Skip to content

Re-Triage the Open Hardening Backlog Against the Trust-Boundary and Design Rules #2517

Description

@ptr727

Problem

#2507 landed "Trust Boundaries and Hardening Effort", and #2516 adds "Design Before Code". Open issues filed before either rule existed still ask for work the rules now decline, and every unattended run that ranks the backlog can pick one up. Carved out of #2516, since closing an issue on judgment is the maintainer's call and the guard's issues are attended-only work.

Clusters to re-triage

Done when

Each issue above has a comment stating its disposition against the two rules, with the reason: close as declined, keep, or fold into a consolidation issue naming every site. The maintainer approves the closes, as one decision over the whole list rather than one per issue.

Related: #2516, #2507, #2431.

🤖 Generated with Claude Code

Activity

  1. added
    decisionA question waiting on the maintainer, alone or beside whatever else the issue carries
    on Oct 8, 2026
  2. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Maintainer's answer, given in the windows lane's closing session: run this triage in an attended session of its own. That session writes a disposition comment on each issue named here, then brings the whole list back for one approval. #2495 stays parked until then. The decision label stays on until that approval is given.

  3. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Drafted dispositions, awaiting the maintainer's approval

    Drafted by a read-only pass against "Trust Boundaries and Hardening Effort" and #2516's reuse rule. Nothing has been closed. The maintainer approves the closes as one decision.

    Close, declined with the reason given (25):

    Issue Reason
    #2399 A reviewer bot does not post thousands of unclosed <summary openers, and GitHub's 65536-character cap holds the measured worst case to about 2s of slowness, not a silent failure.
    #2414 A bot overview does not hide a </details> in an HTML comment, and the issue says it fails loudly.
    #2416 No measured reviewer posts an unclosed blockquoted <details opener, and the issue says it blocks nothing.
    #2438 - #2440, #2442 - #2451 The guard is a backstop against an agent's own mistakes, and each shape (an empty eval prefix, a trailing backslash beside a loop, time -p -p eval, a command of 109 KB to 330 KB, and the rest) is not one an agent session writes. Where the guard misses one, the result is a loud hang or a false deny.
    #2495 -Dir is typed by the maintainer, C:\x\.. is not a realistic typo, and the ownership marker bounds the damage.
    #1044 The maintainer's own .agents/skills tree, where an unreadable nested directory does not realistically occur.
    #1130 GH_WRITE_GUARD_ALLOW_PRIMARY_CHECKOUT is set by the maintainer, so being session-wide is a documented property.
    #1420 --exclude is typed by the maintainer, and the scope line prints the file counts, so an empty scan is visible.
    #1618 Hardens a test that guards a scanner against an input nothing produces.
    #1764 Already landed: host-setup/bootstrap.ps1 on develop takes a lock (Get-LockPath), from e853b3a.
    #1765 A bracketed -Dir is typed by the maintainer and fails loudly.
    #1869 Needs a corrupt git index, and the cost is a wrong dirty flag in that corner case.
    #2013 The issue says no fleet caller writes either shape.

    Consolidate: #2479 into #2480, one recognizer for Copilot's collapsible overview blocks.

    Keep: #1404, #1628, #1637, #1657, #2163, #1071, #1425, #2282, and #2480 are bugs on the ordinary path or silent failures in the real deployment. #1127 needs the maintainer's judgment on whether a deliberate -c core.hooksPath bypass is a mistake the guard must stop.

    Not yet read: about 45 more guard issues in the same family as #2438 - #2451, and #2441 itself, were judged from their titles only, so they get a read of their own before any disposition.

  4. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    First batch applied, second batch drafted

    Applied, approved by the maintainer. The 25 closes above are closed, each with its reason. #2479 is folded into #2480. #1127 is kept: the guard should stop a deliberate hook bypass.

    Second batch, drafted from a full read of the 42 guard-family issues. Nothing here is applied yet.

  5. ptr727 commented on Oct 8, 2026

    @ptr727
    OwnerAuthor

    Second batch applied, approved by the maintainer: 25 closed (all drafted closes except #2200), 12 folded into #1959, and #1959, #2177, #1090, and #2200 kept. The re-triage is complete, so this issue closes.

  6. removed
    decisionA question waiting on the maintainer, alone or beside whatever else the issue carries
    on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions