Skip to content

feat(security): gate AI-agent artifact installation - #129

Draft
seonghobae wants to merge 799 commits into
mainfrom
feat/agent-artifact-admission
Draft

seonghobae wants to merge 799 commits into
mainfrom
feat/agent-artifact-admission

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Closes #128 only when the complete Agent Artifact Admission lineage reaches protected main; serialized child merges into this feature branch do not close protected-main work.

Boundary

wardnet-agent-artifact-admission is Wardnet's Rust-first pre-execution policy/evidence boundary for structured installer intents. It does not fetch, decrypt, install, execute, isolate, activate, route, authorize outbound transport, resolve project dependency groups, or own runtime credential/environment discovery. quarantine-sandbox-runtime owns hostile execution/isolation and effective workspace/filesystem/interpreter lifecycle; contextual-orchestrator owns Agent/LLM/tool orchestration; EgressWeave owns executable outbound transport authorization; AppGuardrail owns its guardrail implementation; Keyverse remains credential/identity backend. Wardnet consumes foreign capabilities only through released/versioned contracts/evidence and does not copy sibling source, query foreign application tables, or pin mutable sibling heads as production authority.

Current exact candidate — 2026-09-21 KST

Protected/default main remains f8260f1e03836039ff9463dd99fa982e4e270c4b. Current #129 head is 9efc804006057f099190d8ffcaa7096c955abe0d, produced by ordinary expected-head integration of serialized child #439. No force update, destructive rebase, self/model approval, gate weakening or bypass was used.

Root movement invalidates every predecessor #129 conclusion. On the unchanged exact root, CI 35477678285, Fuzz 35477678328, SAST Semgrep 35477678290, and Security Scan 35477678327 are terminal SUCCESS. Required CodeQL PR 35477678309 is terminal FAILURE at the delegated current-head settlement boundary, not a Wardnet source/test/SARIF failure: Detect CodeQL languages job 105989636467 succeeded after exact-head checkout/classification; compatibility job 106042665313 successfully read the current-head dispatch verdict and then failed only at Release runner or enforce current-head CodeQL verdict; subsequent dispatch job 106115749380 succeeded. This exact same-head specimen is handed to canonical central owner .github#1929 in comment 5754488399. A later dispatch cannot retroactively replace the already-failed required workflow.

Keep Draft. Do not churn the unchanged Wardnet source to redispatch central evidence, synthesize status, copy central workflows, promote predecessor GREEN, self/model approve, weaken gates or use routine administrator bypass.

Latest integrated serialized repair — #438 / #439

Test-only exact ea9c817a8d0edd0e78052d18493a1f1f0954e91f established hosted semantic RED: uv --project run pip install ... --managed-python treated the value token run consumed by global --project as though it were the active uv run command, erasing causal Python-provider authority evidence while generic ForbiddenCommand still failed closed.

Minimum causal repair exact 1dfcdcb38b5ef9bc2bee25e48dc63a15e65117a5 removed the duplicate raw token-position heuristic and reused the existing parser-aware policy::uv_active_command_index() boundary. Actual parser-active uv run remains outside install-provider semantics; exact submitted-argv hashing and deliberately unsupported global-option command classification remain unchanged. Subsequent child commits only finished canonical rustfmt for the regression fixture.

On unchanged child exact #439@f84787e5b6bb4148be417a98957b24e102dd1137, CI 35460113884 and Fuzz 35460113893 completed SUCCESS; reviews and review threads were empty; parent compatibility remained exact with then-root #129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6. #439 was marked Ready and normally merged with fixed expected-head protection as 9efc804006057f099190d8ffcaa7096c955abe0d.

Issue #438 remains open until this effective repair reaches protected main or a verified complete successor preserves every valid code/test/fixture/contract/evidence delta.

Preserved admission authority

The candidate remains deny-by-default structured-argv admission with reviewed workspace-manifest SHA-256; exact artifact ecosystem/name/version/HTTPS registry/owner/SHA-256 binding; package-manager source/trust/destination/configuration/lifecycle/mutation/dependency/build/platform/cardinality controls; audit-before-allow; bounded remote-instruction provenance; exact submitted-argv identity; and parser-phase separation between package-manager-owned authority and delegated child argv.

An allow receipt is admission authority only. It is not proof of retrieved-byte integrity, effective runtime configuration, outbound transport authorization, installation, runtime/filesystem isolation, activation, LLM/tool execution or guardrail execution. Those remain canonical owner responsibilities and may be consumed only through released compatible evidence/contracts.

Governance / release boundary

Central hosted-runner/OpenCode defects remain .github#712/#1234 or verified successors, delegated CodeQL settlement remains .github#1929 or verified successor, and generic solo-maintainer approval remains .github#772. Wardnet does not copy those workflows, churn source merely to redispatch, synthesize status, self/model approve, weaken gates or use routine administrator bypass.

Protected AGENTS.md, CLAUDE.md and docs/architecture.md remain the current protected ownership baseline. Draft #111 remains the accepted-ADR consolidation lane; Draft #361 remains the canonical PRD/TRD/UML lane; #130 remains the sole docs/product-technical-gap-baseline.md writer; #333 remains the CodeGraph-guidance writer.

Fresh read-only owner truth remains CGC develop@99cb5468ba3c15c5e79688f53dee74724fae2d13, EA develop@dd71e40a86385fb7861b0f1be19891a3f3e29ece, quarantine-sandbox-runtime develop@60a85c7633e03b425b67159ec6822c8178cf87ea, EgressWeave main@bd0339bf43cf5041e861bac86a84cb6e7e32637e, contextual-orchestrator main@5665b0ad1e07ffb5e9f8c59e44b6b2a785298013, and appguardrail develop@e71d37e7c58118e6764c96ab7c4492fe33eed6f8. Their checked immutable GitHub Release inventories remain empty, as does Wardnet's. Mutable heads are inventory/compatibility evidence only, never Wardnet production dependencies.

Protected promotion requires one unchanged exact head with terminal-valid repository/security/coverage/package/SBOM/provenance/review/thread evidence, fresh protected-base compatibility, any actually required released foreign contracts, and satisfiable live governance.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/agent-admission-lock-refresh.yml Fixed

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae seonghobae added the enhancement New feature or request label Sep 2, 2026 — with ChatGPT Codex Connector
@seonghobae
seonghobae changed the base branch from main to fix/pin-hosted-runner-20260902-v3 September 2, 2026 04:14
@seonghobae
seonghobae changed the base branch from fix/pin-hosted-runner-20260902-v3 to main September 2, 2026 04:19
@seonghobae seonghobae added priority: high High-priority or P1 work status: draft type: feature New or expanded product capability labels Sep 2, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Live exact-head override — 2026-09-03

A concurrent non-force writer advanced this Draft after the body snapshot. Current GitHub head is 43837309a042a4016b5497bcda25d8e80193f0ef, not 86abdb91e43d154e1e194780c58b29a63bfb0c82. Fresh comparison proves a one-commit linear advance (ahead_by=1, behind_by=0) whose only delta is crates/agent-artifact-admission/tests/bun_scope_escape_contract.rs: test(admission): keep Bun argv construction explicit replaces the two map(str::to_string) expressions with explicit closures. The intervening delta is adopted; no restack/force update is warranted.

All predecessor check evidence is historical after that move. Exact-current-head workflow state is non-passing: CI 33663428878 queued; Fuzz 33663429017 pending; Security Scan 33663429034 queued; SAST Semgrep 33663429149 pending; OSV 33663429986 queued; Scorecard 33663428806 queued; CodeQL PR 33663431222 completed startup_failure. The current review-thread inventory contains only one historical/outdated Scorecard thread and it is resolved; there is no current unresolved review finding in the returned thread set.

Keep Draft and do not churn the clean source merely to retrigger. .github#712 remains the causal owner for pre-checkout acquisition/startup-failure evidence and .github#1644/#772 for the live solo-maintainer ruleset defect. No predecessor evidence, self/model approval, routine bypass or gate weakening applies.

Copy link
Copy Markdown
Contributor Author

Exact-current-head update — 2026-09-04

Current head is 3a63247e412d17b7bbee2a1d1668dfc84adf1280 on protected main@cc15cc2c34daf8c104eeb83d52a6a66f3cd6e128; keep Draft. This lineage adds one bounded OCI artifact-identity repair without taking over registry transport or quarantine execution:

  • RED d7f429c37a3bd26ea746254defc5d65f33ef71f2: Docker and Podman pull with an otherwise approved digest plus -a / --all-tags must block rather than widen one approved artifact into the repository's mutable tag set.
  • Causal GREEN 7f06137453dc2296e4c4ac8c439777bf19ba7244: the existing artifact-variant predicate now rejects repository-wide pull expansion and preserves the public artifact_not_approved reason domain.
  • Doctoring 37751afc97dd318ae1dd2be48faf54e60069163a -> 3a63247e412d17b7bbee2a1d1668dfc84adf1280 records the exact-set invariant and current Docker/Podman primary command semantics. Wardnet still does not fetch images, validate downloaded bytes, or own runtime isolation.

Fresh exact-head execution is not GREEN. CI 33825032608, Fuzz 33825032507, Security Scan 33825032518, SAST Semgrep 33825032753, Scorecard PR 33825032564, and OSV-Scanner PR 33825033384 are queued. CI job 100875751793 targets exact 3a63247e... with runner_id=0, empty runner/group identity and steps=[]; the specimen is handed to central .github#712. Predecessor workflow evidence does not transfer and no leaf no-op retrigger or bypass is justified.

Copy link
Copy Markdown
Contributor Author

Fresh security-review continuation on current lineage (2026-09-04): Docker's CLI Boolean option grammar permits explicit assignment forms, and Podman pull exposes the same repository-wide all-tags Boolean capability. The prior exact-token guard therefore left a realistic semantic bypass: docker|podman pull --all-tags=true <approved@sha256:...> (and short assigned forms) could retain admission while widening one reviewed digest into the repository's mutable tag set.

RED 883d1d37e05b0ccd9d30b2c1b25fd7d53c6fc8d8 adds assigned-true hostile cases. Causal source fix e9e07e696c013dab88df6a5a6dc1be8306b9b688 recognizes true Boolean assignments in the existing artifact-variant boundary and keeps the public reason domain artifact_not_approved. Coverage 2207a6f79522dc8b6cb95e817be648bb6ef9a7f3 exercises Docker/Podman long/short true spellings plus explicit-false non-regression. Doctoring/primary-reference traceability is current at exact head 6dfd777e1e9ce8b42c87c3311911a35f64f97190.

Fresh exact-head hosted evidence is non-passing, not failed source evidence: CI 33848015533, SAST 33848015479, Security Scan 33848015485, and Fuzz 33848015550 are queued; CI job 100944222630 is pre-checkout. Central runner owner .github#712 has the exact specimen in comment 5537096153. No rerun storm, predecessor evidence transfer, self-approval, or bypass is valid here.

Context Fabric/EA handoffs were refreshed on context-graph-contracts#27 and enterprise-architecture-core#45 without mutating either owner repository's source/PR state. They continue to require Wardnet security-artifact admission to remain distinct from Noema governed activation/orchestration and to consume only released provider-neutral evidence contracts.

@seonghobae
seonghobae marked this pull request as ready for review September 5, 2026 02:11
@seonghobae
seonghobae marked this pull request as draft September 5, 2026 06:12

Copy link
Copy Markdown
Contributor Author

@jules Exact-head repair request for feat/agent-artifact-admission only.

Expected head: f6889079ce49b6f08865180dd6a1ffd8145a8192; protected base observed: main@5829a0f08d78de464dd24393ce5d0f25fba9d126.

