Skip to content

OpenShell: deliver static policy change review and bound verification evidence #942

Description

@pengfei-threemoonslab

Problem

Teams using OpenShell need PR review that explains how a change affects an agent's declared authority, identifies missing evidence, and follows Agents Shipgate's existing merge-review contract. A base-policy YAML diff can miss defaults, selected-file changes and provider contributions. A native containment result alone does not establish current inputs or merge authority.

Product outcome

A reviewer can point Agents Shipgate at supported OpenShell policy inputs, see a concrete before/after authority explanation, understand exactly what was and was not evaluated, and receive the established control route with evidence bound to the reviewed Git state.

Primary users: platform engineers maintaining agent environments, security reviewers approving authority changes, and coding agents preparing those changes.

Delivery plan

MVP — P1: explicitly selected local policy → versioned inventory → conservative semantic diff → replayable Git/receipt identity → existing check/verify review route.

Follow-ups — P2: explicit provider/global-policy composition and optional native prover evidence. These extend the supported claim; they are not prerequisites for releasing the honestly scoped document-review MVP.

P1/P2 here indicate proposed delivery order, not incident severity or a committed release date. Owners and scheduling remain unassigned.

MVP delivery issues

Follow-up delivery issues

Dependency order

MVP acceptance and release criteria

  • The four MVP delivery issues are complete, with focused tests and supported-version documentation.
  • A published example PR changes enforced request restrictions to audit-only and shows the impact, review route and exact source evidence.
  • Supported equivalent changes produce no false authority expansion; genuine supported expansions remain visible.
  • Every unsupported, missing or unread relevant input in the conformance corpus has an explicit limitation; none becomes an unqualified complete result.
  • Results agree across audit, diff, check and verify, while diff remains verdict-free.
  • Changing a selected policy or selecting reference invalidates the prior verification identity.
  • Default scans remain local and static, with no OpenShell installation, gateway connection or secret retrieval.
  • Documentation explicitly distinguishes authored policy, composed policy and observed deployment; no static result claims runtime enforcement.

Product and engineering guardrails

Target fixtures and semantics initially at OpenShell v0.1.2; policy schema version 1 alone is not a runtime compatibility promise. Integrate through the host-boundary pipeline with typed grants and coverage. Keep the actual coding-agent caller independent from the enclosing OpenShell runtime.

Preserve Agents Shipgate's existing control and release-decision vocabulary. Do not infer business effects, authority, approvals or agent bindings from network/MCP permissions. Protect an operator's maximum boundary independently from a candidate policy.

Out of scope

Live gateway monitoring, automatic policy generation/application, credential retrieval, runtime enforcement attestation, broad deployment orchestration, or implementing a second containment solver. The optional prover follow-up uses native evidence through a separate explicit trust boundary.

Alternatives considered

  • Generic YAML/text diffs are useful context but do not establish authority direction.
  • A callable-tool adapter does not represent the runtime's permission relationships.
  • Native proof alone lacks the PR scope, protected-boundary review and current-input identity required by the merge workflow.

References

Surface areas: input reader, CLI, host schemas, control/receipts, documentation.

This epic tracks both increments; the MVP release gate is only the four MVP issues. Close the epic when the follow-ups are completed or explicitly deferred with recorded rationale.

Implementation pull requests

All six implementation pull requests were approved and merged to main in the order below. Each rebased head passed fresh CI, and the final merged Git tree exactly matches the reviewed implementation. Delivery issues #943–#948 are closed.

Final implementation commit: 0e58e6ff2. The remaining acceptance/release checklist above is retained for release tracking; this merge does not publish a package or attest runtime deployment.

Issue Pull request Scope
#943 #949 Explicit policy registration and typed inventory
#944 #950 Conservative declared-authority comparison
#945 #951 Git inputs, receipts and current-control currency
#946 #952 Check, preflight and verifier routing
#947 #958 Global policy and provider composition
#948 #959 Optional trusted native containment evidence

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions