Repository navigation
Verify host answer attestations before durable delivery - #1034
Conversation
|
Independent review gate: PASS
Reviewer inspected all twelve changed files and relevant persistence/protocol contracts, verified the candidate GPG signature, and independently reran 235 tests across nine files with --reporter=default --maxWorkers=1. Eight disposable memory/SQLite probes confirmed that changed head, ended session, expired challenge and changed context prevent a post-admission send claim. Checkout remained clean at the exact candidate. Reviewer verified supplied operation/terminal hashes, manifest and all five receipt/output hash chains. Native fixture source, executable, harness and config hashes match; its persisted signature verifies, stored capture/answer and delivery hash agree, native question bytes match, and the hold remains active. Residual limits: configured-host attestation requires separately qualified human authentication and signing-root protection. Local writes do not prove production consumption or release holds. Storage fencing and pipe writes lack atomic exclusion. Native containment and reboot qualification remain future work. Generic serializer defect #1033 remains open. Author gate evidence: all five exact-head gates passed with complete retained closure. Main CI37568293520 and auxiliary CLI/performance checks passed at the candidate. Native controlled provider observed the persisted answer, one write, and retained hold after reopen and cleanup; no real human UI/authentication, inference or production authority was qualified. |
A worker-supplied identity string must not approve a captured human question, and lost persistence or pipe acknowledgements must not resend its answer. The portable human-hold service now verifies Ed25519 attestations from explicitly configured, Run-scoped human hosts, persists the exact signed answer, and commits one fenced send slot before the owned Codex adapter writes.
Challenges bind the complete question/capture/context and generation/expiry. Trusted keys and allowed actors are immutable constructor inputs; answers cannot enroll a key. Stale context/workspace/session, revoked trust, superseded questions and expired challenges refuse new sends. Claim replay is inspection only. Lost claim/write ACKs, takeover and pipe errors leave durable reconciliation state without automatic retry. String and numeric native request IDs remain distinct.
writtenrecords a local pipe observation, not worker consumption. Signed host admission does not independently prove the host's real human UI or key protection. This is source-only: no signer installation/enrollment, public CLI/MCP answer endpoint or autonomous controller. Captured-question completed receipts remain refused until the real human channel, consumption reconciliation and action boundary are qualified. The core imports no Codex/UI code; both Codex UI and a separate inbox remain possible hosts.Validation: 235 focused tests across nine files; lint/type/docs/format, build, packed boundary and pinned-npm install policy. Exact-candidate installed Codex 0.145.0 probe used isolated SQLite, a simulated workspace binding, an ephemeral controlled signer and a local non-inferencing provider. Codex's next request contained the exact persisted answer as tool output, with one write and five events; reopen/interruption retained the hold. This is fixture conformance, not production human authentication, native containment or OS reboot qualification.
Context binding now preserves special JSON keys while retaining ordinary compact hashes. The separate generic SQLite serializer defect is tracked in #1033 and remains outside this change.
Refs #1026. Independent exact-head review and CI are required before merge.