CI 33904242427, job 101230630469, reached checkout and failed deterministically at cargo fmt --check under Rust/rustfmt 1.98.1. This is a mechanical formatting defect, not a runner wait. Please re-read the branch head before writing; if it is no longer the expected SHA, do not overwrite intervening work. On the unchanged head, run repository cargo fmt with the effective toolchain and commit only the resulting rustfmt changes on the existing PR branch. Do not change semantics, dependencies, workflows, PR base/state, gates, or history; no force push/rebase. Then run cargo fmt --check locally if available and leave remote CI/security evidence to the new exact head. The PR must remain Draft until exact-head deterministic/security gates are terminal and valid review threads are clear.

Copy link
Copy Markdown
Contributor Author

Wardnet writer coordination, 2026-09-10: the test-only d8430278eae6c2a70f09540a58af1ffa70927542 is retained. I fetched CI 34424781388 / job 102707573166 logs: hosted compute did acquire at 01:36:15Z, checked out e5cebde78c61b3a09b340239af3bd036d0dc2c0a (merge d843 into a52), and failed only rustfmt at the two reason_codes.contains chains. The assertion suite was skipped, so this is not the required semantic RED.

The intervening 61ce5d9f3d67ddf0b9dbf8bfc7234a6034cc4f0b was inspected and adopted: exactly +6/-2 formatting lines in the new test, no production change, ordinary descendant preserving all prior work. I will not duplicate that repair or rerun its superseded failing head. Fresh CI 34426475175 is the appropriate next assertion attempt. Fuzz 34424781399 succeeded on d843 but does not execute this integration regression.

Production scope remains the existing policy.rs::requests_alternate_trust_root classifier after observed assertion RED, with unchanged positive admission and stable AlternateTrustRoot deduplication. Please preserve this single lane; any concurrent repair should continue from the fresh head and attach the actual failing assertion plus successor verification rather than create another PR or force-update. The issue's queued d843 snapshot is historical after the formatting successor. No merge, release, transport enforcement, installation or current-head GREEN is claimed.

Copy link
Copy Markdown
Contributor Author

Canonical parent status correction only; #129 source/head remains unchanged. Serialized child #429 exact 0f206d6cb23ca88abfd6f0c0a84e1dcba6e35969 is no longer queued: CI 34927770706 / rust 104249367485 completed SUCCESS. Fuzz 34927770671 / job 104249367457 completed FAILURE without runner materialization (runner_id=0, empty runner name/group, no steps), so this is central hosted-runner assignment evidence rather than Agent Artifact Admission semantic RED. Exact specimen/acceptance is handed to .github#712 comment 5678309257. Keep #429 Draft and source-stable; do not integrate it or start the next serialized admission child until the unchanged head obtains materialized Fuzz terminal GREEN and then-live review/security evidence. No source churn, selector workaround, synthetic status, predecessor evidence transfer, bypass, or merge.

…ct-artifact-source-evidence

test(admission): expose uv global indirect source evidence gap

Copy link
Copy Markdown
Contributor Author

Exact-current status refresh (2026-09-18 KST), superseding the PR body’s earlier mixed/queued snapshot without changing source: #129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6 remains based on protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b, Draft and mechanically mergeable. CI 35160465195, Fuzz 35160465198, SAST Semgrep 35160465226, and Security Scan 35160465204 are terminal SUCCESS. CodeQL PR 35160465225 is terminal FAILURE only at the centrally delegated current-head settlement step after dispatch returned pending; the exact specimen is already handed to .github#1929, so this is not a Wardnet source/test/SARIF RED and does not authorize churn, synthetic status or bypass. Fresh read-only contextual-orchestrator protected head is now aaf9e5d9d84a1a27e54c357b83f62ec7d0dfe7cb via merged #1030/ADR 0129, but its GitHub Releases inventory remains empty; mutable source remains non-authoritative and #129 acquires no new foreign dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: high High-priority or P1 work status: draft type: feature New or expanded product capability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] Gate AI-agent package installs from untrusted llms.txt and web instructions

2 participants