Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.
This repository was archived by the owner on Oct 1, 2026. It is now read-only.

[P1] Make the live DevTools path truthful, bounded, and fail-closed #137

Description

@Xuepoo

Priority: P1 | Area: DevTools client/protocol/privacy | Labels: P1,fix,area:devtools | Milestone: v0.1.0 | RFC: OQ-000 (campaign contract decisions) | Task: CTX-0006

Parent issue for the accepted 2026-09-24 DevTools findings.

Scope:

  • DEV-001/002/006/007/008/013/021: one live request owner, strict decoding, continuation framing, cancellation, and strict rendering;
  • DEV-005/010/011/012/014/017/020: redaction ordering, campaign bounds, trace truthfulness, and session cleanup;
  • DEV-015/027: fail-closed CarryCtx import probing;
  • DEV-016/019/022/023/024/025/028: identity, endpoint budgets, version/platform, quality, and hygiene.

Evidence: research/review/2026-09-24/09-independent-devtools-docs-verification.md, 10-final-cross-authority.md, and 12-final-cross-client-engine.md.

Acceptance: keep unsupported live operations explicitly unavailable, use hermetic loopback/fake-adapter tests, pass bitty-devtools just gates, and obtain independent review. Server peer/session/authority fixes remain in bitty. No Windows compromise or secret-bearing runtime incident is claimed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions