Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .well-known/agents-shipgate.json
Original file line number Diff line number Diff line change
Expand Up @@ -312,6 +312,8 @@
"host_grants_inventory_schema_version": "0.9",
"host_grants_baseline_schema_version": "0.9",
"host_grants_drift_schema_version": "0.9",
"openshell_native_trust_schema_version": "1",
"openshell_native_evidence_schema_version": "1",
"trigger_catalog_schema_version": "0.4",
"capability_standard_version": "0.5",
"governance_benchmark_catalog_schema_version": "0.2",
Expand Down Expand Up @@ -528,6 +530,8 @@
"host_grants_inventory": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/host-grants-inventory-schema.v0.9.json",
"host_grants_baseline": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/host-grants-baseline-schema.v0.9.json",
"host_grants_drift": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/host-grants-drift-schema.v0.9.json",
"openshell_native_trust": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/openshell-native-trust-schema.v1.json",
"openshell_native_evidence": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/openshell-native-evidence-schema.v1.json",
"scenario": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/scenario-schema.v0.1.json",
"checks_catalog": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/checks.json",
"determinism_boundary": "https://raw.githubusercontent.com/ThreeMoonsLab/agents-shipgate/main/docs/determinism-boundary.json",
Expand Down
11 changes: 11 additions & 0 deletions STABILITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -4273,6 +4273,17 @@ tests on every CI run, not by convention:
sanitized environment, isolated/fsck-validated object graph, fixed list
argv, exact force-with-lease, and no shell. They are explicit operational
executor surfaces, not part of static tool extraction.
- **`core/openshell_native.py`** — one `subprocess` import and one
`subprocess.Popen` call serve only explicit
`verify --openshell-proof-config` requests. The operator selects an
external configuration that pins the executable and containment boundary
by hash. Captured bytes run from a private directory with fixed list argv,
no shell, a sanitized environment, bounded output and process-group
lifetime. Linux additionally bounds virtual memory; Darwin does not.
Default static extraction and verification never invoke this boundary.
There is no executable discovery, installation, download or network call.
The result describes modeled containment and grants no merge authority;
see [the OpenShell trust contract](docs/openshell-support.md).
- **`cli/fixture.py`** — one `subprocess.run` helper invokes local
`git init`, `git config`, `git add`, `git commit`, and `git update-ref`
against a temporary bundled fixture copy so
Expand Down
1 change: 1 addition & 0 deletions docs/agent-contract-current.md
Original file line number Diff line number Diff line change
Expand Up @@ -821,6 +821,7 @@ Downstream repos generated with
- Current registry schema: `0.4` — [`docs/registry-schema.v0.4.json`](registry-schema.v0.4.json)
- Current org evidence bundle schema: `shipgate.org_evidence_bundle/v2` — [`docs/org-evidence-bundle-schema.v2.json`](org-evidence-bundle-schema.v2.json)
- Current host-grants inventory, baseline, and drift schemas: `0.9` — [`inventory`](host-grants-inventory-schema.v0.9.json), [`baseline`](host-grants-baseline-schema.v0.9.json), [`drift`](host-grants-drift-schema.v0.9.json). Version 0.9 adds explicit local OpenShell composition, provider profile provenance and effective-snapshot metadata; historical host schemas remain frozen. See [OpenShell support](openshell-support.md).
- Optional OpenShell native trust/evidence schemas: `1` — [`trust`](openshell-native-trust-schema.v1.json), [`evidence`](openshell-native-evidence-schema.v1.json). Only explicit external trust inputs enable local execution; the default remains static. Native containment never grants merge authority. See [OpenShell support](openshell-support.md#optional-native-containment).
- Current trigger catalog schema: `0.4` — [`docs/triggers.json`](triggers.json)
- Current governance benchmark catalog schema: `0.2` — [`docs/governance-benchmark-catalog-schema.v0.2.json`](governance-benchmark-catalog-schema.v0.2.json)
- Current governance benchmark result schema: `0.2` — [`docs/governance-benchmark-result-schema.v0.2.json`](governance-benchmark-result-schema.v0.2.json)
Expand Down
44 changes: 44 additions & 0 deletions docs/checks.json
Original file line number Diff line number Diff line change
Expand Up @@ -3051,6 +3051,50 @@
"requires_human_review_regardless_of_patch": false,
"suggested_patch_kind": "manual"
},
{
"autofix_safe": false,
"category": "verify",
"default_severity": "critical",
"description": "Trusted native OpenShell execution found a modeled candidate action outside the independently pinned maximum boundary.",
"docs_url": "https://github.com/ThreeMoonsLab/agents-shipgate/blob/main/docs/checks.md#ship-verify-openshell-boundary-exceeded",
"dynamic_default": false,
"evidence_fields": [
"status",
"reason_code",
"required"
],
"fires_when": "Opt-in local execution returns a validated exceeds_boundary envelope with matching actual exit status and all required domains.",
"floor_severity": "critical",
"id": "SHIP-VERIFY-OPENSHELL-BOUNDARY-EXCEEDED",
"mvp_tier": "lifecycle",
"rationale": "A known containment counterexample cannot be treated as a passing release input. Native evidence never approves other review obligations.",
"recommendation": "Narrow the candidate and rerun trusted native proof; do not widen the trusted boundary from the candidate PR.",
"requires_human_review": true,
"requires_human_review_regardless_of_patch": false,
"suggested_patch_kind": "manual"
},
{
"autofix_safe": false,
"category": "verify",
"default_severity": "medium",
"description": "Requested native OpenShell containment is unavailable, unsupported, invalid or inconclusive.",
"docs_url": "https://github.com/ThreeMoonsLab/agents-shipgate/blob/main/docs/checks.md#ship-verify-openshell-proof-unavailable",
"dynamic_default": false,
"evidence_fields": [
"status",
"reason_code",
"required"
],
"fires_when": "Opt-in execution cannot establish current modeled containment, or required proof has not been supplied. Optional absent proof is reported only as absent.",
"floor_severity": "medium",
"id": "SHIP-VERIFY-OPENSHELL-PROOF-UNAVAILABLE",
"mvp_tier": "lifecycle",
"rationale": "A missing or failed proof establishes no containment. Required proof also creates an unsuppressible evidence gap through the existing release decision.",
"recommendation": "Repair trusted external inputs or unsupported proof context and rerun verify with the same proof options.",
"requires_human_review": true,
"requires_human_review_regardless_of_patch": false,
"suggested_patch_kind": "manual"
},
{
"autofix_safe": false,
"category": "verify",
Expand Down
18 changes: 18 additions & 0 deletions docs/checks.md
Original file line number Diff line number Diff line change
Expand Up @@ -1427,3 +1427,21 @@ the Conductor finding above. HTTP/custom-worker/A2A/provider-native execution
is recorded as an unsupported capability and source warning in v1, so partial
coverage cannot silently produce `passed`. A `HUMAN` task is structural pause
evidence only; it does not prove reviewer identity or approval.

| `SHIP-VERIFY-OPENSHELL-BOUNDARY-EXCEEDED` | critical | Opt-in trusted native containment found the candidate outside the pinned maximum boundary; narrow it and rerun proof. |
| `SHIP-VERIFY-OPENSHELL-PROOF-UNAVAILABLE` | medium | Requested native containment is absent, invalid, unsupported or inconclusive; required proof retains an evidence gap. Repair trust inputs and rerun the same request. |

### SHIP-VERIFY-OPENSHELL-BOUNDARY-EXCEEDED

Opt-in trusted native execution found a modeled action outside the independently
pinned maximum. The critical verify finding is suppression-immune. Narrow the
candidate and rerun proof; a baseline or proof success cannot approve other
release obligations. Counterexample wording is excluded from finding identity.

### SHIP-VERIFY-OPENSHELL-PROOF-UNAVAILABLE

Requested modeled containment is absent, invalid, unsupported, inconclusive,
failed, cancelled or timed out. Required non-success retains an unsuppressible
evidence gap. Optional missing proof is an absent observation, with no claim of
containment. Repair external trust inputs and rerun the same verification
request. See [OpenShell support](openshell-support.md#optional-native-containment).
20 changes: 20 additions & 0 deletions docs/checks/verify.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -263,3 +263,23 @@ checks:
recommendation: A human must review the removal; restore the config binding or
an explicit literal allowlist, or declare an explicit local tool inventory
for the toolkit so the mounted surface is statically enumerable.
- id: SHIP-VERIFY-OPENSHELL-BOUNDARY-EXCEEDED
default_severity: critical
floor_severity: critical
mvp_tier: lifecycle
requires_human_review: true
description: Trusted native OpenShell execution found a modeled candidate action outside the independently pinned maximum boundary.
rationale: A known containment counterexample cannot be treated as a passing release input. Native evidence never approves other review obligations.
fires_when: Opt-in local execution returns a validated exceeds_boundary envelope with matching actual exit status and all required domains.
evidence_fields: [status, reason_code, required]
recommendation: Narrow the candidate and rerun trusted native proof; do not widen the trusted boundary from the candidate PR.
- id: SHIP-VERIFY-OPENSHELL-PROOF-UNAVAILABLE
default_severity: medium
floor_severity: medium
mvp_tier: lifecycle
requires_human_review: true
description: Requested native OpenShell containment is unavailable, unsupported, invalid or inconclusive.
rationale: A missing or failed proof establishes no containment. Required proof also creates an unsuppressible evidence gap through the existing release decision.
fires_when: Opt-in execution cannot establish current modeled containment, or required proof has not been supplied. Optional absent proof is reported only as absent.
evidence_fields: [status, reason_code, required]
recommendation: Repair trusted external inputs or unsupported proof context and rerun verify with the same proof options.
Loading
Loading