Skip to content

[P2] Doctor/Windows: execute the confinement primitive and settlement corpus #299

Description

@wsdt

[P2] Doctor/Windows: execute the confinement primitive and settlement corpus

Review baseline and scope

Reviewed source: c9d32008e98d0e1711f47cb739f61c42376b884e on main, 22 September 2026.
Classification: REAL WINDOWS EXECUTION.
Predecessors: #236.
This replaces their remaining work; closing a predecessor during backlog migration is not a claim that its original scope was completed.

Already delivered — do not rebuild

The host-independent confinement/capsule/refusal tests exist. The latest evidence corrects the older never-compiled claim: Windows Server 2025 job 105948054658 in run 35462242188 compiled the cfg(windows) source at 7cab8aa. That selector executed no doctor::windows_confinement function, so restricted-token/child/job/ACL/settlement behavior is still unproved.

Remaining implementation / execution

  • Use a real explicitly provisioned Windows host to execute the owning restricted-token, child launch, job-object, ACL and settlement tests.
  • Fix any actual native failures and make the selected CI gate require nonzero execution of the relevant runtime functions, not incidental compilation.
  • Retain exact host/toolchain/commit/job evidence and update the Windows support/nonclaim statement.

Acceptance evidence

  • The real Win32 primitives execute under the declared host policy and hostile corpus.
  • Timeout, cancellation, descendants, resource limits, cleanup and handle settlement meet the stated contract.
  • Missing privileges or provisioning are explicit failures/blocks; a cross-compile or zero-function selector is not acceptance.

Boundaries

Do not reimplement the completed host-independent contract or misreport the current source as never compiled. A task description is not an authorization for provider spend, signing, publication, remote deployment or a change to support policy. Preserve existing stable identities, explicit profile limits, source authority and non-vacuous acceptance gates.

Evidence and implementation entry points

  • Issue #236 update
  • Repository entry point: crates/semaprax-native-rust-interop-platform-sys/src/doctor/windows_confinement (review at the pinned revision).
  • Repository entry point: docs/DOCTOR-PRODUCTION-PROVISIONER-WINDOWS-V1.md (review at the pinned revision).

Test results described above are retained repository evidence, not a fresh full test run performed by this backlog review. Re-run the owning gates for the implementation being accepted.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions