Skip to content

feat: add inert benchmark and operator readiness layer - #31

Draft
kiranmagic7 wants to merge 8 commits into
agent/split-privilege-dependency-reviewfrom
agent/usability-benchmark-runbooks
Draft

feat: add inert benchmark and operator readiness layer#31
kiranmagic7 wants to merge 8 commits into
agent/split-privilege-dependency-reviewfrom
agent/usability-benchmark-runbooks

Conversation

@kiranmagic7

@kiranmagic7 kiranmagic7 commented Aug 10, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a deterministic, inert four-family regression corpus with exact behavior and rule expectations
  • enumerate all 14 protected release proof states without authorizing a release
  • add protected-main proof workflows, strict ledger verification, and bounded report inputs
  • integrate adversarial containment checks for capability allowlists, namespace and mount escalation, trace forgery, blocked TCP and DNS, read-only roots, and missing ptrace support
  • add operator runbooks, an incident template, documentation link checks, a current exact example, a 30-second inert demo, and a complete usability journey
  • record historical incident mappings only as citation-backed projections; no affected package is downloaded or executed

Safety boundaries

  • stacked on the split-privilege CI branch from PR ci: split dependency capture from review comments #30
  • no merge, tag, release, package publication, Marketplace submission, launch, or live-malware execution
  • the checked-in protected-main snapshot remains fail-closed at 0 of 14 gates
  • the protected proof workflow is inactive until this stack is reviewed and merged

Verification

  • make check
  • scripts/usability-check.sh
  • scoped gosec scan over all new Go command and library packages
  • deterministic benchmark replay
  • DCO, actionlint, shellcheck, race tests, schema checks, and documentation link checks
  • Docker is unavailable in the local execution environment; the hosted Hardened runner integration check is the Docker authority for this head

Addresses #23.

Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Signed-off-by: Kiran <262980978+kiranmagic7@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant