docs(track-a): define canonical live runtime lease model - #311
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cf361a44dd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Pull request was converted to draft
0b7683b to
fca15ac
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af81291066
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af81291066
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Pull request was converted to draft
58fe771 to
91ec453
Compare
|
Post-merge P1 findings are now satisfied by merged PR #313 ( |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5a491373f0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6f8774e522
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
New material governance finding from read-only PR #315: current persistent Policy v4 currently says Gate B must prove a selected live process before the first mutation/reuse, while Gate A says every canonical mutation must stay in Fail-closed resolution should distinguish reuse from initial creation. Initial canonical-session creation must remain disabled until a reviewed bootstrap primitive can, under current lease, create the exact-fenced process in the declared canonical namespace, prove/register its PID+start identity+display/window/fence, and then end the mutation lock without leaving an untracked mutation child. Do not weaken this into standalone |
6f8774e to
150460e
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 71045e0283
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
71045e0 to
0ad4759
Compare
Track A canonical-live governance finalization, clean-restacked on final current
main@b0fd474e34c0252220b773b2304d889821080727after the cancellation-safe manager and fresh manager closeout reached terminal main state.Final boundaries:
coordination.lock, validates the current lease under that flock, keeps the flock out-of-band for the complete mutation/process-tree lifetime, launches mutation descendants with no flock FD, and does not drop serialization merely because the foreground process group is cancelled while a guarded descendant survives.registration_generationand bindlease_generationto the current controller. It cannot create a missing registration, bless a new/reused PID, repair a changed fence or ambiguous client, or mutate the client. This governance PR defines but does not implement that primitive./home/runner/_work/_otclient_tibia_re_state/canonical-live-runtime/runtime-registration.jsonmust match the current lease generation and pass fresh boot/PID/start/exact-fence/display/window/state plus target-uniqueness preflight before ordinary reuse/mutation.TRACK_A_CANONICAL_LIVE_BOOTSTRAP_V1.mdtransition originally promoted by PR docs(track-a): define canonical live bootstrap transition #318/docs(track-a): close out canonical live bootstrap contract #320 and reconciled here to PR fix(track-a): retain canonical lease through process-group cancellation #321/docs(track-a): archive final cancellation-safe lease manager #322 plus the post-bootstrap rebind boundary. Ordinary Gate B/rebind is not weakened to create the first runtime.A deterministic GitHub-hosted Track A governance acceptance audit now falsifies these required invariants on every relevant PR head. Repository required CI, the fresh audit and zero unresolved material review findings are required before protected merge.
Exact fence remains
15.32.df7b29 / 51965216 / e6c244bd39fe2e0632f6f000efd3147164696efa8e901718668e0442325ff7fe. Current:98,6082, PID and session status remains UNKNOWN / NOT_REGISTERED until direct evidence.No live client launch/login/mutation, no registration/rebind runtime execution, no credentials, no PR #303 runtime-owned process/path access, no Track B mutation, no protection/security weakening, and no owner-funded Codex/OpenAI API quota use are part of this governance PR.