Skip to content

Add bounded pre-commit enforcement example to OntoGuard Decision Authorization - #236

Open
MMM777-ai wants to merge 4 commits into
agentrust-io:mainfrom
MMM777-ai:ontoguard-bounded-precommit-20260929
Open

MMM777-ai wants to merge 4 commits into
agentrust-io:mainfrom
MMM777-ai:ontoguard-bounded-precommit-20260929

Conversation

@MMM777-ai

Copy link
Copy Markdown
Contributor

Summary

Updates the existing Verified OntoGuard Decision Authorization integration
with the bounded pre-commit enforcement example discussed with Imran.

The example demonstrates:

  • the same permitted capability with different proposed actions producing
    ALLOW, BLOCK, or ESCALATE;
  • exact-action binding of the signed OntoGuard decision;
  • rejection of a materially changed action;
  • fail-closed bypass cases, including missing authorization, digest-only
    input, invalid/tampered authorization, BLOCK, ESCALATE, and an ALLOW
    issued for a different action;
  • no protected commit for denied or bypass cases.

The existing TRACE adapter semantics remain unchanged. OntoGuard core
decision logic is not included.

Reproduction

From:

integrations/ontoguard-decision-authorization/

Run:

python -m pip install -e ".[test]"
python -m pytest -q

@MMM777-ai

Copy link
Copy Markdown
Contributor Author

Hi Imran — I’ve submitted the bounded update we discussed.

It stays within the existing Verified OntoGuard integration and keeps OpenShell/TRACE changes and NVIDIA positioning outside the contribution.

The PR now demonstrates:

  • same permitted capability with ALLOW / BLOCK / ESCALATE driven by the proposed action;
  • exact signed decision-to-action binding;
  • changed-action rejection;
  • explicit bypass/fail-closed cases with no protected commit;
  • documented proof boundaries and limitations.

The current suite is 33/33 passing, and the controlled-execution proof returns PASS.

Would appreciate your review when you have a chance.

Thanks,

Mark

@carloshvp carloshvp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head cb50ed3 against released agentrust-trace 0.11.0. The 33 integration tests pass, as do manifest validation (41 integrations, zero failures), compatibility, generated index/catalog checks, diff checks and a clean merge simulation.

Independent boundary probes found that malformed cross_border values are accepted as the signed Boolean true action and reach EXECUTED/commit_count=1. A separate direct ControlledExecutor.attempt() call also commits with only a caller-computed digest and no signed authorization. The inline comments distinguish the action-validation defect from the overbroad bounded non-bypassability claim. Please validate the action before binding/execution and either enforce authorization at the commit boundary or narrow the wrapper's proof claims and document the trusted routing assumption. Requesting changes.

@MMM777-ai

Copy link
Copy Markdown
Contributor Author

Thanks Carlos — both findings were valid and are addressed in the latest commit.
The bounded example now strictly validates the proposed action before binding or execution, including requiring cross_border to be an actual Boolean and using the same validated representation through the commit path.
Signed authorization verification is now enforced at the controlled executor’s commit boundary, so a caller-computed digest alone cannot form the protected effect.
I added regression coverage for the malformed cross_border cases you identified and for the direct digest-only bypass. Current result: 36 tests passing, controlled proof PASS, and all boundary probes refuse execution with commit_count == 0.
The limitation remains explicit: this proves the bounded software harness, not production-wide network non-bypassability.
Thanks for catching both issues.

@imran-siddique

Copy link
Copy Markdown
Member

@MMM777-ai #240 changed files in controlled-execution-proof-2026-09-17/ on main, so checksums.sha256 now conflicts. Merge main in and regenerate that file from the merged tree rather than hand-merging the two versions. @carloshvp e941cca reports both of your findings addressed (strict Boolean validation of cross_border before binding, signed authorization checked at the commit boundary); please re-review once the merge is pushed.

@MMM777-ai

Copy link
Copy Markdown
Contributor Author

Done - I merged the latest main into #236 and regenerated checksums.sha256 from the merged proof tree rather than hand-merging the manifests. The OntoGuard suite passes 36/36, the controlled proof passes, and the repo Ruff gate passes locally. Ready for re-review.

@carloshvp carloshvp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed exact head 081f0eb against released agentrust-trace 0.11.0 and agentrust-trace-tests 0.6.2. Both previous findings are addressed: cross_border requires an actual Boolean, unexpected action fields are rejected, the validated action representation reaches execution, and ControlledExecutor.attempt independently verifies signed authorization, trusted-key membership, expiry, ALLOW/release status and action binding before mutating the store. Direct digest-only calls now refuse execution.

Validation: 36 integration tests passed; 97 independent negative wrapper/direct-executor probes refused with commit_count=0 and no protected effect; four positive probes executed the validated exact action. The captured proof verifier and fresh live harness passed, a signed historical-fixture TRACE record passed Level 0 conformance (three optional/not-applicable checks skipped), and 28 repository validation tests passed. Manifest/compatibility validation, generated index/catalog checks, repository Ruff, compileall and diff checks passed. A clean merge simulation against current main 0801cd6 also passed the focused suite, boundary probes, proof and static/manifest checks.

Approval covers this bounded software harness and adapter. The documented exclusions for production routing, hardware attestation and OntoGuard semantic reasoning remain appropriate. The hosted approval gate is separate from the local validation evidence.

@MMM777-ai

Copy link
Copy Markdown
Contributor Author

@imran-siddique Carlos has approved the current head 081f0eb, but the maintainer-approval workflow triggered by his review is failing with HttpError: Not Found while reading repository content. This appears to be the hosted approval-gate workflow rather than anything in the OntoGuard changes; all other validation on the current head remains clean.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants