`pwplz` is the write-probe canary — WITHDRAWN, do not countersign
Date: 2026-08-12
Status: open
Supersedes: none
Superseded-by: docs/decisions/2026-08-12-purpose-built-canary-supersedes-pwplz.md (pending its countersign)
WITHDRAWN — 2026-08-12, same day, before countersign
Section titled “WITHDRAWN — 2026-08-12, same day, before countersign”Do not tick the countersign below. This record’s central factual premise is
false and the ruling it proposes must not take effect. Superseded by
docs/decisions/2026-08-12-purpose-built-canary-supersedes-pwplz.md.
Status: stays open rather than superseded because MR-7 forbids a
superseded status while a countersign is unchecked, and an agent must never
tick one. The record is retained unedited below per MR-7’s append-only
discipline; this block is the only addition.
Why it is wrong. The Decision below calls pwplz “the most inert of the
three — no naming tie to a live or planned surface.” pwplz is in fact a live
product at pwplz.com, the operator’s first open-source project, the subject of
a published post at devarno.com/downlink/password-please, a public repo with
stars at Dev4rno/pwplz, and the intended base of a SaaS build. It is the
highest-value repo in the candidate set, not the lowest.
How the error was made, because the method matters more than the row.
Inertness was inferred from the absence of a url: field in registry.yaml.
Absence of a field is not evidence of absence of a surface — the registry was
silent, not the repo. The same inference disqualifies the runner-up as well:
downlink-hq maps to devarno.com/downlink, the operator’s live blog section.
Of the three placeholder entries only thrustr-io has no evidence against it,
which after this is not the same as evidence for it.
Context
Section titled “Context”PTV-SCF-0001’s P3 builds the end-to-end write probe that discharges
PTV-VCRM-DEBT-01 — six requirements verified by T (test) with no executing
test behind them. INV-1 (fatal) permits an applied write against one
designated repo, the canary, and P3 could not start because no canary was named:
registry.yaml has no canary field and Q-CANARY-1 sat open.
P0 evidenced three candidates converging from three independent signals. The
39-entry registry has 36 state/ files, and the three entries with no state file
are exactly the three role: placeholder entries — thrustr-io, downlink-hq,
pwplz. Each has no url:, each carries a provisioned App installation
(PETROVA_INSTALLATION_ID_THRUSTR / _DOWNLINK / _PWPLZ), and each is
annotated “App installed but no repos accessible at 2026-05-13 discovery”.
See docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md
§“Canary candidates”.
The operator selected pwplz on 2026-08-12.
Decision
Section titled “Decision”pwplz is the designated canary for all PETROVA write-verb probes. It is the
single repo against which INV-1 permits an applied write, and the only slug P3’s
probe may target. Every other governed slug remains read-only to the crew.
pwplz was chosen over thrustr-io and downlink-hq because it is the most
inert of the three — no naming tie to a live or planned surface — and over
traceo-mcp-server because that is a real repo where a defective probe has real
consequences.
Selecting the slug does not provision it. The five conditions in
docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md §“What a
conforming P3 credential would look like” stand unchanged, and condition 5 — a
recorded negative test proving the credential is refused against a second repo
— is a P3 deliverable, not an assertion.
Alternatives considered
Section titled “Alternatives considered”thrustr-ioordownlink-hq— identical shape and equally valid; rejected only because both names tie to surfaces that may become real, and a canary should stay disposable.traceo-mcp-server(role: scaffold,profile: permissive) — rejected: a real repo with real content, so a defective probe damages something. Itspermissiveprofile made it attractive precisely because it is the weakest gate, which is the wrong reason.- A fresh repo outside
registry.yaml— rejected: an ungoverned repo does not exercise the registry → App-auth → write-verb path, so a green probe would prove the verb works in a vacuum rather than through the control plane. It would also reproduce D-16, wherePODCASandKALEXhold installations outside governed inventory. petrova-codesitself — rejected: the self-entry declaresfleets_allowed: []by design, so agent automation against it is forbidden by the registry, and a probe there would write to the control plane it is meant to test.
Consequences
Section titled “Consequences”For code:
- No code change.
pwplzis a target, not a feature. - P3’s probe must resolve its target from the registry, never from a literal, so the canary can be changed by ratified supersession rather than by editing code.
For docs:
registry.yaml’spwplzentry (:764-775) needs a note recording canary status. It is arole: placeholderwith nourl:andfleets_allowed: [], so P3 must first create or point at a real repo and widenfleets_allowed. Registry edits are PR-only — this record does not authorise a direct edit.- Q-CANARY-1 and Q-CRED-4 are closed in
docs/findings/20260811-1749-ptv-scf-0001-p0-open-questions.md§“Amendments — 2026-08-12”.
For in-flight phases:
- P3 unblocks on naming, not on capability. It still needs a GitHub App
installation scoped to
pwplzalone, distinct from C-1 (the ambientghuser token, which holdsrepo,admin:org,delete_repo,workflow) and C-3 (thepetrova-actApp key, reaching 28 named installations). A probe run under either proves only that an estate-wide credential works. - P4/P5 unaffected — those block on the n8n credential’s scope (Q-CRED-3).
For invariants:
- INV-1’s “designated canary” now has a referent, so the invariant is checkable rather than vacuous.
- No MR added, modified, or repealed.
- INV-1 remains violated in this environment regardless: C-1 and C-3 are ambient and estate-wide. Naming a canary bounds where the crew intends to write; it does not bound what the crew can write. Containment stays INV-2 discipline, not credential scope, until P3 provisions the scoped installation.
References
Section titled “References”docs/findings/20260811-2027-ptv-scf-0001-credential-scope.md— candidate evidence, the five credential conditions, and C-1/C-3 blast radius.docs/findings/20260811-1749-ptv-scf-0001-p0-open-questions.md— Q-CANARY-1, Q-CRED-4 as raised.docs/findings/20260811-1749-ptv-scf-0001-p0-delta-register.md— D-16 (installed capability exceeds governed inventory).registry.yaml:764-775— thepwplzentry as it stands.docs/PETROVA-SDD-BASELINE.md§8.1 —PTV-VCRM-DEBT-01, the verification debt the probe discharges.docs/decisions/2026-08-10-countersign-gates-closed-status.md— why this staysopenuntil countersigned.
Sign-off
Section titled “Sign-off”- Subagent: PTV-SCF-0001 P1 (session 2026-08-12), recording the operator’s selection
- Human countersign — that
pwplzis the sole designated canary, and that no applied write lands against any other governed slug until this record is superseded