Skip to content

Principal-authorized compositional read cognition

Oracle's read-only cognition entry point can compose reviewed Rubick inspection operations through the shared runtime. A question does not need its own production route. Registration describes evidence sources and bounded arguments; it does not grant access, establish live readiness, or authorize an effect.

This is a bounded Core extension consumed by independent media, notification, governance, runtime, and project evidence readers. It introduces no named component, second capability registry, durable memory store, scheduler, general executor, or background execution loop. General project investigations may iterate within explicit read and inference budgets using existing governed continuations. The code contract is in app/rubick/inspection_operations.py; registrations live on existing Rubick capabilities. Runtime wiring is in app/runtime/compositional_inspection.py and app/runtime/inspection_adapters.py. Oracle aggregation and rendering remain in app/oracle/read_only_cognition.py.

Read architecture and reused boundaries

Existing primitive Role and actual boundary
Shared intent boundary Rejects supplied, quoted, negated, prospective, or ambiguous instruction scope before capability routing. Conceptual explanations can remain ordinary conversation.
Operational Router and runtime pipeline Preserve explicit scoped read owners; generalized observation precedes task/planning/effect-capable fallback. Transports share this pipeline.
Rubick capability, setting, and provider registry Owns operation registrations and declared readiness. Settings, generic authority_mode, or a capability's legacy read hint are not operation authorization. Bootstrap merges new default metadata; inspection uses ensure=False and never bootstraps artifacts.
Canonical principal registry Revalidates active aliases or authenticated device/session context before each source call. A process-readable resource is not automatically principal-readable.
Oracle reports Keep observed facts, warnings, inferred interpretation, and advisory recommendations distinct. Existing descriptor reports remain available.
Governed inference client May suggest bounded reads from the current authorized inventory, choose follow-up reads from evidence, and synthesize source-cited findings. It never receives an executor or an approval method.
Zeus evidence bridge Performs fixed, allowlisted Git revision, history, and worktree checks. No caller-provided shell or Git arguments.
Kernel Records and existing telemetry Retain source, time, integrity hash, bounded safe observation, and optional inference-attempt metadata. These are observations, not approval or execution receipts.
Beastmaster Runs explicitly registered read probes without snapshot persistence. A missing Docker socket is unavailable evidence, not proof that services are stopped.
Lich Supplies revalidated current-principal pending cards. Read adapters never resolve approvals; a separate principal-bound decision stage owns development Gate 1.
Keeper Supplies a bounded task page through its GET API for the explicitly configured shared-system operator. Its natural-language mutation endpoint is not exposed.
Chen / media adapters Supply bounded Plex inventory and durable principal-owned acquisition observations. Refresh, acquisition, promotion, cleanup, retry, and lifecycle pulses are excluded.
Notification/outcome service Supplies owner-filtered outcome, outbox/dispatch, and subscription posture without payloads, endpoints, credentials, enrollment, or delivery effects.
Earthshaker Reads configured/durable physical bindings. Discovery that could first-bind, pairing, wake, input selection, and playback are excluded. Bindings do not prove current control readiness.
IO and Clockwerk Remain lifecycle observation/scheduling infrastructure. Generalized cognition never calls pulse or scheduling methods; an observer name is insufficient effect proof.
LifeVault Remains durable memory authority. Generalized cognition neither writes preferences nor exposes an unrestricted memory/document reader.
Existing MCP/tool gateway Existing allowlisted MCP gates remain unchanged. Advisory risk inference and external gateway rendering do not establish a safe operation contract for this path.

The old descriptor-only cognition router had nine fixed intentions and no tool invocation authority. Existing governed runtime inspections and Oracle reports already composed selected evidence, but were purpose-built. Rubick's legacy read_only metadata also covers some context-mutating Spectre bindings. Therefore neither absence of a mutation word nor a name such as inspect can safely grant new invocation authority.

Effect and authorization contracts

An operation is eligible only when its reviewed contract declares both read_only is True and mutation_allowed is False, and the current Rubick registration exactly matches that contract. Provider-component disablement and Lich's existing utility-probe policy remain authoritative. False, absent, unknown, contradictory, unregistered, disabled, or unavailable classifications never acquire read invocation authority. These reuse the existing read/mutation booleans rather than adding a parallel effect taxonomy. A parent capability may support governed writes; only its separately reviewed observation operation is exposed.

Operation parameters are bounded scalar schemas authored alongside their source contract. Unknown keys, inappropriate scalar types (including Boolean integers), unknown parameter kinds, and out-of-range values refuse before invocation. Callables are bound in reviewed runtime code, never imported or looked up on a service from model-supplied names.

There are two resource policies:

  • owner: each reader filters using the revalidated canonical principal. This applies to pending Lich approvals, acquisition observations, notification dispatch, subscription posture, and durable outcomes.
  • operator: shared Plex, Keeper, host/runtime, physical-device, Rubick, repository, and project evidence requires the explicit configured LUNA_OPERATOR_PRINCIPAL_ID. Merely authenticating another principal does not grant access to these shared service credentials or records.

Ingress authentication and Web session-bound CSRF remain in their existing transport adapters. Shared cognition consumes verified context and checks it again; it does not accept principal IDs from natural-language arguments. Legacy compositions without an identity authority do not gain generalized inspection. Existing scoped deterministic readers keep their prior governance contracts.

Discovery, composition, and inference precedence

Discovery reads current Rubick capability state. Deterministic content-term matching ranks source descriptions using inverse term frequency so common domain words do not crowd out an explicit rare source. Generic availability wording is excluded when a more specific subject exists. For unresolved semantics or filters, the existing governed model can propose operations from the authorized inventory. This fallback is semantic interpretation, not safety classification. Production code contains source vocabulary, not the acceptance questions.

Ordinary service inquiries take a finite batch. General project inquiries can iterate over discovery and document/source ranges, with durable explicit evidence checkpoints. Both validate registration, authorization, arguments and bounds before each call. Source text cannot dispatch a call; model-proposed follow-up reads must pass the same deterministic boundary. The model cannot add a new operation, modify policy, select an executor, approve an action, or turn a recommendation into an effect.

Bounds include:

  • Ordinary composition admits five inspections with no repeated operation within a batch. Project investigations use bounded batches of distinct argument sets; ranges of one source are reauthorized individually.
  • A 25-second admission deadline between inspections. Existing synchronous adapters have their own fixed network/subprocess deadlines; an admitted read finishes within its adapter bound. This is not a thread-cancellation guarantee.
  • At most four Plex sections and twenty titles per section, explicit offset and title filters, and bounded provider response bytes. Counts and partial pages are preserved; no refresh occurs.
  • Twenty owner dispatch/outcome/acquisition/task rows, bounded subscription aggregates, five recent Kernel Records, and bounded runtime projections.
  • A maximum normalized evidence size per read, bounded nesting and collections, a bounded combined synthesis input, and bounded human presentation.
  • Ordinary composition uses at most one selection call and one synthesis call. Project investigation uses the bounded iteration and context contracts described in durable investigation.

A direct Plex library inquiry is resolved from registered evidence without any inference dependency. Multiple observations can still be displayed when optional synthesis fails. Failed capabilities are reported as unavailable; generic model knowledge cannot replace a failed authoritative inspection. Unsupported detail or unresolved filtering remains explicit. A missing read contract is a capability gap, not an invitation to implement a new capability automatically.

Oracle preserves each source separately. Explicit claims about the same subject and field can flag contradictory values; unrelated status words are not treated as a contradiction. Optional inferences and recommendations must cite observed source IDs and are labeled as inference/advice. Missing sources and limitations remain in the deterministic report regardless of what the model says. Citation validation establishes provenance references, not a mathematical proof of every model inference; source facts remain available for inspection.

Oracle applies one 12,000-character presentation budget to observations, optional interpretation, and runtime limitations before any transport renders the answer. Source attribution, scope, missing-evidence and contradiction warnings, and other explicit qualifications are retained before optional whole detail units. Omitted details are acknowledged. If the required qualifications cannot fit, Oracle withholds conclusions and asks for a narrower inquiry instead of clipping them. Short reports retain their existing presentation. Discord splits this shared result into messages; Web and Terminal display the same bounded content.

Evidence normalization also reports incomplete scope when nesting, field, or collection bounds omit material. Overlong values are omitted in full with an explicit qualification, rather than exposing a prefix that could lose a later limitation. Optional synthesis cannot remove these deterministic warnings. Repository summaries pass through this shared bound without an earlier adapter prefix clip that could conceal Zeus's own truncation marker.

Safe evidence and observability

Readers project known safe fields before the common sanitizer. Raw payloads, credentials, push endpoints, file paths from Plex, device pairing data, and arbitrary service internals are not returned. A second sanitizer removes credential-shaped fields, configured secret values, terminal controls, and source-provided URLs. URLs are made inert because the downstream response-quality layer may otherwise probe them.

No evidence reader writes domain records, approves Lich, creates Keeper work, changes LifeVault, acquires media, restarts services, or sends notifications. Normal runtime telemetry, Kernel Record append, bounded conversation continuity, and explicit investigation checkpoints remain infrastructure effects. A completed development inquiry may additionally prepare one immutable independently challenged plan and pending Lich approval through the existing development owner. Neither planning nor checkpointing grants implementation authority. They are not evidence of a target-system mutation and must be distinguished in acceptance snapshots.

A source read timestamp does not make its underlying durable observation fresh. Chen and recent Kernel Records retain their original observation timestamps; Runtime Composition reports wiring rather than provider health. An empty queue, a missing reader, malformed evidence, source failure, an incomplete library page, and an unverified causal explanation have different meanings.

Existing route ownership and subtraction

Classification Retained routes and rationale
A: deterministic semantics Exact download-status/clarification ownership, canonical pending approval cards, Kernel Record history/explainability, model selection/inventory, and governed hardware/disk inspection retain their existing scoped behavior. Runtime Composition remains its canonical wiring view.
B: compatible fast paths Oracle capability truth, operational awareness/review, roadmap reconciliation, media status, financial and meeting reads remain available under their existing contracts. Generalized reads can compose their reviewed evidence sources where registered.
C: superseded scaffolding Duplicate later history/explainability and governed-inspection stage calls were removed after moving those owners ahead of generalized fallback. No new compatibility router was added.
D: governed effects Keeper task creation, Lich decisions, Chen acquisition/promotion/cleanup, configuration, preferences, development planning/delegation, scheduling, publication, and execution remain outside generalized read invocation.

No bespoke Plex movie question route was introduced. No working specialized reader was deleted merely because this substrate exists. The separate draft Git reader was removed in favor of Zeus. Capability-specific parameter validation was moved into operation contracts instead of expanding dispatcher conditionals.

Validation boundary and remaining coverage limits

tests/test_compositional_inspection.py covers registered discovery, explicit effects, argument bounds, principal/session isolation and revocation, multiple sources, bounded batches, repeated calls, failures, conflicts, provenance, credential and URL handling, model outage, fabricated model selections, novel source vocabulary, kernel mutation traps, and Kernel Record reconstruction. Existing runtime, governance, transport, Rubick, Oracle, Zeus, and repository-wide suites remain required alongside deployed acceptance.

This substrate does not expose every process-readable object. Per-service memory, individual torrent peer-discovery details, live TV readiness, unrestricted LifeVault content, arbitrary files, arbitrary MCP/network operations, and complete report history still require safe source contracts where absent. General project text is now exposed through reviewed discovery and range contracts; this is not a Rote implementation. A model recommendation cannot adopt a roadmap objective or authorize implementation. See the durable investigation and development contract for the planning boundary and current lifecycle limitations.