feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(gits): H0 confinement + verifier-critic foundation - #1

Merged
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike
Jun 6, 2026
Merged

feat(gits): H0 confinement + verifier-critic foundation#1
Ecko95 merged 7 commits into
gitsfrom
feat/gits-h0-confinement-spike

Conversation

@Ecko95

Copy link
Copy Markdown
Owner

Foundation for the self-improving orchestration work (design Rev 2 — see docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md §"Revision 2" + docs/brainstorms/self-improving-orchestration.md). Subsequent slices (acceptance-criteria plumbing, verifier wiring, live smoke) build on this.

What's in here

  • H0 execution confinementscripts/gits-confine.sh (verify/peer profiles), scripts/confined-verify.sh; closes the unsandboxed-verification RCE. Autopilot supervisor.py routes verification through it (backward-compatible). 14/14 spike checks.
  • GITS verification gateGitsVerificationGate + GitsConfinedVerifyAdapter (mechanical lint/tsc/test under confinement; fail-closed when bwrap absent). 4/4 tests.
  • Verifier-criticGitsSemanticVerifier + GitsCodexVerifierAdapter: a fresh read-only codex reviewer judges green PRs against per-slice acceptance criteria (catches green-but-wrong), triage not block, escalates gpt-5.4-mini→gpt-5.5 on uncertain. 5/5 tests.
  • Docs — Rev 2 reorientation (codex-only, avoid Claude SDK, Motoko=conductor, memory→SQLite ledger, codex-rate-limit cost, PWA push).

CI note

CI will be red due to pre-existingGitsDevCommands.ts typecheck errors that already exist on gits (dev-launcher WIP) — not introduced here. All code added in this PR typechecks clean in isolation, lints 0/0, and its tests pass (contracts exit 0; gate 4/4; verifier 5/5).

🤖 Generated with Claude Code

Ecko95and others added 7 commits June 4, 2026 00:53
Design (docs/gits/ORCHESTRATION_SELF_IMPROVEMENT_DESIGN.md): an editable, self-improving
Delamain orchestrator as a human-gated MAPE-K loop — peer-outcome telemetry -> shared
memory -> deterministic reflection -> operator-approved structured config patch -> canary
with auto-rollback. Three-tier config (tuning/sensitive/guardrail), shared multi-agent
memory (Basic Memory via a GITS-mediated MCP proxy with provenance + anomaly checks).
Research-backed (Augment Intent/Cosmos, mem0, self-improving multi-agent patterns, Claude
SDK), with prior-art comparison (ORCHESTRATION_PRIOR_ART.md) and a context graph
(graphify-out/). Hardened against /code-review (D1-D7, R1-R9) and an adversarial red-team
(H0-H9).
H0 confinement spike (spikes/h0-confinement/): a bubblewrap wrapper + threat/usability
tests proving peers and verification can run with worktree-only writes, operator secrets
excluded, npm lifecycle scripts disabled, and network off — 10/10 checks, deterministic.
Closes the red-team's unsandboxed-verification RCE finding; the foundational prerequisite
(H0) for any loop auto-apply. Not yet wired into delamain/autopilot (see SPIKE_FINDINGS.md).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…peer cred-min)
Promote the H0 spike to canonical, profiled tooling:
- scripts/gits-confine.sh: bubblewrap wrapper with `verify` (untrusted: worktree-only
writes, no creds, network off, --ignore-scripts) and `peer` (minimal --cred binding,
egress policy) profiles.
- scripts/confined-verify.sh: runs a SERVER-PINNED verification suite confined — the
artifact the autopilot supervisor.py / GITS gate calls instead of executing a hostile
repo's commands on the host (closes the red-team RCE, design H0/D3).
- spikes/h0-confinement: now the test harness for the canonical scripts (14/14: verify
lockdown A-H, peer cred-minimization P1/P2, gate runner V1/V2). Removed the superseded
spike-local wrapper.
- docs/gits/H0_CONFINEMENT.md: integration guide (autopilot/GITS/peer snippets) + the
remaining egress-allowlist gap (needs passt/pasta or root nftables, absent on host).
Verification-under-confinement and peer minimal-credential binding work today; the peer
egress allowlist is blocked on userspace-net availability. Design doc H0 + TODO updated.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ate adapter
Verification-under-confinement (H0) is now wired into both gates the design named:
1. Autopilot (delamain-autopilot/scripts/supervisor.py, external skill): auto_review_and_merge's
per-command run(cmd, cwd=wt) — which executed an untrusted repo's scripts on the host with
operator secrets present — now routes through scripts/gits-confine.sh --profile verify via new
run_gate()/confine_script() helpers when bwrap + the wrapper are locatable, falling back to the
legacy run otherwise so live chains never break. Activated per chain via config.confine_script /
gitscode_path (or GITS_CONFINE_SCRIPT). Validated end-to-end: a hostile `cat <secret>`
verification command runs confined → rc!=0, no leak; benign commands pass. (Recorded here; the
file is a skill outside this repo, backed up at supervisor.py.bak-h0-*.)
2. GITS-side gate: new typed GitsVerificationGate service + GitsConfinedVerifyAdapter layer
(mirrors OpenGsdCliAdapter). Probes bwrap; FAILS CLOSED when confinement is unavailable and
requireConfinement is set; otherwise runs each server-pinned argv command through the verify
profile and returns structured per-command results. Contracts (GitsVerify*) added to
packages/contracts/src/gits.ts; wired into server.ts GitsLayerLive. 4/4 unit tests; contracts
typecheck clean. This is the gate the future canary/OrchestratorConfigExecutor consumes.
docs/gits/H0_CONFINEMENT.md + TODO updated. Peer-spawn confinement (H0b) and egress allowlist
(H0c, blocked on passt/pasta) remain follow-ups.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
A /grill-me session (docs/brainstorms/self-improving-orchestration.md) re-pointed the
design to the operator's actual pain (green-but-wrong PRs + cost/babysitting), superseding
parts of the original:
- #1 deliverable = semantic verifier-critic (fresh read-only codex, judges green PRs vs
per-slice acceptance criteria, triage-not-block: confident-pass auto-merges, flagged held).
- avoid Claude Agent SDK; peers always codex (cursor manual-only); Motoko = persona+conductor
(hybrid default + fully-agentic toggle; consequential gates never relax).
- memory DESCOPED to a server-owned SQLite episode ledger + reflections + one-way prompt
injection (deletes the peer-writable shared store + MCP-proxy + poisoning surface).
- cost = codex rate-limits (reserve 20% weekly), not $ cap; surface codex usage in cockpit.
- surface target = GITS as an installable Android PWA with web push (Telegram = stopgap).
- build order: verifier-critic → ledger+usage → auto-answerer → routing tuning → agentic toggle.
DESIGN.md gets a "Revision 2" callout; H0_CONFINEMENT.md forward-links the verifier-critic;
TODO re-sequenced verifier-first.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…age, not block)
Build item #1 from the grilling (the operator's #1 pain: green-but-wrong PRs). After the
mechanical H0 gate is green, a FRESH read-only codex agent judges the diff against the slice's
acceptance criteria + an adversarial "what did it miss" pass, and TRIAGES the PR — it never
blocks the chain.
- Contracts (packages/contracts/src/gits.ts): GitsVerifier{Verdict,Confidence,Recommendation},
GitsSemanticVerifyInput (worktree, baseRef, acceptanceCriteria[], model), GitsSemanticVerifyResult
(verdict/confidence/recommendation/reasons/missed/criteriaProvided), GitsSemanticVerifierError.
- Service GitsSemanticVerifier + Layer GitsCodexVerifierAdapter:
- computes `git diff baseRef..HEAD` (truncated), builds an injection-aware prompt (diff = UNTRUSTED
data; reviewer must ignore embedded instructions), runs `codex exec --sandbox read-only -m <model>`
against the peer codex home, and Schema-parses the JSON verdict (no raw JSON.parse).
- triage: pass + (medium|high) + criteriaProvided -> auto-merge; else hold-for-review. No criteria
-> criteriaProvided=false -> always hold. Cheap tier (gpt-5.4-mini) escalates ONCE to gpt-5.5 on
uncertain. Read-only: even if prompt-injected it cannot modify the repo.
- wired into server.ts GitsLayerLive. 5/5 unit tests (mocked ProcessRunner); contracts typecheck clean.
Complements GitsVerificationGate (mechanical) with the SEMANTIC layer. Codex-only, no Claude SDK.
Follow-ups: acceptance-criteria slice-format plumbing + autopilot wiring + live codex-exec smoke.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ent-spike
# Conflicts:
#	apps/web/src/components/DevCommandsControl.tsx
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Ecko95