Repository navigation
fix(cp06): harden read-only Pi authentication proof - #11
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Implement and independently validate the captain-authorized CP-06 security correction on top of PR10 head 385b80e while preserving PR8/PR9 ancestry and all corrected R1-R3 behavior. Replace Pi 0.85.1 CLI-default writable AuthStorage with the public SDK: inject a tiny private CredentialStore whose modify/delete reject before callback entry or persistence, use ModelRuntime.create with refreshOnCreate:false/allowModelNetwork:false/modelsPath:null, and createAgentSession with an explicit empty resource loader, in-memory session/settings, exactly built-in read, one exact-original read, and compact hashed event audit. Accept only expected openai-codex OAuth and explicit built-in model; require enough unexpired validity for the bounded worker, and block expired/near-expiry/unsupported Pi before provider request with no refresh, fallback, token export, persistent copy, credential contents, or raw transcript.
Harden the Linux x86-64 proof runner by pinning the regular credential inode O_RDONLY|O_NOFOLLOW, creating distinct source and regular target bind mounts verified ro,nosuid,nodev,noexec in a private user/mount namespace, closing inherited credential FDs, and launching the evaluated SDK child with empty capability sets, locked noroot/no_setuid_fixup securebits, no_new_privs, parent-death handling, and inherited seccomp denial of mount/unmount and new mount APIs, unshare/setns/namespace-bearing clone and clone3, handle-based inode access, ptrace/process memory writes, and child escape tricks. DUMMY-only actual evaluated-child adversarial proofs must cover direct write/unlink/rename/symlink/hardlink, remount/unmount/parent bind, nested user namespace/setns/clone/clone3, UID changes and subprocesses; retain an unsafe CAP_SYS_ADMIN DUMMY control that reproduces mutation. Expired and near-expiry local fake-provider cases must prove zero refresh callback and zero persistence, while normal unexpired OAuth and offline faux SDK event behavior pass without network. Abort before any real credential mount/model when DUMMY preflight, exact Pi version, namespaces, libseccomp, capabilities, seccomp, setup or cleanup is unavailable; unsupported platforms exit blocked with no fallback. Never run a destructive probe against real credentials. Real model proof may run only after the DUMMY and no-refresh protections demonstrably pass and ordinary auth preflight has sufficient validity; otherwise record blocked, never passed. State Linux/WSL2-only limits and make no Windows/macOS claim.
Preserve the existing 98-test-expanded suite (formerly 90), ten-pack 10/10 relevant and zero irrelevant topical provenance, P-07 replay, exact-original/recovered creation rule, budgets, hashes, dates, reviewer and command/exit manifests. Do not change production Factory CLI behavior, Firstmate routing/shipping, CP-07, external tools, or create another orchestrator/gate. Validate npm ci, format check, lint, typecheck, full tests, actual DUMMY OS proof, real offline CTX ten-pack, P-07, and git diff check at the exact final SHA. Ship through this isolated Pi-backed no-mistakes run to a new green PR; never merge. The PR must request independent exact-head critical security/acceptance audit and must not claim CP-06 completed from green CI alone.
What Changed
--documentfilters and block provenance outside that selected retrieval scope.Risk Assessment
Testing
Exercised the focused worker read-audit regression, DUMMY OS/auth-security proof, real offline CTX ten-pack proof, P-07 replay, and isolated real SDK worker proof; all passed and reviewer-visible JSON evidence was copied to the no-mistakes evidence directory, with transient worktree build/state artifacts removed afterward.
Evidence: CP-06 auth-security DUMMY OS proof evidence
Evidence: CP-06 ten-pack offline CTX proof evidence
Evidence: CP-06 P-07 replay evidence
Evidence: CP-06 isolated SDK worker evidence
/home/ansh/.treehouse/Factory-86709f/10/Factory/.factory/nm6/.no-mistakes/evidence/01M3ST105N1602TMRXJVFQNY2Z/cp06-worker-read-audit-behavior.json)Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 1 issue found → auto-fixed ✅
scripts/cp06-worker-audit.mjs:78- User intent requires the worker use "one exact-original read" and the prompt requires it "without offset or limit", but the audit accepts a read event with args{ path: originalPath, offset: 1 }as long as the returned bytes equal the original. That leaves the proof able to pass a non-conforming SDK read invocation instead of enforcing no offset/limit.🔧 Fix: Enforce exact original read arguments
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
node --test test/cp06-worker-audit.test.mjsnpm run proof:cp06:auth-securitynpm run proof:cp06:ten-packnpm run proof:cp06:p07npm run proof:cp06:workerGeneratedcp06-worker-read-audit-behavior.jsonevidence showing valid exact-original read accepted and explicit offset/limit rejected even with complete returned bytes✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.