policy: make managed containment structural - #64
Merged
Conversation
Owner
Author
|
Exact-head managed governance review completed through the installed coordinator (no raw provider, relay, or inbox fallback).
The first review challenged broad canonical-HOME read exposure. The final head integrates that concern by explicitly documenting same-UID read trust and stating that canonical HOME is not a deny-all-read confidentiality boundary. The reviewer confirmed the revised boundary is truthful: caller checkout read-only, private writable request workspace, explicit provider-state writes, output-only OpenCode build, bounded teardown/cleanup, rare structural containment failure, and orthogonal auth/protocol/output/timeout/provider/teardown/cleanup results. |
sumitake
marked this pull request as ready for review
July 26, 2026 05:35
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
opencode/buildas output-only to the caller while preserving tool-capable work in a private temporary workspace.containment_errorfor pre-launch boundary failure or positive escape/protected-state evidence; keep auth, protocol/output, timeout, provider, teardown, and cleanup orthogonal.Boundary declaration
Generated and release surfaces
SKILL.mdfiles are in parity.changelog.d/fragment is present; generatedCHANGELOG.mdis unchanged.Verification
python3 scripts/build_skills.py --checkpython3 scripts/build_marketplace.py --checkpython3 scripts/build-changelog.py --dry-runpython3 -m unittest discover -s tests -t . -v— 579 passedpython3 -m unittest discover -s scripts -p test_*.py -v— 254 passedpython3 scripts/check_release_consistency.py --against-ref current/mainpython3 scripts/secret_scan.pypython3 scripts/check-public-export-safety.py --active-treegit diff --checkThe all-ref
--historyaudit still reports the same legacy pre-unification provider recipes and credential-variable literals reachable on repository history. The active tree is clean; this PR adds no such material and does not mask the historical baseline.Review and post-condition
Tier 3 because the change narrows a route authority and defines containment semantics. Exact-head independent-family review is pending. After merge, the private runtime companion will rebase to this public anchor, build a new continuity-safe candidate, and prove serial installed Gemini governance, Grok governance, and OpenCode plan calls before old-lane retirement.
Compliance trace
author: openai/codex gpt-5.6-sol
standing_directives: public AGENTS.md boundaries, generated-source parity, Tier-3 review, signed commit, and full deterministic validation followed
tier: 3
cross_check: PROCEED — managed Gemini governance exact head 5c783db, artifact f1218a1266bc47288d8584005bb85cf17aef38bd37bfa539d5511f90e3356986, proof 3075db81fe119f1c86adad7e0fbb80262ea6cdaf1013785223e880979fb76ebd
post_condition: merge before private candidate build; prove serial installed Gemini governance, Grok governance, and OpenCode plan with retained-lane rollback continuity
mcp_coverage_gap: NONE
contributor_rights: OWNER-AUTHORED
operator_reserved: no