Skip to content

docs(handoff): record the W3 experiments and decision packet - #17

Merged
novelKR merged 1 commit into
mainfrom
codex/w3-decision-packet-2026-09-28
Sep 30, 2026
Merged

novelKR merged 1 commit into
mainfrom
codex/w3-decision-packet-2026-09-28

Conversation

@novelKR

@novelKR novelKR commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Summary

This is the non-normative W3 record for CS-DG-UPSTREAM-ADAPTER-WORK-SPEC-1 v1.0. It records:

It stops at the next owner decision. Nothing here approves an architecture, dependency, pin, contract,
implementation, upstream submission or merge.

What changed

  • docs/handoff/2026-09-28-w3-decision-packet.md (new).

Key results (macOS, one host; behavioural evidence, not proof):

  • A. A permit-preserving preparation, consumed by Codex's unmodified PTY ChildFds::Attached with DevGuard's
    unchanged helper, wire and authority, preserved single use, first-claim-wins, fencing, no replay and the
    known-not-started rules. The binding needed no PID accessor.
    • The frozen FIFO carriers do not work with the unchanged poll-based readers on this host. The amended run used
      today's carriers and an atomic regular-file permit.
    • With Attached, a PTY signal death still reports exit 1.
  • B. A generic scratch patch to codex-utils-pty (not submitted) keeps the backend as the only reaper. It
    observes the exit before reaping, bounded by a fixed timeout.
    • It turned the reap-first survivor case into normal release: 50 of 50 healthy runs returned their reservations.
    • Stalls, crashes and an unavailable authority degraded to the existing conservative states.
    • On the PTY path, a same-group background descendant receives SIGHUP when the root exits.
  • C. Unrelated std and Tokio children inherited DevGuard's session socket and today's launch carriers while they
    were being created. A holder of an inherited session could read the permit-bearing reply and inject requests.
    • Kernel close-by-default in the spawner removed every leak class in both samples.
    • An atomic file permit removed the permit class.
  • Also: the CodeSpace descriptor-hygiene issue Investigate descriptor inheritance between concurrent spawns on macOS CodeSpace#79 was opened. It is non-implementation and
    justified on CodeSpace's own terms.

What did not change

  • No contract, design document, AGENTS.md, NOTICE, validation script, manifest, lock or Codex pin.
  • No CodeSpace code or policy page. The CS-RG hold stays in force.
  • No service, credential, journal or host setting: the installed LaunchAgent kept the same pid throughout.
  • Nothing was submitted upstream.
  • The experimental DevGuard branch stays local and was never pushed.

Verification

  • python3 scripts/check_docs.py passed (17 pairs, 48 units, 25 groups). test_check_docs.py passed.

  • git diff --check is clean. The new file contains no local paths, and every table row has the header's cell
    count.

  • An independent read-only audit checked 204 claims against the sealed evidence, git and GitHub. It found:

    • two framing errors: amendment-changed cases presented as frozen passes;
    • sixteen minor points.

    All are fixed in this head. It confirmed every evidence digest, protocol digest and merge fact.

  • scripts/validate.py was not run locally; CI runs it.

Merge and rollback

  • Merge only at the exact head the owner approves (packet section 6, decision 1). Merging records the packet; it
    approves nothing proposed in it.
  • The change is documentation only, so rollback is a revert of the merge commit.

Handoff

Record the owner-approved W3 merges (#13, #16, CodeSpace #78) and
housekeeping, the bounded experiments A (launch preparation consumed by
an existing backend), B (backend-owned pre-reap observation in a scratch
patch) and C (attachment and client-session safety), their frozen
protocols, amendments and failed attempts, the updated candidate status,
and the owner decisions now requested.

Non-normative: no contract, gate, manifest, lock or pin is changed, and
nothing is submitted upstream. An independent read-only audit of the
draft found two framing errors and sixteen minor points; all are fixed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant