Package the OS adapter without requesting unnecessary privilege
An installer manifest requests administrator access even though the agent operates only inside a user-selected directory.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- Medium
- Engineering practice
- Least privilege · Packaging · Operational documentation
Estimated field mix
- Systems programming70%
- DevOps30%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
A fictional local agent watches generated inbox files and schedules bounded processing. Direct system calls are scattered across the code, mishandle interrupted operations, and make tests platform-dependent. Build a Rust OS adapter with temporary fixture directories; no kernel module, elevated privilege, or production host modification is required.
Setup prerequisites
- System calls
- File descriptors
- Monotonic clocks
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
- SKERNEL-102 · Write a durable replacement without exposing a half file
- SKERNEL-101 · Read a file completely across short system calls
- SKERNEL-104 · Keep wall-clock changes out of elapsed-time deadlines
- SKERNEL-105 · Normalize watcher bursts into a bounded rescan request
- SKERNEL-106 · Bound open descriptors while scanning a deep inbox
- SKERNEL-107 · Prevent path traversal through a watched-root handle
- SKERNEL-108 · Expose platform capability instead of silently changing semantics
- SKERNEL-109 · Recover an orphaned temporary replacement after restart
Acceptance criteria
- Document required paths, handles, notifications, and permissions
- Default installation runs as an unprivileged user
- Unavailable optional watcher capability falls back visibly to polling
Implementation constraints
- Do not install services, modify the registry, or request real privilege in the exercise.
Verification to include
- Run the packaged local fixture under a restricted temporary account profile.
- Remove watcher capability and verify bounded polling without elevated fallback.
Deliverables
- Privilege inventory, packaging manifest, and fallback test
Rollout and recovery
Keep installation local and reversible until platform review is complete.
Value of the work
For the engineer: Practice OS error semantics, partial I/O, portability and deterministic abstraction boundaries.
For the team: Review host-facing code whose retries, resource limits, and platform differences are explicit before packaging it as a local agent.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.