test(security): prove audit path link and mode safety - #251
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Semantic RED is now proven on unchanged test-only head Exact failures: Minimum causal repair is now authorized: change only the audit-file open/create boundary so Linux uses append/create with no-follow final-component semantics and creation mode |
bf5a48b
into
feat/agent-artifact-admission
Refs #250. Draft child of exact
feat/agent-artifact-admission@fb82aafefb6f014875867407766b7d5e1d9dfcfb.This bounded Wardnet Agent Artifact Admission slice hardens only audit-evidence file creation/opening. It does not move execution/isolation, outbound transport, orchestration or static-analysis authority out of their canonical owners.
Executed hostile RED
Test-only exact
8b65dcd8febff005a18fa105ce779e4e22ddda74changed onlycrates/agent-artifact-admission/tests/audit_path_safety_contract.rs; production remained byte-identical to parent#129@fb82aafe.... Hosted CI34443639338, rust job102763645422, acquired realubuntu-24.04, passed checkout/toolchain/cargo fmt --check, then failed in the workspaceTeststep. The regression requires the file sink to reject a final symlink without modifying its target and to create a new audit file with no group/other permission bits even when an isolated child process runs underumask 000. This is semantic RED, not queue/bootstrap/format noise.Minimum causal repair
Exact
68bebe7e15d0cdb436ad66eab47b61c053fee980changes onlycrates/agent-artifact-admission/src/audit.rs: on Linux the existing append-onlyOpenOptionspath now creates with mode0600, opens withO_NOFOLLOW, and rejects non-regular final objects before returning the descriptor. Existing serialization, append-only behavior, bounded JSON encoding, flush +sync_data, and stableAuditError::StorageUnavailablemapping remain unchanged. Non-Linux builds fail this file-backed sink closed rather than pretending equivalent secure-open semantics without an implemented platform contract.Exact current
f527a4753037357ce7d67c78e75dda59acbe5ce5narrows the platform-specific regression to Linux, matching the production implementation boundary. No security invariant was weakened.Exact-current GREEN
On unchanged exact
f527a4753037357ce7d67c78e75dda59acbe5ce5, repository-owned CI34444655764and Fuzz34444655776are terminal SUCCESS. Current submitted-review inventory is empty; current inline review-thread inventory is empty. Parent remains unchanged exact#129@fb82aafefb6f014875867407766b7d5e1d9dfcfb, so no restack is required.This child is ready to integrate normally into #129. After integration, #129 must reacquire its own exact-head repository/security/coverage/package/SBOM/provenance/review/thread evidence; these child receipts do not transfer.
No quarantine execution, EgressWeave transport policy, contextual-orchestrator behavior, AppGuardrail analysis, foreign-owner source, cross-service SQL, force update, destructive rebase, self/model approval, gate weakening or predecessor evidence transfer.