feat(security): gate AI-agent artifact installation - #129
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
|
Live exact-head override — 2026-09-03 A concurrent non-force writer advanced this Draft after the body snapshot. Current GitHub head is All predecessor check evidence is historical after that move. Exact-current-head workflow state is non-passing: CI Keep Draft and do not churn the clean source merely to retrigger. |
|
Exact-current-head update — 2026-09-04 Current head is
Fresh exact-head execution is not GREEN. CI |
|
Fresh security-review continuation on current lineage (2026-09-04): Docker's CLI Boolean option grammar permits explicit assignment forms, and Podman pull exposes the same repository-wide all-tags Boolean capability. The prior exact-token guard therefore left a realistic semantic bypass: RED Fresh exact-head hosted evidence is non-passing, not failed source evidence: CI Context Fabric/EA handoffs were refreshed on |
|
@jules Exact-head repair request for Expected head: CI |
|
Wardnet writer coordination, 2026-09-10: the test-only The intervening Production scope remains the existing |
…n-uv-no-python-downloads fix(agent-admission): require uv Python download guard
…n-uv-index-strategy-red fix(agent-admission): reject unsafe uv index strategies
Closes #128 only when the complete Agent Artifact Admission lineage reaches protected
main; child merges into this feature branch do not close protected-main work.Boundary
wardnet-agent-artifact-admissionis Wardnet's Rust-first pre-execution policy/evidence boundary for structured installer intents. It does not fetch, decrypt, install, execute, isolate, activate, route, authorize outbound transport, resolve project dependency groups, or own runtime credential/environment discovery.quarantine-sandbox-runtimeowns hostile execution/isolation and effective workspace/filesystem/interpreter lifecycle;contextual-orchestratorowns Agent/LLM orchestration; EgressWeave owns executable outbound transport authorization; AppGuardrail owns static package/security analysis; Noema owns governed activation; Keyverse remains credential/identity backend. Wardnet consumes foreign capabilities only through released/versioned ports or ACLs and does not copy sibling source, query foreign application tables, or pin mutable sibling heads.Policy remains deny-by-default and binds reviewed workspace-manifest SHA-256 plus exact artifact ecosystem/name/version/HTTPS registry/owner/SHA-256, executable family, declared operands, and bounded provenance. An
allowreceipt is admission authority only; it is not proof of retrieved bytes, effective runtime environment, transport enforcement, installation, isolation, or activation.Current exact candidate — 2026-09-13 KST
Protected/default
mainremains exactf8260f1e03836039ff9463dd99fa982e4e270c4b. Current #129 branch head is exacte3bd77284db673e336791e9e21ea28ab8a3e89c6, produced by ordinary expected-head integration of serialized child #396 into predecessor exact30e81ad13e49a0dc6d0e3c53affa60c51471f9bb. No force update, destructive rebase, self/model approval, gate weakening, mutable foreign dependency, or routine bypass was used. This PR remains Draft while protected integration evidence and central required-gate settlement are incomplete.The lineage preserves deny-by-default structured-argv admission; reviewed workspace-manifest SHA-256; exact artifact ecosystem/name/version/HTTPS registry/owner/SHA-256 binding; package-manager source, destination, trust, configuration, lifecycle, mutation, dependency/build/platform/cardinality controls; audit-before-allow; bounded remote-instruction provenance; exact submitted-argv identity; and parser-phase separation between package-manager-owned authority and delegated child argv.
Latest causal slice — uv global-option bytecode authority (#395 → #396)
Fresh review of predecessor exact
30e81ad13e49a0dc6d0e3c53affa60c51471f9bbfound a Wardnet-owned evidence-integrity defect:uv_bytecode_compilation_authorityrecognized exact--compile-bytecode/--compileforuv pip installonly at fixed argv positions. Astral's documenteduv [OPTIONS] <COMMAND>grammar permits reviewed global options before the active command, souv --color never pip install ... --compile-bytecodestayed fail-closed asForbiddenCommandbut lost the separate causalArtifactNotApprovedevidence for caller-selected generated bytecode materialization.Test-only exact
6c24a3d9d4e2f554649346fcb06222e01ff380e9kept production source byte-identical and established semantic RED in hosted CI34734372758, rust job103662996596: the global-option install case omittedArtifactNotApproved, while near-spelling/non-install controls did not fabricate bytecode authority. The minimum repair reused the existinguv_active_command_indexparser, required exact activepipfollowed by exactinstall, scanned only that install argument slice for exact compile selectors, and preserved the existinguv rundelegated-child boundary throughuv_run_owned_argument_end.supported_install_commandwas not widened.Final child exact
f6e407f3d61bf2f1d0babf1b9aef8e0f9a327403was exactly 3 commits ahead / 0 behind its unchanged parent, with that parent as merge base. CI34734790945/ rust103664147833and Fuzz34734790991/ fuzz103664147382were SUCCESS; CodeRabbit and Devin statuses were SUCCESS; submitted reviews and unresolved threads were 0. It merged normally with fixed expected head ase3bd77284db673e336791e9e21ea28ab8a3e89c6. Issue #395 remains open until the effective repair reaches protectedmainor a verified complete successor.Wardnet still does not execute uv/pip, compile bytecode, read ambient package-manager configuration/certificate stores, discover interpreters, resolve/fetch packages, inspect or mutate runtime/filesystem state, or perform DNS/TLS/network I/O.
Exact-current evidence
On unchanged exact
e3bd77284db673e336791e9e21ea28ab8a3e89c6:34737248139— SUCCESS;34737248183— SUCCESS;34737248205— SUCCESS;34737248165— SUCCESS;34737248162— FAILURE at the delegated central terminal-settlement boundary. Detect job103670729682succeeded. Compatibility job103670906653successfully read the current-head dispatch verdict and then failed only atRelease runner or enforce current-head CodeQL verdictat 04:19:47Z. DownstreamDispatch current-head CodeQL scanjob103671708226did not start until 04:21:02Z and then completed SUCCESS at 04:21:09Z on the same unchanged head, too late to repair the already-terminal required workflow.Exact current consumer evidence and RED→GREEN acceptance are on central
.github#1929comment5651110280. This is central owner work, not authorization for Wardnet source churn or a routine bypass. Runner/materialization/OpenCode remains.github#712/.github#1234or verified successors; solo-maintainer generic approval remains.github#772. Wardnet does not copy those central workflows, synthesize statuses, promote predecessor GREEN, or bypass ordinary queued/failed gates.Documentation / architecture alignment
Fresh live guidance remains aligned with this bounded context.
AGENTS.mdandCLAUDE.mdkeep Wardnet Rust-first and central-workflow ownership. PR #361 is the canonical PRD/TRD/UML writer; PR #111 remains the accepted-ADR consolidation lane; PR #130 remains the sole writer fordocs/product-technical-gap-baseline.md. This Agent Artifact Admission PR does not compete with those writers.Context / release boundary
Fresh read-only owner truth remains
context-graph-contractsprotected/defaultdevelop@99cb5468ba3c15c5e79688f53dee74724fae2d13andenterprise-architecture-coreprotected/defaultdevelop@dd71e40a86385fb7861b0f1be19891a3f3e29ece; both release inventories are empty. Wardnet writes neither repository while the Context Fabric writer owns them and consumes only released compatible contracts/provenance. Current release inventories forcontextual-orchestrator, EgressWeave,quarantine-sandbox-runtime, AppGuardrail, and Wardnet are also empty, so mutable sibling heads are development evidence only and not production dependencies.Wardnet has no immutable protected release. Release readiness remains false until one protected exact head binds version/CHANGELOG/tag/package or image identity, SBOM/provenance/signature, reproducibility, deployment promotion, rollback/roll-forward and recovery evidence. Stale, predecessor, queued, skipped, cancelled, synthetic, or model-only evidence is non-passing.
Keep #129 Draft. Protected promotion requires one unchanged exact head with terminal-valid repository/security/coverage/package/SBOM/provenance/review/thread evidence, fresh protected-base compatibility, any actually required released foreign contracts, and satisfiable live governance. Admission issues remain open until their effective deltas reach protected
mainor a verified complete successor carries every valid code/test/fixture/contract/evidence delta.