Lab L4 — Governed Multi-Agent Fabric & The Maker-Checker Protocol
Phase 4 · MULTI-AGENT — Lab L4
Status: Authored & Empirically Verified.
Student Lab Package: Authenticated Direct Download from VTAlgo Platform
Branches:main(clean starter code for students) ·solution(reference architecture & instructor playbook).
Video Master: 05:23 min @ 1080p FHD 60fps NVENC · Audio Elmer Oficial (-16 LUFS, Zero BGM) · Curated Synchronized Subtitles (ASS).
Canonical Path: Student repo only — notE:\bridle, not the Kratos live product.
1. Laboratory Objective
Construct from scratch in pure Go a Governed Multi-Agent Fabric implementing the Maker-Checker Protocol, proving on the student's machine that:
$$\text{More Agents} \neq \text{More Capability by Default}$$
and that multi-agent architectures only provide positive utility when bound by strict typed communication contracts, cryptographic attestation gates, and epistemic isolation between generation and evaluation.
2. The Five Cardinal Subsystems
The fabric is composed of five orthogonal subsystems in pure Go (zero heavy external dependencies):
┌──────────────────────────────────────────────────────────────────────────┐
│ GOVERNED MULTI-AGENT FABRIC │
│ │
│ ┌─────────────────────────┐ ┌──────────────────────────────┐ │
│ │ 1. Typed Envelope & │ │ 2. Blind Trajectory │ │
│ │ Schema Firewalls ├──────────►│ Sanitizer │ │
│ │ (OpenTelemetry / DLQ) │ │ (Purges Maker Rationality) │ │
│ └─────────────────────────┘ └──────────────┬───────────────┘ │
│ │ │
│ ▼ │
│ ┌─────────────────────────┐ ┌──────────────────────────────┐ │
│ │ 4. Ed25519 │ │ 3. Adversarial Verification │ │
│ │ Cryptographic Gate │◄──────────┤ & Mutation Engine │ │
│ │ (Kernel Non-Circumv.) │ │ (Synthetic Fuzzing / Tests) │ │
│ └───────────┬─────────────┘ └──────────────────────────────┘ │
│ │ │
│ ▼ │
│ ┌────────────────────────────────────────────────────────────────────┐ │
│ │ 5. Deterministic Audit Ledger & Test Suite (10/10 in <0.25s) │ │
│ └────────────────────────────────────────────────────────────────────┘ │
└──────────────────────────────────────────────────────────────────────────┘
1. Typed Agent Envelopes & Ingress/Egress Firewalls (internal/transport)
- Replaces unconstrained natural language chatrooms with strongly-typed
AgentEnvelopestructs. - OpenTelemetry distributed tracing (
TraceID,SpanID, parent references). - Deterministic cryptographic idempotency keys (
crypto/sha256) to guarantee zero duplicate state mutations. - In-memory compiled JSON-Schema admission firewalls at ingress and egress boundaries.
- Automatic Dead-Letter Queue (DLQ) isolation for malformed, untyped, or hallucinated payloads.
2. Blind Asymmetric Evaluator & Trajectory Sanitizer (internal/sanitizer)
- Neutralizes Maker confirmation bias and self-serving rationalizations.
- Surgical extraction of candidate deliverables: 1. Proposed code diff anchored to its SHA-256 hash. 2. Original root task specification pinned as immutable attention anchor. 3. Negative security constraints.
- Complete purging of Maker scratchpads, chain-of-thought, and trial-and-error reasoning traces.
3. Adversarial Verification Engine (internal/verifier)
- Active hostile posture: does not merely execute Maker-supplied test suites.
- Synthetic mutation testing: mutates relational boundaries and logical operators (
&&$\leftrightarrow$||,<$\leftrightarrow$<=) to assert that the test suite actively catches injected faults. - Boundary-case injection: nil payloads, buffer overflows, and malicious injection characters.
- Negative AST verification: asserts zero unauthorized file mutations occurred outside declared scopes.
- Strongly typed tri-state verdict:
Approved,Rejected(with structured fault diff), orBlocked(security violation).
4. Ed25519 Cryptographic Attestation Gate (internal/attestation)
- Multi-signature quorum enforcement (dual-key authorization).
- Cryptographically signed tickets using Go's native
crypto/ed25519. - Ticket seals artifact SHA-256 hash, verified oracle IDs, timestamp, and strict 60-second TTL.
- Kernel Non-Circumvention Principle: The execution environment physically refuses any state mutation or Git commit lacking a valid, unexpired cryptographic attestation ticket.
5. Deterministic Audit Ledger & Test Suite (tests/fabric_test.go)
- Append-only cryptographically linked ledger recording every state transition.
- 10/10 deterministic tests pass in approximately 0.25 seconds with zero network flakiness.
3. Hands-On Verification Protocol
To run the complete test suite locally:
cd hefesto-lab4-multi-agent-fabric
go test -v -race ./...
All 10 deterministic tests must pass with zero data races.