← Files Build StewardARCHIVED FILE

skills/build-space/references/safety-contract.md

4.38 KB · Oct 4, 2026 · 12:33 UTC

↓ Download file

# Build Steward safety contract

Read this before preparing or applying a reclaim selection.

## Headroom reservations

`reserve` records an expected build peak against current free space and other active reservations on the same volume. It is blocked when the projected remainder falls below the chosen hard floor. Because reservation is non-destructive, unavailable process visibility produces a warning rather than overriding otherwise-valid headroom math; it is not evidence that process state is safe. `audit` and `apply` still fail closed when their required process or open-handle checks are unavailable. Reservation does not allocate disk, launch or stop a build, or authorize cleanup.

`release` closes one exact reservation with an outcome of `succeeded`, `failed`, or `interrupted`. Release does not remove files. Roots attributed to an active reservation are `active`; roots from a failed or interrupted reservation remain `protected` for later human review and are not made disposable by release.

## Classification

| State | Meaning | Allowed effect |
| --- | --- | --- |
| `eligible` | A built-in rebuildable class passed age, identity, ownership, scan, mount, repository, process, and activity checks | May be selected for `prepare` |
| `review` | The item is not a built-in reclaim class, including inventory-only app and simulator entries, or required evidence is incomplete | Explain the gap; do not apply |
| `active` | Too recent, reserved by an active build, or associated with a running producer | Preserve |
| `protected` | Version-control state, interrupted work, symlink root, foreign ownership, filesystem crossing, or another hard boundary | Preserve |

`eligible` is not permission. User assertion alone cannot make an arbitrary path eligible in v0.1.

## Selection-specific approval

`prepare` takes exact eligible item IDs from one unexpired plan, writes a private local review, and returns an approval digest bound to that selected set and its estimated allocation. The user must inspect that review outside the chat.

`apply` must receive the unchanged plan, the same item IDs, and that exact approval digest from `prepare`. The plan digest by itself is not approval. Adding or removing an item requires a new `prepare`. Unselected plan entries are never authorized.

## Apply contract

Before changing anything, `apply` verifies the plan and selection, checks that control files stay outside candidates, locks the local executor, and rechecks every selected item’s bound location, identity, metadata, process state, and open handles. Any unavailable or changed check fails closed before the batch widens.

For an approved item, the executor records a private pre-action receipt, moves only that exact object through its guarded local quarantine step, and records the final effect and observed volume free-space change. It never accepts a glob, shell fragment, recursive parent target, symlink traversal, or model-supplied replacement path.

## Always protected or unsupported

- A repository root or tree containing `.git`, `.hg`, or `.svn` is not generically reclaimable. A clean status does not prove a checkout is disposable or remotely recoverable.
- A temporary directory may hold authoritative uncommitted work. Active, failed, interrupted, and unattributed session roots do not become reclaimable from age alone.
- Simulator devices may hold test state, credentials, or irreplaceable reproductions. Build Steward inventories but does not remove them.
- App filenames do not prove current, rollback, or superseded lineage. App inventory reads only `CFBundleIdentifier`, `CFBundleShortVersionString`, and `CFBundleVersion` from `Contents/Info.plist`; app bundles cannot be applied.
- Version 0.1 cannot kill processes, stop simulators, move or remove apps, delete session history, schedule work, or run as a daemon, dashboard, hook, MCP server, or background monitor.
- Low disk can make signing, trust, and OS services fail. Treat those failures as inconclusive until space and service health are restored.

## Privacy

Reservation state, plans, local reviews, and receipts remain local and permission-restricted. Normal model-facing output uses category totals, opaque item IDs, reason codes, and byte counts; exact paths appear only in private local artifacts needed for informed review. Build Steward makes no network requests and never uploads file lists, source, credentials, or private paths. Public examples use synthetic data only.

SHA-256: dc2b4f424959641075a3be9c8e0e63e752fdb2fbe9f5633f366b60a9c8db416c