Skip to content

docs: qualify parity and document runner and preopen limits - #16

Merged
timonwong merged 2 commits into
mainfrom
docs/qualify-parity-and-preopen-limits
Sep 21, 2026
Merged

timonwong merged 2 commits into
mainfrom
docs/qualify-parity-and-preopen-limits

Conversation

@timonwong

Copy link
Copy Markdown
Member

Summary

Corrects the README's unconditional parity claim and documents the limits a Host needs to know about: the runner blocks with no timeout, cancellation or output limit, and read-only preopen containment can be raced by a concurrent writer.

Changes

  • README.md: parity now holds "given the same args, stdin, environment and visible files" (e.g. SHELLCHECK_OPTS changes output). Usage example disposes the preopen in finally. New paragraphs on the runner's blocking behaviour and on the preopen race.
  • CONTEXT.md: the Parity definition adds "environment", matching the README.
  • src/host-preopen.ts: createReadOnlyPreopen docstring states that the containment check is not atomic with the open, and that dispose() must run even if the run threw. Comment-only change.

Issues

Closes #13, except its last item: a "documentation test" guarding the parity wording is not added; review covers it.

Refs #11. That issue asks for openat-style traversal, which Node's fs API does not offer, so the race cannot be closed in pure JS. The exploit also needs a process rewriting symlinks in the exposed directory while ShellCheck runs. This PR documents the limit so Hosts can decide; ADR 0005 already gives the Host ownership of isolation. I suggest closing #11 as won't-fix once this lands. Your call.

The README promised byte-identical output unconditionally, but the
environment (e.g. SHELLCHECK_OPTS) and visible files change results too;
the glossary definition of Parity omitted the environment as well.

State that the runner blocks with no timeout, cancellation or output
limit, and that preopen containment is checked per call rather than
enforced atomically, so the Host must not expose directories an
untrusted process rewrites during a run. Show dispose() in a finally.
@timonwong
timonwong merged commit 587baff into main Sep 21, 2026
4 checks passed
@timonwong
timonwong deleted the docs/qualify-parity-and-preopen-limits branch September 21, 2026 13:15
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 0.2.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AI-generated] Correct parity and resource-boundary documentation

1 participant