Skip to content

docs: revise M9-A0 trusted boundary contract - #113

Merged
shenjiecode merged 1 commit into
developfrom
docs/112-m9-a0-contract-revision
Aug 22, 2026
Merged

docs: revise M9-A0 trusted boundary contract#113
shenjiecode merged 1 commit into
developfrom
docs/112-m9-a0-contract-revision

Conversation

@shenjiecode

Copy link
Copy Markdown
Contributor

Summary

  • revises the M9 design after the M9-A0 layer-1 stop recorded in test: record M9-A0 pinned OpenClaw contract stop #111;
  • keeps pinned OpenClaw 2026.4.14 as the research target;
  • removes native before_prompt_build and tool_result_persist from the trusted security boundary;
  • defines TrustedModelCallBoundary for immutable Package/bootstrap admission before the provider request;
  • defines TrustedToolExecutionBoundary for synchronous ToolResult spool closure before releasing a tool result;
  • requires a Tiangong handler-owned pre-tool deadline instead of relying on OpenClaw runner timeout;
  • keeps the spike fail-closed if the pinned runtime cannot expose and prove those seams.

Scope boundary

This PR changes the canonical design only. It does not implement either boundary, change OpenClaw, or start M9-A. The revised M9-A0 spike must be rerun and reviewed before implementation.

Verification

  • git diff --check
  • Markdown whitespace/tab check
  • 84 fenced blocks remain paired
  • 16 fenced JSON examples parse
  • top-level and subsection numbering remains continuous
  • local Markdown links resolve
  • stale native-hook contract wording searched and removed

Refs #112
Related: #110, #111

Signed-off-by: Jay Shen <shenjiecode@gmail.com>
@shenjiecode
shenjiecode merged commit 1c1534f into develop Aug 22, 2026
4 checks passed
@shenjiecode
shenjiecode deleted the docs/112-m9-a0-contract-revision branch August 22, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant