Skip to content

Design discussion: tamper-evident reuse results (hash-chained repair_cache/events) #46

Description

@modacker

repair_cache rows are inputs to future execution decisions: a reused result bypasses a fresh agent call, and its output flows into downstream nodes. Today the SQLite file has no integrity protection — the README is upfront that the service is "not protected against other local processes". This is not about attackers; it is about agent mistakes: a buggy tool call, a careless script, or a well-meant cleanup that silently edits or drops reuse rows would be undetectable before those rows are trusted again.

Would you be open to a small hash chain over the append-only surfaces?

  • repair_cache inserts and events are append-only today; chain them prev-hash style (SHA-256 over the canonical row plus the previous head) and keep the chain head where workflow_status can report it, so a human or the dashboard can check "the results I am about to reuse are the ones earlier runs actually produced"
  • mutating rows (steps) stay out of the chain — they change through their lifecycle by design
  • a workflow_verify-style call (or an extension of workflow_status) recomputes the chain and reports the first divergence instead of a vague mismatch

Constraints we think matter: chain only append-only surfaces; the threat model is accidental mutation, not adversaries; no git, network, or account dependencies. We run a similar append-only hash-chain trail in our own open-source agent-governance engine (sih-engine — NDJSON event trails with prev-hash and a verify sensor), and are happy to work out a full design and a PR if this fits the roadmap — we would rather align on the shape first.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions