Skip to content

docs: D6 option (b) client-session analysis (paper, non-normative) - #21

Merged
novelKR merged 1 commit into
mainfrom
codex/d6-client-session-analysis
Oct 1, 2026
Merged

novelKR merged 1 commit into
mainfrom
codex/d6-client-session-analysis

Conversation

@novelKR

@novelKR novelKR commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Summary

This adds a dated, non-normative handoff record, docs/handoff/2026-09-30-d6-client-session-analysis.md. It is the owner-directed paper analysis (work package C, 2026-09-30) of W3 decision 3, option (b): change DevGuard's client-session design so that an inherited endpoint gains nothing.

What it analyses. Citations are at main 4898259.

  • The W3 candidates: a per-request connection with a one-shot token, and an authenticated or encrypted transport.
  • The candidates that emerged: no secret in any reply, a session outside the owner's process, and binding requests to their connection.
  • Each against:
    • the W3 C holder effects (reply and permit theft, injection under the owner's principal, denial of service, use after close);
    • the connect_timeout creation window (S14);
    • the threat model and N2;
    • wire version 1 and journal compatibility;
    • D6 option (a) and the carrier choice.
  • Each states what it closes, what it leaves open, what it changes, and how it would be tested. W3 C's holder cases become the acceptance tests.

Main findings (inference, paper only):

  • Not "nothing". While the endpoint lives in the owner's process, no (b) candidate removes the creation window or denial of service. The reachable outcome is "no secret and no authority" for an inherited endpoint, not "nothing". Accepting the residual channel exposure would change the packet's reading of N2, which is a separate owner decision and is not requested.
  • The smallest step without cryptography or a new dependency. Self-contained per-request authorization, combined with owner-originated permits and lease tokens (only digests sent), closes secret theft, injection and use after close. It is a wire change, with no change to the journal's format.
  • The one candidate that removes the endpoint. Only a session outside the owner's process does that. It needs a new identity rule, a separate owner decision, and an atomic owner-to-connector channel.
  • Apart from that, only option (a) removes inheritance itself, for each spawner that adopts it. CodeSpace #79's run of 2026-09-30 shows that CodeSpace's pipe path currently passes other executions' transient descriptors to its children.

What this does not change

  • No code, test, CI, wire, journal, contract, dependency or policy change.
  • No D6 direction is selected; decision 3 stays open. N2 and the threat model are not redefined.
  • The CS-RG hold stays in force.
  • Merging this PR would approve nothing proposed in it.

Verification

All output was kept outside the worktree.

Check Result
python3 -B scripts/ci_plan.py --base origin/main --head HEAD profile affected; 1 path, classified historical (docs/handoff/**), 0 unclassified; stages whitespace and documentation; no Rust
python3 -B -m unittest discover -s scripts -p 'test_ci_*.py' 95 tests, OK
python3 -B scripts/validate.py --stages whitespace,documentation --diff-base origin/main whitespace passed; documentation passed
python3 -B scripts/check_docs.py passed (17 reviewed pairs)
git diff --check, and a scan for Hangul and private paths clean

This PR's CI should run the affected profile.

Rollback

Revert the single commit. Nothing depends on this record.

🤖 Generated with Claude Code

Add a dated, non-normative handoff record of the owner-directed paper
analysis of W3 decision 3 option (b): per-request connections with a
one-shot token, an authenticated or encrypted transport, and the
candidates that emerged (no secret in any reply, a session outside the
owner's process, binding requests to their connection). Each is assessed
against the W3 holder effects, the connect_timeout creation window, the
threat model, N2, wire version 1 and journal compatibility, and D6 option
(a) and the carrier choice, with an acceptance-test protocol.

No code, wire, journal, dependency or policy change. Decision 3 stays open.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@novelKR
novelKR merged commit f1f9084 into main Oct 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant