
Ledger/CAS-only reconstruction and encrypted-backup restore are run separately, adversarially mutated, compared, repeated and proven not to restore stale authority.
Disabling every adapter/provider leaves canonical retained state/history intact and rebuildable; replacement/re-enable cannot duplicate or reinterpret it.
Source and final generated artifacts pass reproducible-build, provenance/SBOM/license/dependency/CI and full secret/private-state scans.
Every finding is resolved on an exact re-reviewed head or explicitly retained as a bounded nonblocking residual risk with owner/mitigation/follow-up.
Reviewer issues exact-head APPROVE, then the human owner records explicit same-candidate release GO; otherwise release remains blocked.
Non-goals
No live production penetration test, unsolicited external probing, disclosure of secrets/private canary data, destructive production recovery, or vulnerability publication before coordinated remediation.
No production code fix hidden inside the review claim; fixes use focused claims/PRs and exact-head re-review.
No claim of formal verification, perfect confidentiality, sentience, global freshness, forward secrecy/PCS/MLS, or elimination of every operational risk beyond the documented V0 threat model.
Safety and rollback
All destructive/fault/recovery tests target validated synthetic temporary roots or separately approved isolated backups. Never signal processes by broad name, scan external systems, alter participant infrastructure, or delete live state. Review failure leaves the candidate unreleased and canary disabled/parked through its documented successor procedure; it never regresses high-waters or enables Tribe v0.
Do not claim until every blocker is complete and the candidate/evidence manifest is frozen. The signed review claim may add only review harnesses/fixtures/reports; any implementation change requires a separate claim and resets exact-head approval.
Outcome
Perform an independent, adversarial, release-candidate-bound security and recovery review of the complete Daimon Matrix V0 implementation and private canary evidence. Reproduce the declared tests from a clean environment, add independent attack probes, restore canonical and encrypted state through separate drills, audit migration/rollback/adapter disablement, publish all findings and residual risks, obtain exact-head approval after fixes, and require an explicit human go/no-go decision before release.
This card is a gate, not a ceremonial checklist. Green CI, author self-report, prior component reviews, or a plausible threat model do not prove release readiness.
Blocked by
Keep
status:blockeduntil all gates close. The candidate commit, package bytes, deployment/config template digests, dependency lock, and evidence set must then freeze for review; any code/schema/dependency/build/config change invalidates the approval and requires scoped re-review.Independence and review protocol
APPROVE/REQUEST_CHANGESverdict bound to the exact SHA.critical,high, or release-boundarymediumfindings block. A nonblocking residual risk requires explicit rationale, bounded exposure, mitigation/monitor, future issue and human acceptance; severity cannot be lowered merely to ship.Candidate and evidence manifest
Produce a closed content-addressed
v0-security-review-manifest/v0containing only public/redacted evidence:Manifest mismatch, missing evidence, dirty tree, mutable dependency/action/tag, unreviewed generated artifact, or candidate head movement fails preflight.
Threat model and attacker roles
Test at least these independent/combined actors:
/wegovernance signer, birth parent/bootstrap/witness, and dependency/build/release contributor;For every trust boundary identify assets, authority it may and may not exercise, entry points, persistent state, replay/fork/high-water keys, confidentiality/classification, resource bounds, failure mode, recovery authority, and observable evidence.
Identity, custody, and presence review
me_id, content/key/certificate/genesis/control/revocation/acceptance IDs/hashes/signatures/domains/thresholds and strict JSON/JCS for fresh and checked-in vectors.me_idvalues/roots in one/weand one active body maximum per identity. Shared inputs remain attributed, not shared autobiography.Canonical artifacts, ledger, persistence, and cursors
Cryptography, messages, routes, and privacy
/we, relationship, direct-reply and sealed recipient sets; test wrong route/body/key/cert/adapter, ACK-versus-intake confusion, terminal receipt conflict, expiry/transport classification, outbox after envelope expiry and crash recovery.@localhostrejects remote/mixed audiences before any remote effect/key wrap..status/resolution/inbox/cursor/directory/route/grant/revocation errors and timing as membership/backlog/capability oracles./everyoneremains explicitly bounded/public/disabled by default.Membership, delegation, source, memory, birth, and species
/we: threshold/root acceptance, governance rotation possession, removal/replay, ambiguous alias pin, pending transition, unrepresentable policy, late sibling/fork, active-presence intersection, frozen resolution and no collective key/voice.Adapters, harnesses, Librarian, and Matrix↔Cluster
Separate recovery drills
A. Ledger/CAS reconstruction
/we, events/checkpoints, memory lanes, relationships/grants/revocation, source/species/application, messages/receipts/cursors and adapter evidence.B. Encrypted backup restoration
The drills prove different properties. A ledger rebuild is not proof that backup encryption/restore works, and a byte-restored DB is not proof of canonical reconstruction or current authority.
Migration, v0 containment, supply chain, and release artifacts
Findings, residual risk, and release decision
Publish
SECURITY-REVIEW-V0.md(or equivalent reviewed report) plus machine-readable findings manifest. It includes scope/head, methodology, reproduced commands/counts, independent probes, coverage matrix, findings/evidence/fixes/reviews, recovery results, artifact digests, limitations and residual risks. Redact private canary/external participant data while retaining independently checkable public evidence.Final states:
REQUEST_CHANGES: any blocking finding, missing evidence, unreproduced required test, unresolved consent/privacy issue, weak recovery proof, mutable candidate, or unacceptable residual risk.APPROVE: exact candidate head/artifacts/config-template/evidence were reviewed; all blockers closed; every nonblocker recorded; reviewer explicitly recommends release subject to human approval.After exact-head
APPROVE, the human release owner reviews the full report/residual-risk register and records an explicitGOorNO-GOtied to the same manifest/candidate. Silence, issue closure, merge permission, or author intent is not approval. AGOauthorizes only DM-075 publication/tagging of the already reviewed commit and bytes. Any candidate-affecting code, schema, dependency, build, configuration, fixture, documentation, release-metadata or artifact change reopens review.Acceptance criteria
APPROVE, then the human owner records explicit same-candidate releaseGO; otherwise release remains blocked.Non-goals
Safety and rollback
All destructive/fault/recovery tests target validated synthetic temporary roots or separately approved isolated backups. Never signal processes by broad name, scan external systems, alter participant infrastructure, or delete live state. Review failure leaves the candidate unreleased and canary disabled/parked through its documented successor procedure; it never regresses high-waters or enables Tribe v0.
Canonical references
specs/Concurrent-work gate
Do not claim until every blocker is complete and the candidate/evidence manifest is frozen. The signed review claim may add only review harnesses/fixtures/reports; any implementation change requires a separate claim and resets exact-head approval.