What is not built, what is built and unreached, and what unblocks each
The three states are defined ONCE — in §2's legend table — and this table uses no others (NOT BUILT · BUILT, NOT WIRED · BUILT AND LIVE).
The three states are defined ONCE — in §2's legend table — and this table uses no others
(NOT BUILT · BUILT, NOT WIRED · BUILT AND LIVE). What each one means is deliberately
not restated here: a vocabulary written out in N places drifts in N−1 of them, and this arc
has already paid for that once. SIX ROWS BELOW ARE NOW BUILT AND LIVE, AND THIS SENTENCE
REPLACES THE ONE THAT SAID NONE WERE (four on 2026-08-30; the console rule editor joined
them on 2026-09-02, and the audit record surface moved to BUILT, NOT WIRED the same day —
both without a line of code moving, because both rows had been false since before this arc's
guard was written). The retired wording — "Today no row of
either table is BUILT AND LIVE" — was measured in both directions and is the reason this
edit exists rather than being discovered later: the test turns RED if a row moves into the third
state while that sentence stands, and RED if the sentence is deleted while it is still true, so
deleting it was never a way to silence it. It fired the moment SpawnSpec.EgressPolicy and
Deps.EgressDoor got their first production writers.
READ THE THIRD STATE NARROWLY, BECAUSE IT IS THE SENTENCE MOST LIKELY TO BE QUOTED WRONG.
BUILT AND LIVE here means a production run that passes --egress-policy executes this path,
and the field it needs is assigned in non-test code — it does not mean every run is
governed, and it does not mean any run has taken it. ⛔ NO RUN IN THIS FLEET HAS PASSED THAT
FLAG. The mechanism ships, it is tested end to end, and it is opt-in and so far unused: at
the moment these rows moved, the commit carrying them was not yet an ancestor of develop, and
nothing in the record shows a spawn that declared a policy. The wall follows a run's own
--egress-policy; a run that does not ask for it composes no cut, mints no socket and never has
a door opened for it, exactly as on the build before these rows moved. Turning it on fleet-wide is an owner's
act and has not been taken. §9's first limit is unchanged for every run that stays silent.
Today both return zero rows, which is the same fact stated as a query rather than as a mood.
remark: (b) reads PROSE, because no column records "this run declared a policy" — a refused run
has an empty egress_policy_digest, exactly like a run that never asked; measured 2026-08-30.
remark: the product pins this: it drives every refusal reachable
for a policy-declaring run, checks each reason matches the LIKE term ABOVE — read out of this
file, so the doc and the code cannot drift — and fails naming the reason that escaped.
remark: neither query can see a refusal raised at the CLI before any row is written (an absent or
unreadable document, egress-unavailable): that run is on the operator's terminal and nowhere else.
remark: neither query can see a refusal raised on the CONFINEMENT AXIS — confinementChoice
rejecting an unknown run.confinement value, which is the SECOND of egressDoorAddress's four
arms and the first rung a policy-declaring run hits after the ssh arm. Such a run declared a
policy, is booked refused under rule R5 with no digest (read (a) blind) and its reason carries
no egress (read (b) blind); measured 2026-08-30.
⛔ Read (b) is deliberately NOT widened to %confinement% to catch that one. That term also
matches every run refused for a bad confinement value that never declared a policy, so it
would answer "has anything gone wrong with confinement" under a heading that says "has any run
asked for the wall" — a query that swings from missing rows to inventing them has not been fixed.
The arm is DRIVEN instead: egressrefusalquery_test.go's confinement-axis-unknown-value case
asserts this blind spot as a negative control, so it turns RED if a future edit makes that reason
matchable, if read (b) is widened, or if this remark is deleted.
remark: (b) is deliberately WIDE — one word, so it cannot miss a refusal it is able to see; it may
return a refusal that merely mentions egress, and the reason column is there to be read. A narrow
term is the failure that matters: with %egress-unavailable% it misses FIVE of the eleven paths
it can otherwise see (ssh-lane, vendor-delegated-confinement,
backend-this-engine-jails-nowhere and the two sequence.go inline refusals), measured
2026-08-30 by mutating this line and running the control. ⛔ "Wide" is not "complete": the
twelfth driven path is invisible to %egress% too, and it is the CONFINEMENT AXIS one declared
two remarks above.
⚠ And the instrument that colours §8's rows answers neither —
the product measures the ASSIGNMENT (§8.1's assigned: predicate),
and its own blind spot 6 says so: it "proves that SOME non-test file assigns a field of that
NAME, not that a run is given one." So no test in this tree turns red the day this paragraph goes
stale; these two queries are where a reader checks it by hand.
What this preamble claims, and no more. An earlier edition of it said "every row below is NOT BUILT except the two that say otherwise" — one corrected row generalised into a rule about all of them, and two of the rows it covered were shipped code. So the claim here is deliberately narrow and it is measured rather than asserted: every row below carries a state token and an entry point, and the product re-measures every one of them against the build on every run of the product's own suite. A row whose code appears, or disappears, or gets wired, turns that test RED and names the row. Its blind spots are stated in §8.1 — read them as part of the claim.
The shape of the network-layer row, now that it is built, so the roadmap stays legible: confining a run to the proxy is a ladder that ends in a refusal, not in a fallback — a network namespace, then a control group, then a separate operating-system user, then the run does not start. Filtering by process ID is not on the ladder and never will be. Two of those four rungs REFUSE in this build and say so with the act that would change the answer, which is the ladder working as ratified rather than a gap in it: a rung the host has and this engine cannot use must never be spent as though it had passed.
The table above, in a form a test can refute
This block is why the table above is a measurement rather than a paragraph. Every row of §8 appears here exactly once, in the same order, with its state token and the symbols that decide it. the product parses this block and the table, checks they cover each other one-for-one, and evaluates every predicate against the shipped build. Unplug it and the alarm fires: delete a row from the block or add one to the table and the test names the row it cannot pair; build a symbol declared absent here, or delete one declared present, or assign a field declared unassigned, and the test names the symbol and the row that lied about it.
What round 7 added, and why — because round 6's edition of this block could be emptied
without anyone hearing. A review deleted all twenty-nine predicate lines below, left the nine
row:/state: pairs in place, and the test PASSED while logging "9 of 9 rows paired and
measured … over 0 predicate(s)". It also flipped a row into BUILT AND LIVE in both the table
and this block, changed no Go at all, and the test stayed green — the third state was a word
nothing evaluated. Three things close that:
- A predicate SHAPE per state, so a state is derived from what the row claims rather than
accepted because it is written down. NOT BUILT must name at least one absence
(
undeclared:orno-path:) — its whole content is that there is nothing to audit. BUILT, NOT WIRED must name both adeclared:and theunassigned:field whose absence keeps it unreached. BUILT AND LIVE must name adeclared:and anassigned:, and may not carry anunassigned:— the two together are the self-contradiction that stayed green. A row carrying no predicate at all is refused by name. assigned:, the mirror ofunassigned:, which is the code-visible difference between the second state and the third: wired is a symbol that exists, live is a field a production run is actually given. Until a row can be made to prove that, the third state is decorative.- The count in the log is the count the evaluator RAN, compared against the count parsed. A sentence saying "measured" is read as evidence, so it may not be printed over work that did not happen.
The test carries a negative control that runs this same parser, shape check and evaluator over a synthetic block written to be wrong in every one of those ways, and requires each fault to be named — and over a second synthetic block that is true in every particular, which must produce nothing at all.
What round 8 added, and why — because the one cell §2's legend sends an auditor to was read
by nothing. §2 defines NOT BUILT and tells the reader where to look: "the 'what unblocks
it' cell in §8." The prose scan stops at any line beginning with |, the state check reads a
row's first cell only, and the predicates read this block — so that column was checked by no
state check at all, and the arc's ninth false statement was sitting in it, in the same
sentence as in §7's box. Three additions, and the middle one carries no phrase list:
- Every table cell in this document, and in Security §11, is now scanned for a contradiction, with the whole row as the scope in which a state token counts.
- A decidable pairing on the state surface — §2's two tables and §8's table: a cell that names a mechanism must name the state §8 rules for it, or point at §2 or §8. It cannot be evaded by phrasing, and it is bounded to those tables because the cost of the wider surface was measured rather than guessed.
- The ceilings an operator writes are read out of the code and each must be named in this document (§4.6). That is the alarm behind the tenth false statement, which told an operator that nothing is configurable — a sentence no phrase list in this tree can see.
What round 2 of the headline wagon added, and why — because the guard armed here caught the
lie and not the PROMISE. A named review put the one sentence this chapter's own order forbade
into the lead banner — "Every run in this fleet is governed by all of it, whether or not it
asks" — and every check in the file stayed green. On a security chapter, false assurance is the
more expensive direction than an understated absence: it tells a security officer their runs are
governed when nothing is looking at them. So a second guard pairs a phrase quantifying over the
run population with a phrase asserting governance, and requires the sentence to say which
side of the opt-in it is on. It is a biconditional bound to the code, not a list of banned
sentences: the promise is refused only while every non-test assignment of the run's egress-policy
field consults the run's own request, and the day a fleet-wide default lands the guard inverts and
refuses the caveats instead. Unplug it and the alarm fires, in both directions, and both are
executable: .evidence/r2/negcontrol_governance_promise.sh and
.evidence/r2/negcontrol_the_switch_day.sh. Blind spots 18 and 19 below carry its measured reach
and its floor.
⛔ Read the blind-spot list in the block below as part of this claim, and read it before you trust the checks. It is longer than it was, and that is the honest direction: an undeclared blind spot is what let the ninth statement live, and blind spot 10 names where the next one will most likely arrive.
What lands in the audit record
⚠ The record surface is BUILT, NOT WIRED (§8) — the row, the store and the table all ship; nothing constructs the store, so no judgement is ever written down. THIS BOX SAID "the record surface is NOT BUILT — nothing…
Limits and known gaps
The section a security officer should turn to first.