Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); docs: run report — tasks 2 and 3 shipped by codeitlikemiley · Pull Request #39 · codeitlikemiley/panday · GitHub
Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 29 additions & 5 deletions RUN-REPORT.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -10,7 +10,16 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
CI gates, and there a host proxy is unreachable under `--unshare-net` without a veth pair or a
relay binary shipped into the jail. That is a distribution problem, not a sandbox one.
**Answer: "fail-closed is the milestone" or "build the proxy anyway".**
2. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
2. **M14.9's T3-remote accepts a no-egress policy it does not honour. Intended?** `NetPolicy`'s
own doc says "empty ... means no egress at all", every caller passes `NetPolicy::default()`,
and `t3_remote.rs` does nothing to constrain network — no egress setting in the fork/start
payload, and its suite asserts nothing about it. It *does* call `enforceable()` (line 271), so
the non-empty case is refused correctly; it is the empty case that is unhonoured. A CodeSandbox
microVM having internet is my inference, not something I tested — no token, no live calls. Not
fixed: it is a milestone that merged while I was working and not one of my nine tasks.
**Answer: "known and fine, it is a hosted VM the operator chose" or "make T3Remote refuse, or
say in docs/14 that it cannot honour no-egress".**
3. **Should a released air-gap kit default to packing an inference runner?** `xtask airgap
--runner <path>` exists. Defaulting means vendoring a third-party binary per architecture with
a licensing surface `cargo deny` cannot see. **Answer: yes / no.**

Expand All@@ -19,9 +28,9 @@ Brief: `GOAL.prompt.md`. Baseline `main` at `34dd903`; run started 2026-08-23.
| # | Task | State | PR | Merge |
|---|---|---|---|---|
| 1 | Merge PR #35 (handover docs) | **shipped** | #35 | `e40d4fb` |
| 2 | Fail-closed egress in T2 | in progress | — | |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | scoped, not started | — | |
| 4 | M14.8 decide and land | blocked on question 1 | — | — |
| 2 | Fail-closed egress in T2 | **shipped** | #36 | `54d94ce` |
| 3 | `plugin.toml` `net:` claims enforcement it lacks | **shipped** | #38 | `1e13624` |
| 4 | M14.8 decide and land | **blocked on question 1** | — | — |
| 5 | Executable training gates | not started | — | — |
| 6 | `training/` directories | not started | — | — |
| 7 | Shadow mode behind a flag | not started | — | — |
Expand DownExpand Up@@ -51,9 +60,16 @@ Unrestricted `mach-lookup` remains broad and is worth tightening as hardening, o
|---|---|---|
| `net_policy_tests::a_named_host_is_refused_rather_than_approximated` | `enforceable()` always returns `Ok` | red — `a named host must be refused` |
| `t2_macos_escape::a_named_host_in_the_allowlist_is_refused_not_granted` | `enforceable()` no-op + macOS allowlist branch restored | red — sandbox created a session with an unenforceable policy |
| `plugins::a_requested_network_capability_is_not_presented_as_a_grant` | old consent line restored | red — "must say the request is not granted, not merely list it: network: api.github.com" |

Both green again after restoring.

## Landed alongside, not by me

**M14.9 (PR #37, `2301ec8`) merged onto `main` mid-run** — a T3-remote CodeSandbox backend. It was
not in the brief and I did not touch it. It already calls `NetPolicy::enforceable()`, so task 2's
refusal covers it; the open question is the empty-allowlist case above.

## Environment note that will cost the next run time

**This machine builds another project (`oag-server`) concurrently, and panday's suite has
Expand All@@ -62,6 +78,8 @@ time-sensitive tests that fail or hang under that contention.** Observed three t
test passes in **0.05s** on a quiet machine, on this branch. Not a code defect.
- `panday-sandbox::a_nonzero_exit_is_reported_not_swallowed` fails when the jail's 30s wall clock
elapses under load; a killed process reports no exit code, so `Some(3)` reads as `None`.
- Gates took **60-100 minutes** rather than the usual ~15. The load was not the build: UTM/QEMU
held ~127% CPU for 7+ hours alongside the other project's cargo runs. Load average peaked at 31.
- A gate script that ran `cargo test --workspace` twice left the second copy holding the cargo
lock, blocking an unrelated run. Fixed by running it once.

Expand All@@ -71,4 +89,10 @@ stall by the child, not the parent.
## Unverified claims

- T2 Linux changes are `#[cfg(target_os = "linux")]` and **cannot be compiled on this machine**.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12.
CI is the only authority for `t2_linux.rs`, per the brief's rule 12. CI caught exactly one thing
local checks could not: a dead field and a comment-only import, both `-D warnings` errors.
- `handover.md` says platform-conditional code cannot be checked locally because `ring` needs
`x86_64-linux-gnu-gcc`. Tested: `cargo check --target x86_64-unknown-linux-gnu` does not link at
all, and still fails — on **`zstd-sys`** (via wasmtime), whose *build script* compiles C. The
blocker is a build script, not linking, and there is no local Linux verification of any kind.
- That a CodeSandbox microVM has internet is inferred, not tested.