The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Arcstone MCP Sidecar listing page.
Repository identity: arcstone-mcp-sidecar
Implementation package: arcstone-execution-boundary
Status: Experimental / Downstream / Non-Canonical / Bounded Evidence
Version: 0.1.0 implementation starter
This repository is the initial native implementation of the frozen Arcstone Execution Boundary v0.1 experimental specification.
It tests one bounded question:
Can a deterministic downstream execution boundary prevent an untrusted or nondeterministic producer from causing a protected side effect unless an explicit, boundary-controlled authorization condition has been satisfied?
The Path A Ingress Lab and Execution Boundary are sibling downstream investigations.
This repository does not modify or reinterpret either frozen upstream repository.
The implementation explicitly keeps separate:
v0.1 does not require or claim:
The experimental root has this shape:
An authorization record is trusted because the untrusted producer is not permitted to create or modify the auth tree under the tested authority configuration. The authorization identifier itself carries no authority.
The consumed/<authorization-id>.claim file is created with create_new(true). That atomic local reservation is the v0.1 single-use claim primitive.
Windows CMD:
or:
Create the runtime directories:
Issue one authorization:
Create request.json:
Execute it:
Inspect authorization state:
A replay of the same request should return a denied result because the claim already exists.
The Rust tests verify deterministic authorization, binding, consumption, replay, failure separation, and concurrent claiming.
They cannot by themselves prove producer-to-resource authority separation when producer and boundary run under the same Windows principal.
A separate bounded Windows authority experiment was therefore completed using distinct non-administrator producer and authority principals and a dedicated disposable runtime with explicit ACL separation.
Observed results:
The successful authorized execution transitioned the tested authorization from Issued to Consumed, created the expected protected effect, and a replay was denied before a second actuation attempt.
This evidence does not establish general Windows sandbox security, arbitrary hostile-code containment, production authorization security, or universal bypass resistance.
See docs/WINDOWS-AUTHORITY-BOUNDARY.md for the complete bounded evidence record and freeze limitations.
This repository is intentionally machine-operable and machine-readable.
Start here:
Recommended automated traversal:
Humans are not required in the deterministic request/decision path. Human-facing prose exists primarily for governance, scientific interpretation, and review.
Evidence before expansion. Preserve the core. Test the boundary. Freeze completed evidence.