Skip to content

Record 4.2.0 host receipts and isolated Codex diagnostics - #105

Merged
mzored merged 2 commits into
mainfrom
audit/420-host-receipts
Sep 5, 2026
Merged

Record 4.2.0 host receipts and isolated Codex diagnostics#105
mzored merged 2 commits into
mainfrom
audit/420-host-receipts

Conversation

@mzored

@mzored mzored commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Follow-up to #104 before tagging v4.2.0.

  • Claude Code 2.1.261: clean install and uninstall of the exact 4.2.0 package (scripts/check_hosts.py --smoke).
  • Codex CLI 0.153.0: exact package installed from the approved Git source into the isolated home, all 17 files byte-identical to the committed package, then removed.
  • Three bounded isolated Codex sessions (evals/receipts/isolated-host-420-20260906/): enable through the skill into a non-empty AGENTS.override.md with one confirmation; ordinary-language delivery loaded from that block, four correct repairs verified at the synthetic origin and passing scripts/grade_catalog.py; disable through the skill. Deviations are recorded in the receipt README.
  • evals/host-smoke.json cells, the dated support summary, SECURITY.md rows, README, site, and the 4.2.0 changelog evidence paragraph now state what the receipts show and nothing more.

python scripts/check.py passes locally, including the receipt privacy gate.

🤖 Generated with Claude Code

mzored and others added 2 commits September 6, 2026 02:57
- Claude Code 2.1.261 clean install and uninstall of the exact 4.2.0 package
  (scripts/check_hosts.py --smoke receipts).
- Codex CLI 0.153.0 exact-package install from the approved Git source into an
  isolated home, byte-checked against the committed package, and removed.
- Three bounded isolated Codex sessions: the skill enabling itself into a
  non-empty AGENTS.override.md after one confirmation, an ordinary-language
  delivery loaded from that block with four correct repairs verified at the
  synthetic origin, and the skill disabling itself. Deviations recorded.
- Ledger cells, dated support summary, security policy rows, README, site, and
  changelog evidence paragraph updated to what the receipts show.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
- Redact the macOS temporary path and the filesystem username from the enable
  receipt; public plugin author metadata stays.
- Quote the host stderr rejection of the session's clone cleanup in the
  destination record and say the retained trace does not hold it.
- Describe the managed configuration output as retained with placeholders.
- Separate the September 5 (4.1.0) and September 6 (4.2.0) diagnostics in the
  security policy.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@mzored
mzored merged commit f684eb2 into main Sep 5, 2026
1 check passed
@mzored
mzored deleted the audit/420-host-receipts branch September 5, 2026 23:05
@mzored mzored mentioned this pull request Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant