feat(security): gate AI-agent artifact installation - #129
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@jules Exact-head repair request for Expected head: CI |
Closes #128 only when this candidate reaches protected
main.Boundary
wardnet-agent-artifact-admissionis Wardnet's Rust-first pre-execution policy/evidence boundary for structured installer intents. It does not fetch, decrypt, install, execute, isolate, activate, or route workloads.quarantine-sandbox-runtimeowns hostile execution/isolation,contextual-orchestratorowns Agent/LLM orchestration, EgressWeave owns reusable outbound HTTP policy, AppGuardrail owns static package/security analysis, and Noema owns governed activation/orchestration. Foreign capabilities are consumed only through released/versioned ports or ACLs; no sibling source copy, mutable production dependency, or cross-service SQL is introduced.Policy is deny-by-default and binds reviewed workspace-manifest SHA-256 plus exact artifact ecosystem/name/version/HTTPS registry/owner/SHA-256, executable family, declared operands and bounded provenance. An
allowreceipt is admission authority only; it is not proof of retrieved bytes or runtime activation.Retained TDD and security contract
The branch preserves the hostile RED→causal-fix lineage for package-manager ecosystem binding; exact npm/PyPI source coordinates; alternate registry/index/config/workspace/install-root denial; npm/pnpm/Yarn/Bun lifecycle and trust controls; Cargo source/version/build/overwrite/tracking authority; PyPI build/target variants and exact
--no-depsdependency cardinality; npm-family direct resolver denial until an immutable reviewed lock/material-set contract exists; OCI digest/platform/cardinality; and Podman TLS/certificate/authentication/decryption authority. Resolver-selected or caller-selected material absent from the reviewed intent does not inherit approval.The current PyPI hash-mode repair is also retained: RED
032d74e060e778add00a2cc757ce3582c1135232proves--require-hashesplus hostile--no-require-hashescannot remain admissible; classifier4c0de8a3445d6b062b69440507cd3c81a3323308isolates pip/pip3 hash-mode authority; causal repairbba656c1d776da38a7315d9ec8e6cb5bdfd621d1fails the contradictory request closed. Retrieved bytes still require independent digest/equivalent immutable-provenance verification before installation/execution.Protected-main integration and current exact evidence — 2026-09-06 KST
Protected/default
mainremains5829a0f08d78de464dd24393ce5d0f25fba9d126. The branch adopted that protected truth non-destructively and then advanced through formatting-only repairs. Current exact head remainsdb921e7f855f52870b23de52a4e23f11ff996644; no force push or destructive rebase was used.Four exact-current repository/security lanes are terminal GREEN on this unchanged head:
33977431401— SUCCESS;33977431523— SUCCESS;33977431400— SUCCESS;33977431547— SUCCESS.CodeQL PR
33977431418is terminal FAILURE, but exact compatibility job101354139576acquired Ubuntu 24.04, confirmed OIDC, exchanged the repository-scoped app token successfully, and sent the exactrepository_dispatchtoContextualWisdomLab/.github. It then intentionally failed closed withVERDICT_STATE=pending: no authenticated terminalcodeql-dispatch/actionsstatus for exactdb921e7...had been published/woken back to the consumer job.The central owner plane has advanced materially since that run.
.github#1932is protected at6f8c51d7389c22ebaf294fe8fe9ef495257883c0and lets all three dispatch consumers parse a comma-separated trusted-dispatcher allowlist while preserving same-identityactor == sender;.github#1926is protected at3f88e13af9dcde4b9da6958c02a78ce3b5c85800and fixes CodeQL matrix serialization before authorization. Current owner issue.github#1929records that the live allowlist setting still needs to represent both already-proven trusted paths,github-actions[bot],opencode-agent[bot]. This unchanged #129 specimen and exact rerun acceptance are handed there in comment5555320921. If a post-authorization retry then fails solely because protected base moved while head stayed exact,.github#1931owns that independent base-drift validation defect.Do not create a no-op commit or broad rerun storm. After owner settings convergence, rerun only failed job
101354139576; it must authorize the app identity, execute the exact-head CodeQL dispatch, publish authenticatedcodeql-dispatch/actions, and wake to terminal success or a real scan finding while preserving the four existing GREEN Wardnet lanes.All currently returned inline review threads are resolved/outdated. Thread resolution is finding evidence, not independent approval. Keep Draft while the delegated exact-head CodeQL gate and the live solo-maintainer governance defect remain unresolved.
Context Fabric / EA
Wardnet does not modify
context-graph-contractsorenterprise-architecture-coresource/PR state. Shared artifact/activation objects remaincontext-graph-contracts#27owner work; architecture adoption/risk/provenance projection remainsenterprise-architecture-core#45owner work. Package-manager argv and Wardnet-local reason codes stay local. Both foreign repositories still expose no immutable GitHub Release at the fresh read, so mutable owner heads are not Wardnet production authority.The sole
docs/product-technical-gap-baseline.mdwriter remains PR #130; this PR does not concurrently edit that ledger.Self/model approval, routine bypass, predecessor-evidence reuse, mutable foreign dependency, source churn solely to redispatch, force push/destructive rebase and gate weakening are forbidden.