Skip to content

docs(handoff): record the upstream-adapter W0-W2 packet - #16

Merged
novelKR merged 5 commits into
mainfrom
codex/upstream-adapter-packet-2026-09-28
Sep 28, 2026
Merged

novelKR merged 5 commits into
mainfrom
codex/upstream-adapter-packet-2026-09-28

Conversation

@novelKR

@novelKR novelKR commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

This is the non-normative W0–W2 packet for CS-DG-UPSTREAM-ADAPTER-WORK-SPEC-1 v1.0. It stops at the W3 owner gate.
It records:

  • the intake delta;
  • a draft, adapter-bounded upstream-pin policy;
  • the upstream capability matrix and the macOS descriptor-creation reading;
  • three candidate protocols (A, B, C);
  • the BD-1 bounded diagnostic;
  • the W3 decision packet.

Nothing here approves an architecture, dependency, pin, contract, implementation or merge. Proposed wording is
labelled "DRAFT – candidate wording, not adopted".

What changed

  • docs/handoff/2026-09-28-upstream-adapter-packet.md (new): sections 1–15 and sources.
  • docs/handoff/2026-09-28-cs-dg-upstream-adapter-work-spec-1.md and
    docs/handoff/2026-09-28-cs-dg-upstream-adapter-start-instruction.md (new): normalized derivatives of the
    specification and its start instruction. Only trailing whitespace was removed; packet section 1.4 records both
    digests.

Key findings:

  • Upstream. ChildFds::Attached exists at rust-v0.159.0-alpha.11 (72b8d8b) and main, not in stable
    rust-v0.157.1. No checked revision offers pre-reap observation or a child PID for PTY children.
  • Descriptor creation on macOS. Rust std (1.88.0, 1.95.0, 1.98.1), mio 1.2.3 and tokio 1.53.1 do not create
    pipes and sockets close-on-exec atomically, and std Command does not use POSIX_SPAWN_CLOEXEC_DEFAULT. D6
    cannot be closed by swapping libraries.
  • BD-1 was run and is conclusive. Attached delivered attachments only to the intended PTY child: 0/2000
    unrelated children were observed with an attachment, and 200/200 attached children received theirs. Outside the
    criteria, unrelated std and tokio children received transient PTY descriptors (104/2000) and pipe descriptors
    (39/2000) from other threads' creation windows.
  • CodeSpace gates. check-no-model-deps.sh checks only direct codex-* keys in core manifests, and
    upstream_dependencies.py rejects named crates only: the four FORBIDDEN names from every product root, plus
    RUNNER_FORBIDDEN from the Runner. A transitive codex-utils-pty arriving through a DevGuard client would not be
    flagged today.

What did not change

  • No contract, design document, AGENTS.md, D3/ADR-006, NOTICE, validation script, manifest, lock or pin.
  • The CS-RG implementation hold stays in force, and docs(handoff): record the CS-RG boundary revalidation #13 is untouched.
  • No service, credential, journal or host setting. Nothing was submitted upstream.

Verification

  • python3 scripts/check_docs.py passed (17 pairs, 48 units, 25 groups).
  • git diff --check is clean, and the new files contain no local absolute paths.
  • A script checked that every table row has as many cells as its header.
  • An independent read-only audit checked 320 citations and facts in sections 3–15 against the sources and the
    evidence manifests. It found no errors. Its 20 precision notes are fixed in a67facb.
  • scripts/validate.py was not run locally; CI runs it.

Merge and rollback

  • Merge only at the exact head the owner approves (decision 1 in packet section 14). Merging records the packet; it
    approves nothing proposed in it.
  • The change is documentation only, so rollback is a revert of the merge commit.

Handoff

Record the W0 intake delta of CS-DG-UPSTREAM-ADAPTER-WORK-SPEC-1 v1.0:
the new baseline after the five owner-approved merges, their post-merge
verification and local alignment, the scheduled CodeSpace run tied to
326bdcb, and the authorization record for this pass.

Add the specification and its start instruction as normalized
derivatives: trailing whitespace removed (5 and 2 lines), no word
changed. The byte-identical originals and their stated digests stay in
the git-ignored evidence set; both digests are recorded in section 1.4.

Non-normative record only: no architecture, dependency, pin, gate or
merge is approved, and the CS-RG hold stays in force.
…ntory

Map the adapter boundaries and their placement by process, draft the
flexible upstream-pin policy (candidate classes, pin record, promotion,
same-process and separate-process rules, patches, rollback), list the
Codex-free wording to reconcile later with draft replacements, inventory
the executable dependency gates of both repositories, and report the
candidate crate's dependency facts.

Every proposed text is labelled as draft candidate wording; no document,
gate, manifest or lock is changed.
Summarize the upstream capability matrix and the macOS descriptor-creation
reading, specify the three candidate protocols (permit-preserving
preparation, backend-owned pre-reap observation, attachment and session
safety) with state and failure tables, record the recovery conditions and
support table, report the BD-1 diagnostic, and state the bounded W3
experiment requests, the owner decisions and the handoff with evidence
digests.

Non-normative: no contract, gate, manifest, lock or pin is changed.
Tighten line ranges and scope statements that an independent read-only
audit marked as imprecise (no factual errors were found): package-count
split, validate.py and gate ranges, the macOS-only kernel-applied
descriptor exclusion, the pin's group-kill site, the UDS parent-check
source, and the settled question in spec section 20.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant