Skip to content

feat(evidence): retain original process bytes across harnesses - #245

Merged
drewstone merged 4 commits into
mainfrom
feat/portfolio-shared-raw-capture-20260929
Sep 29, 2026
Merged

drewstone merged 4 commits into
mainfrom
feat/portfolio-shared-raw-capture-20260929

Conversation

@drewstone

@drewstone drewstone commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Change

Retain original stdout/stderr bytes at the shared host, scoped-host and Docker process spawn seam when BRIDGE_RAW_CAPTURE_DIR is configured.
The durable run coordinates bind each stream before harness parsing.
Terminal manifests link observed native session IDs and process IDs.
Claude emits its native identity at initialization, so a later process failure does not discard it.

The capture directory must be private and outside the agent workspace.
Files use mode 0600; writes and terminal manifests are synchronized, and capture failures fail the operation.
Raw files are never exposed through HTTP.
Native stores remain explicitly external; this does not claim a Tangle environment attestation or retained-session API coverage.

Proof

  • Final CI at 37d72a30: 1,212 tests passed, 24 skipped; maintained Runtime consumer regression passed.
  • Focused raw/Claude/profile tests: 19 passed; injected executor tests: 77 passed; TypeScript passed.
  • Exact binary controls cover invalid UTF-8, concurrent bindings, cancellation, a 2 MiB trailing stream, write failure, source cleanup failure and manifest failure.
  • Independent root/science/readiness reviews found no remaining blocking issue in the scoped changes.
  • Existing filesystem jail proof: a real child wrote its workspace but could not see the raw root or private service home.
  • Actual 15-minute Disco Knowledge trial on the earlier capture revision retained three complete process streams with terminal statuses 134, 0 and SIGTERM; all frame sequences, lengths and hashes passed verification.
  • That actual failure exposed missing early native identity, fixed and regression-tested here.

The research trial produced a partial patch; it is not evidence of final product acceptance.
Original evidence stays on the private GTR HDD, with native project JSONL copied separately and credentials excluded.
No production deployment or package publication is included.

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 42dab595

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T07:22:05Z

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — d456e176

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T07:44:05Z

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 37d72a30

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-09-29T07:49:05Z

@drewstone
drewstone merged commit e6537d3 into main Sep 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants