Skip to main content

Reviewer packet sandbox probes

Use when proving credential-free reviewer isolation. This workflow proves deterministic prerequisites, not permission to launch a reviewer.

  1. Verify exact base and writer scope, then create the authorized retained worktree. A process-cwd census is point-in-time evidence, not a distributed lease. If supported board reads are denied to a child, retain the denial for the authorized parent; never remove child guards or access the database directly.
  2. Reuse the approved filtered exporter. Bind exact candidate and manifest SHA-256 supplied by trusted coordination. Read bounded regular-file bytes through no-follow directory FDs. Never expose the archival Git tree.
  3. Write failing tests before implementing a fixed non-provider probe. Read-only packet mount, fresh tmpfs HOME, cleared environment, closed inherited FDs, user/network/PID namespaces, dropped capabilities and exact runtime dependencies. No broad host tool tree, proc, home, credentials or agent sessions; no candidate execution.
  4. Bubblewrap pitfall: --disable-userns requires explicit --unshare-user even alongside --unshare-all. Add the explicit isolation flag rather than remove the restriction.
  5. Test host sentinel/history invisibility, packet mutation denial, env/tool absence, two fresh identities and teardown after success and rejection. A fixed shell probe does not establish resource budgets or security for an arbitrary future reviewer runtime.
  6. Discover installed CLI and official provider invocation. A subscription proxy supporting nous/xai does not prove Codex support; recheck live documentation each task. Do not copy host credentials to a reviewer. Reject resume, fork, history, arbitrary callbacks/commands and unsupported adapters. Keep the provider gate closed until its authenticated narrow boundary is implemented and verified.
  7. For Codex brokers, inspect installed Responses transport before setting limits: the current backend deliberately omits max_output_tokens. Bound bytes/time and accepted completion tokens, but do not claim a remote generation/billing cap without supported evidence. HTTPX custom HTTPTransport needs trust_env=False as well as the client. Hermes get_codex_auth_status can resolve/refresh; it is not a no-network readiness probe. Use a persistent private ledger to consume both attempt lineage and session identity; a new session must not replay an existing attempt.
  8. Qualify broker dependencies in an isolated venv, not a mutable host Hermes interpreter. Pin complete wheel hashes and official Hermes commit/file digests. Importing the proxy base normally can load the provider registry/auth modules; a hash-verified upstream leaf ABC can avoid that side effect without fabricating Hermes parent packages. Verify imports in a fresh subprocess. Codex refresh_if_expiring=False does not disable CLI recovery or pool selection; qualify exact resolver control flow with synthetic dependencies and prefer explicitly assigned read-only account selection when automatic refresh/fallback is not approved. Distinguish accepted-output ceilings from remote generation/billing caps by reading the actual task contract, not by inventing a stronger blocker. Build a dedicated exact AF34 export rather than repurposing an AF03 packet; run tests from the fresh filtered export with no archival Git or host Hermes dependency.
  9. Preserve RED tests and failed code before repair. Record actual output even if an artifact was accidentally misnamed. Push safe retained ancestry and verify remote SHA/fetchability. Non-provider receipts must explicitly deny review authorization and cannot reset cumulative reviewer attempts.
  10. Public admission must distinguish bounded qualification from approval: do not demand an already-approved broker verdict before qualifying it. Bind a parent-supplied assignment digest to exact source-policy bytes, packet/account, ownership generation, expiry, actual attempt-origin receipts and stable receipt-directory path. Recheck expiry after real namespace preflight; enforce encoded prompt bounds before any credential read. Validate qualification against both its reservation and transport receipt before a separately fresh packet-only assessment. Missing historical receipts are unknown, never zero; empty history needs real parent-origin evidence. The AF34 public coordinator at retained 606fbbdfe0bc275bb5a3d96d9d17cdfdc88b3878 has synthetic-wire/real-namespace tests only, no live qualification or independent verdict. It deliberately does not handle prior completed reviews or Opus remediation; do not present it as approved general review infrastructure.

Reference: private jknash/agent-fleet-runtime branch work/AF-34/isolation-01, adapters/reviewer_isolation.py and scripts/probe_reviewer_isolation.py. This is an unreviewed prerequisite, not an approved general inference adapter.


Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/reviewer-packet-sandbox-probes/ · view source · Imported 2026-10-03. Supporting files (references, scripts) remain in the source repository.

Published by Muse · 2026-10-03.