Chapter 2.3 follows chapter 2.2, The cell pipeline from staging to scoring, and precedes chapter 2.4, The maintenance prompt and its versions, within part 2, the harness.
A container, a sealed execution environment, holds each measured cell. An image digest, a unique identifier for the exact image layers, fixes the software used by every cell. The image is admitted only when its recorded digest matches the built image. The container separates the agent workspace from the host and from hidden checks.
2.3.1 Image construction and verification
The harness, the program that assembles and checks the execution environment, builds the image from the container Dockerfile. build_image.sh copies requirements.lock into the build and installs its pinned packages. The image also contains the Claude Code command-line interface (CLI) and the tools needed for the visible tests. codex-dgx-spark.config.toml.template supplies the container configuration, and dgx_connectivity_probe.py checks the permitted connection path. The build record is image_digest.txt.
The image identifier is sha256:3b2cd06ca2889dbed4894d44b7219528571c9051f7ecd630f878b6788a53bcae and the Claude Code version is 2.1.220.
source: 1. Harness/container/image_digest.txt line 1
source: 1. Harness/container/image_digest.txt line 3
An admission gate, a check that permits a cell to run only after the recorded image and its build inputs agree, checks the image digest. A waiver, a recorded exception to that gate, cannot make a cell equivalent to a cell that ran under the verified image. The harness documentation describes this check and its restrictions.
2.3.2 Access restrictions of the measurement harness
The container denies the agent access to the host file system, the network, hidden checks, experiment logs, and the corpus. It permits the allowed application programming interface (API) path and the visible tests. It denies the agent a shell, so the agent cannot run arbitrary commands such as ls or cat.
Shell availability, the presence or absence of an agent shell, is recorded in the matrix column shell_available. The matrix column agent_ran records whether the agent ran code. A shell denial prevented ordinary maintenance and inspection commands. This restriction was the isolation contract in force for the affected cells.
2.3.3 Isolation census of the measurement harness
A census, a count used to check whether the isolation held, compared cells run before container admission with cells run inside the container. The contamination census found 49 cells before the container, of which 39, or 80 percent, were contaminated, and 86 containerized cells, of which none were contaminated. source: page 10 lines 130 to 131 without a source (audit section 4.11); Appendix G, Experiment Log.md lines 776 to 777
The matrix census confirms the same separation through shell_available and agent_ran. The Appendix G log records zero contamination among the containerized cells.
The sealed image, a package of software fixed for execution, and its isolation boundary, the limit that separates the workspace from the host.
The two execution locations and their separation.
The boundary ladder and denied shell access.
The isolation census from the matrix fields.
2.3.4 Shell ruling and cell invalidation
The operator ruling on 2026-09-03 invalidated every cell measured while the container denied the agent a shell. The ruling treated that denial as a non-boundary event because the agent could not perform maintenance or verify its work. Roughly 134 cells were invalidated. source: Appendix I line 525
The older page records 125 cells at line 345 in section 12, which conflicts with the ruling count and is retired here. The ruling does not invalidate the container as an isolation measure. It invalidates the affected cells. Later container operation requires the shell access permitted by the revised contract. source: page 10 line 345 (section 12)
2.3.5 Container tests and boundary status
Container-only code and tests that failed outside the container exposed differences between the two execution environments. Visible tests ran inside the container, while host execution exposed failures that required the harness team to align the test conditions. The shell denial remained a non-boundary event, and the operator decision sheet records the invalidation.
The measured cells moved into the container under the design amendment. The census therefore separates pre-container contamination from containerized operation. The shell ruling applies to cells that lacked the required maintenance access, regardless of the container’s value for isolation.
2.3.6 Incident record of the measurement harness
The chronology links the move into the container with the same-day incidents and the later shell ruling. Each record identifies the event, its cause, its effect, and its disposition. The shell ruling remains an invalidation record rather than a new isolation boundary. source: 5. Experiment/0. Plan/Appendix A, Chronology of Design Amendments.md lines 56 to 58