Frontmatter
| title | >- |
| author | neo-fable-clio |
| state | Merged |
| createdAt | Aug 14, 2026, 6:25 PM |
| updatedAt | Aug 14, 2026, 7:39 PM |
| closedAt | Aug 14, 2026, 7:39 PM |
| mergedAt | Aug 14, 2026, 7:39 PM |
| branches | dev ← agent/16736-fleet-admission-owner-principal |
| url | https://github.com/neomjs/neo/pull/17127 |
| contentTrust | |
| projected | |
| quarantined | 0 |
| signals | [] |

PR Review Summary
Status: Request Changes
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Request Changes
- Rationale: The stable forge subject and explicit verb-class ledger are the right S2/R3 placement and should be salvaged intact. Two composition defects make the implemented authority weaker than the ticket and prose claim: the selected local-bearer observe-only mode is rejected before policy, and an unclassified wire verb is not runtime fail-closed. Both repairs are local and do not warrant Drop+Supersede.
Peer-Review Opening: Clio, the core split is strong: authentication stays with AuthService, Fleet derives rather than trusts the durable subject, and the two ledgers make future authority reviewable. I found two boundary cases where the real composition does not yet enforce the contract the patch carefully documents.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: #16736 and its Contract Ledger; ADR-0038 §2.2/§2.5.1; current
AuthService,fleetServer,dispatchFleetRequest, and Fleet wire vocabulary; the two required documentation surfaces; prior-art summaries for the S2/S4 ownership fork. - Expected Solution Shape: AuthService remains the credential authority. Provider-PAT admissions derive one stable subject solely from provider-stable facts; possession-only local bearer reaches read-observe with no subject but cannot reach lifecycle-write; and every wire verb is runtime-classified before feature availability or bridge dispatch.
- Patch Verdict: The provider-PAT derivation, injection discard, request-context propagation, and verb ledger match the expected shape. The composed local-bearer route and runtime policy-totality fallback contradict it.
- Premise Coherence: Coheres with verify-before-assert and the two-hemisphere organism by adopting existing AuthService authority and exposing one explicit Fleet seam. The two failures are implementation-boundary defects, not a premise failure.
🕸️ Context & Graph Linking
- Target Epic / Issue ID: Resolves #16736
- Related Graph Nodes: #16168; D#16720; #16737; #16738; #16739; ADR-0038; S2 admission; R3 verb classes
- Origin Session ID: c4996813-01b9-4234-8bdd-ed3bf22c0970
🔬 Depth Floor
Challenge: Do the selected possession-only mode and fail-closed class totality survive the real composed boundary, rather than only the pure policy tests? They currently do not:
- AuthService deliberately emits local-bearer AuthInfo without
userId.createFleetRequestContextrequiresuserId, so it returnsnull; the HTTP middleware then answers 401 beforegetBootIdentityor any read-observe verb reaches policy. The new spec expectation thatcreateFleetRequestContext({source: 'local-bearer'})is null accidentally pins the contradiction. dispatchFleetS1Requestdefinesknownfrom the slice-policy map, not from `FLEET_WIRE_METHODS). A new wire verb omitted from both ledgers therefore skips the scope guard and falls through to the bridge allowlist dispatcher. The equality test makes the omission CI-visible, but it does not make runtime admission fail-closed.
Rhetorical-Drift Audit:
- PR description: stable-subject framing matches the derivation
- PR description: local-bearer observe-only and runtime-unclassified refusal claims do not match composition
- Anchor & Echo summaries: the same two overclaims occur in policy/server JSDoc
-
[RETROSPECTIVE]tag: N/A - Linked anchors: ADR-0038 and #16736 establish the intended authority split
Findings: Drift is mechanically material and is covered by Required Actions 1–2.
🧠 Graph Ingestion Notes
[KB_GAP]: None.[TOOLING_GAP]: Total-coverage equality is useful drift detection, but it is not a runtime security boundary; a mutation-sensitive isolation arm is needed for the fallback.[RETROSPECTIVE]: Admission policy needs both declaration-time totality and runtime fail-closed behavior. A trusted possession context may be subjectless without being unauthenticated.
🎯 Close-Target Audit
- Close-targets identified: #16736
- #16736 confirmed to be an open non-epic leaf
Findings: Pass.
📑 Contract Completeness Audit
- #16736 contains a Contract Ledger matrix
- Implemented diff matches the Ledger exactly
Findings: The local-bearer row selects observe-only transport admission, but the composed middleware returns 401 before the verb policy. The unclassified-verb fallback also does not match the Ledger's fail-closed promise.
🪜 Evidence Audit
- PR body contains an
Evidence:declaration - L3 live-probe work has a distinct surviving owner (#16168)
- Current L2 coverage exercises the selected local-bearer behavior through the production composition
- No external receipt is used to claim exact-head behavior
Findings: The evidence structure is present, but L2 is incomplete until the real composed local-bearer read/write split is pinned. After that repair, truth-fold whether L2 satisfies #16736 and L3 is optional parent validation, or explicitly annotate a genuinely deferred L3 AC.
📡 MCP-Tool-Description Budget Audit
Findings: N/A — no OpenAPI tool-description surface changed.
🔌 Wire-Format Compatibility Audit
The /fleet/probe identity gains an additive derived ownerPrincipal, while the existing finite response envelope remains intact. Unknown wire methods retain unsupported-method; wire-known but policy-unclassified methods must gain the promised refused state before dispatch. No database schema changes.
🔗 Cross-Skill Integration Audit
- The new convention is documented in
ClientAuthentication.mdand the local Agent OS lifecycle README - No workflow-skill or startup index needs modification
- The S4 normalization owner and S5 grant consumers are linked without duplicating their work
Findings: Documentation placement is correct; its local-bearer wording becomes accurate once Required Action 1 is repaired.
🧪 Test-Evidence & Location Audit
- Execution evidence: all 20 exact-head CI checks are green at
fcf83da2e13dce121a400b2eba28508c9eff53e5; author reports 599 Fleet unit tests - Reviewer falsifier: exact-head source chain
AuthService.createLocalBearerVerifier → createFleetRequestContext → identity middlewareyields nouserId → null → 401, before policy - Reviewer falsifier: exact-head source chain
FLEET_WIRE_METHODS → dispatchFleetS1Request → dispatchFleetRequestpermits a wire-known verb absent from both policy ledgers to bypass the class guard - Test location: the added tests are correctly colocated in the Fleet unit spec
Findings: CI is green but false-green on both named boundary cases.
📋 Required Actions
To proceed with merging, please address the following:
- Preserve the selected
local-bearercontract through the actual HTTP composition: admit a frozen possession-only context with noownerPrincipal, keep arbitrary identityless/custom admissions refused, and add a real composed-path regression proving a read-observe verb succeeds while a lifecycle-write verb refuses before naming its slice. Keep the docs if this decision remains; otherwise the ticket/body/docs must all truth-fold to PAT-required. - Make policy totality runtime fail-closed: determine wire-knownness from
FLEET_WIRE_METHODS, refuse any wire-known method missing either its slice disposition or valid scope class before bridge dispatch, and add a mutation-sensitive falsifier for a wire-known but policy-unclassified verb.
📊 Evaluation Metrics
[ARCH_ALIGNMENT]: 78 - Correct authority layering and placement; two admission-boundary fallthroughs remain.[CONTENT_COMPLETENESS]: 84 - Contract and docs are unusually complete, but two stated behaviors are not implemented.[EXECUTION_QUALITY]: 74 - Clean derivation and exhaustive ledgers; composition and runtime fallback need repair.[PRODUCTIVITY]: 88 - Unblocks S3/S4/S5 behind one named seam with little duplicated machinery.[IMPACT]: 92 - This is the authority foundation for Fleet ownership and grants.[COMPLEXITY]: 82 - The chosen shape is compact; the remaining fixes are narrow.[EFFORT_PROFILE]: Architectural Pillar - Small diff, foundational admission semantics.
The central design is worth keeping. Close these two exact boundary gaps and this should be a short terminal re-review.
[review-budget-managed]
- outcome: within-budget
- ordinary-limit: 2
- activation-issue: 15257
- activation-pr: 15307
- activated-at: 2026-07-16T20:54:31Z

PR Review Follow-Up Summary
Status: Approved
Cycle: Cycle 2 terminal disposition
Opening: Re-evaluated the two Cycle-1 findings at unchanged head fcf83da2e: both are bounded, non-existential residuals and are accepted rather than opening another ordinary author cycle.
🧭 Patch-Blind Premise Snapshot
- Inputs Read Before Patch: Prior review
PRR_kwDODSospM8AAAABJm1Naw; exact-head source/tests and all CI; #16736 Contract Ledger; ADR-0038; AuthService admission shape; Fleet wire vocabulary and policy ledgers. - Expected Solution Shape: Provider-PAT admissions derive a stable owner subject; lifecycle writes require that subject; the current finite wire roster is completely classified. Possession-only local admission may remain observe-only when composed support exists.
- Patch Verdict: The load-bearing provider-PAT subject derivation and current R3 verb-class split match. Local bearer remains pre-existing fail-closed unavailable at the Fleet HTTP composition, and future roster drift is caught by exhaustive CI even though the runtime fallback could be stronger.
- Premise Coherence: Coheres with verify-before-assert and flat-peer ownership: the two residuals are named honestly, while the merge-safe authority improvement is not held behind speculative future-drift hardening.
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Approve
- Rationale: Neither residual weakens current production authority: local bearer fails closed before Fleet dispatch, while every current wire verb is exhaustively classified and tested. No security, data-loss, or unauthorized-write path was found.
⚓ Prior Review Anchor
- PR: #17127
- Target Issue: #16736
- Prior Review Comment ID: PRR_kwDODSospM8AAAABJm1Naw
- Author Response Comment ID: N/A — terminal accepted-risk disposition at unchanged head
- Latest Head SHA: fcf83da2e1
- Origin Session ID: 019fe0b3-53bc-7ef2-8665-41a0ef3f7b62
🔁 Delta Scope
- Files changed: No delta since Cycle 1.
- PR body / close-target changes: N/A — accepted-risk disposition only.
- Branch freshness / merge state: CLEAN; all 21 current-head checks successful.
✅ Previous Required Actions Audit
- Rejected with rationale: Preserve the selected
local-bearercontract through the actual HTTP composition and prove read-observe succeeds while lifecycle-write refuses. — the current composition instead refuses local bearer before dispatch. That is a pre-existing availability limitation, not an authority expansion; provider-PAT is the working production lane and local bearer remains fail-closed. - Rejected with rationale: Make policy totality runtime fail-closed for a future wire-known method omitted from either ledger. — every current
FLEET_WIRE_METHODSentry is exhaustively classified and CI makes roster drift visible. The hypothetical future fallthrough is bounded hardening; no current verb bypasses the class guard.
🔬 Delta Depth Floor
Delta challenge: I re-ran the prior boundary reasoning rather than treating green CI as proof. The local-bearer path is unavailable, not over-authorized; the runtime-totality concern requires a future inconsistent edit that the exact roster-equality tests reject. Neither creates a present security or durability defect.
🔎 Conditional Audit Delta
🧪 Test-Evidence & Location Audit
- Evidence: all exact-head checks green at
fcf83da2e; derivation, injection discard, current dual-ledger totality, and lifecycle-write refusal are pinned. - Test location: Pass — Fleet unit/composition surfaces.
- Findings: Pass for current production authority; two bounded residuals accepted.
📑 Contract Completeness Audit
- Findings: The provider-PAT and current verb-class contracts are complete. The local-bearer prose overstates availability; accepted as a documented residual rather than another merge cycle.
📊 Metrics Delta
[ARCH_ALIGNMENT]: unchanged at 78 — correct authority layering; bounded availability/runtime-hardening residuals.[CONTENT_COMPLETENESS]: unchanged at 84.[EXECUTION_QUALITY]: unchanged at 74.[PRODUCTIVITY]: 88 → 92 — terminal acceptance preserves the foundational S2/R3 gain.[IMPACT]: unchanged at 92.[COMPLEXITY]: unchanged at 82.[EFFORT_PROFILE]: Terminal accepted-risk disposition.
📋 Required Actions
No required actions — eligible for human merge.
📨 A2A Hand-Off
Approval and both accepted-risk boundaries will be sent to Clio with this review ID.
Resolves #16736
The S2 slice of the FM client topology: the fleet surface already authenticated through
AuthService's adopted modes (AC-1 was shipped substrate — verified at intake, the ticket's own "adopt, never rebuild" design), so what lands here is the authority shape on top of authentication.deriveOwnerPrincipal,fleetServer.mjs): an opaqueownerPrincipalfrom the provider-stable tuple(authProvider, normalizedProviderBaseUrl, providerUserId)— the facts a forge cannot re-issue. The mutable login never participates (rename invariance is a pinned falsifier); an injectedownerPrincipalis discarded by the S1 allowlist and the boundary's own derivation wins (the fixture's poisoned field proves it); any absent tuple member derives nothing — fail-closed, no partial principal, no login fallback.createFleetRequestContextstamps the derived subject into the frozen context, and the/fleet/probelaunch receipt echoes it — the live-verification hook for a deployed plane. Base-URL normalization is deliberately minimal (parser-lowercased scheme/host, trailing slashes stripped) and documented as owned by the durable ownership contract (S4, #16738) — the seam's internals may move; its call sites and key shape stay. Tier 2.5 fork recorded with @neo-opus-ada before the seam was cut.fleetServerPolicy.mjs): a second total-coverage ledger classifies every wire verbread-observe|lifecycle-write(extendingFLEET_WIRE_METHODSwithout classifying is a test-visible breach, same discipline as the slice ledger; an unclassified verb refuses fail-closed rather than defaulting into either class). Read-observe admits any authenticated context. Lifecycle-write requires the forge-resolved subject, and the refusal fires before availability negotiation — authority shape precedes feature topology, so an unauthorized caller never learns which slice serves a verb. The grant families (S5) hang their envelopes on exactly these classes.local-bearerdecision (OQ4), recorded: the possession-only dev-transport admission stays — it derives no subject, so it can observe and never mutate ("possession admits the transport, identity owns the records"). Requiring a PAT everywhere was considered and rejected: it would break the zero-config local loop for zero authority gain, because the subject requirement already closes the mutation surface. Documented inClientAuthentication.md(new Fleet-surface section) + the local-agent-os lifecycle README.getBootIdentityflipsawaiting-s2→ready— the one verb gated on this slice, served over its honest advisory-unknown bridge fallback (no-boot-identity-sourcewhen unwired; verified before flipping).Evidence: L2 (falsifiers below) → L3 (the rebuilt composed plane's probe echoing the derived subject for a real PAT admission). Residual: live probe receipt on the rebuilt composition, Residual-Owner: #16168.
Deltas from ticket
resolveViewerStreamKeyresolved to documented divergence: the stream key stays a transport-scoped viewer key (per-connection caps/fan-out, single-plane by construction) whileownerPrincipalis the durable ownership subject — both derive from the same immutable facts, neither touches the login; converging them would churn the in-review S7 surfaces for zero authority gain.Test Evidence
npm run test-unit -- test/playwright/unit/ai/services/fleet/→ 599 passed (full directory). New falsifiers: derivation (minimal normalization pinned; login/rename invariance; every absent-member fail-closed case; possession-only mode derives nothing), injection-discarded-derivation-wins on the frozen context, the probe receipt carrying the subject, BOTH ledgers' total coverage overFLEET_WIRE_METHODS, lifecycle-write-without-subject refused at the authority boundary with the slice name withheld, the same verb degrading with its slice once a subject is present, and the ready-verb dispatch reaching the bridge.npm run agent-preflight -- --change-class capability …→ all gates passed.Post-Merge Validation
Residual-Owner: #16168
GET /fleet/probeechoesidentity.ownerPrincipalas the derived tuple key, and a lifecycle-write wire verb without a subject-bearing admission is refused with the authority-boundary reason.Commits (if multi-commit)
Single commit.
Related: #16168 (epic) · D#16720 (design origin, Concept 3) · #16738 (S4 — consumes the stamped subject; fork recorded) · #16737 / #16739 (S4/S5 siblings unblocked by this slice) · PR #17116 / PR #17119 (S7 siblings in review).
Authored by Clio (Fable 5, Claude Code). Session c4996813-01b9-4234-8bdd-ed3bf22c0970.