Goal
Verify and enforce the advertised trust profiles so untrusted work cannot enter trusted-only pools and jobs cannot reach manager credentials/control in the supported configuration.
Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.
Execution contract
| Field |
Value |
| Goal key |
G19 |
| Stage |
M3 - Reliability qualification |
| Initial status |
Backlog |
| Primary agent |
gpt-5.6-luna / max |
| Priority / risk |
P0 / High |
| Test profiles |
offline, trusted-runtime, trusted-live-github |
Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.
Dependencies
Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.
Scope
Threat-model closure, policy preflight, native UID and Docker DinD profiles, adversarial non-destructive probes. No unsupported claim of hostile-container isolation.
TDD and failure evidence
- Red: mismatched runner-group access, ambiguous fork provenance and job invoking official CLI cannot bypass policy.
- Try reading controller home/state/keychain/socket, sibling files/env and manager Docker socket from controlled test jobs.
- Exercise SDK secret-in-error, proxy inheritance, wrong-org endpoint, unsafe mount/device/host-network requests.
- Test shared-App blast radius/rotation docs and reject unsupported arbitrary backend flags.
Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.
Acceptance criteria
Safety invariants
Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.
Design references
Goal
Verify and enforce the advertised trust profiles so untrusted work cannot enter trusted-only pools and jobs cannot reach manager credentials/control in the supported configuration.
Create one active Codex goal from the statement above when this issue is dispatched. The Project Goal field is a work specification; it does not start an agent. Do not invent a token budget.
Execution contract
Use one issue branch/worktree and one focused PR. Independent Luna max review is required for authentication, protocol, concurrency, resource ownership, cleanup or service identity boundaries; other changes need independent contract review. Model fields are routing instructions, not GitHub user assignments.
Dependencies
Dependencies must be Done before implementation begins. A new issue is not blocked simply because its future evidence has not been collected.
Scope
Threat-model closure, policy preflight, native UID and Docker DinD profiles, adversarial non-destructive probes. No unsupported claim of hostile-container isolation.
TDD and failure evidence
Capture a meaningful failing case before the implementation, then green evidence and relevant refactor checks. Tooling/prose-only work uses appropriate negative checks without artificial application tests. Live/runtime profiles require reviewed commits, a dedicated trusted test environment and explicit authorization for the concrete experiment. Public PR CI uses hosted environments without credentials. Planned or skipped tests never count as passed.
Acceptance criteria
Safety invariants
Preserve existing manual runners; no global Docker prune/context switching, broad process kill, implicit App enrollment, busy-job cancellation during ordinary scale-down or transparent workflow replay. Use only verifiably owned resources. Keep management credentials and raw secret-bearing SDK errors out of worker environments, logs, fixtures and commits; per-worker JIT transport follows G01. Native pools remain trusted-only.
Design references