Skip to content

Certify framework handoffs and agent containment - #25

Merged
forhappy merged 1 commit into
mainfrom
codex/certify-framework-handoffs
Aug 12, 2026
Merged

forhappy merged 1 commit into
mainfrom
codex/certify-framework-handoffs

Conversation

@forhappy

Copy link
Copy Markdown
Contributor

What changed

  • add sealed semantic A → B → C qualification for Go, pnpm, npm, Python, and CMake, including exact ancestry, source/test edits, stale-output rejection, and adapter-specific reuse assertions
  • harden Python environments with hash-pinned requirements, uv.lock support, .python-version selection, shared download caches, and lane-private virtual environments
  • make mounted managed execution use direct private bindings and return actionable guidance for unsupported materialized environment execution
  • add contained default terminal-agent profiles for Claude Code, Codex, and generic providers, with isolated HOME/XDG/temp roots, an explicit environment allowlist, lane-rooted Git state, disabled project integrations, and macOS kernel-enforced write boundaries
  • add typed containment evidence to agent reports and regression coverage proving the original checkout cannot be modified
  • make summary-only root diffs content-aware so task views report correct addition/deletion counts
  • update CI, public contracts, security/design docs, and user guidance

Why

The framework adapters introduced by #24 needed production evidence that successor lanes inherit the exact semantic checkpoint and reuse only compatible dependencies or build state. Python and CMake also require private mutable outputs rather than shared immutable layers.

Terminal agents previously inherited too much host and project context. A project integration could escape a lane even when the process cwd pointed at its Trail workdir. The new default profiles make the containment policy explicit, kernel-enforce writable roots on macOS, and expose a receipt callers can audit.

Finally, lane/task summaries used a lightweight root-diff path that hard-coded line counts to zero. The shared indexed diff now calculates counts from changed content while retaining bounded changed-path traversal and linear rename lookup.

User impact

  • Go, pnpm, npm, Python, and CMake handoffs now have executable, sealed A → B → C qualification rather than design-only support.
  • Claude Code and Codex start contained by default unless project integrations are explicitly allowed.
  • Claude user settings import is limited to documented auth/provider endpoint variables; hooks, plugins, and permissions are not copied.
  • Agent task views now report accurate text line statistics.

Verification

  • cargo fmt --all -- --check
  • cargo check --workspace --locked
  • cargo test --workspace --locked --quiet (full feature patch before the final root-summary correction)
  • cargo test -p trail --lib --locked — 905 passed, 4 ignored
  • cargo test -p trail --test e2e terminal_agent_ --locked — 7 passed
  • cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
  • python3 -m unittest scripts/test_edit_real_framework_semantic.py scripts/test_check_real_framework_handoff.py — 7 passed
  • all five sealed evidence directories revalidated with scripts/check-real-framework-handoff.py
  • real redb Claude Code run edited only src/error.rs inside an NFS Trail lane; Trail recorded exact source ancestry, macOS kernel containment, an unchanged original checkout, Cargo environment re-sync with 234,235,159 reused bytes, and successful managed cargo fmt --check
  • the rebuilt task view reports the real four-line replacement as +4/-4

Real framework repositories used: bbolt (Go), clob-client-v2 (pnpm), uuid (npm), tappy (Python), and LevelDB (CMake).

@forhappy
forhappy marked this pull request as ready for review August 12, 2026 13:37
@forhappy
forhappy merged commit 01e32c2 into main Aug 12, 2026
49 of 52 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant