Conversation
|
Hi Imran — I’ve submitted the bounded update we discussed. It stays within the existing Verified OntoGuard integration and keeps OpenShell/TRACE changes and NVIDIA positioning outside the contribution. The PR now demonstrates:
The current suite is 33/33 passing, and the controlled-execution proof returns PASS. Would appreciate your review when you have a chance. Thanks, Mark |
carloshvp
left a comment
There was a problem hiding this comment.
Reviewed exact head cb50ed3 against released agentrust-trace 0.11.0. The 33 integration tests pass, as do manifest validation (41 integrations, zero failures), compatibility, generated index/catalog checks, diff checks and a clean merge simulation.
Independent boundary probes found that malformed cross_border values are accepted as the signed Boolean true action and reach EXECUTED/commit_count=1. A separate direct ControlledExecutor.attempt() call also commits with only a caller-computed digest and no signed authorization. The inline comments distinguish the action-validation defect from the overbroad bounded non-bypassability claim. Please validate the action before binding/execution and either enforce authorization at the commit boundary or narrow the wrapper's proof claims and document the trusted routing assumption. Requesting changes.
|
Thanks Carlos — both findings were valid and are addressed in the latest commit. |
|
@MMM777-ai #240 changed files in |
|
Done - I merged the latest main into #236 and regenerated checksums.sha256 from the merged proof tree rather than hand-merging the manifests. The OntoGuard suite passes 36/36, the controlled proof passes, and the repo Ruff gate passes locally. Ready for re-review. |
carloshvp
left a comment
There was a problem hiding this comment.
Re-reviewed exact head 081f0eb against released agentrust-trace 0.11.0 and agentrust-trace-tests 0.6.2. Both previous findings are addressed: cross_border requires an actual Boolean, unexpected action fields are rejected, the validated action representation reaches execution, and ControlledExecutor.attempt independently verifies signed authorization, trusted-key membership, expiry, ALLOW/release status and action binding before mutating the store. Direct digest-only calls now refuse execution.
Validation: 36 integration tests passed; 97 independent negative wrapper/direct-executor probes refused with commit_count=0 and no protected effect; four positive probes executed the validated exact action. The captured proof verifier and fresh live harness passed, a signed historical-fixture TRACE record passed Level 0 conformance (three optional/not-applicable checks skipped), and 28 repository validation tests passed. Manifest/compatibility validation, generated index/catalog checks, repository Ruff, compileall and diff checks passed. A clean merge simulation against current main 0801cd6 also passed the focused suite, boundary probes, proof and static/manifest checks.
Approval covers this bounded software harness and adapter. The documented exclusions for production routing, hardware attestation and OntoGuard semantic reasoning remain appropriate. The hosted approval gate is separate from the local validation evidence.
|
@imran-siddique Carlos has approved the current head |
Summary
Updates the existing Verified OntoGuard Decision Authorization integration
with the bounded pre-commit enforcement example discussed with Imran.
The example demonstrates:
ALLOW, BLOCK, or ESCALATE;
input, invalid/tampered authorization, BLOCK, ESCALATE, and an ALLOW
issued for a different action;
The existing TRACE adapter semantics remain unchanged. OntoGuard core
decision logic is not included.
Reproduction
From:
integrations/ontoguard-decision-authorization/Run:
python -m pip install -e ".[test]" python -m pytest -q