Skip to content

[P0] Enforce a fail-closed destination policy for all outbound traffic #79

Description

@seonghobae

Production blocker and ownership correction

Every Wardnet-owned outbound HTTP call site must fail closed unless its destination/network authority is proven. Wardnet owns gateway/SOC purpose, call-site policy, admission outcome, deadline/evidence correlation, and protocol behavior. EgressWeave is the canonical reusable owner of outbound destination/address/DNS-rebinding/redirect/proxy/TLS/resource authorization. Wardnet must not keep a second local implementation of those reusable semantics.

Protected/default Wardnet truth is main@5829a0f08d78de464dd24393ce5d0f25fba9d126 through #159. Fresh EgressWeave GitHub Release inventory remains empty, so no immutable Rust-consumable owner contract is currently production authority.

Current preservation candidate — 2026-09-05

PR #136 is exact 28e5776388b2fc31e1d0567382871a1f599aa3ed and intentionally Draft. It is not an integrable Wardnet-local outbound-policy implementation. Its value is hostile consumer evidence that must be preserved and later reconstructed as a thin released-owner ACL/conformance slice after EgressWeave publishes a compatible immutable contract. Canonical owner issue ContextualWisdomLab/EgressWeave#237 already carries the Wardnet consumer handoff (comment 5540660961).

The branch remains on the older Wardnet base and must not be mechanically restacked merely to appear current while the owner release is absent. Do not close it either: unique RED/test/fixture/evidence must first be transferred to a verified successor.

Preserved RED → candidate-local GREEN evidence

The current preservation branch demonstrates consumer requirements including:

  • credentials/fragments, localhost/trailing-dot aliases, denied literal address classes, and insecure non-loopback HTTP fail closed;
  • DNS answer validation and connection binding resist DNS rebinding;
  • ambient proxies and automatic redirects do not widen authority;
  • validated-address/client state remains finite;
  • hop-by-hop and Connection-nominated metadata is not reintroduced;
  • Wardnet phishing/TAXII/KEV-style operations have one bounded end-to-end budget across owner-required DNS work and HTTP I/O;
  • purpose-specific Wardnet operations may own their deadline/purpose/evidence fields without owning reusable DNS/address/HTTP authorization semantics.

A previous review finding was valid: manual DNS resolution occurred outside the intended request timeout. The preserved lineage is:

  • hostile RED f408500d8aeb4beb386caa48a7525508d59da193 for one shared DNS+HTTP deadline;
  • Tokio-time prerequisite 83e2b4fdfae6eb927dd1b6ce5a263af654c52540;
  • runnable RED 3cb1047416c3aa7fa8eb352b842cc55ad8c21b19, with real CI failure 33698726857 at phishing_feed_dns_resolution_shares_the_end_to_end_operation_deadline;
  • local repair present by 9978f8c643433b5df0398e3d9f3608546fdadecd;
  • current 28e5776388b2fc31e1d0567382871a1f599aa3ed adds deterministic pending-resolver acceptance.

That proves the consumer contract, not owner authority. The architectural GREEN is a released EgressWeave boundary satisfying the same hostile timing, DNS, address, redirect, proxy, TLS and resource constraints.

Reconstruction contract

After a compatible immutable EgressWeave release exists:

  1. Start from the exact then-current protected Wardnet main; do not consume a mutable EgressWeave branch/head or sibling checkout.
  2. Replace Wardnet-local reusable destination/DNS/redirect/proxy/TLS/resource policy with a thin versioned EgressWeave port/ACL.
  3. Preserve Wardnet-owned purpose, operation budget, call-site policy, evidence correlation and fail-closed behavior.
  4. Reject unsupported, unavailable, stale, malformed, incompatible or unverifiable owner evidence.
  5. Bind exact owner version/digest/SBOM/provenance/reproducibility in Wardnet release evidence.
  6. Re-express every still-valid draft(architecture): preserve outbound-policy RED pending EgressWeave release #136 hostile test as consumer/conformance acceptance without copying EgressWeave internals.
  7. Prove no cross-service SQL, mutable git dependency, source copy or parallel policy authority remains.

Other dependencies and live control-plane state

PR #155 exact f74ff25a321dfb1d7109719e2a1fc77e47dc4898 independently owns fail-closed management authentication and must reach protected truth through ordinary governance. Queue/runner acquisition remains .github#712; solo-maintainer ruleset reconciliation remains .github#772 / current owner-plane successor #1644. Those conditions do not authorize self/model approval, source churn, routine administrator bypass, or gate weakening.

Completion gate

Close only after EgressWeave publishes an immutable compatible released contract, a Wardnet successor on fresh protected main carries every valid #136 consumer test/fixture/evidence delta through the released ACL, and one unchanged integration candidate has terminal current repository/security/coverage/package/SBOM/provenance/review/thread/governance evidence. The current local semantic implementation must never be promoted merely because its checks eventually turn green.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: accessibilityAccessibility and assistive-technology supportarea: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions