Skip to content

fix: reject unresolved image references and verify native settings - #73

Draft
TheRealBecks wants to merge 7 commits into
mainfrom
TheRealBecks/issue39-integrated
Draft

TheRealBecks wants to merge 7 commits into
mainfrom
TheRealBecks/issue39-integrated

Conversation

@TheRealBecks

@TheRealBecks TheRealBecks commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Closes #39 only after fresh exact-candidate native gates and independent evidence
review pass. Parents #3/#30/#31 and BoxFerry #343/#366 remain open. Draft status
is intentional: offline success is not native compatibility or release readiness.

Integrated scope

Preserve the original PR #50 and #73 checkpoints/dirty checkout while integrating
current main's PID1 identity (#74/#75) and strict cleanup presence (#76/#77).
The separate final checkout is /tmp/dockerlens-issue39-final-integration;
reviewed head ee16951c775b73ab8cecc7ed7b95c104586c40aa is a fast-forward of the
previous published candidate, not an overwrite.

Retain all eleven mandatory native tests: original checks, container settings,
volume labels and PID1 identity. Preserve both independent proof groups and
exact candidate/run/image/mode/API bindings in the reconciled evidence emitter.
Private captured-output handling, fail-closed presence, cleanup and budgets stay.

Resource effect reads now authenticate full owned identity/private PID namespace,
PID1/helper placement, active cgroup mount-parent topology and stable before/after
placement. Reject shadowed, ambiguous, cyclic, missing-parent or unowned evidence.
Both finite assertions and unlimited baselines resolve the actual leaf rather than
assuming a fixed cgroup root. Strict memory/PID values, START failures, unknown
enforcement and the genuine failed no-swap result remain unchanged.

The narrow product correction rejects unresolved image references before planning;
registry-port/digest/image-ID forms and the existing Unreleased note are retained.
No catalogue capability or historical observation is admitted or rewritten.

Verification

  • Independent original-requirements, native-expectation, lifecycle/privacy and
    final integration reviews cleared the frozen source with stated limits.
  • Final canonical format/lint and complete gate passed: Rust/MSRV/Clippy/unit,
    public/doc/Rustdoc and 257 Python tests, wrapper exit 0. Log
    /tmp/dl39-integrated-final-gate-20261005.log.
  • Final standalone mock suites also passed: harness 91, emitter 26 and minimal
    startup diagnostics 18. Post-format review proved the sole formatting change
    was test-module ordering. Exact owned runner lifecycle and silent ID/name absence
    were authenticated; original dirty checkpoint remains untouched.
  • Fresh trusted-main exact-head native dispatcher, all four independent
    Debian11/upstream rootful/rootless lanes, all eleven required checks each.
  • Independent authentic candidate/archive/digest/outcome/cleanup review.
  • All PR checks and immediate exact-head readiness before a normal merge.

Historical failed native run 37233669686 remains immutable; this mapping
correction does not establish its startup cause or turn failed cleanup into proof.
No unchanged native retry, host repair or stress-threshold relaxation occurred.

Shared consumers / Renovate

No operational pin, dependency, manifest/lockfile, workflow/action or canonical
extraction location changed. Existing native image/Engine/package/BusyBox managers,
grouping and approvals remain authoritative; no Renovate edit is needed. Other
Lens products/website do not consume this Docker-specific harness. BoxFerry has
its own application consumer gate; Lens products never depend on BoxFerry.

No release, release-PR merge, publication, deployment, Windows support or macOS
runner work is authorized or claimed.

@TheRealBecks
TheRealBecks force-pushed the TheRealBecks/issue39-integrated branch from cb58aee to f2e16ac Compare October 4, 2026 16:51
@TheRealBecks TheRealBecks changed the title Integrate independent typed-container native proof harness fix: reject unresolved image references and verify native settings Oct 4, 2026
@TheRealBecks
TheRealBecks marked this pull request as draft October 4, 2026 17:11
@TheRealBecks

Copy link
Copy Markdown
Member Author

Fresh trusted native run 37218370132 failed for exact candidate f2e16ac0c5936f42c3e147717f5094272fd51257. This PR must not merge; marking it draft while diagnosis proceeds.

Independent log review found tests 1–8 passed in every lane, the container-settings test failed, and the tenth label test never ran. Rootful memory-only START controls returned HTTP500 with bounded cgroup/controller diagnostics. Rootless renamed-device controls returned Debian500/upstream400 with bounded ENOENT/device diagnostics; same-path controls started. These controls do not establish causality or resolve Containers #344.

Debian rootless subsequently timed out in repeated-dynamic IPv4 START and explicitly reported unverified inner ports cleanup. The other three reported successful final inner cleanup. Outer teardown had no logged error, but there is no explicit positive outer-inventory record, so blanket cleanup success is not claimed. No native artifacts were uploaded.

Offline gate/source review remains recorded, but cannot substitute for native acceptance. No unchanged retry, host repair, lane substitution or gate weakening is authorized. Logs preserved at /tmp/dockerlens73-failure-review.pPmy8g/run.log; parent/coordinator checklist tracks the pending diagnosis.

@TheRealBecks

Copy link
Copy Markdown
Member Author

Diagnostic-only follow-up at current head 12ab538a30ea896ea9a18f6f4cc650e0ba7f3f1d adds closed configured-versus-read memory/PID categories to the already-failed resource control matrix. All records explicitly retain enforcement=unknown; START204, matching limits or visible controller flags cannot establish enforcement. Strict native START/effect/cleanup assertions and outcome/emitter/catalogue inputs are unchanged. Canonical lane-account documentation is corrected.

Independent four-file source review cleared the final SHA-256 freeze. Primary canonical format/lint and complete offline gate passed, including 235 Python tests and both new pure Rust regressions. Logs: /tmp/dockerlens39-diagnostics-format-20261004.log, /tmp/dockerlens39-diagnostics-complete-20261004.log. All local/main/reviewed-dispatch/release consumers use the same exact-test wrapper. No operational pins or Renovate extraction/ownership changed; canonical five-pin ownership regressions passed.

The PR remains draft and merge-blocked. Run37218370132 belongs to predecessor f2e16ac... and failed; it is not evidence for this new head. Rootful fixture delegation, rootless renamed-device proof and Debian-rootless dynamic-port timeout/cleanup remain unresolved. No new native run, host repair or release readiness is claimed.

@TheRealBecks

TheRealBecks commented Oct 5, 2026 •

Copy link
Copy Markdown
Member Author

Diagnostic checkpoint for #39 (not capability admission or release readiness).

  • Reviewed candidate: 388e416f626026cd0d4654bb22a6e4020b689143, fast-forwarded onto this existing draft PR. The original dirty integration checkpoint remains untouched.
  • The four-file change retains each failed group's first closed checkpoint and the original resource-oracle START status before supplemental controls. The exact runner rejects missing, duplicate, malformed, inconsistent or success-forged failure records without exposing private values.
  • Independent final source review passed. Canonical format/lint and complete gate passed, including 264 Python contracts plus Rust/MSRV/unit/doc checks, in /tmp/dl39-first-failure-gate-20261005.log. Reviewed hashes remain unchanged. Exact gate runner removal/absence authenticated.
  • Fresh trusted-main validation: https://github.com/Strukturpiloten/docker-lens/actions/runs/37246772132 / attempt 1. Admission and complete offline gate passed; all four native lanes and the fail-closed aggregate failed. Every lane passed checks 1–8, then failed container check 9; volume-label check 10 and PID1-identity check 11 did not execute, and all artifact uploads were skipped. The workflow's own head is trusted main; candidate jobs separately verified the supplied PR head.
  • All eleven mandatory native tests, strict resource/device/START assertions, cleanup decisions, proof inputs, five image pins and capability catalogue are unchanged. Independent shared-consumer/Renovate audit found no changed extraction ownership or external consumer.

Earlier run 37242621463 remains failed evidence. This is a changed diagnostic candidate, not an unchanged retry. No unsupported reclassification, relaxed assertion, host repair, merge, publication or release is performed. This PR remains draft until genuine native acceptance and downstream rehearsal are independently established.

Independently reviewed failure evidence

The new diagnostic contract was exercised: all four original resource START failures remained their groups' first checkpoints (500 for both Debian modes and upstream rootful; 400 for upstream rootless). Later controls never replaced those failed positives. Rootful memory-only START remains rejected; rootless renamed-device START remains rejected despite same-path success. Resource enforcement and underlying causes remain unknown.

Debian rootless separately retains its later port timeout and unverified inner cleanup. The other three lanes report final successful inner readback; generic outer warnings are not independently authenticated outer-absence proof. Private run/job/log evidence is retained at /tmp/dockerlens73-native-388e416.F6WdJLOy; raw runtime output is not published. Source and independent log review found no new diagnostic-contract defect. No unchanged rerun or capability admission is authorized by these results; separately verified fixture/runtime prerequisites remain necessary.

@TheRealBecks

Copy link
Copy Markdown
Member Author

Diagnostic-only continuation at exact head 7345ea3c529e6b85aaa558b6fbf403f00af11da2; PR73 remains draft. No native compatibility, admission, merge or release claim.

The previous 388e416 run's original numeric START statuses are intact, but its generic body categories were selected after controls and cannot reliably be attributed to the original rejection. This amendment emits a dedicated original-oracle, status-bound closed body classification directly from the already-returned protected response, before inspect/controls. It adds no request, raw error text, private path/ID or causal inference and leaves every assertion/control/cleanup/admission rule unchanged. Strict regressions reject missing, malformed, duplicate, misordered, status/group-inconsistent and success-forged records; deliberately different original/later messages stay distinct.

Independent source and post-format reviews passed. Canonical format/lint and complete gate passed: Rust/MSRV/unit/doc checks and all265 Python contracts. Private gate log /tmp/dl39-oracle-body-gate-20261005.log, SHA256 6b462f97588edb17d32effba0f0ef55b4dee51c7171feb5288d38c5e570de4dc. Exact task runner create/exit-zero/remove events and fresh ID/name absence were independently authenticated; event evidence /tmp/dl39-oracle-body-runner-events-20261005.jsonl. Final four-file diff SHA256 8d22a5769715c84ac09e5ef97842aaeb15b5f249daa2e22a19e4d40ac3a73b3f; all other source/pins and the original dirty checkpoint are preserved.

The old failed native run is not validation of this new candidate. One new exact-head validation-only acquisition may exercise the corrected original-response diagnostics under the unchanged four-lane contract; it is not an unchanged retry, fixture repair or release run. Preserve every failed result and do not repeat the same failed head, weaken assertions, substitute control success, infer unsupported modes or request publication. Actual resource failure causes/enforcement and later volume/PID1 checks remain unestablished pending genuine evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prove typed container settings on exact native Engine profiles

1 participant