Add inactive kill-switch evaluator - #211
Conversation
…ntrol-kill-switch-v1
Deploying ystack with
|
| Latest commit: |
d12b97a
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://3d2d41bc.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://codex-control-kill-switch-v1.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: d12b97a BugsNo Important findings. Scope precedence is fail-closed: any matching stop wins; missing state is inconclusive; ambiguity, mismatch, rollback, stale state, replay, or digest mismatch are violated. Duty violations and unverifiable evidence cannot produce a cleared result. Output is canonical and deterministic. The exact targeted proof passed 37 of 37 checks. Linux CI proved evaluator-owned TERM-resistant descendant group ownership before repeated signals, then required status 143, empty output, descendant reap, and empty scratch. All 24 repository test scripts passed. Non-blocking nit: if the initial self process-group lookup fails before traps are installed, an empty private scratch directory can remain for operating-system cleanup. No input has been copied and no child exists on that path. SecurityNo findings. Policy, decision, driver, jq program, validator, duty decision and policy, policy-set, and portable-core identities are closed and checked again. Inputs are single-read snapshots and shipped-source mutation fails closed. Paths reject symlinks, subprocess arguments are not shell-evaluated, and active child groups receive bounded TERM, KILL, and reap handling. A satisfied observation explicitly has authority_effect set to none and cannot create caller authority. No credential, network, candidate execution, signal action, activation, publish, deploy, or external write is enabled. ComplianceNo findings. The exact diff is one inactive kill-switch concern across README.md, RESTORE.md, ci/required-files.txt, the five kill-switch product files, and the targeted test. It does not touch constitution, workflow, forbidden, live, or frozen paths. README and RESTORE accurately describe the observation-only boundary. Restore-manifest additions are append-only. The branch preserves recoverable ancestry from the exact reviewed base without rebase or rewrite. Required app-15368 CI run 33516932826 and check 99886189038 succeeded on this exact head/base. No exceptional implementation or scope expansion was introduced. |
|
Construction merge receipt
Postflight verified squash-only ancestry, exact tree equality, and the main ref. |
Scope
Roadmap item 2: add one inactive, repo-only kill-switch evaluator. It observes a pinned state snapshot across five scopes and fails closed. It grants no authority and performs no signal, cancellation, credential, network, release, install, deployment, or external-write action.
Exact candidate:
d12b97a08b5ae2bd15ef2a4c9a9f87b4fabb6adfa6ebfe11a9a417148c7406fc6d06d821bea3aa32Changed paths:
README.mdRESTORE.mdci/required-files.txtcontrol/v1/evaluate-kill-switch.shcontrol/v1/kill-switch-decision.jsoncontrol/v1/kill-switch-policy.jsoncontrol/v1/kill-switch.jqscripts/test/control-kill-switch.test.shLinux CI revision
The first exact CI reached kill-switch case 35, then the teardown-signal test raced its own short-lived marker on Linux. Seeing that regular file did not prove an owned descendant still held the evaluator inside teardown.
The revised test creates a TERM-resistant descendant in the evaluator-owned child process group. It verifies the leader, group, and descendant identities while teardown is active, sends repeated outer-group signals, then requires normalized status 143, empty output, complete descendant/group reap, and empty scratch state. Product behavior and lifecycle assertions are unchanged.
Targeted proof
Run on the exact candidate tree with a 240-second process-group outer bound:
Required exact GitHub CI and the one final independent review remain the publish gates.