Skip to content

Defect: Decouple request-deadline verification from hosted cleanup timing - #199

Merged
Niko4417 merged 15 commits into
epic/98-codex-tracerfrom
codex/198-request-deadline-verification
Aug 12, 2026
Merged

Defect: Decouple request-deadline verification from hosted cleanup timing#199
Niko4417 merged 15 commits into
epic/98-codex-tracerfrom
codex/198-request-deadline-verification

Conversation

@Niko4417

@Niko4417 Niko4417 commented Aug 11, 2026

Copy link
Copy Markdown
Collaborator

Scope

Product and architecture alignment

  • The implemented contract version and fingerprint match the automated readiness record; no
    semantic planning change was absorbed during implementation.
  • The change follows the Decision Addendum, CONTEXT.md, accepted ADRs, and the issue Quality
    Plan.
  • Existing Keiko material was used only after a recorded Reuse Assessment, or the issue records
    why Existing Keiko evidence is not applicable.
  • This greenfield change creates no mandatory build-time or runtime dependency on Existing
    Keiko.
  • Product authority, policy, evidence, and privileged effects remain in their owning Native
    layer.
  • Any durable architecture change is recorded in an ADR.

Existing Keiko evidence is not applicable: this is Native-owned test and verification hardening.
No durable architecture decision, product constant, production interface, or privileged effect
changed. The test-only observer is excluded from release output and does not become product state.

Acceptance criteria and evidence

Acceptance criterion Evidence Exact head or artifact Result
AC1 #98 v41 fingerprint 887a77ef1e4c803b9958459abbc3bad23418f729f2162d7453f3afbafcb63d4e and #198 v30 fingerprint 0e0b3bfd81e87f29d2222c137cf07bccf1e887239247acb0ee3487652310222b retain matching accepted readiness records; exact local head is clean, signed, private-email authored, and linearly based on exact epic tip 4bf31401d043605ff933c51e3eb534424d9222ed 63b0f02aa7eff60a859eb451875387c179d59b72 Pass
AC2 The v28 postcommit chain passed all focused checks, three sequential host suites, native coverage, repository quality, high-severity dependency audit, macOS acceptance, fresh verification and audit receipts, and release exclusion scans before the sole cleanup-only inventory comparison stopped 63b0f02aa7eff60a859eb451875387c179d59b72 Pass
AC3 The v28 TMP transition is an exact strict subset: 1,130 pre rows, 1,077 post rows, 53 exact foundation-state files only before, and zero only after; process snapshots are both empty. The v29 read-only finalizer found the current inventory byte-identical to v28 post, zero further additions or removals, and zero attributable process residue sha256:b27bce290673ec5b78fa625e84fcf52377ab16efd074c07d428b106b299a83c6 Pass
AC4 Mandatory independent audit covered the 15-commit, six-file test-only aggregate, exact-head signatures and release exclusion, v28/v29 artifacts, receipt schemas and ordering, quarantines, cleanup-only adjudication, trust and teardown paths, and delivery governance; confirmed findings are zero sha256:342034df10f58ba58c9094094f912a6ee97df1bfd76b443d4a347cb422d37a9a Pass
AC5 Ordinary fast-forward publication to the accepted epic target is topology-safe. Exact-head remote checks, a fresh Codex review, and settlement of the named review thread remain mandatory before integration 63b0f02aa7eff60a859eb451875387c179d59b72 Pending remote settlement

Acceptance journey evidence

  • Applicability: Not applicable — Defect: Decouple request-deadline verification from hosted cleanup timing #198 changes only test and verification behavior; the release
    binary, user interface, and user-visible product behavior are unchanged.

  • Automated checks exercise user-visible outcomes rather than incidental implementation
    details. Not applicable for this non-user-facing issue; the wired runtime composition and
    observable cleanup outcome are exercised instead.

  • Required failure, recovery, accessibility, visual, and platform observations are settled.
    Failure and recovery evidence is complete; accessibility and visual observations are excluded
    because no user interface changes.

Quality Plan settlement

  • Applicable positive, negative, boundary, failure, cancellation, and recovery behavior is
    covered.
  • The actually wired production composition was tested where this change crosses layers.
  • Applicable security, accessibility, performance, resource, visual, and platform evidence is
    attached or linked.
  • Excluded quality areas retain the rationale accepted in the issue.
  • Secrets, credentials, raw customer content, private endpoints, and PII are absent from source,
    tests, logs, evidence, artifacts, issues, and this pull request.

The real keiko-host-macos composition is observed under test from request deadline forwarding
through readiness, protocol execution, and cleanup. Authentication, PID-reuse refusal, owned-child
settlement, cleanup failure, bounded recovery, poison recovery, and zero-residue paths are covered.
The observer is compiled only for tests; release strings and symbol scans prove it absent from the
packaged binary. Accessibility, visual, localization, and Windows evidence are not applicable to
this non-user-facing macOS verification defect.

Verification

  • npm ci --ignore-scripts
  • npm run quality
  • npm audit --audit-level=high
  • Every declared native target-specific gate passed on its authoritative platform.
  • I reviewed the complete diff against requirements, contracts, trust boundaries, and failure
    modes.

Additional affected checks and concise results:

Exact head: 63b0f02aa7eff60a859eb451875387c179d59b72
Exact tree: 333fb6ec7f5ab6a46f9ad59ba72ee889ba2a7077
Aggregate base: 4bf31401d043605ff933c51e3eb534424d9222ed
Aggregate binary diff: sha256:88075daafdbfab88d4f4931ab7f05cccecfcd0488c3a75278840177254611afa

V28 precommit driver: sha256:d6fbe7fa25d912667c78f3f52b295cd509335905a8390fd65f25b70aca28da89
V28 postcommit driver: sha256:a133aedae43ccfa16477bd1970eee3220ed69d830e37043314e822698c37b683
  Focused composition, policy, and smoke tests; fmt and clippy; complete keiko-host-macos suite
  three times sequentially; native:coverage; npm run quality; npm audit --audit-level=high;
  acceptance:macos; fresh receipts; package manifest and release scans: all passed, no retry.

Verify receipt: mode 0600, sha256:1f41ab7c899b3d6ef0602f94e0a323d3eaf53401ce5837fe9d21a28d202d1609
Audit receipt: mode 0600, findings 0, user-facing false,
  sha256:342034df10f58ba58c9094094f912a6ee97df1bfd76b443d4a347cb422d37a9a
Package manifest: sha256:85cc0c933e42a6d57bf8d5bfe096f6fcc7ba2cb94b2a78a0eee0b2cca9b6784d
Release binary: mode 0755, 7,255,088 bytes,
  sha256:2b7b924ecc1b754dcd8e6551f51f50ad1cae3a4d7ec96acc5a38f0f07576f899
Release observer strings and symbols: zero hits.

V28 cleanup-only evidence:
  pre TMP 1,130 rows / 83,714 bytes / sha256:77ef9e4c23e471d25d1a4dc7cb8c514d77628a59cc5af0a2294d06e9431fda9c
  post TMP 1,077 rows / 79,020 bytes / sha256:ec599721fb17f1126d353fc36887d6725ec69d596b3a1ace7481e73209a72a7c
  only-pre 53 exact legacy foundation-state files / only-post 0; process pre/post empty.
V29 finalizer driver: mode 0700, 16,135 bytes,
  sha256:b27bce290673ec5b78fa625e84fcf52377ab16efd074c07d428b106b299a83c6
  current TMP equals v28 post; additions 0; removals 0; current attributable process set empty.

Independent audit and findings

Confirmed finding Evidence Disposition Settlement evidence or follow-up
None Aggregate binary diff SHA-256 88075daafdbfab88d4f4931ab7f05cccecfcd0488c3a75278840177254611afa; exact-head audit receipt SHA-256 342034df10f58ba58c9094094f912a6ee97df1bfd76b443d4a347cb422d37a9a; v29 driver SHA-256 b27bce290673ec5b78fa625e84fcf52377ab16efd074c07d428b106b299a83c6 Findings zero Exact-head gates, release exclusion, strict cleanup-only subset proof, current zero-addition inventory, clean state, and zero process residue passed
  • Findings are evidence-cited; speculative observations are advisory rather than blockers.
  • Every confirmed finding is resolved, explicitly accepted by an authorized human, or linked to
    a scoped follow-up that does not invalidate current acceptance.
  • Verification and audit were repeated after the latest implementation or audit fix.

Integrated epic acceptance

  • Applicability: Required

#198 restores the runtime verification and recovery evidence consumed by the parent epic Quality
Envelope; final end-to-end epic acceptance remains owned by #104.

  • Production-composition result: the exact wired deadline value is observed through readiness,
    protocol execution, and cleanup; complete keiko-host-macos suites passed three sequential runs.
  • Machine-enforced acceptance result: native branch coverage, complete repository quality,
    high-severity dependency audit, security, signing, packaging, release exclusion, receipt
    verification, and residue adjudication passed at the exact head.
  • macOS evidence: npm run acceptance:macos passed against the revision-bound frontend and package.
  • Windows evidence: Not applicable — Windows is excluded by ADR-0006 for this macOS-native slice.
  • Manual usability, accessibility, visual, signing, or packaging evidence: manual usability,
    accessibility, and visual review are not applicable to a non-user-facing test-only change;
    automated signing and packaging evidence passed.

Delivery

  • Target path: child issue -> epic branch
  • The target branch matches the delivery path accepted in the issue; no direct push, force
    push, gate bypass, finding dismissal, or authority widening occurred.
  • Commits are signed and every required check must be bound to the exact current head and
    expected producer before integration.
  • Advisory tools are not treated as required merge authority under the current quality-gate
    policy.
  • Documentation, ADRs, contracts, known limitations, and follow-ups are current.
  • A draft pull request was not promoted to Ready for Human Review before every required
    Acceptance Journey result and exact-head gate was complete.

For this child-issue pull request targeting its designated epic integration branch:

  • The accepted issue authorizes this epic-branch target.
  • Acceptance and audit evidence is complete; every currently applicable exact-head gate must be
    green and no blocking finding or review conversation may remain before integration. Fresh
    remote checks, a fresh Codex review, and explicit settlement of the named thread remain
    mandatory.

Agent delivery stops at the accepted epic-branch boundary. No direct dev delivery, force-push,
provider auto-merge, or agent-initiated epic merge is authorized by this evidence handoff.

Residual risks and follow-ups

  • The current remote PR head, checks, and Codex review are still bound to stale head
    f2efe02bf4be070941c134f1a8b9f44fc3eb63e0. They must not be credited to this head. Publication
    must be an ordinary fast-forward to 63b0f02aa7eff60a859eb451875387c179d59b72, followed by fresh
    exact-head checks and review.
  • Review thread PRRT_kwDOTZu8Oc6YYV5z remains unresolved. Reply factually after publication,
    request @codex review, and resolve the thread only after exact-head checks and review establish
    that no actionable finding remains.
  • The v28 final comparison stopped only because 53 exact legacy foundation-state files disappeared;
    there were no additions and no process residue. V29 proves the current set remains byte-identical
    to v28 post. This cleanup-only transition receives no gate rerun or acceptance credit.
  • Recoverable, private audit quarantines remain intentionally retained under the worktree Git
    directory. The v13 quarantine preserves twelve historical quality-fixture roots; the v18
    quarantine preserves two 57-byte foundation-state files. Original paths are absent, identities
    remain authenticated, and permanent deletion is not authorized.
  • Coverage direction 4457F remains excluded from semantic credit as a non-hermetic kernel or invalid
    state path; unrelated pre-existing direction 3999F receives no semantic credit. The canonical
    branch threshold remains green.

@Niko4417
Niko4417 requested a review from oscharko as a code owner August 11, 2026 21:13

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f2efe02bf4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread native/crates/keiko-host-macos/src/runtime.rs
@Niko4417

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: 63b0f02aa7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@Niko4417
Niko4417 merged commit b7a7a4b into epic/98-codex-tracer Aug 12, 2026
57 of 61 checks passed
@Niko4417
Niko4417 deleted the codex/198-request-deadline-verification branch August 12, 2026 08:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant