diff --git a/docs/runtime-decomposition/validation/wave-3-closure-focused-tests.txt b/docs/runtime-decomposition/validation/wave-3-closure-focused-tests.txt new file mode 100644 index 000000000..50e316a64 --- /dev/null +++ b/docs/runtime-decomposition/validation/wave-3-closure-focused-tests.txt @@ -0,0 +1,102 @@ +tests/test_action_intents_shell_verbs.py +tests/test_auth_config_lock_concurrency.py +tests/test_auth_disabled_document_access.py +tests/test_auth_event_loop.py +tests/test_auth_policy.py +tests/test_auth_regressions.py +tests/test_auth_require_privilege_nondict.py +tests/test_auth_root_path.py +tests/test_auth_session_revocation.py +tests/test_background_chat_completion_ui_static.py +tests/test_background_containment.py +tests/test_background_resource_identity.py +tests/test_background_tool_jobs.py +tests/test_bg_job_tools.py +tests/test_bg_jobs_store.py +tests/test_bg_monitor_stream.py +tests/test_browser_identity_transport.py +tests/test_browser_lifecycle.py +tests/test_browser_observation.py +tests/test_browser_producer_live_contract.py +tests/test_browser_progress.py +tests/test_browser_resource_identity.py +tests/test_browser_screenshot_artifact_safety.py +tests/test_browser_target_correction.py +tests/test_browser_transport_recovery.py +tests/test_builtin_actions_cookbook_serve_state.py +tests/test_builtin_actions_nonstring.py +tests/test_builtin_actions_owner_scope.py +tests/test_builtin_mcp_bg_tasks.py +tests/test_chat_background_stream_isolation.py +tests/test_chat_helpers_bg_tasks_tracked.py +tests/test_chat_preprocess_tool_policy.py +tests/test_codex_cookbook_admin_gate.py +tests/test_containment_process_tree.py +tests/test_cookbook_agent_tool_ssh_validation.py +tests/test_cookbook_cache_scan_isolation.py +tests/test_cookbook_cached_scan_refresh.py +tests/test_cookbook_chat_deeplinks_static.py +tests/test_cookbook_cpu_only_serve.py +tests/test_cookbook_dead_download_status.py +tests/test_cookbook_dependency_completion_regression.py +tests/test_cookbook_deps_recipes.py +tests/test_cookbook_diagnosis.py +tests/test_cookbook_diagnosis_js.py +tests/test_cookbook_docker_access.py +tests/test_cookbook_download_toast_duration.py +tests/test_cookbook_endpoint_registration.py +tests/test_cookbook_error_feedback.py +tests/test_cookbook_error_tail_lines.py +tests/test_cookbook_finished_download_label.py +tests/test_cookbook_gemma4_thinking_template.py +tests/test_cookbook_helpers.py +tests/test_cookbook_hf_token.py +tests/test_cookbook_local_serve_pid_winpid.py +tests/test_cookbook_official_trending_filter.py +tests/test_cookbook_package_detection.py +tests/test_cookbook_port_parsing_js.py +tests/test_cookbook_progress_signal_js.py +tests/test_cookbook_remote_windows_diffusers.py +tests/test_cookbook_same_host_server_profiles_js.py +tests/test_cookbook_serve_lifecycle.py +tests/test_cookbook_stop_without_procfs.py +tests/test_cookbook_tool_dry_run.py +tests/test_cookbook_windows_stop_tree_js.py +tests/test_deep_research_browser_fallback.py +tests/test_doc_library_open_orphaned.py +tests/test_docs_no_orphan_images.py +tests/test_document_editor_background_static.py +tests/test_email_oauth_connect_smtp_security.py +tests/test_email_oauth_docker_config.py +tests/test_email_oauth_settings_redirect.py +tests/test_host_shell_polling.py +tests/test_orphan_reaping.py +tests/test_owned_resource_identity.py +tests/test_pr6020_browser_review_regressions.py +tests/test_private_browser_tool.py +tests/test_process_lifecycle.py +tests/test_process_ownership.py +tests/test_process_resource_identity.py +tests/test_remote_resource_identity.py +tests/test_request_authority.py +tests/test_reserved_username_admin_escalation.py +tests/test_resolve_session_auth_chatgpt.py +tests/test_resource_identity.py +tests/test_runtime_resource_integration.py +tests/test_scheduled_remote_ssh_refusal.py +tests/test_security_regressions.py +tests/test_settings_shell_js_behavior.py +tests/test_setup_device_auth_static.py +tests/test_shell_routes.py +tests/test_shell_service.py +tests/test_stale_process_intersection.py +tests/test_startup_shell_js.py +tests/test_task_cookbook_admin_gate.py +tests/test_task_shell_tools.py +tests/test_wave3_background_followup.py +tests/test_wave3_browser_platform.py +tests/test_wave3_diagnostics.py +tests/test_wave3_launch_cost_lifecycle.py +tests/test_wave3_local_control.py +tests/test_wave3_subprocess_environment.py +tests/test_webhook_trigger_auth_exempt.py diff --git a/docs/runtime-decomposition/wave-3-browser-authority.md b/docs/runtime-decomposition/wave-3-browser-authority.md index 992a51942..df562905a 100644 --- a/docs/runtime-decomposition/wave-3-browser-authority.md +++ b/docs/runtime-decomposition/wave-3-browser-authority.md @@ -160,12 +160,12 @@ Re-audit of Checkpoint A seams found: | Path | Remaining enforcement | | --- | --- | -| PTY/native manager routes | `routes/shell_routes.py:setup_shell_routes.shell_exec/shell_stream` call `_require_admin` before `_exec_shell/_generate_pty/_generate_tmux`; internal/anonymous controls denied, authenticated human administration separate | +| PTY/native manager routes | `routes/shell_routes.py:setup_shell_routes.shell_exec/shell_stream` call `_require_admin` before `_exec_shell/_generate_pty/_generate_tmux`; internal tool controls denied; auth-enabled human administration and explicit auth-disabled direct-local operator administration remain separate | | Additional process producers | `resources.ProcessResource.__post_init__` admits only frozen native producer/role combinations; `process_resources.resolve_process_operation` requires sealed observations | | Raw scheduled SSH | `TaskScheduler._execute_action` → `builtin_actions.action_ssh_command` → `_run_subprocess` refuses SSH without an external workload adapter | | Local Cookbook scheduled auto-stop | `routes/cookbook_routes.py:setup_cookbook_routes.protect_native_control` applies shell admin boundary to local mutation; `tools/cookbook._cookbook_kill_session` refuses registry-less local control; legacy internal shell route cannot gain administration | | Legacy/unscoped tasks | `authority.restore_task_authority` → `process_resources.resolve_process_operation` admits no missing creation scope | -| Anonymous administration / generic app_api | `owned_resources.needs_owned_binding` rejects shell/model/Cookbook namespaces; `_require_admin` also rejects unlabelled loopback when anonymous or unauthenticated | +| Anonymous administration / generic app_api | `owned_resources.needs_owned_binding` rejects shell/model/Cookbook namespaces; `_require_admin` rejects auth-enabled anonymous and auth-disabled untrusted/forwarded requests; direct-local operator administration is supported | No model-reachable page producer entry remains in the native/research wrapper. Trusted observation/setup methods are not tools or routes. Native arbitrary diff --git a/specs/auth-security.md b/specs/auth-security.md index 13164f089..bc1d6ec0d 100644 --- a/specs/auth-security.md +++ b/specs/auth-security.md @@ -78,6 +78,10 @@ Missing-owner values remain state-dependent at legacy call sites, but new storag loopback connection without proxy forwarding, cross-site indicators, or an internal-tool header. Remote/proxied anonymous traffic remains denied at these controls. Auth-enabled administration still requires a human admin. + This mode trusts local programs as well as the local operator: a headerless + loopback request cannot identify which local program sent it. Agent program + launches retain inherited networking; this is not protection against hostile + local code. Use authenticated mode when local programs are outside that trust. Local Cookbook tools use a separate one-use capability for an admitted exact request/operation/native backend and resolved launch body; that capability cannot administer shell, PID, SSH-key, or arbitrary Cookbook state routes. diff --git a/website/configuration-reference.md b/website/configuration-reference.md index 17d1dc0de..40d6309d2 100644 --- a/website/configuration-reference.md +++ b/website/configuration-reference.md @@ -75,7 +75,7 @@ The source tree reads **112** `ODYSSEUS_*` variables: 81 an operator may want to | `ODYSSEUS_MAX_VISUAL_EVIDENCE_FRAMES` | `'3'` | `src/agent_loop.py:15361` | How many video frames one tool result may contribute. Clamped to 1-8. | | `ODYSSEUS_MAX_VISUAL_EVIDENCE_IMAGES` | `'1'` | `src/agent_loop.py:15329` | How many images one tool result may contribute to the model turn. Clamped to 1-8. | | `ODYSSEUS_MCP_ALLOWED_COMMANDS` | `''` | `src/agent_tools/admin_tools.py:140` | Security-relevant. Comma-separated allowlist of MCP launcher basenames the agent may start. Empty by default, and the deny list still wins. | -| `ODYSSEUS_PYTHON_TOOL_SITE_PACKAGES` | `''` | `src/agent_runtime/process_resources.py:58` (+2 more) | Security-relevant. Absolute package roots, separated by the platform path separator, exposed to the sandboxed Python tool. Empty exposes none. | +| `ODYSSEUS_PYTHON_TOOL_SITE_PACKAGES` | `''` | `src/agent_runtime/process_resources.py:59` (+2 more) | Security-relevant. Absolute package roots, separated by the platform path separator, exposed to the sandboxed Python tool. Empty exposes none. | | `ODYSSEUS_SCRIPT_HOST` | `'localhost'` | `src/builtin_actions.py:925` | Default host for the run-script action. `localhost`, `127.0.0.1`, `local` and empty run locally; any other value runs over SSH. | | `ODYSSEUS_TOOL_APPROVAL_GATE` | `'0'` | `src/tool_capabilities.py:645` | Security-relevant. Truthy makes tool calls pass through the approval gate. Off by default. |