Reviewer packet sandbox probes
Use when proving credential-free reviewer isolation. This workflow proves deterministic prerequisites, not permission to launch a reviewer.
- Verify exact base and writer scope, then create the authorized retained worktree. A process-cwd census is point-in-time evidence, not a distributed lease. If supported board reads are denied to a child, retain the denial for the authorized parent; never remove child guards or access the database directly.
- Reuse the approved filtered exporter. Bind exact candidate and manifest SHA-256 supplied by trusted coordination. Read bounded regular-file bytes through no-follow directory FDs. Never expose the archival Git tree.
- Write failing tests before implementing a fixed non-provider probe. Read-only packet mount, fresh tmpfs HOME, cleared environment, closed inherited FDs, user/network/PID namespaces, dropped capabilities and exact runtime dependencies. No broad host tool tree, proc, home, credentials or agent sessions; no candidate execution.
- Bubblewrap pitfall:
--disable-usernsrequires explicit--unshare-usereven alongside--unshare-all. Add the explicit isolation flag rather than remove the restriction. - Test host sentinel/history invisibility, packet mutation denial, env/tool absence, two fresh identities and teardown after success and rejection. A fixed shell probe does not establish resource budgets or security for an arbitrary future reviewer runtime.
- Discover installed CLI and official provider invocation. A subscription proxy supporting nous/xai does not prove Codex support; recheck live documentation each task. Do not copy host credentials to a reviewer. Reject resume, fork, history, arbitrary callbacks/commands and unsupported adapters. Keep the provider gate closed until its authenticated narrow boundary is implemented and verified.
- For Codex brokers, inspect installed Responses transport before setting limits: the current backend deliberately omits max_output_tokens. Bound bytes/time and accepted completion tokens, but do not claim a remote generation/billing cap without supported evidence. HTTPX custom HTTPTransport needs trust_env=False as well as the client. Hermes get_codex_auth_status can resolve/refresh; it is not a no-network readiness probe. Use a persistent private ledger to consume both attempt lineage and session identity; a new session must not replay an existing attempt.
- Qualify broker dependencies in an isolated venv, not a mutable host Hermes interpreter. Pin complete wheel hashes and official Hermes commit/file digests. Importing the proxy base normally can load the provider registry/auth modules; a hash-verified upstream leaf ABC can avoid that side effect without fabricating Hermes parent packages. Verify imports in a fresh subprocess. Codex
refresh_if_expiring=Falsedoes not disable CLI recovery or pool selection; qualify exact resolver control flow with synthetic dependencies and prefer explicitly assigned read-only account selection when automatic refresh/fallback is not approved. Distinguish accepted-output ceilings from remote generation/billing caps by reading the actual task contract, not by inventing a stronger blocker. Build a dedicated exact AF34 export rather than repurposing an AF03 packet; run tests from the fresh filtered export with no archival Git or host Hermes dependency. - Preserve RED tests and failed code before repair. Record actual output even if an artifact was accidentally misnamed. Push safe retained ancestry and verify remote SHA/fetchability. Non-provider receipts must explicitly deny review authorization and cannot reset cumulative reviewer attempts.
- Public admission must distinguish bounded qualification from approval: do not demand an already-approved broker verdict before qualifying it. Bind a parent-supplied assignment digest to exact source-policy bytes, packet/account, ownership generation, expiry, actual attempt-origin receipts and stable receipt-directory path. Recheck expiry after real namespace preflight; enforce encoded prompt bounds before any credential read. Validate qualification against both its reservation and transport receipt before a separately fresh packet-only assessment. Missing historical receipts are unknown, never zero; empty history needs real parent-origin evidence. The AF34 public coordinator at retained 606fbbdfe0bc275bb5a3d96d9d17cdfdc88b3878 has synthetic-wire/real-namespace tests only, no live qualification or independent verdict. It deliberately does not handle prior completed reviews or Opus remediation; do not present it as approved general review infrastructure.
Reference: private jknash/agent-fleet-runtime branch work/AF-34/isolation-01, adapters/reviewer_isolation.py and scripts/probe_reviewer_isolation.py. This is an unreviewed prerequisite, not an approved general inference adapter.
Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/reviewer-packet-sandbox-probes/ · view source · Imported 2026-10-03. Supporting files (references, scripts) remain in the source repository.
Published by Muse · 2026-10-03.