Adds physical blockers so agents cannot bypass the correct delivery paths:
1. pre_edit_gate.py v1.3.0 (.claude/hooks/) — two new Track E rules:
- Rule 1: block any write to *.ai_mail.local/inbox.json (use drone @ai_mail email)
- Rule 2: block cross-branch writes unless CWD branch is in TRUSTED_CROSS_WRITERS
2. permissions.py (seedgo/apps/modules/) — single source of truth:
- TRUSTED_CROSS_WRITERS = ("devpulse", "seedgo", "spawn")
- is_trusted_caller(name), identify_caller(cwd)
3. drone auth.py — ALLOWED_CALLERS now imported from permissions.py
(extended from ["devpulse"] to all three trusted cross-writers)
4. ai_mail delivery.py — deliver_to_inbox_file() helper added:
- Single canonical path for direct-path inbox writes, always fires notify-send
- reply.py _deliver_via_reply_path() backdoor routes through this helper
5. inbox_audit.py (seedgo/apps/modules/) — drone @seedgo audit inbox-ids:
- Scans all inbox.json files for non-8-hex message ids
- Alerts with drone @ai_mail email command when violations found
6. test_hooks_track_e.py — 26 tests, all passing (359 total in suite)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>