Skip to content

test(security): prove audit path link and mode safety - #251

Merged
seonghobae merged 3 commits into
feat/agent-artifact-admissionfrom
test/admission-audit-path-safety
Sep 10, 2026
Merged

seonghobae merged 3 commits into
feat/agent-artifact-admissionfrom
test/admission-audit-path-safety

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Refs #250. Draft child of exact feat/agent-artifact-admission@fb82aafefb6f014875867407766b7d5e1d9dfcfb.

This bounded Wardnet Agent Artifact Admission slice hardens only audit-evidence file creation/opening. It does not move execution/isolation, outbound transport, orchestration or static-analysis authority out of their canonical owners.

Executed hostile RED

Test-only exact 8b65dcd8febff005a18fa105ce779e4e22ddda74 changed only crates/agent-artifact-admission/tests/audit_path_safety_contract.rs; production remained byte-identical to parent #129@fb82aafe.... Hosted CI 34443639338, rust job 102763645422, acquired real ubuntu-24.04, passed checkout/toolchain/cargo fmt --check, then failed in the workspace Test step. The regression requires the file sink to reject a final symlink without modifying its target and to create a new audit file with no group/other permission bits even when an isolated child process runs under umask 000. This is semantic RED, not queue/bootstrap/format noise.

Minimum causal repair

Exact 68bebe7e15d0cdb436ad66eab47b61c053fee980 changes only crates/agent-artifact-admission/src/audit.rs: on Linux the existing append-only OpenOptions path now creates with mode 0600, opens with O_NOFOLLOW, and rejects non-regular final objects before returning the descriptor. Existing serialization, append-only behavior, bounded JSON encoding, flush + sync_data, and stable AuditError::StorageUnavailable mapping remain unchanged. Non-Linux builds fail this file-backed sink closed rather than pretending equivalent secure-open semantics without an implemented platform contract.

Exact current f527a4753037357ce7d67c78e75dda59acbe5ce5 narrows the platform-specific regression to Linux, matching the production implementation boundary. No security invariant was weakened.

Exact-current GREEN

On unchanged exact f527a4753037357ce7d67c78e75dda59acbe5ce5, repository-owned CI 34444655764 and Fuzz 34444655776 are terminal SUCCESS. Current submitted-review inventory is empty; current inline review-thread inventory is empty. Parent remains unchanged exact #129@fb82aafefb6f014875867407766b7d5e1d9dfcfb, so no restack is required.

This child is ready to integrate normally into #129. After integration, #129 must reacquire its own exact-head repository/security/coverage/package/SBOM/provenance/review/thread evidence; these child receipts do not transfer.

No quarantine execution, EgressWeave transport policy, contextual-orchestrator behavior, AppGuardrail analysis, foreign-owner source, cross-service SQL, force update, destructive rebase, self/model approval, gate weakening or predecessor evidence transfer.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 285dca06-a75b-42b9-864e-f28951cc5aa7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Semantic RED is now proven on unchanged test-only head 8b65dcd8febff005a18fa105ce779e4e22ddda74. CI 34443639338, rust job 102763645422, acquired hosted Ubuntu 24.04 runner 1001848106; checkout, toolchain and cargo fmt --check passed, the pre-existing Wardnet and Agent Artifact Admission tests passed, and only the new audit-path contract failed.

Exact failures: file_sink_rejects_final_symlink_without_modifying_target expected Err(StorageUnavailable) but current OpenOptions returned Ok(()), proving the final symlink was followed; newly_created_audit_file_is_private_even_with_permissive_umask observed mode & 0o077 == 54 (0o66) rather than zero under the isolated umask 000, proving creation inherited group/other access. The helper positive control passed. This is a semantic filesystem-authority RED, not runner/bootstrap/formatting noise.

Minimum causal repair is now authorized: change only the audit-file open/create boundary so Linux uses append/create with no-follow final-component semantics and creation mode 0600, verifies the opened descriptor is a regular file, and fails closed on platforms where this exact property is not implemented. Preserve serialization locking, bounded NDJSON, no truncation, flush + sync_data, and the stable storage error surface.

@seonghobae
seonghobae marked this pull request as ready for review September 10, 2026 07:01
@seonghobae
seonghobae merged commit bf5a48b into feat/agent-artifact-admission Sep 10, 2026
3 of 4 checks passed
@seonghobae
seonghobae deleted the test/admission-audit-path-safety branch September 10, 2026 07:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant