← Lab L14 — Failure Injection All modules

Lab L15 — Governed Multi-Harness Capstone System (Pure Go)

Phase 11 · CAPSTONE PROJECT — Lab L15
Status: Authored & Empirically Verified.
Student Lab Package: Authenticated Direct Download from VTAlgo Platform (hefesto-lab15-capstone.zip)
Branches: main (starter template) · solution (reference architecture).
Canonical Path: Student repo only (hefesto-lab15-capstone) — not E:\bridle, not the live product.

1. Laboratory Objective

Construct from scratch in pure Go standard library (zero external dependencies in go.mod) an enterprise-grade Governed Multi-Agent / Multi-Harness System, demonstrating how orthogonal subsystems, cryptographic ledgers, deterministic failure containment, two-phase budget circuit breakers, and heterogeneous harness adapters deliver mission-critical reliability and resilience under adversarial conditions.

The student implements:


2. System Architecture

┌──────────────────────────────────────────────────────────────────────────┐
│          HEFESTO GOVERNED MULTI-HARNESS CAPSTONE ENGINE (PURE GO)        │
│                                                                          │
│  ┌─────────────────────────┐           ┌──────────────────────────────┐  │
│  │ 1. Canonical State      │           │ 2. Epistemic Memory Store    │  │
│  │    sync.RWMutex Engine  │           │    Multi-Tenant Scoping      │  │
│  │    Monotonic Clocks     │           │    Cryptographic Digests     │  │
│  │    SHA-256 Merkle Log   │           │    TierHistorical Storage    │  │
│  └───────────┬─────────────┘           └──────────────┬───────────────┘  │
│              │                                        │                  │
│              ▼                                        ▼                  │
│  ┌────────────────────────────────────────────────────────────────────┐  │
│  │ 3. Deterministic Inconsistency Detector                            │  │
│  │    Evaluates candidate memories against active canonical state     │  │
│  │    Intercepts: Stale · False · Conflicting · Scope · Inversion     │  │
│  └───────────────────────────────────┬────────────────────────────────┘  │
│                                      │                                   │
│              ┌───────────────────────┴───────────────────────┐           │
│              │ Anomaly Detected                              │ Clean     │
│              ▼                                               ▼           │
│  ┌─────────────────────────────────────┐         ┌────────────────────┐  │
│  │ 4. DCRA Quarantine Engine           │         │ 5. Normal Path     │  │
│  │    • Non-destructive Isolation      │         │    • Admitted      │  │
│  │    • Authority Revoked = true       │         │    • Promoted to   │  │
│  │    • Canonical Fallback Injected    │         │      Prompt Buffer │  │
│  │    • SHA-256 Sealed Audit Receipt   │         │    • Zero Leakage  │  │
│  └──────────────────┬──────────────────┘         └─────────┬──────────┘  │
│                     │                                      │             │
│                     └───────────────────┬──────────────────┘             │
│                                         │                                │
│                                         ▼                                │
│  ┌────────────────────────────────────────────────────────────────────┐  │
│  │ 6. Governance & Control Plane                                      │  │
│  │    • Two-Phase Micro-Dollar Budget Fencing (Reserve / Settle)      │  │
│  │    • Human Approval Gates with Cryptographic Signatures            │  │
│  │    • Typed Multi-Role Handoffs (Inference ≠ Evidence)              │  │
│  └───────────────────────────────────┬────────────────────────────────┘  │
│                                      │                                   │
│            ┌─────────────────────────┴─────────────────────────┐         │
│            ▼                                                   ▼         │
│  ┌───────────────────────────────────┐   ┌────────────────────────────┐  │
│  │ 7. Native In-Process Harness      │   │ 8. Subprocess CLI Adapter  │  │
│  │    Low-latency Go Execution       │   │    Isolated OS Sandbox     │  │
│  └───────────────────────────────────┘   └────────────────────────────┘  │
└──────────────────────────────────────────────────────────────────────────┘

3. Package Structure

hefesto-lab15-capstone/
├── cmd/
│   └── capstone-cli/
│       └── main.go                  # Entrypoint: 5 operational CLI modes
├── pkg/
│   ├── benchmark/
│   │   └── runner.go                # Equal-compute benchmark runner (SAS vs MAS)
│   ├── budget/
│   │   └── circuit_breaker.go       # 2PC micro-dollar budget governor
│   ├── containment/
│   │   └── dcra_engine.go           # Non-destructive quarantine & audit receipts
│   ├── detector/
│   │   └── inconsistency_rules.go   # O(1) deterministic anomaly detector
│   ├── domain/
│   │   └── types.go                 # Core types, roles, tiers, handoff payloads
│   ├── governance/
│   │   ├── approval_gate.go         # HITL cryptographic approval gates
│   │   └── handoff_validator.go     # Typed role handoffs & evidence segregation
│   ├── harness/
│   │   ├── adapter.go               # AgentHarness interface & registry
│   │   ├── native.go                # In-process Go native harness
│   │   └── subprocess.go            # External CLI subprocess adapter
│   ├── memory/
│   │   └── epistemic_store.go       # Multi-tenant memory store & lineage
│   ├── metrics/
│   │   └── summary.go               # FCE, MTTR, CTax, and certification reporter
│   ├── recovery/
│   │   └── amnesic_agent.go         # Stateless recovery from Merkle checkpoints
│   └── state/
│       ├── fsm.go                   # Concurrent state machine & version clocks
│       └── merkle_ledger.go         # Append-only SHA-256 Merkle chain
├── tests/
│   └── capstone_test.go             # 17/17 automated integration & race tests
├── go.mod                           # Pure standard library (Go 1.26.3, 0 deps)
└── README.md

4. Operational Modes of cmd/capstone-cli

Mode 1: Nominal Execution (-mode nominal)

Executes an end-to-end multi-role task under governed control:

go run cmd/capstone-cli/main.go -mode nominal

Mode 2: Failure Injection & DCRA Containment (-mode inject-failure)

Simulates an adversarial stale-memory injection attack:

go run cmd/capstone-cli/main.go -mode inject-failure

Mode 3: Stateless Recovery (-mode stateless-recovery)

Certifies the *Amnesic Agent Test*:

go run cmd/capstone-cli/main.go -mode stateless-recovery

Mode 4: Equal-Compute Benchmark (-mode benchmark)

Executes SAS vs MAS under an identical \$0.05 compute budget:

go run cmd/capstone-cli/main.go -mode benchmark

Mode 5: Industrial Certification Report (-mode certify)

Runs all verification suites and emits an authenticated ASCII + JSON compliance receipt suitable for enterprise governance audits:

go run cmd/capstone-cli/main.go -mode certify

5. Verification Suite

Run all automated unit, concurrency, and race-detection tests:

go test -v -race ./tests

Expected Output:

=== RUN   TestCanonicalStateMonotonicVersions
--- PASS: TestCanonicalStateMonotonicVersions (0.00s)
=== RUN   TestStateMerkleLedgerTamperingDetection
--- PASS: TestStateMerkleLedgerTamperingDetection (0.00s)
=== RUN   TestStateSnapshotIsolation
--- PASS: TestStateSnapshotIsolation (0.00s)
=== RUN   TestMemoryScopedTenancy
--- PASS: TestMemoryScopedTenancy (0.00s)
=== RUN   TestDetectorStaleMemoryTrap
--- PASS: TestDetectorStaleMemoryTrap (0.00s)
=== RUN   TestDetectorAuthorityInversionTrap
--- PASS: TestDetectorAuthorityInversionTrap (0.00s)
=== RUN   TestDetectorCrossScopeBreach
--- PASS: TestDetectorCrossScopeBreach (0.00s)
=== RUN   TestDetectorConflictingMemory
--- PASS: TestDetectorConflictingMemory (0.00s)
=== RUN   TestDCRAQuarantineAuthorityRevocation
--- PASS: TestDCRAQuarantineAuthorityRevocation (0.00s)
=== RUN   TestDCRACanonicalFallback
--- PASS: TestDCRACanonicalFallback (0.00s)
=== RUN   TestBudgetTwoPhaseReservation
--- PASS: TestBudgetTwoPhaseReservation (0.00s)
=== RUN   TestBudgetHardCircuitBreaker
--- PASS: TestBudgetHardCircuitBreaker (0.00s)
=== RUN   TestGovernanceHandoffInferenceSegregation
--- PASS: TestGovernanceHandoffInferenceSegregation (0.00s)
=== RUN   TestGovernanceHumanApprovalGate
--- PASS: TestGovernanceHumanApprovalGate (0.00s)
=== RUN   TestStatelessRecoveryAmnesicAgent
--- PASS: TestStatelessRecoveryAmnesicAgent (0.00s)
=== RUN   TestConcurrentMultiHarnessExecution
--- PASS: TestConcurrentMultiHarnessExecution (0.00s)
=== RUN   TestEqualComputeBenchmarkExecution
--- PASS: TestEqualComputeBenchmarkExecution (0.00s)
PASS
ok      hefesto-lab15-capstone/tests    0.226s

All 17 tests must pass deterministically with zero data races. Congratulations on mastering the architecture of Governed Agent Runtimes!