docs(handoff): record the upstream-adapter W0-W2 packet - #16
Merged
Merged
Conversation
Record the W0 intake delta of CS-DG-UPSTREAM-ADAPTER-WORK-SPEC-1 v1.0: the new baseline after the five owner-approved merges, their post-merge verification and local alignment, the scheduled CodeSpace run tied to 326bdcb, and the authorization record for this pass. Add the specification and its start instruction as normalized derivatives: trailing whitespace removed (5 and 2 lines), no word changed. The byte-identical originals and their stated digests stay in the git-ignored evidence set; both digests are recorded in section 1.4. Non-normative record only: no architecture, dependency, pin, gate or merge is approved, and the CS-RG hold stays in force.
…ntory Map the adapter boundaries and their placement by process, draft the flexible upstream-pin policy (candidate classes, pin record, promotion, same-process and separate-process rules, patches, rollback), list the Codex-free wording to reconcile later with draft replacements, inventory the executable dependency gates of both repositories, and report the candidate crate's dependency facts. Every proposed text is labelled as draft candidate wording; no document, gate, manifest or lock is changed.
Summarize the upstream capability matrix and the macOS descriptor-creation reading, specify the three candidate protocols (permit-preserving preparation, backend-owned pre-reap observation, attachment and session safety) with state and failure tables, record the recovery conditions and support table, report the BD-1 diagnostic, and state the bounded W3 experiment requests, the owner decisions and the handoff with evidence digests. Non-normative: no contract, gate, manifest, lock or pin is changed.
Tighten line ranges and scope statements that an independent read-only audit marked as imprecise (no factual errors were found): package-count split, validate.py and gate ranges, the macOS-only kernel-applied descriptor exclusion, the pin's group-kill site, the UDS parent-check source, and the settled question in spec section 20.
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This is the non-normative W0–W2 packet for CS-DG-UPSTREAM-ADAPTER-WORK-SPEC-1 v1.0. It stops at the W3 owner gate.
It records:
Nothing here approves an architecture, dependency, pin, contract, implementation or merge. Proposed wording is
labelled "DRAFT – candidate wording, not adopted".
What changed
docs/handoff/2026-09-28-upstream-adapter-packet.md(new): sections 1–15 and sources.docs/handoff/2026-09-28-cs-dg-upstream-adapter-work-spec-1.mdanddocs/handoff/2026-09-28-cs-dg-upstream-adapter-start-instruction.md(new): normalized derivatives of thespecification and its start instruction. Only trailing whitespace was removed; packet section 1.4 records both
digests.
Key findings:
ChildFds::Attachedexists at rust-v0.159.0-alpha.11 (72b8d8b) andmain, not in stablerust-v0.157.1. No checked revision offers pre-reap observation or a child PID for PTY children.
pipes and sockets close-on-exec atomically, and std
Commanddoes not usePOSIX_SPAWN_CLOEXEC_DEFAULT. D6cannot be closed by swapping libraries.
Attacheddelivered attachments only to the intended PTY child: 0/2000unrelated children were observed with an attachment, and 200/200 attached children received theirs. Outside the
criteria, unrelated std and tokio children received transient PTY descriptors (104/2000) and pipe descriptors
(39/2000) from other threads' creation windows.
check-no-model-deps.shchecks only directcodex-*keys in core manifests, andupstream_dependencies.pyrejects named crates only: the fourFORBIDDENnames from every product root, plusRUNNER_FORBIDDENfrom the Runner. A transitivecodex-utils-ptyarriving through a DevGuard client would not beflagged today.
What did not change
AGENTS.md, D3/ADR-006,NOTICE, validation script, manifest, lock or pin.Verification
python3 scripts/check_docs.pypassed (17 pairs, 48 units, 25 groups).git diff --checkis clean, and the new files contain no local absolute paths.evidence manifests. It found no errors. Its 20 precision notes are fixed in
a67facb.scripts/validate.pywas not run locally; CI runs it.Merge and rollback
approves nothing proposed in it.
Handoff
comments follow.
.github/notes/pointer to this packet at heada67facbbebb192d83126c5afa1a9ef2d713c2e2e.or credential change, and no upstream submission.