ipc: a seed_event method, step-up gated, refused by the store (V-518)

The pattern detector needs four events for one action+object spread by at
least two hours before it proposes a routine. The only writer in the tree is
a fact write at time.Now(), so V-43, V-46, V-247 and V-254 all stopped at the
same missing step. This is the wire half of the seam that unblocks them.

The request takes a fact — key, value, timestamp — not an event, so
pattern.Extract runs for real on the daemon side and a key the extractor
ignores seeds nothing. The response says which of those happened, because a
caller that assumed a seed always yields an event would read four silent
successes as a broken detector.

AuthStepUp, the same rung as mutating the tool allowlist, and not because
backdating is privileged in the usual sense: every other write records when
something happened and this one asserts it. StoreAPI refuses outright — the
method needs the daemon's detect-and-propose step, and a direct store caller
would write a fact and quietly skip it.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011x5DgnExQ5XZy8TZPs5bot
This commit is contained in:
2026-08-05 01:10:06 +04:00
parent c586346a60
commit d3c63e6493
8 changed files with 85 additions and 0 deletions
+13
View File
@@ -91,6 +91,19 @@ func Requirement(m ipc.Method) Authority {
// can do is make Maven stop recognising someone, which is the state the
// box ships in anyway.
return AuthWrite
case ipc.MethodSeedEvent:
// The one backdating write path in the tree (Vikunja #518). AuthStepUp,
// the same rung as mutating the tool allowlist, and for a reason that is
// not about privilege: every other write records when something actually
// happened, and this one asserts it. A caller who can place a fact in the
// past can manufacture a routine Maven will then act on forever, which is
// the tick loop obeying evidence nobody produced.
//
// Step-up is not the real gate and is not meant to be. mavend refuses the
// method entirely unless started with -allow-seed, so the ordinary state
// of the box is that no gesture reaches it. This rung is what stops a
// module from calling it on a box where QA left the flag on.
return AuthStepUp
case ipc.MethodWriteFact:
return AuthWrite
case ipc.MethodIngestMail: