Skip to content

feat(cli): expose runtime JSONL observations and minimal device defaults - #265

Draft
jamesboyzj-design wants to merge 4 commits into
multikernel:mainfrom
jamesboyzj-design:feat/runtime-events-devices
Draft

jamesboyzj-design wants to merge 4 commits into
multikernel:mainfrom
jamesboyzj-design:feat/runtime-events-devices

Conversation

@jamesboyzj-design

@jamesboyzj-design jamesboyzj-design commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Draft for review of the CLI runtime JSONL observation contract and minimal device defaults. This branch is synchronized with current main. The certificate fix from #264 and its strict X509 regression coverage are already in main; this PR contains only the remaining CLI/runtime feature changes. It contains no Agent Workbench wrapper, product data or dependency bump.

Changes

  • run --events-jsonl PATH: private, exclusive, versioned JSONL file, kept separate from child output and outside sandbox writable/mounted trees.
  • Export existing policy_fn observations and RunResult.changes. Never label a non-denied supervisor observation as kernel success, or a COW change set as a commit receipt. Omit argv, environment, file content and credentials.
  • Sequence and terminal records, timeout distinction, bounded output file, explicit failure for incomplete/unrepresentable observations. No-supervisor mode rejects this flag.
  • CLI minimal device defaults: null read/write; zero/random/urandom read-only. Validate character-device type and major/minor, reject replaced nodes. --no-default-devices opts out; library callers explicitly opt in via .standard_devices()? without changing the library's default policy.

Validation

Before synchronizing with current main, the Linux ARM64 run reported 113 CLI tests passed and 842 core unit tests passed with two known root-environment COW failures (rename_staging_failure_fails_rename_and_rolls_back and write_open_in_unreadable_dir_virtualizes). The old CLI strict TLS test was included in that historical CLI count; it has since been removed because #264 moved this regression coverage into sandlock-core. These figures do not describe validation of the current synchronized head.

CI for the synchronized head is running: https://github.com/multikernel/sandlock/actions/runs/37090872119

Boundaries

policy_fn observations are not final kernel return values and may incur tracking/freezing overhead. supervisor_denied reflects an errno action, not proof that every such error is a security denial. The core does not expose that final errno through this callback. SIGKILL or host failure can leave an incomplete stream; there is no exactly-once replay or cryptographic sealing. No x86_64 VM or workload-capacity benchmark was run in the earlier validation.

Set leaf Authority Key Identifier and CA keyCertSign/cRLSign usages. Add a real local HTTPS probe with Python strict verification and synthetic credential injection; do not weaken client verification.
Add protected opt-in JSONL observations and COW change records without claiming kernel outcome coverage. Add validated standard character-device grants, explicit CLI opt-out and library opt-in. Cover spoofed output, timeout, path isolation, invalid encoding and real Git operation.
@jamesboyzj-design

Copy link
Copy Markdown
Contributor Author

Synced this branch with current main and resolved the TLS conflict by taking the certificate fix and core-level strict X509 coverage now present on main. I also removed the obsolete CLI strict-TLS test so this PR no longer duplicates #264 coverage, and updated the validation notes accordingly.

The remaining diff is the CLI runtime JSONL observation feature, minimal standard-device defaults, and their tests/docs. The synchronized head is c8a269d; all 17 CI checks pass, and GitHub reports the PR as mergeable with a clean merge state.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant