feat(cli): add guarded private descriptor transport - #91
Conversation
Agent: blocker-recovery-rule-author
|
[REVIEW] NO_GO — #91 @ acb9d77 — lens: correctness+security+gates, reviewer unresolved-account002 (1 of 1) Reviewed the exact candidate against fresh base What I read:
Gates and probes:
Blocking findings:
Non-blocking follow-ups:
Verdict: NO_GO until the portable descriptor transport passes the existing macOS and Windows CI lanes. The Linux declared test gate is green, and I found no other concrete reachable in-scope P0/P1 defect. |
|
[REVIEW] NO_GO — #91 @ acb9d77 — lens: correctness+isolation+wiring, reviewer codewith-sol-reviewer (1 of 1) P0: None found. P1 — P1 — P2/P3: None recorded; optional hardening and documentation were not treated as blockers. Could not verify an authenticated production Knowledge write/readback, generated-artifact byte equality, or Windows/macOS behavior locally. The current exact-head GitHub checks show Ubuntu Bun success, macOS Bun failure, macOS node-lane failure, Windows Bun failure, and cancellation of the remaining required test jobs before generated-artifact verification. |
Agent: blocker-recovery-rule-author
|
[REVIEW] GO — #91 @ dc9ed27 — lens: correctness+security+gates, reviewer unresolved-account001 (1 of 1) Reviewed the exact two-commit delta from fresh base 9a1732e through dc9ed27. I read every changed source, declaration, documentation, and test diff; traced the guarded descriptor helpers through the CLI parser, IPC worker, opaque descriptor materialization, writer/query/readback paths, proof validation, and surrounding tests; and verified the generated bundle against that source. Commands and results:
Blocking P0/P1 findings: none. The guarded helper keeps descriptor payloads off argv, stdin, environment variables, files, stdout, and stderr; direct invocation without inherited IPC fails closed; request/result digests and the public acknowledgement are cross-checked; writes retain binding, precondition, replay, exact-readback, and receipt checks. Non-blocking follow-up: |
Tracks Todos task b042f78b-bf20-4528-9a18-edf9a40983b7.
Summary:
Verification:
This PR does not merge or publish the package.