Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
95 commits
Select commit Hold shift + click to select a range
bca0a80
feat(provider): add the closed P17 driver envelope and capability con…
ajhcs Aug 22, 2026
79e0fa9
test(provider): add the provider-agnostic driver conformance harness
ajhcs Aug 22, 2026
bafa8d7
docs(changelog): record the P17 driver contract
ajhcs Aug 22, 2026
a28b3ed
feat(v3): add the strict relative artifact path policy
Aug 22, 2026
773b44f
feat(v3): bind the closed ArtifactRefV1 contract and digest authority
Aug 22, 2026
bb452c6
docs(changelog): record the P07 artifact reference and path policy
Aug 22, 2026
de743a1
feat(run): add durable local run store with exclusive idempotent subm…
ajhcs Aug 22, 2026
da69ebe
test(run): cover hostile replay, restart, and path-safety
ajhcs Aug 22, 2026
3cf06ab
docs(changelog): record the P24 durable run store
ajhcs Aug 22, 2026
778cc01
feat(v3): add the atomic raw/sanitized artifact store
Aug 22, 2026
88c3bb7
test(v3): pin the atomic artifact store against hostile callers
Aug 22, 2026
0cbd6b8
docs(changelog): record the P08 atomic artifact store
Aug 22, 2026
ef0d7dc
fix(v3): reject reserved parents and verify stored snapshots
ajhcs Aug 22, 2026
210545c
feat(v3): add digest-checked sanitized range primitive and reader con…
ajhcs Aug 22, 2026
832016f
feat(v3): tell clipping from unknown upstream truncation
ajhcs Aug 22, 2026
b161519
feat(redaction): stream sanitized artifact content
ajhcs Aug 22, 2026
498aeac
test(v3): pin the bounded sanitized reader against hostile callers
ajhcs Aug 22, 2026
aca00c1
feat(redaction): protect chunk-boundary secrets and Unicode
ajhcs Aug 22, 2026
d80a8fd
test(redaction): add split-token and oversized-stream cases
ajhcs Aug 22, 2026
04c904c
feat(grok): add the Grok ACP ProviderDriverV1 adapter
ajhcs Aug 22, 2026
08d533c
test(grok): cover injected Grok ACP transport sequences
ajhcs Aug 22, 2026
6ac19db
docs(changelog): record the P18 Grok ACP driver slice
ajhcs Aug 22, 2026
f2dda07
fix(grok): close replay and terminal lifecycle boundaries
ajhcs Aug 22, 2026
738cb4e
fix(redaction): deny own overrides on intrinsic byte views
ajhcs Aug 22, 2026
e143944
merge: compose accepted P10 reader with accepted P09 sanitizer
ajhcs Aug 22, 2026
3c4a145
merge: compose accepted P17 driver contract for P11
ajhcs Aug 22, 2026
760d62d
feat(provider): add the DSH ACPX provider driver for Muse Spark and O…
Aug 22, 2026
4884814
test(provider): add DSH ACPX driver conformance and hostile coverage
Aug 22, 2026
a089b28
docs(changelog): record the P20 DSH ACPX driver slice
Aug 22, 2026
c977085
fix(provider): make DSH terminal evidence absorbing
ajhcs Aug 22, 2026
0450a2e
merge: compose accepted P20 with accepted P18
ajhcs Aug 22, 2026
86fc0c4
feat(provider): route local ACP results to artifacts
ajhcs Aug 23, 2026
f64a463
feat(provider): retain bounded sanitized inline tails
ajhcs Aug 23, 2026
48c1a1c
test(provider): cover Grok Cursor and DSH result limits
ajhcs Aug 23, 2026
8a9596f
fix(provider): bind P11 sink identity and fail closed
ajhcs Aug 23, 2026
ca34c38
merge: compose accepted provider adapters with P11 result sink
ajhcs Aug 23, 2026
02b4696
feat(provider): add minimal driver template
ajhcs Aug 23, 2026
a594cd8
test(provider): publish reusable conformance fixtures
ajhcs Aug 23, 2026
54fba3b
docs(provider): document capability and evidence requirements
ajhcs Aug 23, 2026
fc40f97
refactor(cloud): implement SDK driver
ajhcs Aug 23, 2026
1bd23d9
feat(cloud): reconcile pushed base agent run and branch identity
ajhcs Aug 23, 2026
6c3ef97
test(cloud): cover cancel, terminal latches, and archive evidence
ajhcs Aug 23, 2026
65bcb9b
test(cloud): enforce no-PR and hostile receipt boundaries
ajhcs Aug 23, 2026
3ae392e
feat(evidence): define provider claim and verified fact types
ajhcs Aug 23, 2026
d8dca96
feat(evidence): define discrepancy and artifact references
ajhcs Aug 23, 2026
b06b62f
merge(provider): compose accepted Cursor Cloud driver
ajhcs Aug 23, 2026
4310661
test(evidence): reject unproven accepted states
ajhcs Aug 23, 2026
13dfccb
fix(evidence): require proof artifacts for model attestation
ajhcs Aug 23, 2026
f0bccd6
chore(integration): compose evidence and provider result clusters
ajhcs Aug 23, 2026
0ec4386
feat(authority): define protected refs and branch namespaces
ajhcs Aug 23, 2026
a8cebdf
feat(authority): prohibit merge push and create-pr operations
ajhcs Aug 23, 2026
a1b33f9
test(authority): reject merge histories and default-branch targets
ajhcs Aug 23, 2026
3857ba6
feat(verify): add trusted VerificationPolicyV1 schema and owner loader
ajhcs Aug 23, 2026
5bc7095
test(verify): cover focused and adversarial trusted-policy surfaces
ajhcs Aug 23, 2026
60c2666
docs(changelog): record the P16A trusted verification policy
ajhcs Aug 23, 2026
8c620cb
fix(authority): require trusted receipts for evidence projection
ajhcs Aug 23, 2026
a624914
fix(verify): close missing-catalog deny, exotic options, and env acce…
ajhcs Aug 23, 2026
18beb83
feat(verify): validate repository base branch and head
ajhcs Aug 23, 2026
66a14e3
feat(verify): validate ancestry and merge base
ajhcs Aug 23, 2026
ded99cb
test(verify): add forged stale and rewritten history fixtures
ajhcs Aug 23, 2026
43732b4
fix(verify): close hostile Git provenance boundaries
ajhcs Aug 23, 2026
e2004b4
merge: compose accepted P14 verifier
ajhcs Aug 23, 2026
f54a2d2
feat(verify): add approved verification-command resolver
ajhcs Aug 23, 2026
8cda832
test(verify): cover focused and adversarial approved-command surfaces
ajhcs Aug 23, 2026
fbbf622
docs(changelog): record the P16B approved-command resolver
ajhcs Aug 23, 2026
dec2280
merge: compose accepted P16B resolver
ajhcs Aug 23, 2026
f3a7cf9
feat(verify): add the scope, read-only, and merge-commit verifier
ajhcs Aug 23, 2026
95049bc
test(verify): cover ownership, merge, unicode, and observation races
ajhcs Aug 23, 2026
42c2d09
docs(changelog): record the P15 scope verifier
ajhcs Aug 23, 2026
5915212
feat(verify): add constrained verification runner
ajhcs Aug 23, 2026
3064e38
test(verify): cover focused and adversarial runner surfaces
ajhcs Aug 23, 2026
f3ca446
docs(changelog): record the P16C constrained verification runner
ajhcs Aug 23, 2026
2c886cf
fix(verify): close ignored, index, merge-head, copy, lstat, and fsmon…
ajhcs Aug 23, 2026
eaf50bd
merge: compose accepted P15 scope verifier
ajhcs Aug 23, 2026
caf1bd4
fix(verify): close P16C isolation and cleanup blockers
ajhcs Aug 23, 2026
7c57e7b
merge: compose accepted P16C runner
ajhcs Aug 23, 2026
c6a231b
feat(provider): add the cursor-local driver lifecycle
Aug 23, 2026
01160e4
test(provider): prove the cursor-local driver against hostile callers
Aug 23, 2026
997fba8
docs(provider): specify the cursor-local driver reconstruction
Aug 23, 2026
03b6d3b
fix(provider): close the option quarantine and session-correlation seam
Aug 23, 2026
04de7cb
Merge commit '03b6d3b1856e725d915dbfc19e8c8fdace0b5a98'; commit '54fb…
ajhcs Aug 24, 2026
1d071be
feat(provider): add the closed provider registry composition authority
Aug 24, 2026
22d8c01
test(provider): compose every accepted driver behind the P23 registry
Aug 24, 2026
f6467f1
docs(provider): record the P23 registry cutover boundary
Aug 24, 2026
8635f4c
Merge accepted P28 Git authority into P23 baseline
ajhcs Aug 25, 2026
69201ad
Merge accepted P24 durable run store into P23 baseline
ajhcs Aug 25, 2026
c7c36db
feat(run): validate exact repository and base SHA
ajhcs Aug 25, 2026
b359a5c
feat(run): enforce eight-child and independent-fanout limits
ajhcs Aug 25, 2026
fba6e6e
feat(run): detect overlapping writer scopes and capacity
ajhcs Aug 25, 2026
f0508fb
test(run): prove no workspace exists after failed preflight
ajhcs Aug 25, 2026
b4f2fd9
feat(boundary): strip Git SSH and hosting credentials
ajhcs Aug 25, 2026
2947e01
feat(boundary): load provider auth without process-argument secrets
ajhcs Aug 25, 2026
74a8016
feat(boundary): disable worker push URLs
ajhcs Aug 25, 2026
8f7eea9
test(boundary): inspect and close credential isolation
ajhcs Aug 25, 2026
0fd091e
merge: compose accepted P26 and P29
ajhcs Aug 25, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
348 changes: 348 additions & 0 deletions CHANGELOG.md

Large diffs are not rendered by default.

3 changes: 3 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,9 @@ and local; sanitized bounded evidence is the model-facing projection.
Profiles are data-only. `VerificationPolicyV1` is the only executable
command catalog for verification lanes; provider-reported or requested
commands are evidence/attention and are never automatically executed.
The constrained verification runner executes only a genuine owner-approved
ExecutionIntent in a disposable workspace and does not treat
provider-reported PASS as a fact.
Manual run cleanup is proof-bound; there is no automatic garbage
collection.

Expand Down
7 changes: 7 additions & 0 deletions docs/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,13 @@ Codex-Co-Engineer has no executable project policy file. The only
project-scoped configuration data is the data-only ProfileV1 catalog
described in [Profiles](#profiles); verification commands never come from
profiles and remain a separate owner-maintained `VerificationPolicyV1`.
The approved-command resolver consumes that owner policy plus a closed
Codex/owner `command_id` selection and returns a frozen ExecutionIntent
receipt; it does not execute the command. The constrained verification
runner consumes only a genuine P16B receipt plus that trusted policy,
runs the exact owner-approved executable and argv once in a disposable
workspace separate from the candidate, and records bounded sanitized
host-observed evidence. It is not wired into the MCP server.
Provider authentication is normal persistent login/session state or an
owner-only key file. The setup command installs the pinned local composition
and creates the default DSH configuration; it never performs login on the
Expand Down
137 changes: 137 additions & 0 deletions docs/credential-isolation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,137 @@
# Credential and remote-mutation isolation (P29)

Status: implemented as an additive v3 boundary
Complements: [threat model](threat-model.md), [ADR 0001](adr/0001-r1-bounded-run-architecture.md), P23 provider registry, P28 Git authority policy

P29 is the credential and remote-mutation isolation boundary. It does not
sandbox a selected provider, substitute for P23 composition, or replace P28
policy. Same-UID malicious filesystem access is outside this non-sandboxed
boundary. P30 live protected-ref audit remains later work.

## Closed environment projection

Supervisor launch, the systemd service, the credential-handoff loader
child, nested Grok/Cursor Local ACP children, and readiness children
receive a **closed** provider/operation environment. Projection starts
empty and copies only allowlisted operational keys plus the selected
provider's required route. It does not enumerate caller objects, so
hostile getters on unrelated keys never run. It does not spread
`process.env` and does not rely on a denylist.

The following never reach provider or readiness children:

- Git, SSH, and hosting credentials (`GIT_*` except a small hardening set,
`SSH_*`, `GH_TOKEN` / `GITHUB_*` / GitLab / Bitbucket tokens, askpass,
`insteadOf`, push URLs);
- control tokens (`WORKTREE_BOOTSTRAP_*`, MCP/supervisor lock secrets,
state-root tokens);
- owner-only key-file **paths** (`*_API_KEY_FILE` and Co-Engineer file
pointers);
- unrelated ambient secrets, `FAKE_ACPX_*`, and `NODE_OPTIONS` / `NODE_PATH`.
Explicit test injection of `FAKE_ACPX_*` is a closed in-process hook, not
ambient `process.env`.

Lane hardening always sets `GIT_TERMINAL_PROMPT=0`, empty `GIT_ASKPASS`,
and `GIT_PUSH_OPTION_COUNT=0`. That is not a git sandbox; it removes the
platform's push/credential-helper environment.

## Provider route isolation

| Route | Receives | Does not receive |
| --- | --- | --- |
| Grok | `XAI_API_KEY` when present, Grok command, operational keys | Muse/Ox/Cursor keys, Git/SSH/hosting, key-file paths |
| Cursor Local | Cursor command, operational keys (CLI session under `HOME`) | `CURSOR_API_KEY`, Muse/Ox/Grok keys |
| DSH Muse | `MODEL_API_KEY`, Muse config path, DSH/ACPX commands | `OPENROUTER_API_KEY`, Grok/Cursor keys |
| DSH Ox | `OPENROUTER_API_KEY`, Ox config path, DSH/ACPX commands | `MODEL_API_KEY`, Grok/Cursor keys |
| Cursor Cloud local SDK | `CURSOR_API_KEY` plus bounded repository/ref/prompt data | Other provider keys, Git/SSH/hosting, key-file paths |
| Cursor Cloud remote | Credential-free origin URL, pinned SHA, prompt, optional `create_pr` flag | Local credentials, SSH agent, hosting tokens, key files |

Readiness probes use the same closed maps. DSH `--version` / `which` and
`npm root --global` do not inherit ambient secrets. Credential presence for
DSH and Cursor Cloud is checked by an in-process owner-only file read, not
by leaking the value into an unrelated child.

## Credential file reads

Credential values may come from the selected env key or from an owner-only
file. File reads require:

- an absolute, normalized path. Credential-file overrides are checked
before any `path.resolve` conversion; relative, non-normalized, and
double-separator inputs fail closed;
- `O_NOFOLLOW|O_RDONLY|O_NONBLOCK` open of a regular file;
- owner equal to the effective UID;
- exact mode `0600`;
- link count 1 (hardlinks denied);
- size in `1..=16 KiB`;
- a post-read `fstat` identity match (dev/ino/mode/nlink/uid/size/mtime/ctime).

Errors are content-free: they never echo the path, the bytes, or the
credential. Symlink, FIFO, directory, oversize, empty, owner, mode, and
in-place swap during read fail closed. Same-UID replacement of a path
between checks is the documented non-sandbox residual.

## systemd-run argv handoff

Credential values never appear in `systemd-run` argv. Non-secret projected
keys may use `--setenv`. `systemd-run --setenv` is additive to the
user-manager environment, so the unit also sets `UnsetEnvironment=` for
inherited names that are not in the closed projection and exec's the
service through `env -i` of that same allowlist. Secret keys are written
to a bounded owner-only no-follow regular file under `XDG_RUNTIME_DIR`
(else the process temp dir), mode `0600`, directory `0700`. The service
command is always wrapped by `credential-handoff-loader.mjs`, including
Cursor Local which has no provider secrets of its own, so the worker is
never the manager-inherited leader.

The loader opens the file with the same no-follow rules, applies the
values, unlinks the file (and best-effort the directory), then runs the
original command as a child with a closed service projection plus those
credentials. It does not spread `process.env`. Nested Grok and Cursor
Local ACP children receive that same closed projection through
`createAcpRuntime` / `closedProviderEnv`; ACPX does not start from
ambient `process.env`. The loader stays the service leader so
`KillMode=control-group` still reaches descendants.

Cleanup unlinks any remaining handoff file after spawn failure, cancel,
terminal stop, or a later restart (a restart creates a new file). The
bounded internal identity is the process-boundary unit token, from which
the owner-only handoff path is reconstructed without persisting the path
or credential values on the public receipt. Stale identity directories
can be recovered the same way. The short-lived `systemd-run` client
receives only the D-Bus session keys needed to talk to the user manager
(`DBUS_SESSION_BUS_ADDRESS`, `XDG_RUNTIME_DIR`, `XDG_SESSION_ID`).

Cursor Cloud workers are local Node processes, not systemd services; they
still receive the closed projection and never put secrets in argv.

## Exact-value redaction

ACP events, public errors, worker logs, and Cursor Cloud receipts redact
the exact credential values for the selected route, including values of
length 1–3 and 16 KiB secrets split across chunks, events, errors, and
logs. Redaction uses the full value plus overlapping 32-byte fragments so
a chunked log line cannot reassemble the secret. Pattern redaction for
common token shapes remains as defense in depth.

## No worker remote-mutation authority

Workers do not receive push URLs, credential helpers, or hosting tokens.
Profiles and manifests stay data-only. This boundary denies worker
push/merge/rebase/PR/tag/release/protected-ref/credential-helper/remote
mutation rather than performing those Git operations. P28 remains the
authority-policy seam; P29 does not wrap it and does not audit live refs
(P30).

Cursor Cloud `create_pr` stays a supervisor-to-remote SDK option. It is
not merge authority, does not send local Git/SSH/hosting credentials, and
does not grant workers a push URL.

## Compatibility

P23 `provider-registry.mjs` remains the only composition authority for the
four accepted adapters. P29 does not add a fifth slot, a wrapper factory,
or ambient discovery. P28 `git-authority.mjs` remains policy at the
authority seam; P29 consults its denied-operation vocabulary without
mutating Git. 3.2.1 Muse/Ox credential routing (one route never substitutes
the other) is preserved.
118 changes: 118 additions & 0 deletions docs/cursor-cloud-driver.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,118 @@
# Cursor Cloud SDK provider driver (P21)

Status: implemented against an injected bounded Cursor SDK transport port.
Not real-transport qualified.

The P21 `CursorCloudDriverV1` (`plugins/codex-co-engineer/mcp/v3/cursor-cloud-driver.mjs`)
is the Cursor Cloud adapter over the accepted P17 `ProviderDriverV1`
contract. It owns only the Cloud-specific wiring; every request/result
shape, capability posture, transition rule, and denial code is inherited
from the accepted contract. It defines no parallel envelope or capability
schema. Existing `mcp/v3/cursor-cloud-worker.mjs` is unchanged.

## Hard binding

- Provider slot: `cursor-cloud` exactly. Every other provider fails closed
with `provider_slot_mismatch`.
- Exact requested and effective model: preflight is ready only when the
transport attests the envelope model on both `requested_model` and
`effective_model`. Substitution is `model_unattested`.
- Workspace: remote provider-managed, starting at a pinned pushed SHA. The
envelope `starting_ref` must be a lowercase 40-hex commit identical to
the immutable run `base_sha`.
- Repository identity: credential-free host/path plus https URL. Credentials,
query, fragment, and mutable/duplicate identities fail closed.

## Honest capability

The shipped declaration is fixed to:

- `workspace_semantics: remote_provider_managed`
- `workspace_starting_point: pinned_pushed_sha`
- `exact_model_selection: exact_and_attested`
- `dispatch_certainty: confirmed_launch`
- `same_session_reply: unsupported_unresolved_attention`
- `create_pr_posture: prohibited`
- `merge_authority: none_codex_only_integration`
- `replay_posture: never_replay`

Concretely:

- Launch reports `dispatched` only after an authoritative SDK run identity:
cloud agent id, provider run id, and stable request id, plus branch
identity.
- Any uncertainty after create or send intent is `dispatch_uncertain` and is
never replayed, retried, or fallback-substituted.
- Same-session reply is unsupported. Reconcile surfaces pending questions as
`unresolved_attention` and never starts a replacement run.
- `auto_create_pr` is always `false`. Merge, create-PR, and push keys fail
closed.

## Preflight rejections

Preflight blocks (closed detail pair, no transport-authored text):

- dirty checkout
- absent origin
- non-commit starting ref
- invisible starting SHA
- base advancement (`head_sha` or starting SHA drifted from the pin)
- unattested model

Preflight throws (security/identity):

- credential-bearing repository identity
- ambiguous duplicate identities
- automatic PR authorization

## Injected bounded SDK transport port

`createCursorCloudDriverV1(transport)` / `bindCursorCloudDriverV1(transport)`
require a plain record exposing exactly six concrete synchronous functions
(Proxies, accessors, exotic prototypes, missing or extra operations are
denied):

| Operation | Argument (frozen, bounded) | Receipt |
| ----------- | -------------------------- | ------- |
| `preflight` | child identity + starting SHA | workspace cleanliness, visibility, attested model, repository identity |
| `create` | identity + `auto_create_pr: false` | `{ created, agent_id, ...identity }` |
| `send` | identity + `agent_id` + `request_id` + envelope text | `{ acknowledged, agent_id, provider_run_id, request_id, branch, ...identity }` |
| `observe` | exact recorded agent/run/request identity | status plus independently verifiable Git/branch/base evidence |
| `cancel` | exact recorded agent/run/request identity | `{ outcome, archived, ...identity }` |
| `reattach` | exact recorded agent/run/request identity | `{ reattached, agent_id, provider_run_id, request_id, ...identity }` |

Reconcile mapping: `running → in_progress`, `needs_attention →
unresolved_attention`, `completed/failed/cancelled → terminal` after Git
evidence verification, `lost → dispatch_uncertain`. Terminal verification
requires provider-reported state plus head SHA, merge-base, and branch.
The adapter claims nothing the transport did not expose.

`restart_reattach` recovers only the exact recorded agent/run/request
identity and never relaunches.

## Cancellation and terminal latches

Cancel targets only the exact recorded run. The receipt must report both
`outcome` (`cancel_requested` / `cancel_confirmed` / `already_terminal`) and
a boolean `archived`. `cancel_requested` stays nonterminal so a later cancel
may still be delivered. Completed/failed/cancelled observe status and
`cancel_confirmed` / `already_terminal` latch: later cancel is
`already_terminal` with no further transport.

## Bounds and telemetry hygiene

Event pages are at most 32 records of `{ kind, bytes }` from a closed kind
vocabulary. Detail messages are composed only from closed vocabulary words
and validated identifiers. Provider prompt, envelope text, secrets, PR URLs,
and transport-authored strings never reach a driver result, a detail pair,
or inspectable evidence.

## Coverage and non-claims

Coverage lives in `test/r1-cursor-cloud-driver.test.mjs` and
`test/r1-cursor-cloud-driver-adversarial.test.mjs`.

This slice does NOT qualify a real Cursor Cloud transport. It claims no
durable store, scheduler, registry cutover, supervisor cutover, merge
authority, or automatic PR creation. One Luna Max exact review follows;
real Cursor Cloud transport qualification follows exact acceptance.
Loading
Loading