feat(security): gate AI-agent artifact installation - #129
seonghobae wants to merge 799 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
|
Live exact-head override — 2026-09-03 A concurrent non-force writer advanced this Draft after the body snapshot. Current GitHub head is All predecessor check evidence is historical after that move. Exact-current-head workflow state is non-passing: CI Keep Draft and do not churn the clean source merely to retrigger. |
|
Exact-current-head update — 2026-09-04 Current head is
Fresh exact-head execution is not GREEN. CI |
|
Fresh security-review continuation on current lineage (2026-09-04): Docker's CLI Boolean option grammar permits explicit assignment forms, and Podman pull exposes the same repository-wide all-tags Boolean capability. The prior exact-token guard therefore left a realistic semantic bypass: RED Fresh exact-head hosted evidence is non-passing, not failed source evidence: CI Context Fabric/EA handoffs were refreshed on |
|
@jules Exact-head repair request for Expected head: CI |
|
Wardnet writer coordination, 2026-09-10: the test-only The intervening Production scope remains the existing |
…ct-operand-evidence fix(admission): preserve uv global artifact operand evidence
|
Canonical parent status correction only; #129 source/head remains unchanged. Serialized child #429 exact |
…ct-artifact-source-evidence test(admission): expose uv global indirect source evidence gap
test(security): prove global pip log authority causal evidence
…he-directory-authority-20260916 fix(security): preserve global pip cache authority evidence
|
Exact-current status refresh (2026-09-18 KST), superseding the PR body’s earlier mixed/queued snapshot without changing source: |
…lues (#439) fix(admission): preserve uv provider evidence across global option values
Closes #128 only when the complete Agent Artifact Admission lineage reaches protected
main; serialized child merges into this feature branch do not close protected-main work.Boundary
wardnet-agent-artifact-admissionis Wardnet's Rust-first pre-execution policy/evidence boundary for structured installer intents. It does not fetch, decrypt, install, execute, isolate, activate, route, authorize outbound transport, resolve project dependency groups, or own runtime credential/environment discovery.quarantine-sandbox-runtimeowns hostile execution/isolation and effective workspace/filesystem/interpreter lifecycle;contextual-orchestratorowns Agent/LLM/tool orchestration; EgressWeave owns executable outbound transport authorization; AppGuardrail owns its guardrail implementation; Keyverse remains credential/identity backend. Wardnet consumes foreign capabilities only through released/versioned contracts/evidence and does not copy sibling source, query foreign application tables, or pin mutable sibling heads as production authority.Current exact candidate — 2026-09-21 KST
Protected/default
mainremainsf8260f1e03836039ff9463dd99fa982e4e270c4b. Current #129 head is9efc804006057f099190d8ffcaa7096c955abe0d, produced by ordinary expected-head integration of serialized child #439. No force update, destructive rebase, self/model approval, gate weakening or bypass was used.Root movement invalidates every predecessor #129 conclusion. On the unchanged exact root, CI
35477678285, Fuzz35477678328, SAST Semgrep35477678290, and Security Scan35477678327are terminal SUCCESS. Required CodeQL PR35477678309is terminal FAILURE at the delegated current-head settlement boundary, not a Wardnet source/test/SARIF failure:Detect CodeQL languagesjob105989636467succeeded after exact-head checkout/classification; compatibility job106042665313successfully read the current-head dispatch verdict and then failed only atRelease runner or enforce current-head CodeQL verdict; subsequent dispatch job106115749380succeeded. This exact same-head specimen is handed to canonical central owner.github#1929in comment5754488399. A later dispatch cannot retroactively replace the already-failed required workflow.Keep Draft. Do not churn the unchanged Wardnet source to redispatch central evidence, synthesize status, copy central workflows, promote predecessor GREEN, self/model approve, weaken gates or use routine administrator bypass.
Latest integrated serialized repair — #438 / #439
Test-only exact
ea9c817a8d0edd0e78052d18493a1f1f0954e91festablished hosted semantic RED:uv --project run pip install ... --managed-pythontreated the value tokenrunconsumed by global--projectas though it were the activeuv runcommand, erasing causal Python-provider authority evidence while genericForbiddenCommandstill failed closed.Minimum causal repair exact
1dfcdcb38b5ef9bc2bee25e48dc63a15e65117a5removed the duplicate raw token-position heuristic and reused the existing parser-awarepolicy::uv_active_command_index()boundary. Actual parser-activeuv runremains outside install-provider semantics; exact submitted-argv hashing and deliberately unsupported global-option command classification remain unchanged. Subsequent child commits only finished canonical rustfmt for the regression fixture.On unchanged child exact
#439@f84787e5b6bb4148be417a98957b24e102dd1137, CI35460113884and Fuzz35460113893completed SUCCESS; reviews and review threads were empty; parent compatibility remained exact with then-root#129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6. #439 was marked Ready and normally merged with fixed expected-head protection as9efc804006057f099190d8ffcaa7096c955abe0d.Issue #438 remains open until this effective repair reaches protected
mainor a verified complete successor preserves every valid code/test/fixture/contract/evidence delta.Preserved admission authority
The candidate remains deny-by-default structured-argv admission with reviewed workspace-manifest SHA-256; exact artifact ecosystem/name/version/HTTPS registry/owner/SHA-256 binding; package-manager source/trust/destination/configuration/lifecycle/mutation/dependency/build/platform/cardinality controls; audit-before-allow; bounded remote-instruction provenance; exact submitted-argv identity; and parser-phase separation between package-manager-owned authority and delegated child argv.
An
allowreceipt is admission authority only. It is not proof of retrieved-byte integrity, effective runtime configuration, outbound transport authorization, installation, runtime/filesystem isolation, activation, LLM/tool execution or guardrail execution. Those remain canonical owner responsibilities and may be consumed only through released compatible evidence/contracts.Governance / release boundary
Central hosted-runner/OpenCode defects remain
.github#712/#1234or verified successors, delegated CodeQL settlement remains.github#1929or verified successor, and generic solo-maintainer approval remains.github#772. Wardnet does not copy those workflows, churn source merely to redispatch, synthesize status, self/model approve, weaken gates or use routine administrator bypass.Protected
AGENTS.md,CLAUDE.mdanddocs/architecture.mdremain the current protected ownership baseline. Draft #111 remains the accepted-ADR consolidation lane; Draft #361 remains the canonical PRD/TRD/UML lane; #130 remains the soledocs/product-technical-gap-baseline.mdwriter; #333 remains the CodeGraph-guidance writer.Fresh read-only owner truth remains CGC
develop@99cb5468ba3c15c5e79688f53dee74724fae2d13, EAdevelop@dd71e40a86385fb7861b0f1be19891a3f3e29ece, quarantine-sandbox-runtimedevelop@60a85c7633e03b425b67159ec6822c8178cf87ea, EgressWeavemain@bd0339bf43cf5041e861bac86a84cb6e7e32637e, contextual-orchestratormain@5665b0ad1e07ffb5e9f8c59e44b6b2a785298013, and appguardraildevelop@e71d37e7c58118e6764c96ab7c4492fe33eed6f8. Their checked immutable GitHub Release inventories remain empty, as does Wardnet's. Mutable heads are inventory/compatibility evidence only, never Wardnet production dependencies.Protected promotion requires one unchanged exact head with terminal-valid repository/security/coverage/package/SBOM/provenance/review/thread evidence, fresh protected-base compatibility, any actually required released foreign contracts, and satisfiable live governance.