Skip to content

docs: record the CS-RG suspension handoff note - #77

Merged
novelKR merged 2 commits into
mainfrom
codex/cs-rg-suspension-handoff
Sep 27, 2026
Merged

novelKR merged 2 commits into
mainfrom
codex/cs-rg-suspension-handoff

Conversation

@novelKR

@novelKR novelKR commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Issue

Refs #76 (tracker; stays open until the owner's decisions). Primary cross-repository tracker: novelKR/DevGuard#14.

Summary

Adds .github/notes/pr75-cs-rg-suspension-handoff.md, a dated note that hands off the CodeSpace side of the 2026-09-27 session. The session suspended the planned CS-RG managed-execution design (#75) and revalidated the CodeSpace–DevGuard boundary. The note guarantees that a CodeSpace agent can learn four things from GitHub alone:

It is a record, not a design decision. It approves no architecture, starts no work and authorizes no merge.

The note sits in .github/notes/ next to the PR #51 and PR #53 notes. The documentation site avoids past-session narrative and unexplained work-package numbers, so the note does not belong there.

Contract changes

None. No tool schema, error code, status value, ID, dependency, CI policy or pin changes.

Tests

  • Checks passed:
    • python3 -B scripts/check_docs.py: registry verified (17 paired documents).
    • git diff --check: clean.
  • Content checks:
    • No local absolute paths; English only.
    • Cited line ranges were checked at 794867e. Outside tests, the code is identical to b6e7ed2; the only change since then is in the mod tests of linux_sandbox.rs, after line 408.
  • CI plan: python3 -B scripts/ci_plan.py --base 794867e --head HEAD selects the full profile (12 legs). A .github/** change is in the full list of scripts/ci-policy.json, so this documentation-only PR runs every Rust leg by policy.
  • Not run locally: the Rust legs and the documentation site build (host memory was tight). This PR's CI runs them.

Security scenarios

Not applicable to runtime behaviour, because the note changes no code. The note records the following:

  • DevGuard's client session-socket inheritance window (D6) is reachable from CodeSpace's pipe, patch-helper and sandbox-probe spawns, because those spawns neither take DevGuard's spawn_guard nor close unintended descriptors. Exposure has not been demonstrated.
  • OX-02: a stored numeric process group can be signalled up to 15 minutes after exit.

Both are recorded as open issues; neither is fixed.

Out of scope

Revision history

  1. Initial note.
  2. Revised after an independent, context-free review, with each point checked against the sources first. The revision:
    • states that CS-RG is owned by CodeSpace and planned in DevGuard;
    • says where owner approvals and the local-only evidence come from;
    • defines the runner modes;
    • adds the merged-state check to the merge steps;
    • words the ETXTBSY status as merged but not confirmed.

Merging requires the owner's explicit approval of this exact head, followed by one read of the post-merge CI. Rollback: revert the commit.

Adds a dated note under .github/notes that hands off the CodeSpace side of
the 2026-09-27 session: the state of #75, the constraints a CodeSpace agent
follows for CS-RG, source facts from the boundary review, CodeSpace-only
issues, intermittent CI failures and the remaining checks. It approves no
architecture. Tracked by #76; primary tracker novelKR/DevGuard#14.
…note

States who owns CS-RG, where approvals and evidence come from, the runner modes, the full merge check, and that the ETXTBSY fix is merged but not confirmed. Refs #76.
@novelKR
novelKR merged commit 326bdcb into main Sep 27, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant