Proposal: ports in allow.hosts (host:port)

Status rejected
Author Claude Code for the maintainer. The proposal came from the harness documentation set of 28 September 2026; recorded here after the decision (DR-184, task 2.2)
Date 2026-10-05
Issue DR-183 D2 in the harness repository ("Hosts: refuse IP literals, or admit them"), which decided the host rule and this with it
Lands in nothing. The fixture that refuses the form, fixtures/invalid/agent-lease-manifest.host-port.json, landed in PR #15

Summary

Admit host:port entries so a lease can confine an agent to one port of a host. Rejected for 1.x.

Motivation

A host entry that names api.example.com opens every port on it. The harness documentation set of 28 September 2026 proposed api.example.com:443 as a narrower grant.

Design

Not adopted. The host identity rule of SPEC §4.4 refuses a port, and the SPEC reserves the form: a host:port form is reserved for a version in which something enforces it.

Backward compatibility

Would have been additive to the host pattern, and that is not the ground for refusing it. A field nothing enforces is a claim the corpus cannot test.

Security

Admitting the form would let a lease state a confinement no gate applied: a reader would believe a port was closed that was open. That is the kind of record this contract exists to refuse.

Alternatives

A separate host_ports list: the same objection. Enforce ports in the egress proxy first and admit the form afterwards: the path the decision leaves open.

Decision

Rejected for 1.x, 2026-10-05, by the maintainer in DR-183 D2: "No host_ports form in 1.x: the egress proxy matches hostnames, and a field nothing enforces is a claim." SPEC §4.4 carries the reservation. Evidence that nothing written is refused: the ten built-in providers' hosts carry no port (fixtures/evidence/2026-10-05-lease-identity.md), and the fixture refuses api.example.com:443 at /allow/hosts/0.