f/hold docs

Managed harness policy verification

Initial branch qualification

Local Linux x64 verification on 2026-10-04, branch codex/managed-harness-policy, based on public main c6c5487. This is a development change, not a published release or GitHub CI result.

The local image is fhold/assistant:managed-policy-20261004. The final startup and restart smoke used image ID sha256:d6de8f2298fbaf33b08e0a9bba2355eda39a1c2b75d3312a93742f09918a4ebf. The permission, recovery and keep-alive checks also passed for this runtime implementation; the final image refresh changed only bundled setup guidance.

Passed checks

Host tests used Bun 1.4.1 and real Node 24.19.0. Image tests verified its pinned Bun 1.4.2 and native harness versions (OpenCode 1.18.34, Codex 0.160.0, Claude Code 2.1.289). The host's Bun-backed node shim was excluded from tests that require real Node; the product image already supplies real Node.

These tests use disposable instances and synthetic account data. They prove native loading, permissions, recovery and local activity signaling without claiming real account sign-in, provider/model responses, remote-client pairing, Azure scaling behavior, ARM64 execution or a release vulnerability scan. No live deployment, published image or vendor-specific provisioner was changed.

Integration review against main

The branch was reviewed against main 61ebba7 on 2026-10-04, preserving the single --name/-n instance selector. The review retained native managed files and standard plugin installation; no vendor patches, cloud adapters, startup installs or alternative permission store were added.

Review changes and checks:

Host checks used Bun 1.4.2 and Node 24.18.0: type/lint checks, CLI/Admin builds, 523 passing suite tests with socket cases enabled, and all four native-history tests separately. The two conditional history cases in the suite are included in that separate image-backed run. All Compose profiles and shell syntax passed.

fhold/assistant:policy-review-20261004 passed the full startup/security/harness smoke and the compiled-CLI installation. Its final local image identity was sha256:a4501ef371c02abf1ef7ad1ab16a8ad7e469cd5dc0a4ef4275e5776865477dba. The native-policy, ephemeral-recovery, history and real keep-alive tests passed against the same runtime filesystem; the final rebuild added only the capability label. Keep-alive produced two requests during active work and none while idle.

This remains local, credential-free qualification, not a new release or a claim of live provider authentication, remote pairing, cloud scaling or ARM64 execution. The reusable GitHub gates also run the native-policy smoke for each architecture.