Skip to content

Latest commit

 

History

History
76 lines (61 loc) · 4.03 KB

File metadata and controls

76 lines (61 loc) · 4.03 KB

Executable tool controls

Portable foreground execution

Every host uses bounded foreground processes and separate SDK file workers. There is no native addon, process-origin admission, owner/environment scan, namespace backend, descendant discovery, or recovered-PID signalling. Capability records select baseline with no platform-tier degradation warning. Historical execution_policy: { mode: strict } remains parseable but does not restore the removed mechanism. See the approved removal scope.

Roles and subagent profiles can configure these pinned defaults:

tool_execution:
  timeout_seconds: 300
  max_recoverable_timeouts: 2
  termination_grace_seconds: 2

Values are positive safe integers; the deadline is at most 3,600 seconds. A model can shorten, not extend, the pinned deadline. Output and CPU activity do not reset it. File workers prevent synchronous SDK work from blocking the host's deadline. Mutation turns remain serialized while active; interruption does not permanently poison the path solely because descendant cleanup cannot be proved.

Timeouts request cancellation and allow a finite settlement window. Cancellation is best effort against the currently held child handle and freshly launched process group where supported. Foreground close is not descendant-cleanup proof. New terminals report cleanup: not-guaranteed, even on success.

Two timeouts are recoverable by default; the third exhausts the invocation's budget. Historical timeout records still contribute to the appropriate logical invocation budget across physical/model replacement. An explicit checkpoint resume creates a new invocation budget where the existing orchestration contract allows it. Foreground signal exits remain ordinary failures.

Keep complete workloads in the foreground. Detached work can outlive the tool, and the host neither discovers it nor guarantees stopping it. Inspect partial effects and any continuing work before explicitly requesting repair or retry. The host never automatically replays interrupted commands. Explicit session/run close seals admission; persistence ambiguity remains fatal.

Resume and historical records

Unmatched starts, missing close observations, historical interruption and legacy origin/owner metadata do not by themselves bar ordinary resume or replacement. Timeline correlation and record/schema integrity remain validated. History is not evidence authorizing signals, cleanup claims, or successful effect publication.

conduct reconcile-tools --log-dir <path> <run-id> inspects durable records under the run lease. It does not scan processes. Historical operator attestations remain readable; new controller attestations record inspected partial effects, not process-ownership verification. The legacy --confirm-cleanup spelling does not provide descendant-cleanup proof for baseline records. No recorded PID is signalled.

Effect authorization, owner epochs, immutable publication evidence, budgets, tool grants and FSM checks remain separate from removed subprocess policing. Interrupted effects are inspected, not automatically replayed or relabelled as successful publication.

Removed backends and limits

Linux Bubblewrap command/verification/snapshot delivery and built-in executable controllers are removed. Explicit configuration and approval requests receive migration errors, never an unsandboxed fallback. Container delivery is unavailable. Ordinary Git workspaces and file-tool delegation use portable Node/Git operations.

Filesystem helpers retain canonical paths, regular-file/link checks, bounds, content measurements and observable replacement checks, not caller-UID or POSIX permission admission. Mandatory directory hardening/read-only chmod sealing was removed as well; read-only tool grants and byte verification are not kernel write protection. Creation mode hints and Git executable metadata may remain. Operators manage any required host ACLs. These helpers are not race-proof confinement or OS isolation. Upstream Pi and external tools retain their own platform requirements.