Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
8e69bbf
Add enclave GitHub issues handoff
lpcox Aug 24, 2026
12d405f
Merge branch 'main' into lpcox-enclave-cli-handoff
github-actions[bot] Aug 24, 2026
efa862c
Add enclave regression tests for scope and teardown
Copilot Aug 24, 2026
5c0a988
Merge branch 'main' into lpcox-enclave-cli-handoff
github-actions[bot] Aug 24, 2026
8b3be4c
Merge branch 'main' into lpcox-enclave-cli-handoff
github-actions[bot] Aug 25, 2026
f6799e8
Clear stale enclave proxy TLS CA before startup
Copilot Aug 25, 2026
39d420a
Address unresolved enclave review follow-ups
Copilot Aug 25, 2026
600919c
Merge branch 'main' into lpcox-enclave-cli-handoff
github-actions[bot] Aug 25, 2026
c71821d
Update enclave proxy release dependencies
lpcox Aug 26, 2026
e786f2f
Merge origin/main into lpcox-enclave-cli-handoff
Copilot Aug 26, 2026
8469fe9
Recompile lockfiles after main merge
Copilot Aug 26, 2026
1b65d28
Defer enclave MCP readiness to AWF
lpcox Aug 26, 2026
1cf55bd
Merge origin/main into enclave CLI handoff
lpcox Aug 26, 2026
7b6edf0
Preserve enclave gateway key for host AWF
lpcox Aug 26, 2026
dd6e724
Add enclave proxy TLS DNS SAN
lpcox Aug 26, 2026
a534bc6
Upgrade enclave proxy to mcpg v0.4.12
lpcox Aug 26, 2026
55bc32b
Merge origin/main into enclave CLI handoff
lpcox Aug 26, 2026
b5db66c
Upgrade enclave firewall to v0.28.9
lpcox Aug 27, 2026
ff94cf2
Merge origin/main into enclave CLI handoff
lpcox Aug 27, 2026
22246f3
Merge remote-tracking branch 'origin/main' into lpcox-enclave-cli-han…
Copilot Aug 27, 2026
371b027
Plan pr-finisher status pass
Copilot Aug 27, 2026
9fccef7
Sort actions-lock entries and synced pin mirrors
Copilot Aug 27, 2026
8fbb98b
Merge main and upgrade MCPG to v0.4.13
lpcox Aug 27, 2026
988b210
Define optional PR metadata for MCP gateway
lpcox Aug 27, 2026
042b8ab
Extend enclave MCP transport allowance
lpcox Aug 27, 2026
972d4cd
Translate gateway timeout for Copilot
lpcox Aug 27, 2026
a0c62ba
Discard all workflow lockfile updates
Copilot Aug 27, 2026
17d068d
Discard .lock.yml updates from PR branch
Copilot Aug 27, 2026
cde5ce3
Expand enclave disclosure timing range
lpcox Aug 28, 2026
3d6274c
Plan pr-finisher pass
Copilot Aug 28, 2026
c1c5da3
Fix enclave proxy review follow-ups
Copilot Aug 28, 2026
27c31fe
Merge main and keep lockfiles from main
Copilot Aug 28, 2026
f2f9309
Add ADR draft for enclave GitHub issues access
github-actions[bot] Aug 28, 2026
67cbcb4
Apply remaining changes
Copilot Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
10 changes: 10 additions & 0 deletions .changeset/enclave-github-issues-profile.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

80 changes: 65 additions & 15 deletions .github/aw/actions-lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,11 @@
"version": "v1.24.1",
"sha": "54075bcc5e249e4758d363f27d099f55d843f124"
},
"github/codeql-action/upload-sarif@v4.37.8": {
"repo": "github/codeql-action/upload-sarif",
"version": "v4.37.8",
"sha": "db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28"
},
"github/codeql-action/upload-sarif@v4.37.9": {
"repo": "github/codeql-action/upload-sarif",
"version": "v4.37.9",
Expand Down Expand Up @@ -215,6 +220,16 @@
"digest": "sha256:40a1e30b1b8d70642d4292485146cd5af612730d7a6a2e12706ddd13df375059",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.7@sha256:40a1e30b1b8d70642d4292485146cd5af612730d7a6a2e12706ddd13df375059"
},
"ghcr.io/github/gh-aw-firewall/agent:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/agent:0.28.8",
"digest": "sha256:0a94ad1b9976881fb88ba5db3aa6f4f26b91535a1b00986799fe87cdbe6105f9",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.8@sha256:0a94ad1b9976881fb88ba5db3aa6f4f26b91535a1b00986799fe87cdbe6105f9"
},
"ghcr.io/github/gh-aw-firewall/agent:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/agent:0.28.9",
"digest": "sha256:54b2fb3068efc15a4cc1bd4033f8fa056a9b1779baeba0cb80ae95ea55e7e343",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.9@sha256:54b2fb3068efc15a4cc1bd4033f8fa056a9b1779baeba0cb80ae95ea55e7e343"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1",
"digest": "sha256:288e7d2a12d5b430500d739f9c16e20bb1ed51b91f986f3f3eccde189f489f5c",
Expand Down Expand Up @@ -250,6 +265,16 @@
"digest": "sha256:4f209dd4cbc74d47a6c7379956143de293429d1b1b2fb2647776cdcbf65836a1",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.7@sha256:4f209dd4cbc74d47a6c7379956143de293429d1b1b2fb2647776cdcbf65836a1"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.8",
"digest": "sha256:531fb75f54c07d66200be6973033db98838d9e838316549fd9af09329a56b848",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.8@sha256:531fb75f54c07d66200be6973033db98838d9e838316549fd9af09329a56b848"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9",
"digest": "sha256:a0ffb1dc926c6e5a500b336893e032a8f167d3db43c869be886874ef14280bb8",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9@sha256:a0ffb1dc926c6e5a500b336893e032a8f167d3db43c869be886874ef14280bb8"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1",
"digest": "sha256:f931e5e1e13f765605d03ef9511fc755d779a51b76581ea14586e9871506a610",
Expand Down Expand Up @@ -285,6 +310,31 @@
"digest": "sha256:ebc8758c9b085ca244234e3e3ee22300d150095f9bfe7312ca8a61c5acb34a78",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.7@sha256:ebc8758c9b085ca244234e3e3ee22300d150095f9bfe7312ca8a61c5acb34a78"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.8",
"digest": "sha256:c10f37b8677fc208c052b57f9035c4ad1b08c76d8e6d9545ee24173e31e29023",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.8@sha256:c10f37b8677fc208c052b57f9035c4ad1b08c76d8e6d9545ee24173e31e29023"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9",
"digest": "sha256:38d7ac0585ee5aa6a06eb71e087d514b059db36005c7783c6485e0dfd36fea35",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9@sha256:38d7ac0585ee5aa6a06eb71e087d514b059db36005c7783c6485e0dfd36fea35"
},
"ghcr.io/github/gh-aw-firewall/enclave-agent:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/enclave-agent:0.28.9",
"digest": "sha256:8d548153f18d9b44406bebe3f71e2e080c15c89cbf8c0f72e8aa7bc0681efcf2",
"pinned_image": "ghcr.io/github/gh-aw-firewall/enclave-agent:0.28.9@sha256:8d548153f18d9b44406bebe3f71e2e080c15c89cbf8c0f72e8aa7bc0681efcf2"
},
"ghcr.io/github/gh-aw-firewall/enclave-mcp-server:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/enclave-mcp-server:0.28.9",
"digest": "sha256:9edfa59fe0cf96f86c0be2f3280743a95032cf730526a204f729a06fbe7e4727",
"pinned_image": "ghcr.io/github/gh-aw-firewall/enclave-mcp-server:0.28.9@sha256:9edfa59fe0cf96f86c0be2f3280743a95032cf730526a204f729a06fbe7e4727"
},
"ghcr.io/github/gh-aw-firewall/enclave-script:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/enclave-script:0.28.9",
"digest": "sha256:def4cc9669c0723cbdcdcdbd0ad4c72b6d977c02e4e0978797e9116fffd8e25d",
"pinned_image": "ghcr.io/github/gh-aw-firewall/enclave-script:0.28.9@sha256:def4cc9669c0723cbdcdcdbd0ad4c72b6d977c02e4e0978797e9116fffd8e25d"
},
"ghcr.io/github/gh-aw-firewall/squid:0.28.1": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.1",
"digest": "sha256:9d428af47899bf18ef2d5618075777d76ef344c91e76c1f44ec1aaa0ee347e5f",
Expand Down Expand Up @@ -320,15 +370,20 @@
"digest": "sha256:fb362a08d4d2f0da6c036e3f5d3b2fd87931e857fec3ca4a241cd2f2b61131f9",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.7@sha256:fb362a08d4d2f0da6c036e3f5d3b2fd87931e857fec3ca4a241cd2f2b61131f9"
},
"ghcr.io/github/gh-aw-mcpg:v0.4.12": {
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.12",
"digest": "sha256:92d5377b6bd32cd5b9306b2a553f7ef3549bccff9207e46f931e7249bc718713",
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.12@sha256:92d5377b6bd32cd5b9306b2a553f7ef3549bccff9207e46f931e7249bc718713"
"ghcr.io/github/gh-aw-firewall/squid:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.8",
"digest": "sha256:9ede51772d89f6c70049753e36c62d5e3690e3cbd0fef327eb6c1fdd22c61b73",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.8@sha256:9ede51772d89f6c70049753e36c62d5e3690e3cbd0fef327eb6c1fdd22c61b73"
},
"ghcr.io/github/gh-aw-mcpg:v0.4.12": {
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.12",
"digest": "sha256:92d5377b6bd32cd5b9306b2a553f7ef3549bccff9207e46f931e7249bc718713",
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.12@sha256:92d5377b6bd32cd5b9306b2a553f7ef3549bccff9207e46f931e7249bc718713"
"ghcr.io/github/gh-aw-firewall/squid:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.9",
"digest": "sha256:3d5dba0b0a139bbb11b5d5b8b44f277d2b18f69cf43090e3c283d750cf864baa",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.9@sha256:3d5dba0b0a139bbb11b5d5b8b44f277d2b18f69cf43090e3c283d750cf864baa"
},
"ghcr.io/github/gh-aw-mcpg:v0.4.13": {
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.13",
"digest": "sha256:ec4008521c610e1113ed557ecec0ff64a2c2111e4cfa817bab54d9b7da24c7cc",
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.13@sha256:ec4008521c610e1113ed557ecec0ff64a2c2111e4cfa817bab54d9b7da24c7cc"
},
"ghcr.io/github/gh-aw-node": {
"image": "ghcr.io/github/gh-aw-node",
Expand All @@ -340,11 +395,6 @@
"digest": "sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699",
"pinned_image": "ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699"
},
"ghcr.io/github/github-mcp-server:v1.11.0": {
"image": "ghcr.io/github/github-mcp-server:v1.11.0",
"digest": "sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699",
"pinned_image": "ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699"
},
"ghcr.io/oraios/serena:1.7.0": {
"image": "ghcr.io/oraios/serena:1.7.0",
"digest": "sha256:6c9459e4246a39c9deaa4f23fb05a526ac6e237b24c8e84a927a098fa1ab6730",
Expand All @@ -357,8 +407,8 @@
},
"node:lts-alpine": {
"image": "node:lts-alpine",
"digest": "sha256:d32cdf619f63fe0471182d08996dd516c6275bb5fd31ae06e55a570bd9e1ad43",
"pinned_image": "node:lts-alpine@sha256:d32cdf619f63fe0471182d08996dd516c6275bb5fd31ae06e55a570bd9e1ad43"
"digest": "sha256:e67514e5d0f6c46656005e1b693b2ec9d52e80b641307de684d4a015ba7a4eaf",
"pinned_image": "node:lts-alpine@sha256:e67514e5d0f6c46656005e1b693b2ec9d52e80b641307de684d4a015ba7a4eaf"
}
}
}
36 changes: 35 additions & 1 deletion .github/aw/enclaves.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,40 @@ enclaves:
- If the same repository appears in both entries, its `sensitivity` must match — the information budget is shared across executor types.
- AWF fixes the script enclave's network and interpreter, and the agent enclave's network, internally; do not attempt to override these in workflow frontmatter.
- A fresh masked capability is generated per workflow run and passed only to the MCP gateway and AWF, never to the primary agent environment.
- `timeout:` per enclave entry is capped at 540 seconds (AWF reserves the final 60 seconds of its 600-second finite-disclosure bucket for cleanup). The gateway itself enforces a 630-second tool timeout (600s AWF bucket + 30s transport allowance) — treat this as an enforcement bound, not a wall-clock guarantee.
- `timeout:` per enclave entry is capped at 4,740 seconds (AWF reserves the final 60 seconds of its 4,800-second finite-disclosure bucket for cleanup). The gateway itself enforces a 4,860-second tool timeout (4,800s AWF bucket + 60s transport allowance) — treat this as an enforcement bound, not a wall-clock guarantee.

## Agent GitHub Issues profile

Use only this closed opt-in:

```yaml
sandbox:
mcp:
version: v0.4.13
enclaves:
- agent:
model: gpt-5
github:
cli: issues-read-v1
repos:
- repo: octo-org/private-service
sensitivity: confidential
```

- `issues-read-v1` permits only paginated REST GETs for issue lists, one issue,
and that issue's comments. Use `gh api --method GET`; do not promise stock
`gh issue` commands because they may use denied GraphQL calls.
- GraphQL, search, writes, and all other REST paths fail closed.
- V1 allows at most one non-`public` repository in the agent entry.
- Public data inherits explicit `tools.github.min-integrity`, or the compiler's
primary default (`approved`) when the primary GitHub tool is omitted.
- Private repository responses carry the `private:<owner>/<repo>` DIFC secrecy
label.
- The compiler starts a dedicated bridge-mode mcpg proxy holding the PAT. AWF
supplies only its own local PAT-free proxy to the enclave and keeps the
`awf-egh1` invocation capability in a mode-`0600` file.
- The primary agent receives no enclave proxy address, key, CA path, container
identity, capability, PAT, or repository catalog.
- Minimum versions are AWF `v0.28.9` and mcpg `v0.4.13`.

See also: [agent-runtime-instructions.md](agent-runtime-instructions.md) for `sandbox.agent` fields, and [network.md](network.md) for network isolation defaults.
Loading
Loading