Skip to content

docs(hook-budget): Windows kernel Token leak host defect (#4372) - #5136

Merged
cursor[bot] merged 3 commits into
mainfrom
cursor/4372-token-leak-host-defect-37e9
Sep 28, 2026
Merged

cursor[bot] merged 3 commits into
mainfrom
cursor/4372-token-leak-host-defect-37e9

Conversation

@kyle-sexton

Copy link
Copy Markdown
Contributor

Summary

Closes #4372.

Records the Windows kernel Token leak as an allowed host-defect exception on the hook-budget convention (Claim / Basis / As of 2026-09-28 / Recheck: Windows build > 26200.9550 or Microsoft acknowledgement). token-leak-amplification.sh checks the #4372 rows against one leaked token per child-creating process. This is not a park ledger.

Test plan

  • token-leak-amplification.test.sh (15 passed)
Open in Web Open in Cursor 

A host-defect record with claim, basis, as-of date, and a recheck on a Windows
build greater than 26200.9550 or a Microsoft acknowledgement. The probe checks
the published one-token-per-child-creating-process rows.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

PR body contract — issue linkage

This PR body does not yet satisfy the issue-linkage contract:

  • Missing a "## Fix" section. State the concrete change and how it addresses the problem.
  • Missing a "## Verification" section. Record concrete evidence the change works (commands, gates, output).
  • Missing a "## Related" section. List related PRs, ADRs, or decision-log entries this PR does not close.

Edit the body and this comment updates itself on the next run.

cursoragent and others added 2 commits September 28, 2026 09:13
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot marked this pull request as ready for review September 28, 2026 09:26
@cursor
cursor Bot merged commit 8d57cae into main Sep 28, 2026
31 checks passed
@cursor
cursor Bot deleted the cursor/4372-token-leak-host-defect-37e9 branch September 28, 2026 09:35
kyle-sexton added a commit that referenced this pull request Sep 29, 2026
…correct convention text (#5313)

No related issue: audit remediation; no issue is closed by this PR

## Summary

An unattended Cursor run edited `docs/conventions/` and took decisions
that belong to the owner, stated false facts in the config-cascade
tables, left conversational residue and parked records in several
conventions, and left one fleet-wide rule contradicting its own measured
record. This branch removes the agent rulings, corrects the text, and
changes nothing outside `docs/conventions/`. No decision is implemented
in place of the removed ones; each goes to the owner in a decision
packet posted on its issue. No plugin version bump and no plugin
CHANGELOG entry.

## Fix

Look at these first:

- **T13, plugin-reconfiguration caveat 2.** A fleet-wide rule corrected
against the doc's own measured record ("pass the scope `claude plugin
list` reports", not a blanket `-s user`). `main` now carries the same
rule from #5267; the merge kept main's wording and this branch's drop of
the origin aside. It sits on an issue this group does not own (#3356, no
needs-human label; both edits came from unattended PRs).
- **T11 step 3, skill-argument-shape.** Restores the owner-merged #4768
wording to the text of the owner's issue.
- **T1 and T2, agent rulings removed.** T1 restores hook-telemetry to
baseline 7acaf08 (the "park schema validation" ruling for #3410). T2
removes the #3577 location-outlier rulings and the glance-table rows
that mirror them, including the two unsourced rationales for keeping the
songwriting and recurring-schedule files in place. No replacement option
is written.
- **T9, loop-lane.** The background-job launch-mode paragraph now points
at the work-items work-loop skill paragraph instead of restating it.
- **Merge order.** T13 is already on main. T14 (detector-findings
crosswalk) goes with claude-config's T2. T9 goes after work-items
rewrites its SKILL.md paragraph. T10 (invocation-mode ledger pointer)
goes with decisions-docs' ledger deletion.

Other edits: config-cascade glance-table facts, consumer-gotchas
rationale and single local form, shell-test-helpers wording, hook-budget
(host-defect section reduced to a pointer, tautological token-leak probe
deleted, exec-form cost, prerequisite, failure behavior and measurement
slot stated), rendered-views parked record dropped, hook-precision and
hook-observability records reduced to pointers, permission-rule-hygiene
house position, native-references Adopters row, topic-docs "no config
persisted" wording.

Cross-group requests applied (all in `docs/conventions/`):

- core-docs: rendered-views parked userConfig smoke record removed
(#3604 holds the gate); the #3574 packet is linked from the #3573, #3575
and #3577 packets.
- work-items: loop-lane background-job paragraph is a pointer to the
work-loop skill paragraph by blob URL, "foreground is the only mode"
removed, CHANGELOG 9.3.1 corrects the 9.3.0 claim (#4598 stays with the
owner).
- playbooks: skill-argument-shape earned-flag ground 2 restored to
"destructive, such as `--execute` or `--force`" (#4001).
- claude-ops: the hint notation legend lives only in argument-hint;
#4372 reopened with the operator steps (#5136 stays Refs-only).
- hook-launcher: hook-budget exec-form section states k = 2 for a
bash-scripted row behind the node launcher, the node prerequisite, the
failure behavior, the scope of "no shell-form row remains", and a marked
slot for the paired measurement on #3686.
- bugs: consumer-gotchas plugin-cache rationale corrected and the
dedicated `gotchas.md` form removed (#3547).
- ci: token-leak probe and test deleted (#4372, no CI step wired);
origin aside dropped from plugin-reconfiguration; the #3577 revert
leaves no unsourced rationale behind.
- decisions-docs and session-flow: invocation-mode ledger pointer and
the "skipped (map / pixel / Fable)" paragraph removed; topic-docs says
"no config persisted".
- testing: native-references `/testing:run-e2e` Adopters row updated.
- context-budget: hook-precision Platform gap restates no probe and
points at the context-budget README and #3680; caveat 2 agrees with its
measured record.
- claude-config and review: detector-findings crosswalk rows I31, I32,
I33 follow criteria.md; CHANGELOG 3.3.0 corrects the 3.1.3 output claim
(Rule 2 unchanged).
- guardrails: decision packet filed as #5324, no edit.
- attribution: the 14 `make_sink()` pointer comments are a consequence
of Option 2, carried in the #3412 packet, no edit.
- event-storming: the argument-hint budget versus a 10-member closed
enum is an owner decision, recorded on #3542, no edit.

## Verification

Run at the branch tip in the worktree after merging `origin/main`, all
exit 0:

- `bash scripts/check-purged-em-dashes.sh --check`: 1289 files scanned,
no em dashes.
- `bash scripts/check-docs-naming.sh --check`: every tracked file under
docs/ is lower-kebab-case.
- `python3 scripts/check-contract-clause-coverage.py`: passed.
- `bash scripts/check-loop-lane-floor-drift.sh --check`: 6 consumers
match, no unregistered copy.
- `bash scripts/check-detector-findings-crosswalk.sh --check`: 38 rows
OK.
- `bash scripts/check-changelog-parity.sh --check --check-order`:
passed.
- `git diff --name-only origin/main...HEAD` lists only
`docs/conventions/` paths.
- `git diff 7acaf08 -- docs/conventions/hook-telemetry` is empty; no
"Option A" or "parked" text remains in hook-telemetry or config-cascade.

## Related

Refs #3410 #3412 #3549 #3573 #3575 #3577 #3603 #3604 #4287 #4372 #3547
#3615 #3680 #4598 #4661 #4657 #4001 #3542 #3356 #4116 #4656 #4267 #3686
#3708 #4828 #5324

#3356 and #4001 are already closed and stay closed; #4828 is a merged
PR. #5324 is a new decision packet for the owner (hook-observability
carve-out condition 3), filed for the guardrails group's request on
#4679, which the guardrails group owns.

Audit findings by issue number are in `.work/audit/REPORT.md` (action
tables 3a to 3e).

Cross-group requests received: 26, from core-docs, work-items,
markdown-format, playbooks, hook-launcher, bugs, go-format, ci,
event-storming, repo-fleet-hygiene, actionlint, decisions-docs, testing,
planning, source-control, guardrails, claude-ops, session-flow,
context-budget, attribution, claude-config, review and biome-format.

Requests not edited here:

- repo-fleet-hygiene, a `repo-fleet-hygiene:sync` row (KEEP `true`) in
the invocation-mode fleet grade: the table is a dated grade
(2026-08-17), and a KEEP row would encode a ratification of the sync
verb while #3992 (ratify or park it) is open. A one-row edit after the
owner rules on #3992.
- source-control, config-cascade Implementers adopter row for
`lib/config-root.sh`: the file is not on main, and the table states
conformance as it exists on main. A one-row edit after that PR merges;
whether to sync a fleet-wide copy is the owner's call (#4671).
- biome-format, invocation-mode rubric class (ii): held by the requester
until the owner answers #4240 Q2.
- actionlint, hook-precision Rule 6 conformance record: waits for the
owner's #4671 decision. The dim-9 row in
`docs/conformance-dimensions.md` is outside `docs/conventions/` and sits
with core-docs.
- markdown-format (a): `eol-normalizer` and `go-format` setup skills
still say "Do not copy a scope from `claude plugin list`" on main; each
owning group's plugin PR fixes its own skill. (b): a fixed cluster-sync
CHANGELOG line is a repo-wide doctrine call for the owner; no convention
owns plugin CHANGELOG wording.
- go-format: `scripts/sync-plugin-options-docs.py` already emits "pass
the scope `claude plugin list` reports" on main and a run rewrites no
README, so there is nothing to regenerate.
- context-budget, the probe-log note that #5057 narrowed the 0.6.32
guidance: not added; origin and history stay in git.
- planning: its setup skill and README already carry the short form the
convention prescribes, so no sweep is needed.

Every owner-reserved question above stays with the owner; decision
packets and operator steps are posted on the issues.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01EugXnFddtpHcY5gTuyEirB

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

perf(host): Windows kernel Token leak, one per child-creating process, amplified by hook and Bash fan-out (melo-lap-001, melo-desk-001)

2 participants