mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-09 00:12:21 +02:00
fix(runtime): verify namespace init death and record Wave 3-S validation
This commit is contained in:
@@ -0,0 +1,128 @@
|
||||
[
|
||||
"tests/test_app_db_permissions.py::test_app_db_created_with_0600",
|
||||
"tests/test_app_db_permissions.py::test_app_db_sidecars_relocked",
|
||||
"tests/test_app_db_permissions.py::test_app_db_file_uri_created_with_0600",
|
||||
"tests/test_app_db_permissions.py::test_app_db_localhost_file_uri_created_with_0600",
|
||||
"tests/test_app_db_permissions.py::test_app_db_non_uri_mode_query_created_with_0600",
|
||||
"tests/test_app_db_permissions.py::test_app_db_plain_file_uri_created_with_0600",
|
||||
"tests/test_auth_config_lock_concurrency.py::TestConcurrentCreateUser::test_parallel_creates_no_lost_users",
|
||||
"tests/test_auth_config_lock_concurrency.py::TestConcurrentCreateUser::test_parallel_creates_same_username_only_one_wins",
|
||||
"tests/test_auth_config_lock_concurrency.py::TestConcurrentDeleteUser::test_parallel_deletes_no_corruption",
|
||||
"tests/test_auth_config_lock_concurrency.py::TestConcurrentRenameUser::test_parallel_renames_no_lost_users",
|
||||
"tests/test_auth_config_lock_concurrency.py::TestConcurrentMixedOperations::test_mixed_operations_no_corruption",
|
||||
"tests/test_auth_config_lock_concurrency.py::TestDiskConsistency::test_file_always_valid_json_during_concurrent_ops",
|
||||
"tests/test_auth_root_path.py::test_real_auth_middleware_uses_application_relative_path",
|
||||
"tests/test_caldav_bidirectional_sync.py::test_event_to_ical_serializes_core_fields_and_rrule",
|
||||
"tests/test_caldav_google_principal_url.py::test_google_sync_pulls_events_instead_of_empty",
|
||||
"tests/test_caldav_writeback.py::test_build_ical_timed_event_has_core_fields",
|
||||
"tests/test_caldav_writeback.py::test_build_ical_all_day_uses_date_values",
|
||||
"tests/test_caldav_writeback.py::test_build_ical_includes_rrule",
|
||||
"tests/test_caldav_writeback.py::test_push_create_calls_save_event",
|
||||
"tests/test_caldav_writeback.py::test_push_update_overwrites_existing",
|
||||
"tests/test_doc_library_open_orphaned.py::test_mobile_explicit_load_restores_full_editor_from_bottom_dock",
|
||||
"tests/test_document_followup_integrity.py::test_unavailable_active_target_never_falls_back_to_other_document[deleted-document-edit_document]",
|
||||
"tests/test_document_followup_integrity.py::test_unavailable_active_target_never_falls_back_to_other_document[deleted-document-update_document]",
|
||||
"tests/test_document_followup_integrity.py::test_unavailable_active_target_never_falls_back_to_other_document[foreign-document-edit_document]",
|
||||
"tests/test_document_followup_integrity.py::test_unavailable_active_target_never_falls_back_to_other_document[foreign-document-update_document]",
|
||||
"tests/test_document_followup_integrity.py::test_targeted_edit_and_undo_preserve_other_occurrences",
|
||||
"tests/test_document_followup_integrity.py::test_no_target_legacy_fallback_still_scopes_to_owner",
|
||||
"tests/test_document_followup_integrity.py::test_invalid_multi_edit_saves_only_exact_matches_and_reports_remainder",
|
||||
"tests/test_document_followup_integrity.py::test_batch_with_only_bad_anchors_reports_all_without_saving",
|
||||
"tests/test_document_followup_integrity.py::test_long_proofreading_batch_saves_safe_matches_and_identifies_remainder",
|
||||
"tests/test_document_followup_integrity.py::test_inline_suggestion_is_reviewable_then_applies_only_its_target",
|
||||
"tests/test_document_followup_integrity.py::test_whole_document_update_persists_exact_replacement",
|
||||
"tests/test_document_followup_integrity.py::test_ambiguous_or_partial_word_edits_do_not_mutate[alpha-beta]",
|
||||
"tests/test_document_followup_integrity.py::test_ambiguous_or_partial_word_edits_do_not_mutate[vio-new]",
|
||||
"tests/test_document_followup_integrity.py::test_ambiguous_or_partial_word_edits_do_not_mutate[tha-that]",
|
||||
"tests/test_document_followup_integrity.py::test_explicit_replace_all_corrects_every_occurrence",
|
||||
"tests/test_document_followup_integrity.py::test_replace_all_cannot_change_fragments_of_correct_words",
|
||||
"tests/test_document_followup_integrity.py::test_ambiguous_suggestion_returns_exact_recovery_anchors",
|
||||
"tests/test_document_followup_integrity.py::test_mixed_suggestion_batch_queues_valid_items_and_reports_bad_anchors",
|
||||
"tests/test_document_history_controls.py::test_mobile_rich_text_history_state_and_document_switch",
|
||||
"tests/test_document_library_mobile_footer.py::test_mobile_open_in_new_chat_copies_to_materialized_session",
|
||||
"tests/test_document_module_api.py::test_default_export_surface_is_complete_and_callable",
|
||||
"tests/test_document_module_api.py::test_named_exports_survive_and_stay_callable",
|
||||
"tests/test_document_module_api.py::test_window_bridge_is_the_default_export",
|
||||
"tests/test_document_outline.py::test_outline_jumps_in_markdown_and_rich_text_and_fits_mobile",
|
||||
"tests/test_document_rich_checklist_enter.py::test_enter_creates_unchecked_task_and_empty_enter_exits_cleanly",
|
||||
"tests/test_document_rich_color_reset_and_contrast.py::test_rich_colors_follow_theme_and_undo_as_one_edit",
|
||||
"tests/test_document_rich_docx_export.py::test_browser_word_export_contains_native_rich_docx_ooxml",
|
||||
"tests/test_document_rich_docx_export.py::test_browser_markdown_word_export_keeps_heading_and_inline_formatting",
|
||||
"tests/test_document_rich_find_boundaries.py::test_find_rejects_cross_block_matches_but_supports_inline_matches_and_replacement",
|
||||
"tests/test_document_rich_font_color_controls.py::test_numeric_font_size_and_custom_colors_work_on_desktop_and_mobile",
|
||||
"tests/test_document_rich_heading_enter.py::test_mobile_heading_enter_exits_cleanly_and_is_one_step_undoable",
|
||||
"tests/test_document_rich_heading_enter.py::test_heading_enter_preserves_shift_middle_and_empty_heading_semantics",
|
||||
"tests/test_document_rich_image_caption.py::test_mobile_image_caption_survives_resize_history_and_empty_removal",
|
||||
"tests/test_document_rich_input_rules.py::test_typing_markers_converts_blocks_and_preserves_following_text",
|
||||
"tests/test_document_rich_keyboard_shortcuts.py::test_rich_document_shortcuts_work_at_desktop_and_mobile_widths",
|
||||
"tests/test_document_rich_selection_toolbar.py::test_selection_toolbar_formats_and_stays_inside_desktop_and_mobile_viewports",
|
||||
"tests/test_document_rich_slash_menu.py::test_slash_menu_filters_converts_blocks_inserts_tables_and_fits_mobile",
|
||||
"tests/test_document_rich_smart_link_paste.py::test_rich_url_paste_links_selections_and_plain_urls_without_unsafe_autolinks",
|
||||
"tests/test_document_rich_structure_tools.py::test_mobile_headings_page_break_history_and_persistence",
|
||||
"tests/test_document_rich_table_cell_alignment.py::test_mobile_table_cell_alignment_tracks_state_and_native_history",
|
||||
"tests/test_document_rich_table_header_preservation.py::test_mobile_structural_edits_preserve_header_modes_and_history",
|
||||
"tests/test_document_rich_table_headers.py::test_mobile_header_row_and_column_toggle_independently_with_undo",
|
||||
"tests/test_document_rich_table_merge_split.py::test_mobile_merge_split_round_trip_preserves_headers_formatting_and_history",
|
||||
"tests/test_document_rich_table_tab_history.py::test_mobile_table_tab_navigation_row_creation_and_history",
|
||||
"tests/test_document_rich_toolbar_menus.py::test_mobile_toolbar_uses_native_momentum_and_distinct_activation_tokens",
|
||||
"tests/test_document_rich_toolbar_menus.py::test_mobile_toolbar_menu_preserves_selection_and_restores_focus",
|
||||
"tests/test_document_rich_toolbar_menus.py::test_rich_toolbar_menus_track_live_formatting_values",
|
||||
"tests/test_document_save_shortcut.py::test_ctrl_s_saves_rich_text_immediately_once_and_updates_status",
|
||||
"tests/test_document_save_status.py::test_save_status_is_dirty_race_safe_and_reports_failures",
|
||||
"tests/test_document_toolbar_order.py::test_rich_toolbar_rendered_order_is_stable_on_desktop_and_mobile",
|
||||
"tests/test_email_library_module_graph_js.py::test_every_package_module_evaluates_on_its_own_in_a_browser",
|
||||
"tests/test_email_library_module_graph_js.py::test_wrapper_and_entry_module_hand_out_the_same_functions",
|
||||
"tests/test_email_package_compatibility.py::test_legacy_email_modules_alias_canonical_module_objects",
|
||||
"tests/test_escape_inner_layers.py::test_rich_escape_closes_toolbar_then_selection_badge",
|
||||
"tests/test_escape_inner_layers.py::test_email_escape_closes_inner_states_without_closing_library",
|
||||
"tests/test_extract_text_tool.py::test_extract_text_renders_and_ocr_scans_pdf_pages",
|
||||
"tests/test_history_resume_rendering_js.py::test_history_resume_rendering_browser_suite",
|
||||
"tests/test_image_provider_transport.py::test_image_provider_protocol[https://openrouter.ai/api/v1-True]",
|
||||
"tests/test_image_provider_transport.py::test_image_provider_protocol[https://openrouter.ai/api/v1-False]",
|
||||
"tests/test_image_provider_transport.py::test_image_provider_protocol[https://api.openai.com/v1-True]",
|
||||
"tests/test_image_provider_transport.py::test_image_provider_protocol[https://api.openai.com/v1-False]",
|
||||
"tests/test_live_fallback_round_attribution.py::test_detached_resume_reconciles_canonical_terminal_failures",
|
||||
"tests/test_live_fallback_round_attribution.py::test_detached_resume_surfaces_fallback_then_provider_alias_without_reload",
|
||||
"tests/test_live_fallback_round_attribution.py::test_detached_resume_renders_preoutput_error_without_empty_reload",
|
||||
"tests/test_manage_tasks_cron.py::test_cron_create_edit_resume_and_invalid_edit_rollback",
|
||||
"tests/test_manage_tasks_cron.py::test_named_weekdays_create_and_edit_preserve_actual_clock",
|
||||
"tests/test_manage_tasks_cron.py::test_time_only_edit_changes_cron_clock_not_calendar_fields[15 9 * * 1,3,5]",
|
||||
"tests/test_manage_tasks_cron.py::test_time_only_edit_changes_cron_clock_not_calendar_fields[15 9 15 * *]",
|
||||
"tests/test_manage_tasks_cron.py::test_time_only_edit_changes_cron_clock_not_calendar_fields[0,30 8-10 * * 2,4]",
|
||||
"tests/test_manage_tasks_cron.py::test_invalid_cron_retime_rolls_back_all_edits",
|
||||
"tests/test_reserved_username_admin_escalation.py::test_rename_into_reserved_username_is_blocked[internal-tool]",
|
||||
"tests/test_reserved_username_admin_escalation.py::test_rename_into_reserved_username_is_blocked[api]",
|
||||
"tests/test_reserved_username_admin_escalation.py::test_rename_into_reserved_username_is_blocked[demo]",
|
||||
"tests/test_reserved_username_admin_escalation.py::test_rename_into_reserved_username_is_blocked[system]",
|
||||
"tests/test_reserved_username_admin_escalation.py::test_rename_into_reserved_username_is_blocked[__odysseus_local__]",
|
||||
"tests/test_reserved_username_admin_escalation.py::test_normal_usernames_still_allowed",
|
||||
"tests/test_review_calendar_invitation.py::test_reschedule_and_cancellation_target_same_event",
|
||||
"tests/test_review_calendar_invitation.py::test_cancellation_before_invite_does_not_create_event",
|
||||
"tests/test_review_calendar_invitation.py::test_same_ics_uid_is_scoped_to_owner",
|
||||
"tests/test_review_calendar_invitation.py::test_attendee_reply_does_not_create_event",
|
||||
"tests/test_review_calendar_invitation.py::test_overlapping_revisions_do_not_race",
|
||||
"tests/test_review_calendar_invitation.py::test_same_title_time_does_not_link_different_senders",
|
||||
"tests/test_review_calendar_invitation.py::test_occurrence_reschedule_excludes_original_without_moving_series",
|
||||
"tests/test_review_calendar_invitation.py::test_occurrence_cancellation_before_series_is_preserved",
|
||||
"tests/test_review_calendar_invitation.py::test_series_cancellation_also_cancels_detached_events",
|
||||
"tests/test_review_document_conversion.py::test_imported_office_document_is_owned_at_first_commit",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[alice-https://api.example.test/v1/chat/completions-Bearer alice-secret-task]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[alice-https://api.example.test/v1/chat/completions-Bearer alice-secret-skill]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[bob-https://api.example.test/v1/chat/completions-None-task]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[bob-https://api.example.test/v1/chat/completions-None-skill]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[alice-https://api.example.test.evil.test/v1-None-task]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[alice-https://api.example.test.evil.test/v1-None-skill]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[alice-https://evil.test/https://api.example.test/v1-None-task]",
|
||||
"tests/test_review_endpoint_credentials.py::test_credential_resolution_is_exact_and_owner_scoped[alice-https://evil.test/https://api.example.test/v1-None-skill]",
|
||||
"tests/test_setup_admin_user.py::test_create_default_admin_normalizes_env_username",
|
||||
"tests/test_setup_admin_user.py::test_main_loads_admin_password_from_env_file",
|
||||
"tests/test_turn_rendering_js.py::test_turn_rendering_browser_suite",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_endpoint_id_rejects_another_owners_private_endpoint",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_endpoint_id_returns_callers_own_endpoint",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_endpoint_id_allows_legacy_null_owner_shared_row",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_endpoint_id_skips_disabled_even_when_owned",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_fallback_never_picks_another_owners_endpoint",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_fallback_returns_none_when_only_others_endpoints",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_null_owner_is_legacy_single_user_noop",
|
||||
"tests/test_research_endpoint_owner_scope.py::test_runtime_resolution_uses_provider_auth_for_chatgpt_subscription"
|
||||
]
|
||||
@@ -0,0 +1,2 @@
|
||||
|
||||
added 4 packages in 560ms
|
||||
@@ -0,0 +1,256 @@
|
||||
# Wave 3-S delivery record
|
||||
|
||||
Branch: `feature/runtime-containment`. The final production/delivery commit
|
||||
contains namespace-init verification, this record and validation evidence;
|
||||
its exact HEAD is in the delivery message. All commits are local. No push,
|
||||
PR, merge into lab, branch switch,
|
||||
reset, rebase, merge abort, cleanup, or other Odysseus worktree mutation occurred.
|
||||
|
||||
## Reconciliation
|
||||
|
||||
| Revision | Exact commit |
|
||||
| --- | --- |
|
||||
| Original containment head | `8e101fdcb8e775105bd4297298be580988bc7ad0` |
|
||||
| Frozen integration lab | `1e3c50d2dd66484dd515c8caff3614e4ee9cea20` |
|
||||
| Merge base | `d6c3c98c75e03f70c05ebe4058c6fa12e0395f62` |
|
||||
| Reconciliation checkpoint | `083a573f7eab63d014331e669178cc367c22a2c8` |
|
||||
|
||||
The checkpoint has exactly the original containment head and frozen lab as its
|
||||
two parents. The in-progress merge was recovered, not restarted. Its only
|
||||
unmerged path was `website/configuration-reference.md`. All three conflict
|
||||
stages were inspected; regenerating the reference from the merged sources
|
||||
preserved containment references and newer lab references together.
|
||||
|
||||
Automatic merges of `src/agent_tools/subprocess_tools.py`,
|
||||
`src/tool_execution.py`, and `tests/test_agent_bash_windows.py` preserved the
|
||||
Windows Bash environment/cwd/capture contract and authority before dispatch.
|
||||
The checkpoint also corrected two test assumptions: exact result equality after
|
||||
adding containment metadata, and an approval-test database stub that needed to
|
||||
be isolated to that test. Reconciliation validation passed 1,224 tests before
|
||||
the merge was committed.
|
||||
|
||||
RequestAuthority, SemanticIntent, ExactOperation, OperationGrant, TurnContract,
|
||||
approval policy, and trusted/untrusted request boundaries were preserved.
|
||||
Since reconciliation, `src/agent_runtime/authority.py`, `src/turn_contract.py`,
|
||||
and `src/tool_approvals.py` have no changes. The edits to tool execution pass the
|
||||
existing trusted environment into the contained background launcher and report
|
||||
its refusal; authority evaluation and background authority sealing retain their
|
||||
original ordering and owner.
|
||||
|
||||
## Subsequent commits
|
||||
|
||||
| Commit | Change |
|
||||
| --- | --- |
|
||||
| `5bb1326183306e8341d3ca1e6e6f31e4bf9cb0b3` | ODY-152: shared native execution, capture, persistence and teardown |
|
||||
| `765d79cadf3113e973048ff2e04b0c51d64a88b6` | ODY-143: unconditional native Python containment |
|
||||
| `f48931407a81bac138cd231d95b95ec0b326ad5b` | Correct the Python namespace test's outside-sibling fixture |
|
||||
| `127f9b0836456cd95ac8fe4bd5a7ee0c238d8f0d` | ODY-145: contained detached Bash supervisor |
|
||||
| `f63d333a61404656885be9546e5102f46c248b1c` | ODY-147: retire automatic tmux sessions and reap verified legacy sessions |
|
||||
| `929987dde7920afb90f0590c24474ae3fa2b4e58` | ODY-150: replace pane capture with bounded, explicit output capture |
|
||||
| `865968c8d5c0ff72c3faeeaa993705064dca33d9` | ODY-141 LAST: functional namespaces, readiness, cancellation and enforcement |
|
||||
| `a655abf69839f5a83f14bd48675a9fb178a9b028` | Release and report a background supervisor's failed initialization |
|
||||
| Commit containing this record | Verify namespace-init death, pin the probed binary, make completed release idempotent, and record final validation |
|
||||
|
||||
## Item status
|
||||
|
||||
| Item | Status and evidence |
|
||||
| --- | --- |
|
||||
| ODY-152 | Implemented. Native tools, detached jobs and compatibility callers use shared containment/teardown; transactional stores preserve concurrent job receipts. |
|
||||
| ODY-143 | Implemented. Every native Python execution takes the shared boundary, independent of source content. Final-expression output and configured imports remain supported. |
|
||||
| ODY-145 | Implemented. `#!bg` acquires the same required dimensions before supervisor launch; the supervisor receives the command only after durable ownership/job recording. |
|
||||
| ODY-147 | Implemented. Chat IDs no longer create tmux shells. Legacy cleanup checks launcher, runtime HOME, session generation, server/pane lineage and start tokens. Ambiguous sessions remain unsignalled and reported. |
|
||||
| ODY-150 | Implemented. Native Bash no longer reads a 2,000-line pane. A 3,002-line result is complete; actual byte/presentation truncation has metadata and a visible notice. |
|
||||
| ODY-141 | Implemented last. Shipped mode is enforcing. Missing required dimensions or failed namespace initialization refuse execution deterministically. No tool/configuration host-access mode was introduced. |
|
||||
|
||||
## Final containment architecture
|
||||
|
||||
`agent_spec` fixes the required dimensions from trusted runtime configuration;
|
||||
tool text cannot weaken them. `acquire` selects capabilities without examining
|
||||
the command. Installed bubblewrap must pass a functional PID/mount namespace
|
||||
probe. Launch uses the absolute trusted binary path, so the execution environment
|
||||
cannot substitute a workspace binary through PATH. `run` checks the declared mechanism's dimensions again, establishes the
|
||||
namespace, and consumes a private readiness receipt before acknowledging the
|
||||
trusted wrapper and starting model code. Bind/setup failure cannot produce a
|
||||
successful containment result.
|
||||
|
||||
The shared bubblewrap recipe uses a private root, private PID namespace, private
|
||||
`/proc` and devices, read-only system/interpreter mounts, private `/tmp`, and
|
||||
writable workspace mounts. Extras are mounted before the workspace, so a
|
||||
read-only ancestor cannot hide its writable workspace bind. Active Python
|
||||
environments under `/home` are bound explicitly rather than assumed visible.
|
||||
The compatibility namespace builder also uses this shared recipe.
|
||||
|
||||
Spawn is shielded until its process handle is recovered. Timeout, initialization
|
||||
failure, clean exit and cancellation converge on shared teardown. Repeated
|
||||
cancellation cannot interrupt TERM, bounded wait, KILL and death verification.
|
||||
Bubblewrap's separate info pipe records the namespace's PID 1 before model
|
||||
execution starts. Linux held owners and namespace init use pidfds when available.
|
||||
Release verifies death of both, including init's kernel cleanup of descendants
|
||||
that used `setsid()` or double-fork/session escape. Outer-owner exit alone cannot
|
||||
claim whole-tree death. The receipt retains a live/unverifiable init after failed
|
||||
signals; recovered teardown validates its start identity before signalling it.
|
||||
Completed release is idempotent and cannot signal a reused PID; a released grant
|
||||
cannot execute again. The namespace target uses the same escalating teardown
|
||||
primitive, not a second escalation implementation.
|
||||
|
||||
Detached jobs run a trusted supervisor, not model code outside the boundary.
|
||||
Its child executes through `containment.run`; completion metadata is published
|
||||
before the exit receipt. Failed log initialization releases an unstarted grant
|
||||
and still publishes failure metadata when those destinations are available.
|
||||
An owned live supervisor remains responsible across server restart; killing a
|
||||
job validates ownership and checks actual teardown before claiming it was killed.
|
||||
|
||||
Process ownership compares PID plus start identity. Linux tokens now include
|
||||
boot identity, preventing a receipt from matching the same start tick after a
|
||||
reboot. Recovered teardown validates identity and the recorded PGID before
|
||||
signals, including again before escalation. EPERM means unknown/live, never
|
||||
verified death. A gone leader with a populated but unowned group is retained as
|
||||
a failed cleanup rather than signalled. Foreign/unverifiable receipts remain
|
||||
visible. JSON read/modify/write operations are serialized across processes.
|
||||
|
||||
`src/path_confinement.py` remains the centralized canonical path boundary for
|
||||
in-process tools. It was preserved rather than replaced by a second policy.
|
||||
|
||||
## Explicit dimensions
|
||||
|
||||
| Dimension | Native contract |
|
||||
| --- | --- |
|
||||
| Filesystem | Required. Functional mount namespace and the trusted workspace/mount recipe. No alias-rewrite fallback in shipped enforcement. |
|
||||
| Process tree | Required. Private PID namespace and parent-death semantics. Process groups and Windows taskkill do **not** advertise this dimension. |
|
||||
| Wall clock | Required. Startup/readiness, stdin backpressure and child waiting share the execution timeout; teardown then has bounded escalation waits. |
|
||||
| Network | Inherited by default, explicitly reported, not isolated. Explicit `none` requests add a real network namespace or refuse at initialization. Loopback sidecars remain reachable by default. |
|
||||
| Memory | Optional existing Linux RLIMIT_AS hook when the requested hard limit can be applied. No generic resource authority was added. |
|
||||
| Process count | Optional existing RLIMIT_NPROC hook where supported and not root. This is a user-level limit, not a per-grant quota. |
|
||||
| Output | Bounded bytes per stream, fully drained to avoid pipe deadlock; UTF-8 decoding spans chunks. Truncation is visible and reported. Presentation caps also carry a notice. |
|
||||
|
||||
## Production and test inventory
|
||||
|
||||
Production changes after the reconciliation checkpoint:
|
||||
|
||||
```text
|
||||
core/atomic_io.py
|
||||
core/platform_compat.py
|
||||
src/agent_tools/bg_job_tools.py
|
||||
src/agent_tools/subprocess_tools.py
|
||||
src/bg_jobs.py
|
||||
src/containment.py
|
||||
src/containment_worker.py
|
||||
src/process_ownership.py
|
||||
src/process_reaper.py
|
||||
src/tool_execution.py
|
||||
website/configuration-reference.md
|
||||
```
|
||||
|
||||
Tests changed or added after reconciliation:
|
||||
|
||||
```text
|
||||
tests/containment_helpers.py
|
||||
tests/test_agent_bash_tmux_env.py
|
||||
tests/test_agent_bash_windows.py
|
||||
tests/test_agent_tmux_retirement.py
|
||||
tests/test_background_containment.py
|
||||
tests/test_bg_job_tools.py
|
||||
tests/test_containment_contract.py
|
||||
tests/test_containment_enforcement.py
|
||||
tests/test_containment_process_tree.py
|
||||
tests/test_execution_filesystem_boundary.py
|
||||
tests/test_native_execution_containment.py
|
||||
tests/test_orphan_reaping.py
|
||||
tests/test_process_ownership.py
|
||||
tests/test_workspace_artifact_tool_floor.py
|
||||
tests/test_workspace_confine.py
|
||||
```
|
||||
|
||||
The reconciliation commit additionally imports the frozen lab's production/test
|
||||
changes, including its authority and PTY changes; these are distinct from the
|
||||
Wave 3-S edits above. `git diff --name-only
|
||||
8e101fdcb8e775105bd4297298be580988bc7ad0
|
||||
083a573f7eab63d014331e669178cc367c22a2c8` gives that exact inventory.
|
||||
The only additional test edits made while reconciling were the Windows result
|
||||
assertion and `tests/test_tool_approvals.py`'s isolated stub.
|
||||
|
||||
## Validation
|
||||
|
||||
| Check | Result |
|
||||
| --- | --- |
|
||||
| Reconciliation overlap | 1,224 passed |
|
||||
| ODY-152 focused | 193 passed, 2 skipped |
|
||||
| ODY-143 focused, corrected sibling fixture | 186 passed |
|
||||
| ODY-145 focused | 205 passed, 1 skipped |
|
||||
| ODY-147 focused, including private real tmux server | 71 passed |
|
||||
| ODY-150 focused | 64 passed |
|
||||
| ODY-141 focused | 306 passed, 1 skipped |
|
||||
| Final containment/path/background/authority/PTY/Windows overlap | 657 passed, 2 skipped |
|
||||
| Supervisor follow-up plus containment/authority/bridge/PTY/Windows tests | 426 passed, 1 skipped |
|
||||
| Namespace-init ownership/teardown follow-up | 626 passed, 2 skipped |
|
||||
| Final delivery containment/background/authority/turn-contract/PTY/Windows overlap | 1,608 passed, 2 skipped |
|
||||
| Full Python suite, single completed run | 11,727 passed; 118 failed; 8 errors; 68 skipped; 2 xfailed; 6 subtests passed; 182 warnings |
|
||||
| Exact failed/error nodes after environment repair | All 126 passed; 4 deprecation warnings |
|
||||
| `compileall app.py core routes src tests` | Passed, including final production revision |
|
||||
| JS/MJS syntax | Not applicable: no JS/MJS changed from the original containment head; affected browser tests were exercised by targeted recovery. |
|
||||
| Whitespace, conflict markers and unmerged paths | Checked at reconciliation and delivery; no remaining conflict markers or unmerged paths. Captured log trailing whitespace normalized for the final diff check. |
|
||||
|
||||
Counts overlap and must not be summed. The initial system-Python full attempt
|
||||
stopped at collection with 16 missing-dependency errors and ran no tests. It is
|
||||
preserved as `validation/wave-3-s-full-collection.txt`. An isolated ignored
|
||||
`.venv` with system packages was created in this worktree. Missing test/runtime
|
||||
dependencies from `requirements.txt` were installed there; `npm ci` used the
|
||||
existing lockfile in this worktree. No package manifest or lockfile was changed.
|
||||
|
||||
The completed full run is preserved as `validation/wave-3-s-full.txt`; it was
|
||||
**not green**. Its failures included missing bcrypt/calendar/cron/PDF-rendering
|
||||
dependencies, import mocks following failed ORM pre-import, and absent Node
|
||||
test packages. Repairing those dependencies and executing exactly its 126
|
||||
failed/error node IDs produced 126 passes. The full suite was not repeated, in
|
||||
accordance with the one-run instruction. This proves targeted recovery, not a
|
||||
new all-green full run in the repaired environment. The final supervisor and
|
||||
namespace-init fixes were validated by focused follow-ups after that full run.
|
||||
|
||||
Focused commands and summaries are retained under `validation/wave-3-s-*`.
|
||||
Real tests cover private PID namespaces, a hidden host sibling, sidecar
|
||||
connectivity, explicit network isolation or deterministic refusal, escaped
|
||||
session death on timeout and clean parent exit, startup failure, stdin closure,
|
||||
cancellation during spawn, repeated cancellation during escalation, denied
|
||||
namespace-init signals after owner death, recovered/reused init identities,
|
||||
idempotent release, the old PATH substitution and its pinned-path fix, concurrent
|
||||
job recording, server restart ownership, verified legacy tmux cleanup and
|
||||
output above 2,000 lines. Existing request-authority and #44/#45 regression
|
||||
tests passed in the overlap runs.
|
||||
|
||||
## Limits, concerns and independent review
|
||||
|
||||
No unresolved P0/P1 was observed in the tested Wave 3-S native execution paths.
|
||||
The implementation and focused Wave 3-S validation are complete. The original
|
||||
full-run failure result remains part of the delivery evidence.
|
||||
|
||||
Platform support is deliberately truthful. Native required containment refuses
|
||||
on macOS/Windows without a suitable mechanism and on Docker/Linux where
|
||||
bubblewrap is missing or namespace creation is blocked. Windows Bash contract
|
||||
tests used platform simulation; no real Windows/macOS machine was validated.
|
||||
Installing bubblewrap alone does not establish Docker namespace support.
|
||||
Network egress/LAN access remains inherited by default. Existing externally
|
||||
owned Wave 2 bridges are not attested as locally contained by this work.
|
||||
|
||||
P2 follow-up concerns: independently validate the entire suite in the repaired
|
||||
environment/CI; adversarially review identity/token and PGID races in recovered
|
||||
or legacy processes that lack a retained kernel handle; inspect migration of
|
||||
older identity receipts and ambiguous legacy sessions. Token granularity remains
|
||||
finite (Linux clock ticks, macOS seconds); boot identity removes cross-boot
|
||||
matches, not every inspection-to-signal race. Failed/unverifiable receipts are
|
||||
kept visible rather than expired as if teardown succeeded. Remote bridge
|
||||
containment claims require an independent assessment of the remote owner.
|
||||
|
||||
Maestrum was used for bounded read review. An earlier audit identified the
|
||||
functional namespace, session escape and cancellation gaps that were verified
|
||||
and addressed. Its suggestion to signal a group after losing leader identity
|
||||
was rejected; retaining uncertain receipts is deliberate. Its store-lock claim
|
||||
did not account for the current transactional writer decorators. The final
|
||||
review of `865968c8d5c0ff72c3faeeaa993705064dca33d9` failed before any worker ran
|
||||
because Maestrum placement selected an unrecognized model. The current
|
||||
orchestrate-work skill assigns placement/retries to Maestrum and directs failed
|
||||
work to targeted local inspection; no native worker fallback was used. Final
|
||||
independent adversarial review remains outstanding, especially for detached
|
||||
supervisor cancellation and recovered ownership under hostile timing.
|
||||
|
||||
Work stops at Wave 3-S. No subsequent authority, provenance/egress, browser,
|
||||
generic lifecycle or decomposition wave was started.
|
||||
Reference in New Issue
Block a user