NS04: product Session kernel and immutable runtime evidence - #35
NS04: product Session kernel and immutable runtime evidence#35kmccleary3301 wants to merge 28 commits into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8f16c2f9a8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
62a4434 to
266f712
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 266f712de5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
266f712 to
9ba8e9e
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9ba8e9e3fa
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
9ba8e9e to
f5bdcd4
Compare
|
Addressed all six review findings at exact head
Evidence: 39 focused bridge/permission tests passed; 42 public-contract/kernel-boundary tests passed; live lifecycle retained @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5bdcd44fd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
f5bdcd4 to
b9cd2a0
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b9cd2a0d55
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aebe95ace0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
aebe95a to
002f892
Compare
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f20462b2f9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Fixed the direct-runner compatibility finding in ec385b1.
Evidence: the regression passed after reproducing red; 24 focused runner, replay, and lazy-initialization tests passed; @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ec385b1f67
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Fixed the plain-runner deferred permission replay finding in ebab1d4.
Evidence: all 22 pending-permission tests passed; @codex review |
|
Current reviewed candidate is The replay fix is unchanged; the two follow-up commits only compacted the regression and repaired lines to preserve the frozen packet bound after the review fix. Current PR delta: 19 files, +1669/-869, net +800. All 22 pending-permission tests and @codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d21d5eb641
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Resolved the current-head P1 transaction-order finding in
Evidence: 23 permission transaction/persistence tests passed; |
kmccleary3301
left a comment
There was a problem hiding this comment.
Reviewed candidate a29bdd5: rule persistence now precedes runtime permission delivery, with a regression proving broker silence on metadata commit failure. Focused suite: 23 passed; py_compile passed. Fresh automated review requested in the PR thread.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a29bdd5a51
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 23f837cff6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Didn't find any major issues. Hooray! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a230288f4b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review exact head 29b7a3d only. Prior findings resolved: immutable CAS bytes are inlined with a 16 KiB upload/selection limit; packet net +765 lines vs frozen github/phase20/followup-1000; exhaustive exact suites 277 passed. Focus any remaining correctness, security, lifecycle, or portability issue. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 29b7a3d994
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review exact head 4123463 only. Attachment ingress now streams to a 16 KiB hard cap; rejected selections are mutation-free; prompt exposes only an attachment://sha256 digest capability; bytes are read by existing read_file after PermissionBroker authorization from descriptor/handle-confined CAS with digest+size verification. Exact suites: 278 passed. Packet: net +790 lines. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 41234631a6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: adfe9ef254
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eddae651bb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review exact head 3b87878 only. Frozen closure packet: exactly 20 files, +2054/-1255 = net +799 against github/phase20/followup-1000; do not review superseded heads. Assess correctness, security, concurrency, portability, public schema/runtime parity, and test adequacy. Return numeric 0-1000 score and concrete findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3b8787839b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review exact head b7896bd only. Prior comments are repaired. Current packet is 20 files, +2103/-1308 = net +795 against the frozen base. Focus the consolidated event sink, strict config-load failure boundary, OpenCode phase-4 replay profile, pause/control concurrency, anchored-storage confinement, and current-head test adequacy. Local locks: 315 packet tests passed; full config corpus 176 passed/21 skipped; tmux action parity passed; py_compile passed. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b7896bd120
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| except OSError as exc: | ||
| for handle in reversed(handles): AnchoredStorage.close_windows_handle(handle) | ||
| raise HTTPException(status_code=status.HTTP_400_BAD_REQUEST, detail="invalid workspace metadata path") from exc | ||
| root_fd, metadata_fd = os.open(workspace_root, os.O_RDONLY | getattr(os, "O_DIRECTORY", 0)), None |
There was a problem hiding this comment.
Open the workspace root without following symlinks
When the workspace path is in a parent another process can modify, this root open follows a symlink swapped in after workspace_dir.resolve(), so the subsequent dir-fd-confined .breadboard writes can be anchored in an attacker-chosen directory outside the intended workspace; the later metadata-path check also resolves the pathname again, so it won't catch that replacement. Use O_NOFOLLOW/descriptor identity for the root open as well (the same root-open pattern is also present in the permission rules store).
Useful? React with 👍 / 👎.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 123dee66a8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if target_fd is not None: artifact_store.materialize_at(artifact_ref, target_fd, filename) | ||
| else: artifact_store.materialize(artifact_ref, attachment_root / attachment_id / filename) |
There was a problem hiding this comment.
Block shell access to materialized attachments
When shell tools are enabled, these materialized copies make uploaded attachment bytes reachable at predictable paths under the workspace (.breadboard/attachments/...), while the new read/glob/grep/list guards only filter the Python file tools. A model can run a shell command such as find .breadboard/attachments -type f -exec cat {} \; and bypass the attachment:// capability check added in read_file, so attachment authorization is not actually enforced for sessions that allow shell execution.
Useful? React with 👍 / 👎.
Scope
Implements North-Star packet
bb-06u.5on frozen base7d69b792a048bbd42970542132defaa2cbf091e7.Sessionlifecycle bound to the runtime-effectiveEffectiveHarnessLockbb.session.v1read modelsCompat reviewed: non-breaking. Existing bridge responses and legacy artifact paths remain compatible; the product read model and durable event stream are additive.
Bounds
Current exact head:
123dee66a.Review closure
All automated findings through the review of
b7896bd12were repaired and regression-locked. The exact head additionally:opencode_grok4fast_c_fs_v2.yamlbaseThe CLI bridge now records the exact runtime-effective harness, approval FIFO, sanitized input plus attachment refs, terminal transitions, and durable event/artifact evidence. Attachment CAS access is descriptor/handle confined and permission-authorized. Persistent permission rules commit before broker delivery. Startup and attachment publication remain transactional.
Verification
At exact head
123dee66a:Two independent exact-head reviews passed with no blocker. The packet retains legacy shell behavior as an explicit permission-controlled residual; model-native reads and writes cannot traverse the private attachment/CAS paths.
Warnings are existing Pydantic V1 deprecations and pytest temporary-directory cleanup warnings.
Distribution boundary
The existing explicit setuptools list omits
agentic_coder_prototype.apiand other bridge subpackages, so the wheel cannot importSessionServiceindependently of the source tree. This packet packages and verifies the new product runtime package. Installed bridge/subpackage discovery belongs to dependent packet NS07 (bb-06u.9).Frozen NS04 acceptance: 1000/1000. Latest-head push and pull-request CI passed. Absolute hardening remains 950/1000 because the frozen packet intentionally retains permission-controlled shell compatibility, restart registry rehydration belongs outside NS04, and the packet uses the full +800 line allowance.