Skip to content

fix(optics): P1 security slice, including api_base lockdown - #145

Merged
zacharybalicki merged 5 commits into
mainfrom
cursor/optics-p1-security-split-c44b
Oct 1, 2026
Merged

zacharybalicki merged 5 commits into
mainfrom
cursor/optics-p1-security-split-c44b

Conversation

@zacharybalicki

@zacharybalicki zacharybalicki commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

CANDIDATE_ONLY. No npm publish, no PyPI publish, and no install.vantio.ai go-live.

Kate queue

Order: #142 → #144 → #145 → #146 → #148 (#147 already merged).

Approve exact head only (kvantio). No admin bypass.

Current head: 8b0af9e29f45a6aa230a4b843f6125d729a14c09

What this does

  • The installer refuses a symlinked stage with lstat and O_NOFOLLOW and leaves the target.
  • Live apply, rollback, and uninstall require effective uid 0.
  • The observe image pins @vantio/cli@0.3.24 and starts vantio run node.
  • gate_get_policy and gate_residual_risk read VANTIO_API_KEY from the environment. They do not take an api_key argument.
  • Those tools also do not take api_base. The host is VANTIO_API_BASE, or https://api.vantio.ai when that variable is unset or blank. A caller-supplied host is ignored.
  • Source metadata records @vantio/gate-mcp 0.1.1 as a candidate. Not an npm release.

Not in this pull request

Optics enforcement removal was #147 (merged). Observation fixes are #146. CLI 0.3.25 and Python 3.1.1 candidate notes are #148.

Do not merge until CI is green, independent council is PASS or PASS_WITH_NONBLOCKING_NOTES, and exact-head kvantio APPROVE.

Refuse a symlinked installer stage, require effective root for live
mutations, pin the observe image to CLI 0.3.24 and wrap node, and read
the gate-mcp API key from the environment. @vantio/gate-mcp 0.1.1 is a
source candidate only.
The API-key environment tests ship in this pull request. CI has to
run them before the slice can be called green. Source candidate only.
gate_get_policy and gate_residual_risk no longer take api_base.
The key goes to VANTIO_API_BASE, or https://api.vantio.ai when that
variable is unset or blank. A tool argument cannot choose the host.
Source candidate only. Not published.
The security slice bumps @vantio/gate-mcp to 0.1.1 in source only.
Version metadata, the AI guide, and the generated release inventory
now match that candidate. Not an npm release.
The documentation release check rebuilds llms-full.txt from the canonical guide. The guide already names gate-mcp 0.1.1 and the host lockdown. This file now matches that rebuild.

CANDIDATE_ONLY. Not published.
@zacharybalicki
zacharybalicki merged commit a81df8b into main Oct 1, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants