Skip to content

fix: retain complete Daytona verifier evidence - #14

Merged
nmogil merged 1 commit into
mainfrom
fix-daytona-verifier-evidence-paths
Jul 12, 2026
Merged

fix: retain complete Daytona verifier evidence#14
nmogil merged 1 commit into
mainfrom
fix-daytona-verifier-evidence-paths

Conversation

@nmogil

@nmogil nmogil commented Jul 12, 2026

Copy link
Copy Markdown
Contributor

Summary

The first real Harbor-managed Daytona activation found two provider-specific evidence gaps. This fixes both without weakening fail-closed behavior:

  • use Daytona's actual /tests upload paths for trusted workspace capture while preserving Docker's /mogil image paths
  • evaluate verifier assertions against raw bounded streams, then redact hidden-verifier canaries before retaining stdout/stderr
  • strengthen Docker and Daytona regression coverage so no retained run artifact may contain a hidden canary

Real activation evidence

After the fix, the credential-gated fictional calculator run passed end to end through Harbor 0.18.0, Daytona SDK 0.196.0, the digest-pinned Pi 0.80.6 runtime, Anthropic, and a separate no-network hidden verifier:

  • evidence_status: quality_eligible
  • agent: succeeded
  • verifier: passed
  • infrastructure: succeeded
  • provider policy evidence: complete
  • cleanup: confirmed
  • deletion receipts: 2
  • remaining resources: 0
  • retained files scanned: 29
  • credential/canary matches: 0

Verification

  • live Daytona smoke: 1 passed
  • non-Docker suite: 103 passed, 1 gated skip, 1 deselected
  • real Docker smoke: 1 passed
  • Ruff: passed
  • mypy: passed
  • git diff --check: passed

@nmogil
nmogil merged commit 8f68b2a into main Jul 12, 2026
2 checks passed
@nmogil
nmogil deleted the fix-daytona-verifier-evidence-paths branch July 12, 2026 13:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant