Skip to content

docs(research): close Windows containment unknowns by live experiment (#258) - #264

Merged
Sandstorm831 merged 1 commit into
mainfrom
research/258-windows-containment-followup
Sep 29, 2026
Merged

Sandstorm831 merged 1 commit into
mainfrom
research/258-windows-containment-followup

Conversation

@Sandstorm831

Copy link
Copy Markdown
Collaborator

Follow-up research for Establish how Secant can contain a Harness's descendant processes on Windows. It updates docs/research/windows-process-containment.md in place, closing its Still Unknown list by live experiment on Windows 11 with Claude Code 2.1.283 and codex-cli 0.155.0.

  • Codex's Windows sandbox. Git Bash can't run in it, an outer job still contains a sandboxed command, and turn/interrupt still leaves the command running.
  • Codex PTY mode. The kill comes from the pseudoconsole closing, not the job.
  • Job chains and the gap. It maps the job chains, and measures the assign-after-spawn gap as never populated (0 of 20 runs per Harness).
  • Git Bash cases. More cases are recorded, and CLAUDE_CODE_GIT_BASH_PATH doesn't change the escape.
  • Claude Code's interrupt. A raw interrupt still runs taskkill /T /F.
  • Detached processes. A no-breakaway job kills them, and CREATE_BREAKAWAY_FROM_JOB fails with error 5 inside it.
  • A contained spawn with streamed stdio. It uses bun:ffi CreateProcessW with PROC_THREAD_ATTRIBUTE_JOB_LIST, with stdio carried over node:net named pipes. Live Claude Code and Codex were contained 3 of 3 each, and so was a parent crash.

Facts only. The choice belongs to Decide how Secant contains a Harness's descendant processes on Windows. Merge with a merge commit (not squash or rebase) so the pinned links in the resolution comments survive.

🤖 Generated with Claude Code

@Sandstorm831
Sandstorm831 merged commit 31e8f9e into main Sep 29, 2026
26 of 27 checks passed
@Sandstorm831
Sandstorm831 deleted the research/258-windows-containment-followup branch September 29, 2026 12:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant