Skip to content

`pwplz` is the write-probe canary — WITHDRAWN, do not countersign

Date: 2026-08-12 Status: open Supersedes: none Superseded-by: docs/decisions/2026-08-12-purpose-built-canary-supersedes-pwplz.md (pending its countersign)

WITHDRAWN — 2026-08-12, same day, before countersign

Section titled “WITHDRAWN — 2026-08-12, same day, before countersign”

Do not tick the countersign below. This record’s central factual premise is false and the ruling it proposes must not take effect. Superseded by docs/decisions/2026-08-12-purpose-built-canary-supersedes-pwplz.md.

Status: stays open rather than superseded because MR-7 forbids a superseded status while a countersign is unchecked, and an agent must never tick one. The record is retained unedited below per MR-7’s append-only discipline; this block is the only addition.

Why it is wrong. The Decision below calls pwplz “the most inert of the three — no naming tie to a live or planned surface.” pwplz is in fact a live product at pwplz.com, the operator’s first open-source project, the subject of a published post at devarno.com/downlink/password-please, a public repo with stars at Dev4rno/pwplz, and the intended base of a SaaS build. It is the highest-value repo in the candidate set, not the lowest.

How the error was made, because the method matters more than the row. Inertness was inferred from the absence of a url: field in registry.yaml. Absence of a field is not evidence of absence of a surface — the registry was silent, not the repo. The same inference disqualifies the runner-up as well: downlink-hq maps to devarno.com/downlink, the operator’s live blog section. Of the three placeholder entries only thrustr-io has no evidence against it, which after this is not the same as evidence for it.

PTV-SCF-0001’s P3 builds the end-to-end write probe that discharges PTV-VCRM-DEBT-01 — six requirements verified by T (test) with no executing test behind them. INV-1 (fatal) permits an applied write against one designated repo, the canary, and P3 could not start because no canary was named: registry.yaml has no canary field and Q-CANARY-1 sat open.

P0 evidenced three candidates converging from three independent signals. The 39-entry registry has 36 state/ files, and the three entries with no state file are exactly the three role: placeholder entries — thrustr-io, downlink-hq, pwplz. Each has no url:, each carries a provisioned App installation (PETROVA_INSTALLATION_ID_THRUSTR / _DOWNLINK / _PWPLZ), and each is annotated “App installed but no repos accessible at 2026-05-13 discovery”. See docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md §“Canary candidates”.

The operator selected pwplz on 2026-08-12.

pwplz is the designated canary for all PETROVA write-verb probes. It is the single repo against which INV-1 permits an applied write, and the only slug P3’s probe may target. Every other governed slug remains read-only to the crew.

pwplz was chosen over thrustr-io and downlink-hq because it is the most inert of the three — no naming tie to a live or planned surface — and over traceo-mcp-server because that is a real repo where a defective probe has real consequences.

Selecting the slug does not provision it. The five conditions in docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md §“What a conforming P3 credential would look like” stand unchanged, and condition 5 — a recorded negative test proving the credential is refused against a second repo — is a P3 deliverable, not an assertion.

  • thrustr-io or downlink-hq — identical shape and equally valid; rejected only because both names tie to surfaces that may become real, and a canary should stay disposable.
  • traceo-mcp-server (role: scaffold, profile: permissive) — rejected: a real repo with real content, so a defective probe damages something. Its permissive profile made it attractive precisely because it is the weakest gate, which is the wrong reason.
  • A fresh repo outside registry.yaml — rejected: an ungoverned repo does not exercise the registry → App-auth → write-verb path, so a green probe would prove the verb works in a vacuum rather than through the control plane. It would also reproduce D-16, where PODCAS and KALEX hold installations outside governed inventory.
  • petrova-codes itself — rejected: the self-entry declares fleets_allowed: [] by design, so agent automation against it is forbidden by the registry, and a probe there would write to the control plane it is meant to test.

For code:

  • No code change. pwplz is a target, not a feature.
  • P3’s probe must resolve its target from the registry, never from a literal, so the canary can be changed by ratified supersession rather than by editing code.

For docs:

  • registry.yaml’s pwplz entry (:764-775) needs a note recording canary status. It is a role: placeholder with no url: and fleets_allowed: [], so P3 must first create or point at a real repo and widen fleets_allowed. Registry edits are PR-only — this record does not authorise a direct edit.
  • Q-CANARY-1 and Q-CRED-4 are closed in docs/findings/20260811-1749-ptv-scf-0001-p0-open-questions.md §“Amendments — 2026-08-12”.

For in-flight phases:

  • P3 unblocks on naming, not on capability. It still needs a GitHub App installation scoped to pwplz alone, distinct from C-1 (the ambient gh user token, which holds repo, admin:org, delete_repo, workflow) and C-3 (the petrova-act App key, reaching 28 named installations). A probe run under either proves only that an estate-wide credential works.
  • P4/P5 unaffected — those block on the n8n credential’s scope (Q-CRED-3).

For invariants:

  • INV-1’s “designated canary” now has a referent, so the invariant is checkable rather than vacuous.
  • No MR added, modified, or repealed.
  • INV-1 remains violated in this environment regardless: C-1 and C-3 are ambient and estate-wide. Naming a canary bounds where the crew intends to write; it does not bound what the crew can write. Containment stays INV-2 discipline, not credential scope, until P3 provisions the scoped installation.
  • docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md — candidate evidence, the five credential conditions, and C-1/C-3 blast radius.
  • docs/findings/20260811-1749-ptv-scf-0001-p0-open-questions.md — Q-CANARY-1, Q-CRED-4 as raised.
  • docs/findings/20260811-1749-ptv-scf-0001-p0-delta-register.md — D-16 (installed capability exceeds governed inventory).
  • registry.yaml:764-775 — the pwplz entry as it stands.
  • docs/PETROVA-SDD-BASELINE.md §8.1 — PTV-VCRM-DEBT-01, the verification debt the probe discharges.
  • docs/decisions/2026-08-10-countersign-gates-closed-status.md — why this stays open until countersigned.
  • Subagent: PTV-SCF-0001 P1 (session 2026-08-12), recording the operator’s selection
  • Human countersign — that pwplz is the sole designated canary, and that no applied write lands against any other governed slug until this record is superseded