feat(security): gate AI-agent artifact installation - #129
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@jules Exact-head repair request for Expected head: CI |
Closes #128 only when this candidate reaches protected
main.Boundary
wardnet-agent-artifact-admissionis Wardnet's Rust-first pre-execution policy/evidence boundary for structured installer intents. It does not fetch, decrypt, install, execute, isolate, activate, or route workloads.quarantine-sandbox-runtimeowns hostile execution/isolation,contextual-orchestratorowns Agent/LLM orchestration, EgressWeave owns reusable outbound HTTP policy, AppGuardrail owns static package/security analysis, and Noema owns governed activation/orchestration. Foreign capabilities are consumed only through released/versioned ports or ACLs; no sibling source copy, mutable production dependency, or cross-service SQL is introduced.Policy is deny-by-default and binds reviewed workspace-manifest SHA-256 plus exact artifact ecosystem/name/version/HTTPS registry/owner/SHA-256, executable family, declared operands and bounded provenance. An
allowreceipt is admission authority only; it is not proof of retrieved bytes or runtime activation.Retained TDD and security contract
The branch preserves hostile RED→causal-fix lineage for package-manager ecosystem binding; exact npm/PyPI source coordinates; alternate registry/index/config/workspace/install-root denial; npm/pnpm/Yarn/Bun lifecycle and trust controls; Cargo source/version/build/overwrite/tracking authority; PyPI build/target variants and exact
--no-depsdependency cardinality; npm-family direct resolver denial until an immutable reviewed lock/material-set contract exists; OCI digest/platform/cardinality; and Podman TLS/certificate/authentication/decryption authority. Resolver-selected or caller-selected material absent from the reviewed intent does not inherit approval.The PyPI hash-mode repair remains retained: RED
032d74e060e778add00a2cc757ce3582c1135232proves--require-hashesplus hostile--no-require-hashescannot remain admissible; classifier4c0de8a3445d6b062b69440507cd3c81a3323308isolates pip/pip3 hash-mode authority; causal repairbba656c1d776da38a7315d9ec8e6cb5bdfd621d1fails the contradictory request closed. Retrieved bytes still require independent digest/equivalent immutable-provenance verification before installation/execution.Protected-main adoption — 2026-09-06 KST
The prior exact source candidate
db921e7f855f52870b23de52a4e23f11ff996644was based on protected5829a0f08d78de464dd24393ce5d0f25fba9d126. Fresh comparison to current protected/defaultmain@a52ccd0a24a727d9349bb32def7713882d8cad1eproved the entire intervening protected delta is exactly two #171 files:docs/adr/2026-09-05-anti-bot-acquisition-boundary.mdanddocs/adr/README.md. Fresh inventory of this PR's 67 feature paths proves neither path is modified by Agent Artifact Admission.The branch therefore adopted current protected truth non-destructively with two-parent merge
14c0af32e7e4f68c682d55a1b1117629fa940336, preserving exact prior candidatedb921e7...and exact protectedmain@a52ccd0...as parents and carrying both protected ADR blobs byte-for-byte. No force push or destructive rebase was used. Fresh compare against protected main is merge-base=a52ccd0..., ahead 251 / behind 0; the effective product/security delta remains the same 67 Agent Artifact Admission paths.All workflow conclusions from
db921e7...are predecessor evidence after this real ancestry movement. Current exact source remains14c0af32e7e4f68c682d55a1b1117629fa940336and remains Draft.Exact-current execution — refreshed 2026-09-07 KST
The earlier queued snapshot is superseded. On unchanged exact
14c0af32e7e4f68c682d55a1b1117629fa940336, CI34020063254, Fuzz34020063220, Security Scan34020063214, and SAST Semgrep34020063245are terminal SUCCESS.CodeQL PR
34020063240is the sole failing repository gate.Detect CodeQL languagesjob101450870096is terminal success on a realubuntu-24.04runner.CodeQL compatibility analysis (actions)job101455085963also acquired a real hosted runner and successfully completedRequest current-head CodeQL scan dispatch; it fails only atRelease runner or enforce current-head CodeQL verdict. This is the same central authenticated-dispatch/verdict boundary tracked in.github#1927/#1929after.github#1926repaired the earlier matrix-serialization defect. Do not source-churn this unchanged Agent Artifact Admission candidate or promote predecessor/manual/synthetic CodeQL evidence.Current inline review-thread inventory is fully resolved/outdated. The only recorded review submissions are COMMENTED records and do not constitute independent approval. Keep Draft while CodeQL and the live solo-maintainer governance rule remain non-passing.
Context Fabric / EA
Wardnet does not modify
context-graph-contractsorenterprise-architecture-coresource/PR state. Shared artifact/activation objects remain canonical owner work and architecture adoption/risk/provenance projection remains EA owner work. Package-manager argv and Wardnet-local reason codes stay local. Fresh foreign release inventory remains empty for the required CGC/EA/EgressWeave boundaries, so mutable owner heads are not Wardnet production authority.The sole
docs/product-technical-gap-baseline.mdwriter remains PR #130; this PR does not edit that ledger.Merge only through ordinary protected governance after one unchanged exact head has terminal-valid repository/security/coverage/package/SBOM/provenance/review/thread gates, fresh protected-base compatibility, and governance satisfiable without self/model approval or routine administrator bypass. No mutable foreign dependency, source churn solely to redispatch, gate weakening, force push/destructive rebase, or predecessor-evidence reuse.