Skip to content

[PureFlow v0.3 R7] Add digest-pinned Docker SandboxRunner - #17

Merged
yava-code merged 3 commits into
codex/shadow-cockpit-rndfrom
codex/r7-docker-sandbox
Aug 1, 2026
Merged

[PureFlow v0.3 R7] Add digest-pinned Docker SandboxRunner#17
yava-code merged 3 commits into
codex/shadow-cockpit-rndfrom
codex/r7-docker-sandbox

Conversation

@yava-code

Copy link
Copy Markdown
Owner

What changed

  • freezes a strict Phase-B SandboxRunner specification and negative contract
  • adds exact request and command validators plus project-scoped trust, consent, workspace, mount, and toolchain authorities
  • implements the digest-pinned Docker CLI backend with active network, read-only, resource, and descendant-kill probes
  • runs frozen commands with network none, read-only root/workspace/oracles, tmpfs write paths, fixed limits, no shell, and controller-only environment values
  • adds exact-source oracle revalidation, bounded redacted evidence, single-use execution IDs, exact-name cancellation, cleanup verification, and no host fallback
  • records the post-R7 Software Controllability and Context-Starved Relay concept lab
  • makes protected Linux CI provision the exact image digest and run the real Docker suite

Why

R7 cannot evaluate the preregistered 30-patch corpus on the host. This supplies the replaceable arbitrary-code execution boundary selected by ADR-003 while keeping production agents and released v0.1 behavior unchanged.

Validation

  • strict spec validator: 100/100, no warnings
  • TypeScript: pass
  • default extension suite: 79/79 pass; 2 explicitly provisioned Docker tests skipped
  • local Windows Docker Desktop suite: 2/2 pass against the pinned Node image digest
  • production build and VSIX packaging: pass
  • git diff --check: pass
  • exact-name cleanup audit: no residual PureFlow R7 containers

Gate

Keep this PR draft until protected Linux Docker integration and Windows contract checks pass. This PR does not start corpus execution, implement the readiness ledger or cockpit, or claim skill retention.

@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 822a4cd0-77ca-4047-83af-4bacfd165c26

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yava-code
yava-code marked this pull request as ready for review August 1, 2026 00:05
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@yava-code
yava-code merged commit d26b6a0 into codex/shadow-cockpit-rnd Aug 1, 2026
6 checks passed
@yava-code
yava-code deleted the codex/r7-docker-sandbox branch August 1, 2026 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant