Skip to content

Bound Iris token-required launches to controller TTL#49

Merged
penfever merged 2 commits into
penfever/workingfrom
penfever/capability-token-duration-guard
Jul 23, 2026
Merged

Bound Iris token-required launches to controller TTL#49
penfever merged 2 commits into
penfever/workingfrom
penfever/capability-token-duration-guard

Conversation

@penfever

Copy link
Copy Markdown
Collaborator

Implements the capability-token duration guard.

  • Read the controller maximum from Marin/Iris source at runtime; do not duplicate the limit.
  • Default token-required datagen/eval jobs to a bounded Iris timeout and reject unsafe explicit values.
  • Keep terminus-2 unlimited and controller-token-free.
  • Persist a secret-free policy manifest locally and with the task environment.
  • Apply the same policy to the external federated OpenCode eval wrapper.

Tests: pytest tests/hpc/test_capability_token_duration.py tests/iris/test_launch_external_opencode_eval.py tests/hpc/test_resume_determinism.py tests/hpc/test_iris_launcher_args.py (32 passed).

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@penfever
penfever force-pushed the penfever/capability-token-duration-guard branch from 85be945 to b5e4d8a Compare July 23, 2026 12:40
@penfever
penfever merged commit 699b5fc into penfever/working Jul 23, 2026
2 checks passed
@penfever
penfever deleted the penfever/capability-token-duration-guard branch July 23, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant