mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-06 06:52:20 +02:00
docs(runtime): record Wave 3 closure evidence and contracts
This commit is contained in:
@@ -0,0 +1,102 @@
|
||||
tests/test_action_intents_shell_verbs.py
|
||||
tests/test_auth_config_lock_concurrency.py
|
||||
tests/test_auth_disabled_document_access.py
|
||||
tests/test_auth_event_loop.py
|
||||
tests/test_auth_policy.py
|
||||
tests/test_auth_regressions.py
|
||||
tests/test_auth_require_privilege_nondict.py
|
||||
tests/test_auth_root_path.py
|
||||
tests/test_auth_session_revocation.py
|
||||
tests/test_background_chat_completion_ui_static.py
|
||||
tests/test_background_containment.py
|
||||
tests/test_background_resource_identity.py
|
||||
tests/test_background_tool_jobs.py
|
||||
tests/test_bg_job_tools.py
|
||||
tests/test_bg_jobs_store.py
|
||||
tests/test_bg_monitor_stream.py
|
||||
tests/test_browser_identity_transport.py
|
||||
tests/test_browser_lifecycle.py
|
||||
tests/test_browser_observation.py
|
||||
tests/test_browser_producer_live_contract.py
|
||||
tests/test_browser_progress.py
|
||||
tests/test_browser_resource_identity.py
|
||||
tests/test_browser_screenshot_artifact_safety.py
|
||||
tests/test_browser_target_correction.py
|
||||
tests/test_browser_transport_recovery.py
|
||||
tests/test_builtin_actions_cookbook_serve_state.py
|
||||
tests/test_builtin_actions_nonstring.py
|
||||
tests/test_builtin_actions_owner_scope.py
|
||||
tests/test_builtin_mcp_bg_tasks.py
|
||||
tests/test_chat_background_stream_isolation.py
|
||||
tests/test_chat_helpers_bg_tasks_tracked.py
|
||||
tests/test_chat_preprocess_tool_policy.py
|
||||
tests/test_codex_cookbook_admin_gate.py
|
||||
tests/test_containment_process_tree.py
|
||||
tests/test_cookbook_agent_tool_ssh_validation.py
|
||||
tests/test_cookbook_cache_scan_isolation.py
|
||||
tests/test_cookbook_cached_scan_refresh.py
|
||||
tests/test_cookbook_chat_deeplinks_static.py
|
||||
tests/test_cookbook_cpu_only_serve.py
|
||||
tests/test_cookbook_dead_download_status.py
|
||||
tests/test_cookbook_dependency_completion_regression.py
|
||||
tests/test_cookbook_deps_recipes.py
|
||||
tests/test_cookbook_diagnosis.py
|
||||
tests/test_cookbook_diagnosis_js.py
|
||||
tests/test_cookbook_docker_access.py
|
||||
tests/test_cookbook_download_toast_duration.py
|
||||
tests/test_cookbook_endpoint_registration.py
|
||||
tests/test_cookbook_error_feedback.py
|
||||
tests/test_cookbook_error_tail_lines.py
|
||||
tests/test_cookbook_finished_download_label.py
|
||||
tests/test_cookbook_gemma4_thinking_template.py
|
||||
tests/test_cookbook_helpers.py
|
||||
tests/test_cookbook_hf_token.py
|
||||
tests/test_cookbook_local_serve_pid_winpid.py
|
||||
tests/test_cookbook_official_trending_filter.py
|
||||
tests/test_cookbook_package_detection.py
|
||||
tests/test_cookbook_port_parsing_js.py
|
||||
tests/test_cookbook_progress_signal_js.py
|
||||
tests/test_cookbook_remote_windows_diffusers.py
|
||||
tests/test_cookbook_same_host_server_profiles_js.py
|
||||
tests/test_cookbook_serve_lifecycle.py
|
||||
tests/test_cookbook_stop_without_procfs.py
|
||||
tests/test_cookbook_tool_dry_run.py
|
||||
tests/test_cookbook_windows_stop_tree_js.py
|
||||
tests/test_deep_research_browser_fallback.py
|
||||
tests/test_doc_library_open_orphaned.py
|
||||
tests/test_docs_no_orphan_images.py
|
||||
tests/test_document_editor_background_static.py
|
||||
tests/test_email_oauth_connect_smtp_security.py
|
||||
tests/test_email_oauth_docker_config.py
|
||||
tests/test_email_oauth_settings_redirect.py
|
||||
tests/test_host_shell_polling.py
|
||||
tests/test_orphan_reaping.py
|
||||
tests/test_owned_resource_identity.py
|
||||
tests/test_pr6020_browser_review_regressions.py
|
||||
tests/test_private_browser_tool.py
|
||||
tests/test_process_lifecycle.py
|
||||
tests/test_process_ownership.py
|
||||
tests/test_process_resource_identity.py
|
||||
tests/test_remote_resource_identity.py
|
||||
tests/test_request_authority.py
|
||||
tests/test_reserved_username_admin_escalation.py
|
||||
tests/test_resolve_session_auth_chatgpt.py
|
||||
tests/test_resource_identity.py
|
||||
tests/test_runtime_resource_integration.py
|
||||
tests/test_scheduled_remote_ssh_refusal.py
|
||||
tests/test_security_regressions.py
|
||||
tests/test_settings_shell_js_behavior.py
|
||||
tests/test_setup_device_auth_static.py
|
||||
tests/test_shell_routes.py
|
||||
tests/test_shell_service.py
|
||||
tests/test_stale_process_intersection.py
|
||||
tests/test_startup_shell_js.py
|
||||
tests/test_task_cookbook_admin_gate.py
|
||||
tests/test_task_shell_tools.py
|
||||
tests/test_wave3_background_followup.py
|
||||
tests/test_wave3_browser_platform.py
|
||||
tests/test_wave3_diagnostics.py
|
||||
tests/test_wave3_launch_cost_lifecycle.py
|
||||
tests/test_wave3_local_control.py
|
||||
tests/test_wave3_subprocess_environment.py
|
||||
tests/test_webhook_trigger_auth_exempt.py
|
||||
@@ -160,12 +160,12 @@ Re-audit of Checkpoint A seams found:
|
||||
|
||||
| Path | Remaining enforcement |
|
||||
| --- | --- |
|
||||
| PTY/native manager routes | `routes/shell_routes.py:setup_shell_routes.shell_exec/shell_stream` call `_require_admin` before `_exec_shell/_generate_pty/_generate_tmux`; internal/anonymous controls denied, authenticated human administration separate |
|
||||
| PTY/native manager routes | `routes/shell_routes.py:setup_shell_routes.shell_exec/shell_stream` call `_require_admin` before `_exec_shell/_generate_pty/_generate_tmux`; internal tool controls denied; auth-enabled human administration and explicit auth-disabled direct-local operator administration remain separate |
|
||||
| Additional process producers | `resources.ProcessResource.__post_init__` admits only frozen native producer/role combinations; `process_resources.resolve_process_operation` requires sealed observations |
|
||||
| Raw scheduled SSH | `TaskScheduler._execute_action` → `builtin_actions.action_ssh_command` → `_run_subprocess` refuses SSH without an external workload adapter |
|
||||
| Local Cookbook scheduled auto-stop | `routes/cookbook_routes.py:setup_cookbook_routes.protect_native_control` applies shell admin boundary to local mutation; `tools/cookbook._cookbook_kill_session` refuses registry-less local control; legacy internal shell route cannot gain administration |
|
||||
| Legacy/unscoped tasks | `authority.restore_task_authority` → `process_resources.resolve_process_operation` admits no missing creation scope |
|
||||
| Anonymous administration / generic app_api | `owned_resources.needs_owned_binding` rejects shell/model/Cookbook namespaces; `_require_admin` also rejects unlabelled loopback when anonymous or unauthenticated |
|
||||
| Anonymous administration / generic app_api | `owned_resources.needs_owned_binding` rejects shell/model/Cookbook namespaces; `_require_admin` rejects auth-enabled anonymous and auth-disabled untrusted/forwarded requests; direct-local operator administration is supported |
|
||||
|
||||
No model-reachable page producer entry remains in the native/research wrapper.
|
||||
Trusted observation/setup methods are not tools or routes. Native arbitrary
|
||||
|
||||
@@ -78,6 +78,10 @@ Missing-owner values remain state-dependent at legacy call sites, but new storag
|
||||
loopback connection without proxy forwarding, cross-site indicators, or an
|
||||
internal-tool header. Remote/proxied anonymous traffic remains denied at
|
||||
these controls. Auth-enabled administration still requires a human admin.
|
||||
This mode trusts local programs as well as the local operator: a headerless
|
||||
loopback request cannot identify which local program sent it. Agent program
|
||||
launches retain inherited networking; this is not protection against hostile
|
||||
local code. Use authenticated mode when local programs are outside that trust.
|
||||
Local Cookbook tools use a separate one-use capability for an admitted exact
|
||||
request/operation/native backend and resolved launch body; that capability
|
||||
cannot administer shell, PID, SSH-key, or arbitrary Cookbook state routes.
|
||||
|
||||
@@ -75,7 +75,7 @@ The source tree reads **112** `ODYSSEUS_*` variables: 81 an operator may want to
|
||||
| `ODYSSEUS_MAX_VISUAL_EVIDENCE_FRAMES` | `'3'` | `src/agent_loop.py:15361` | How many video frames one tool result may contribute. Clamped to 1-8. |
|
||||
| `ODYSSEUS_MAX_VISUAL_EVIDENCE_IMAGES` | `'1'` | `src/agent_loop.py:15329` | How many images one tool result may contribute to the model turn. Clamped to 1-8. |
|
||||
| `ODYSSEUS_MCP_ALLOWED_COMMANDS` | `''` | `src/agent_tools/admin_tools.py:140` | Security-relevant. Comma-separated allowlist of MCP launcher basenames the agent may start. Empty by default, and the deny list still wins. |
|
||||
| `ODYSSEUS_PYTHON_TOOL_SITE_PACKAGES` | `''` | `src/agent_runtime/process_resources.py:58` (+2 more) | Security-relevant. Absolute package roots, separated by the platform path separator, exposed to the sandboxed Python tool. Empty exposes none. |
|
||||
| `ODYSSEUS_PYTHON_TOOL_SITE_PACKAGES` | `''` | `src/agent_runtime/process_resources.py:59` (+2 more) | Security-relevant. Absolute package roots, separated by the platform path separator, exposed to the sandboxed Python tool. Empty exposes none. |
|
||||
| `ODYSSEUS_SCRIPT_HOST` | `'localhost'` | `src/builtin_actions.py:925` | Default host for the run-script action. `localhost`, `127.0.0.1`, `local` and empty run locally; any other value runs over SSH. |
|
||||
| `ODYSSEUS_TOOL_APPROVAL_GATE` | `'0'` | `src/tool_capabilities.py:645` | Security-relevant. Truthy makes tool calls pass through the approval gate. Off by default. |
|
||||
|
||||
|
||||
Reference in New Issue
Block a user