Enforce reusable reliability controls and evidence-based release readiness - #360
Conversation
|
Self-review completed against main. Checked tenant/role admission, cross-tenant ancestry and dependencies, adapter routing without legacy CLI fallback, immutable and complete billing manifests, release SHA/artifact/expiry/drift gates, and process-group cleanup. Added regression coverage for handoff symlink/hardlink/FIFO attacks and service-target brakes that must not deadlock existing work. Verified the clean checkout reports the actual commit SHA. Recovery creates a new quarantined DB and does not replay uncertain external effects. Local verification: 839 passing tests, ten passing orchestration scenarios including actual host isolation, secret scan, and desktop/mobile browser checks. Remaining deployment/customer-specific requirements are explicit; no live execution pin or privileged job was changed. |
|
Remote CI completed successfully on push and pull_request: 835 passed, 4 skipped. The four skips are the Bubblewrap host-boundary cases; this runner lacks Bubblewrap. All four passed on the Acemagic host (839 passed total), and the dedicated qualification report passed all ten scenarios. Qualification explicitly maps skipped mandatory scenarios to failure, so a green generic CI job cannot authorize an unsupported execution host. |
Scope
Adds tenant-scoped roles and retained memory, measured provider receipts and traces, a bounded model-to-isolated-tool worker loop, qualified release/drift gates, service-level admission controls, a private readiness view, and tested backup/restore plus incident procedures. Legacy observation mode remains compatible; enforced mode rejects unqualified work and disables legacy autonomous bypasses.
Verification
Operational boundary
No live policy, credential, cron, service deployment or approved execution SHA changed. Activation requires actual tenant identities, trusted measured provider adapters and an independently approved immutable release. Fixture evaluations do not prove customer business quality or months of production reliability. See docs/reliability.md and the dated worklog.
Review focus
Identity scope, stale authority, immutable billing receipts, completeness seals, process isolation, symlink/hardlink/FIFO handoff attacks, changed/expired approval, and recovery without repeating external effects.