Repository navigation
feat(api): Reach::within for confining a caller-supplied reach - #242
Conversation
Add a within method that reports whether one reach reads nothing an outer reach does not, so a host can confine a caller-supplied reach to the subtree it allows. It checks the anchor, inherited ancestors, and descendant coverage, with tests covering containment and escapes. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper reviewThe PR adds `Reach::within`, a confinement predicate for caller-supplied reaches, with unit tests and documentation updates. All six review lanes reported 0 actionable findings; the security lane judged the containment logic consistent with namespace admission semantics and safe to merge. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedAdds `Reach::within(outer)` to the namespace reach type: it returns true when every namespace the inner reach admits, the outer reach also admits. The rules are: `at` must be admitted by `outer`; when `inherit`, every ancestor of `at` must also be admitted (inheriting above a subtree's top would escape it); when `descendants`, `outer` must read descendants and `at` must lie at or below `outer.at` (descendants of an ancestor of `outer.at` include its siblings), with a reach at the deepest legal node counting as exact since no descendants can exist. Documentation in the namespace architecture doc and the memory-v2 spec was updated to describe the predicate. The predicate is not yet wired into any route, command, or running-system path. Features
Tests
FindingsNo active actionable findings. Before mergeNone. Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Warning Review limit reached
This review includes 4 billable files and costs up to $1.00. Or wait 10 minutes for your next included review. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (4)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughAdds ChangesReach Containment
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The containment API appears ready to merge after normal checks; no unresolved issue is identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The new check rejects wider namespace access without changing existing access enforcement. No newly widened access was found. It remains a validation primitive: the host must derive the allowed scope from a trusted identity and enforce the result. That external integration is not included here. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
A rabbit checks each reach with care, Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0034 · 77,328 in / 6,748 out · 3,988 cached (5%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0017 · 26,094 in / 2,044 out · 2,116 cached (8%) · gpt-5.6-luna
security: $0.0014 · 25,606 in / 1,016 out · 1,872 cached (7%) · gpt-5.6-luna
tests: $0.0001 · 11,766 in / 489 out · 0 cached (0%) · glm-5.3-flash
description: $0.0000 · 4,639 in / 73 out · 0 cached (0%) · glm-5.3-flash
e2e: $0.0001 · 5,559 in / 431 out · 0 cached (0%) · glm-5.3-flash
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af92f3463e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
A reach with `descendants` at the deepest legal node now counts as exact when tested with `within`, since no descendants can exist below it. The confinement rules are documented in the namespaces architecture note and the memory-v2 spec. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a test asserting that a subtree rooted at the maximum namespace depth behaves as a singleton, since no node can exist below it, while a sibling node at the same depth still falls outside. Auto-committed-on: macbook Co-authored-by: Medulla <medulla@tinyhumans.ai>
Summary
Adds
Reach::within(&self, outer: &Reach) -> bool: true when every namespaceselfadmits is admitted byouter.OpenHuman needs this to confine the ambient
openhuman.memory_*RPCs and MCP memory tools to the caller's identity root (memory audit F5/S6). A caller may narrow its reach, never widen it, and the host needs an exact containment check to refuse a wider one.Rules:
atmust be admitted byouter.inherit, every ancestor ofatmust be admitted too, so a reach that inherits above a subtree's top is refused.descendants,outermust also read descendants, andatmust be at or belowouter.at. The descendants of an ancestor include its siblings.admits.Tests
namespace/mod_tests.rs: three new tests cover a reach inside a subtree, one leaving it (sibling, root, inherit above the top, service sandbox), and the descendants rule against an agent reach.cargo test -p tinymemory-api namespaceandcargo clippy -p tinymemory-api --all-targets -D warningsboth pass.Co-authored-by: Medulla medulla@tinyhumans.ai
Summary by CodeRabbit