Skip to content

docs: preserve falsifiable ExecSurface CI stdout privacy boundary - #169

Draft
hippoley wants to merge 3 commits into
mainfrom
docs/execsurface-privacy-boundary-repro
Draft

hippoley wants to merge 3 commits into
mainfrom
docs/execsurface-privacy-boundary-repro

Conversation

@hippoley

@hippoley hippoley commented Oct 8, 2026

Copy link
Copy Markdown
Owner

Why

ExecSurface #164 records a successful first zero-assistance trial plus a separate CI-log privacy concern. The upstream trial harness currently inherits stdout/stderr for its observe subprocess, unlike its helper run_text. This makes inspect-before-sharing insufficient for path-bearing bytes printed during observation.

What

  • Pin the exact source-level boundary and an independently runnable synthetic subprocess reproduction.
  • Specify a bounded regression contract for stream containment without changing evidence semantics or qualification state.
  • Keep explicit non-claims: this is not an upstream fix, not an executed ExecSurface regression, and not an externally qualified trial.

External intake: AETHERXGLOBAL/execsurface#164

Next verification

Run the synthetic probe and seek upstream owner confirmation before proposing a producer-side patch. Do not publish raw typed-evidence streams.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant