Carolopedia

A public encyclopedia of Carolverse.

πŸ“– Carolopedia β€Ί Droids β€Ί Core Lock SweepEntity page

Core Lock Sweep

Droid shared machinery, run under Themis's own OS identity. Calls shared.core_lock.audit, emits run-audit either way, and raises an Agentbook escalation to Orion on any finding.

πŸ“–About

Core Lock Sweep is a droid that checks whether the estate’s protected core remains protected. Its purpose is to detect when those protections have changed.

πŸ“–Usage

It supports recurring checks in the estate’s work, reporting findings that need attention and making clear when a check could not be completed.

πŸ“–Purpose

Watch that the protected core is actually locked on the OS, not just named on a list β€”. A correct lock was silently reverted on 2026-09-02 and sat unnoticed for two days because nothing re-checked.

πŸ“–Duties

Run the core-lock audit daily. Report clean as clean. When a protected path has lost its lock, go RED and escalate to Orion by the one ruled route, naming WHEN and HOW each path changed (inode time versus content time, which distinguishes a re-own from an edit). When the audit itself cannot run, say the core state is UNKNOWN and go red β€” never report an unrunnable check as a pass.

πŸ“–Constraints

Read-only. It never repairs: repair is shared machinery and needs root, and a watcher that could fix what it inspects would be a second door into the core. It holds no idea of 'locked' of its own β€” that comes from shared machinery, which takes it from what the sanctioned install lane writes.

Some source information is confidential and is not published here.

πŸ‘€Belongs to

Source: Droid Families Β· Public information reflected here.