Skip to content

Enforce reusable reliability controls and evidence-based release readiness - #360

Merged
kai-linux merged 1 commit into
mainfrom
codex/general-reliability-20260919
Sep 19, 2026
Merged

kai-linux merged 1 commit into
mainfrom
codex/general-reliability-20260919

Conversation

@kai-linux

Copy link
Copy Markdown
Owner

Scope

Adds tenant-scoped roles and retained memory, measured provider receipts and traces, a bounded model-to-isolated-tool worker loop, qualified release/drift gates, service-level admission controls, a private readiness view, and tested backup/restore plus incident procedures. Legacy observation mode remains compatible; enforced mode rejects unqualified work and disables legacy autonomous bypasses.

Verification

  • 839 local tests passed.
  • Ten real orchestration qualification scenarios passed, including host Bubblewrap isolation, restore, and the measured model/tool/verification path. Missing host isolation fails qualification rather than becoming a pass.
  • Secret scan and whitespace checks passed.
  • Browser checked at 390px and 1440px using a temporary database, without production data.

Operational boundary

No live policy, credential, cron, service deployment or approved execution SHA changed. Activation requires actual tenant identities, trusted measured provider adapters and an independently approved immutable release. Fixture evaluations do not prove customer business quality or months of production reliability. See docs/reliability.md and the dated worklog.

Review focus

Identity scope, stale authority, immutable billing receipts, completeness seals, process isolation, symlink/hardlink/FIFO handoff attacks, changed/expired approval, and recovery without repeating external effects.

@kai-linux

Copy link
Copy Markdown
Owner Author

Self-review completed against main. Checked tenant/role admission, cross-tenant ancestry and dependencies, adapter routing without legacy CLI fallback, immutable and complete billing manifests, release SHA/artifact/expiry/drift gates, and process-group cleanup. Added regression coverage for handoff symlink/hardlink/FIFO attacks and service-target brakes that must not deadlock existing work. Verified the clean checkout reports the actual commit SHA. Recovery creates a new quarantined DB and does not replay uncertain external effects. Local verification: 839 passing tests, ten passing orchestration scenarios including actual host isolation, secret scan, and desktop/mobile browser checks. Remaining deployment/customer-specific requirements are explicit; no live execution pin or privileged job was changed.

@kai-linux

Copy link
Copy Markdown
Owner Author

Remote CI completed successfully on push and pull_request: 835 passed, 4 skipped. The four skips are the Bubblewrap host-boundary cases; this runner lacks Bubblewrap. All four passed on the Acemagic host (839 passed total), and the dedicated qualification report passed all ten scenarios. Qualification explicitly maps skipped mandatory scenarios to failure, so a green generic CI job cannot authorize an unsupported execution host.

@kai-linux
kai-linux merged commit d7330eb into main Sep 19, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant