Repository navigation
[desgin-docs] v1.0.0 design set, Phase 1 implementation plan, and Stage 0 + Stage 1 of failproofaid #625
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
[desgin-docs] v1.0.0 design set, Phase 1 implementation plan, and Stage 0 + Stage 1 of failproofaid #625
Changes from 1 commit
Commits
Show all changes
60 commits
Select commit
Hold shift + click to select a range
fdbbc14
docs: add v1 design documents directory
github-actions[bot] a16399f
docs: link design docs changelog entry to PR
NiveditJain bda251b
docs: draft failproofaid architecture
NiveditJain 1c8a823
docs: design centralized policy management
NiveditJain eea0076
docs: split failproofaid design by concern
NiveditJain 30ef934
docs: make policy evaluation location configurable
NiveditJain 18aa936
docs: scope cloud evaluation beyond v1
NiveditJain 95b8e58
docs: preserve standalone OSS policy workflows
NiveditJain 6e94b39
docs: scope failproofaid v1 to linux and macos
NiveditJain bed7c98
docs: define login and OSS setup choice
NiveditJain 66d938e
docs: harden setup delivery and update contracts
NiveditJain ef37b44
docs: narrow v1 distribution to npm
NiveditJain b947a96
docs: close setup and spool crash gaps
NiveditJain 87127f7
docs: design user and system daemon scopes
NiveditJain e393e43
docs: prefer tamper-resistant enforcement scope
NiveditJain 61ae486
docs: reconcile removed harness hooks
NiveditJain 9a1c1c0
docs: replace binary updater with hook schemas
NiveditJain ec28e46
docs: make the enforcement boundary a service account, not root
NiveditJain 4171a46
docs: close four holes in the service-account boundary
NiveditJain 5cb4d84
docs: give the local dashboard an access model
NiveditJain bfb2b2c
docs: ship one service scope and split v1 into two phases
NiveditJain 9799459
docs: move the whole collector into Phase 1
NiveditJain fe1cd14
docs: add the Phase 1 implementation plan
NiveditJain 9de5c4f
feat: land Phase 1 Stage 0 and Stage 1 of failproofaid
NiveditJain da0fa55
fix: withdraw the corrupt bench baseline and gate the daemon's defaul…
NiveditJain 47bcd33
fix: four defects an adversarial review found in the Stage 1 daemon
NiveditJain 509e6e6
docs: record the four review fixes in the changelog
NiveditJain ca4c771
fix: make the bench harness's own integrity gate non-vacuous
NiveditJain 2b3a61d
docs: record the bench-harness gate fix
NiveditJain a2cb9ee
fix: make two concurrent bench captures impossible
NiveditJain 05ed3bb
docs: record the bench capture lock
NiveditJain 912ff1b
fix(ci): run CI on every pull request, not only those targeting main
NiveditJain 443c681
Revert "fix(ci): run CI on every pull request, not only those targeti…
NiveditJain 9bf1311
fix: two failures CI caught that local runs never would have
NiveditJain 4e00e93
docs: fold the Stage 0 amendments into the design set (in progress)
NiveditJain 2c0f0a3
docs: finish folding the Stage 0 amendments, and record where each la…
NiveditJain 35f890e
docs: record the amendment fold in the changelog
NiveditJain 40a1d11
docs: name the sealed runtime accurately in the tier table
NiveditJain 5dc478e
docs: cross-reference the per-user agent exception where the rule is …
NiveditJain 4535acd
fix: make the remaining hooks-config mocks additive
NiveditJain d2a7b9e
perf: capture the cold-start latency baseline, cleanly this time
NiveditJain 07f3998
refactor: run entirely in user scope for v1.0.0
NiveditJain 11f211c
docs: record the user-scope simplification in the changelog
NiveditJain 91298cb
docs: rewrite the user experience and harness integration for user sc…
NiveditJain 3b6bed2
docs: state what hook reconciliation can and cannot do in user scope
NiveditJain e57f40b
refactor: finish the user-scope sweep across code and tests
NiveditJain d957171
docs: rewrite the daemon, service, collector and release docs for use…
NiveditJain 122034f
refactor: make the client's path resolution pure, mirroring the Rust
NiveditJain 8ce4e45
docs: rewrite the stages and verification layers for user scope
NiveditJain d67e6e8
docs: replace L3's boundary probes with assertions user scope can act…
NiveditJain 3fe1c0b
fix: resolve the daemon socket after parsing arguments, not before
NiveditJain 038b81d
docs: record which amendments the scope decision superseded
NiveditJain 8209abf
docs: follow the scope decision into Phase 2's enrollment model
NiveditJain 7d4dff9
test: drive the real binary in the path-agreement check
NiveditJain d71f806
docs: final consistency pass on the user-scope rewrite
NiveditJain c3f3f12
docs: state that the delivery key is readable by the user's agent
NiveditJain 5f74c5b
fix: actually refuse a peer whose uid is not the daemon's
NiveditJain 14b0b44
fix(ci): build dist/index.js before the unit suite
NiveditJain 72967bb
fix: three defects an adversarial sweep found, all in code from this …
NiveditJain 17192ff
docs: record the three adversarial-sweep fixes
NiveditJain File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,3 @@ | ||
| # failproofai v1.0.0 design documents | ||
|
|
||
| This directory contains checked-in design documents for the next major version of failproofai. |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.