Skip to content

Derive the serve peer's identity from its credential - #344

Merged
SaladDay merged 1 commit into
feature/agent-outside-sandboxfrom
aos/link-serve-identity
Oct 1, 2026
Merged

SaladDay merged 1 commit into
feature/agent-outside-sandboxfrom
aos/link-serve-identity

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Link protocol change: the serve peer's identity now comes only from its credential.

ServeHello.PeerID had no source on the serve side, because the Sandbox I/O bootstrap carries no peer ID, and the relay only compared it with the Authority's answer. The Hello now carries no peer ID. The Authority still returns ServePeer{PeerID, Resource} for the credential, and the relay requires only Resource to equal the Hello's.

  • internal/sandboxlink: the ServeHello type, its codec and validation, ServeConfig, the relay check, and the golden frames in testdata/link_v1.hex.
  • docs/sandbox-link-protocol.md: the Hello listing and the serve-peer Authority rule.

Checks:

  • go test -race on link, relay and bootstrap
  • FuzzDecode, 20 s
  • vet and gofmt
  • darwin and windows builds
  • markdown link check

Part of the agent-outside-sandbox work, milestone M1. Found while assembling oac-sandbox-io (lane L3b).


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit b1702aa into feature/agent-outside-sandbox Oct 1, 2026
1 check passed
@SaladDay
SaladDay deleted the aos/link-serve-identity branch October 1, 2026 00:39
ServeHello no longer carries a PeerID: the serve side has no source for it
and the credential already identifies the peer. The relay checks only the
Hello's Resource against the Authority's ServePeer, which still returns the
peer's identity. Updates the codec, validation, serve config, relay, tests,
golden frames and the Link protocol document.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant