T4 Reordering
The user set a rule, then made an exception. The attacker swaps the two records, so the exception now comes first and the rule overrides it.
What stops it
Position inside the authenticated data: the record's tag must cover where it sits, not only what it says.
What does not
Everything that authenticates content alone.
Today, measured 2026-10-07
- rejected on read
- OpenFang model, tip-persistence fix, Agent Memory reference runtime, SQLite canonical substrate, bucketed row digests, fail-closed open
- reported on audit
- inspeximus, receipts on, attacker holds the store directory, inspeximus, receipts on, attacker also holds the config home, langgraph-ledger over SqliteSaver, hash-chained ledger, verify_thread audit, memory-blackbox memory.md watcher, agent process alive, scan audit, memory-blackbox memory.md watcher, agent restarted before the scan, scan audit, Atelya Attest, keyed hash chain, verify_chain audit, Atelya Attest, keyed hash chain plus anchored head, verify and consistency audit, CONTINUUM event log, hash chain, verify_events audit, CONTINUUM event log, hash chain plus Ed25519-signed head, attest-verify audit
- accepted
- LangGraph SqliteSaver, LangGraph PostgresSaver, LangGraph RedisSaver, OpenAI Agents SDK SQLiteSession, LlamaIndex Memory, SQLAlchemy chat store, CrewAI long-term memory, LanceDB dataset, Letta block checkpoint history, Mem0 local Qdrant store, inspeximus, receipts off (default), AtMem 2.3.7, audit chain alone, verify() audit, AtMem 2.3.7, audit chain with an external checkpoint outside the attacker-controlled store directory, verify() audit, acrf-memory-guard, per-entry HMAC over a JSON store
agmi-check --adapter agmi.adapters.langgraph_sqlite:LangGraphSqliteAdapter # runs T1 to T8; this is T4