docs: write the threat model - #302
Merged
Merged
Conversation
What mechanical admission establishes, what it does not, and the six things that actually went wrong: import-time code execution, meaning drift under a stable name, deprecation debt, a conjecture probe that silently never ran, orphaned processes exhausting a contributor's host, and a rejection that blamed a submitter for the maintainer's merges. Each with the check that now catches it. It also states the residual risks rather than leaving them implied: nothing reads prose, maintenance pull requests bypass the receiver entirely, upstream Mathlib and CI are trusted, and one producer's taste shapes the corpus with nothing mechanical to notice. A contract test keeps the document honest: every diagnostic code and sandbox flag it advertises has to appear in the receiver and the workflow. Writing that test caught the deprecation section describing a rule without naming its code. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The last item from the plan, and the piece §3 called the publishable asset: the document another maintainer reads before deciding whether mechanical admission could work for them.
Structure
--network none --read-only --cap-drop ALLcontainer, nopull_request_target, branch names granting nothing, narrow auto-merge, docs proposals carrying no code.The closing point is the one worth making publicly: admission can be mechanical only if the checks cover what actually goes wrong, and that list is learned by running the thing in the open and writing down each failure.
Keeping it honest
A contract test asserts that every diagnostic code and sandbox flag the document advertises also appears in
frontier_validate.pyandvalidate-submission.yml, so the document cannot drift away from the code. Writing that test immediately caught the deprecation section describing the rule without namingDEPRECATED_API.README.mdlinks it. Full suite: 152 tests, 6 skipped.🤖 Generated with Claude Code