Skip to content

feat(api): Reach::within for confining a caller-supplied reach - #242

Merged
senamakel merged 3 commits into
mainfrom
memory-confinement
Oct 8, 2026
Merged

senamakel merged 3 commits into
mainfrom
memory-confinement

Conversation

@senamakel

@senamakel senamakel commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds Reach::within(&self, outer: &Reach) -> bool: true when every namespace self admits is admitted by outer.

OpenHuman needs this to confine the ambient openhuman.memory_* RPCs and MCP memory tools to the caller's identity root (memory audit F5/S6). A caller may narrow its reach, never widen it, and the host needs an exact containment check to refuse a wider one.

Rules:

  • at must be admitted by outer.
  • With inherit, every ancestor of at must be admitted too, so a reach that inherits above a subtree's top is refused.
  • With descendants, outer must also read descendants, and at must be at or below outer.at. The descendants of an ancestor include its siblings.
  • Service sandboxes stay excluded, consistent with admits.

Tests

namespace/mod_tests.rs: three new tests cover a reach inside a subtree, one leaving it (sibling, root, inherit above the top, service sandbox), and the descendants rule against an agent reach.

cargo test -p tinymemory-api namespace and cargo clippy -p tinymemory-api --all-targets -D warnings both pass.

Co-authored-by: Medulla medulla@tinyhumans.ai

Summary by CodeRabbit

  • New Features
    • Added a way to check whether one access scope is fully contained within another. The check considers inherited access, descendant coverage, and subtree boundaries, including whether the containing scope covers the candidate scope’s location and any required ancestors.
    • Service sandboxes remain excluded when checking containment within broader subtree scopes.

Add a within method that reports whether one reach reads nothing an outer
reach does not, so a host can confine a caller-supplied reach to the
subtree it allows. It checks the anchor, inherited ancestors, and
descendant coverage, with tests covering containment and escapes.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

The PR adds `Reach::within`, a confinement predicate for caller-supplied reaches, with unit tests and documentation updates. All six review lanes reported 0 actionable findings; the security lane judged the containment logic consistent with namespace admission semantics and safe to merge.

State: Ready for maintainer review
Priority: low
Reviewed head: 67f62b6e9d16
Updated: 1791481876 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 1 Active findings 0
Tests 1 Noted findings 0
Documentation 2 Resolved findings 0
Configuration 0 Pending checks/questions 0

Completeness: Complete
Test assessment: Test coverage is assessed from changed tests and lane evidence; execution is not claimed without trusted check data.

What changed

Adds `Reach::within(outer)` to the namespace reach type: it returns true when every namespace the inner reach admits, the outer reach also admits. The rules are: `at` must be admitted by `outer`; when `inherit`, every ancestor of `at` must also be admitted (inheriting above a subtree's top would escape it); when `descendants`, `outer` must read descendants and `at` must lie at or below `outer.at` (descendants of an ancestor of `outer.at` include its siblings), with a reach at the deepest legal node counting as exact since no descendants can exist. Documentation in the namespace architecture doc and the memory-v2 spec was updated to describe the predicate. The predicate is not yet wired into any route, command, or running-system path.

Features

  • Added — Reach::within: Gives hosts a way to confine a caller-supplied reach to an allowed one (e.g., an agent's or identity's subtree): a reach `within` the allowed one may be used as given; any other would widen it. Pure predicate, no runtime path affected yet. (crates/tinymemory-api/src/namespace/mod.rs#impl Reach {, docs/architecture/namespaces.md#or `GetRequest::reach` left `None`) reads as `Reach::subtree(Namespace::ROOT)`, docs/specs/memory-v2.md#listing can be ordered by it. An item's id is its `StoreItem::fingerprint()`.)

Tests

  • addition — A reach inside a subtree is within it, including self-containment, exact reads, and everything being within the root's subtree except service sandboxes.: Exercises the documented invariant with assertions that would fail on regression; correctness depends on `admits` behaving as documented. (crates/tinymemory-api/src/namespace/mod_tests.rs#fn refuses_a_child_past_the_depth_limit() {)
  • addition — A reach leaving a subtree is not within it: sibling, root, ancestor's subtree, inheriting above the subtree's top, and a service sandbox below the subtree.: Covers escape cases including the inherit-above-subtree rule and sandbox exclusion. (crates/tinymemory-api/src/namespace/mod_tests.rs#fn refuses_a_child_past_the_depth_limit() {)
  • addition — Descendant reaches require the outer reach to read descendants and the node to lie at or below `outer.at`; the team subtree is not within an agent's descendants reach.: Covers the descendants-vs-exact rule including the siblings argument. (crates/tinymemory-api/src/namespace/mod_tests.rs#fn refuses_a_child_past_the_depth_limit() {)
  • addition — A subtree at MAX_DEPTH is a singleton: it is within an exact reach of the same node, but a different node of that depth is not.: Covers the maximum-depth edge case where `descendants` counts as exact. (crates/tinymemory-api/src/namespace/mod_tests.rs#fn refuses_a_child_past_the_depth_limit() {)

Findings

No active actionable findings.

Before merge

None.

Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 4 files; 0 findings. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The security lane found the containment check and its boundary-focused tests consistent with the namespace admission semantics and judged the change safe to merge.
  • Lane summary: The reach containment check and its boundary-focused tests are consistent with the namespace admission semantics. The change looks safe to merge. 2 files were not security-reviewed: docs/architecture/namespaces.md (prose or tabular data), docs/specs/memory-v2.md (prose or tabular data). _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The tests exercise each documented rule of the predicate: sibling escape, inherit-above-subtree escape, sandbox exclusion, the descendants-vs-exact rule, and the MAX_DEPTH singleton edge case.
  • Lane summary: `Reach::within` is a behaviour change with real security meaning (confinement of caller-supplied reaches), and the diff does include tests in `namespace/mod_tests.rs` that exercise the documented invariant: sibling escape, inherit-above-subtree escape, sandbox exclusion, the descendants-vs-exact rule, and the MAX_DEPTH singleton edge case, each with assertions that would fail on regression. The logic matches the stated contract given `admits`, `is_within` and `ancestors_and_self` behave as documented. No findings. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The PR description matches the implementation's rules closely; the only noted inaccuracy is the test count (description says three new tests, four are present).
  • Lane summary: The PR adds `Reach::within` with docs and tests, and the description matches the implementation's rules closely. The only inaccuracy is the test count: the body says three new tests were added, but four are present. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The predicate is pure and not yet wired into any route, command, or running-system path, so it introduces no end-to-end behavior change.
  • Lane summary: This change adds `Reach::within`, a confinement predicate on the namespace reach type, plus unit tests and doc updates. It is a pure predicate not yet wired into any route, command or running-system path, so no end-to-end harness can drive it yet; the added tests cover the confinement logic directly. The change looks sound and safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.004993
  • Tokens: 109727 input · 7147 output · 6014 cached · 0 embedding
Head State Pass summary
af92f3463efe ready for maintainer review 0 active finding(s), 0 resolved finding(s) (at 1791478879)
67f62b6e9d16 ready for maintainer review 0 active finding(s), 0 resolved finding(s) (at 1791481876)

tinysweeper 0.1.0

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T17:52:19.417680Z 67f62b6 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

  • Run on-demand review

This review includes 4 billable files and costs up to $1.00.

Or wait 10 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 65871452-532d-478c-9390-8cbc09af7688
📥 Commits

Reviewing files that changed from the base of the PR and between af92f34 and 67f62b6.

📒 Files selected for processing (4)
  • crates/tinymemory-api/src/namespace/mod.rs
  • crates/tinymemory-api/src/namespace/mod_tests.rs
  • docs/architecture/namespaces.md
  • docs/specs/memory-v2.md

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2c3d5ee7-05a8-4588-8107-b966fbf4805d
📥 Commits

Reviewing files that changed from the base of the PR and between d229ebd and af92f34.

📒 Files selected for processing (2)
  • crates/tinymemory-api/src/namespace/mod.rs
  • crates/tinymemory-api/src/namespace/mod_tests.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Adds Reach::within to test whether one reach is contained by another. Tests cover inherited and descendant reaches, team subtrees, sibling nodes, and service sandboxes.

Changes

Reach Containment

Layer / File(s) Summary
Containment logic and tests
crates/tinymemory-api/src/namespace/mod.rs, crates/tinymemory-api/src/namespace/mod_tests.rs
Reach::within checks whether the outer reach admits the candidate's starting node and required ancestors. For descendant reads, the outer reach must also include descendants and contain the candidate node. Tests cover containment and exclusion cases, including service sandboxes.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: m3ga-mind

Merge Risk: ⚪ Minimal · up to af92f

The containment API appears ready to merge after normal checks; no unresolved issue is identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to af92f

The new check rejects wider namespace access without changing existing access enforcement. No newly widened access was found. It remains a validation primitive: the host must derive the allowed scope from a trusted identity and enforce the result. That external integration is not included here.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The security-relevant scope is namespace read authority described by the supplied outer reach. The added predicate does not itself obtain credentials, access memory, or expose an RPC, and no production consumer was identified in the repository.

Security Findings and Attack Paths

  • inferred — No introduced widening path was identified in the inspected change. A sibling or excluded service root fails root admission; inheritance above an allowed subtree fails ancestor admission; an ancestor's broader subtree fails the descendant condition. Source inspection and added assertions support these conclusions, without establishing external host enforcement.

Trust Boundaries and Controls

  • observed — within compares two supplied Reach values; it neither authenticates an identity nor derives an authorized outer reach. Its documentation assigns confinement to the host, which must reject a reach that would widen the allowed one.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding Reach::within to the API for confining a caller-supplied reach.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 2 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks each reach with care,
It traces ancestors through the air.
Descendants stay within their bounds,
While sandbox paths are not allowed.
The tests hop through each case they found.

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0034 · 77,328 in / 6,748 out · 3,988 cached (5%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0017 · 26,094 in / 2,044 out · 2,116 cached (8%) · gpt-5.6-luna
security:    $0.0014 · 25,606 in / 1,016 out · 1,872 cached (7%) · gpt-5.6-luna
tests:       $0.0001 · 11,766 in / 489 out   · 0 cached (0%)     · glm-5.3-flash
description: $0.0000 · 4,639 in  / 73 out    · 0 cached (0%)     · glm-5.3-flash
e2e:         $0.0001 · 5,559 in  / 431 out   · 0 cached (0%)     · glm-5.3-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Oct 8, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af92f3463e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/tinymemory-api/src/namespace/mod.rs
Comment thread crates/tinymemory-api/src/namespace/mod.rs Outdated
senamakel and others added 2 commits October 8, 2026 23:19
A reach with `descendants` at the deepest legal node now counts as exact
when tested with `within`, since no descendants can exist below it. The
confinement rules are documented in the namespaces architecture note and
the memory-v2 spec.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a test asserting that a subtree rooted at the maximum namespace depth
behaves as a singleton, since no node can exist below it, while a sibling
node at the same depth still falls outside.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel
senamakel merged commit fb817fe into main Oct 8, 2026
42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant