Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 15 additions & 34 deletions dsl/extdeps/access/aws_iam.dag
Original file line number Diff line number Diff line change
@@ -1,23 +1,9 @@
// extdeps/access/aws_iam.dag -- "What is AWS IAM (policy language)?"
//
// AWS Identity and Access Management JSON policy documents: a list of statements, each granting
// or denying actions on resources for principals, optionally conditioned. Faithful model of the
// policy grammar, keeping its real element names.
//
// Source: AWS IAM JSON policy grammar, policy language version "2012-10-17".
// https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_grammar.html
//
// One of several access-control systems in extdeps/access; the std abstraction is derived from
// their commonality and validated against each (DESIGN §3), not re-coined from one.

module extdeps.access.aws_iam

import std.types { NonEmptyStr }
import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }

// External-authority anchor (promotes the Source citation above to the structured carrier
// that v2.lens.extdeps_external_authority gates on — DESIGN §3).
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
Expand All @@ -29,35 +15,30 @@ type Effect
= Allow
| Deny

// The Principal element (resource-based policies): "*" (anyone) or specific AWS/service/federated
// identities. (IAM also has the dual NotPrincipal; modeled as the negated form when present.)
type Principal
= AnyPrincipal // "Principal": "*"
| AwsPrincipal { arns: List<NonEmptyStr> } // "AWS": [arn ...]
| ServicePrincipal { services: List<NonEmptyStr> } // "Service": [...]
| FederatedPrincipal { providers: List<NonEmptyStr> } // "Federated": [...]
| CanonicalUserPrincipal { ids: List<NonEmptyStr> } // "CanonicalUser": [...]
= AnyPrincipal
| AwsPrincipal { arns: List<NonEmptyStr> }
| ServicePrincipal { services: List<NonEmptyStr> }
| FederatedPrincipal { providers: List<NonEmptyStr> }
| CanonicalUserPrincipal { ids: List<NonEmptyStr> }

// One Condition entry: operator -> key -> values, e.g. StringEquals { "aws:username": ["alice"] }.
type ConditionEntry {
operator: NonEmptyStr // e.g. "StringEquals", "IpAddress", "DateGreaterThan", "Bool"
key: NonEmptyStr // e.g. "aws:SourceIp", "s3:prefix", "aws:username"
operator: NonEmptyStr
key: NonEmptyStr
values: List<NonEmptyStr>
}

// A statement. Exactly one of action/not_action and resource/not_resource is used in real IAM;
// here `actions`/`resources` carry the positive form and `*` is a legal token.
type Statement {
sid: NonEmptyStr? // optional "Sid"
sid: NonEmptyStr?
effect: Effect
principal: Principal? // present in resource-based policies
actions: List<NonEmptyStr> // "Action": ["s3:GetObject", "*"]
resources: List<NonEmptyStr> // "Resource": [arn ...]
conditions: List<ConditionEntry> // "Condition" block (empty = unconditional)
principal: Principal?
actions: List<NonEmptyStr>
resources: List<NonEmptyStr>
conditions: List<ConditionEntry>
}

type PolicyDocument {
version: NonEmptyStr // "2012-10-17"
id: NonEmptyStr? // optional "Id"
statements: List<Statement> // "Statement": [...]
version: NonEmptyStr
id: NonEmptyStr?
statements: List<Statement>
}
40 changes: 11 additions & 29 deletions dsl/extdeps/access/posix.dag
Original file line number Diff line number Diff line change
@@ -1,51 +1,33 @@
// extdeps/access/posix.dag -- "What are POSIX file permissions?"
//
// The classic discretionary file-permission model: read/write/execute bits for three classes
// (owner / group / other), plus the setuid / setgid / sticky special bits, over a file owned by
// a numeric user id and group id. Faithful model of the <sys/stat.h> mode bits.
//
// Source: POSIX.1-2017 (IEEE Std 1003.1-2017), file mode bits (S_IRWXU/G/O, S_ISUID/ISGID/ISVTX);
// `chmod` permission model.
// https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/sys_stat.h.html
//
// One of several access-control systems in extdeps/access; the std abstraction is derived from
// their commonality and validated against each (DESIGN §3), not re-coined from one.

module extdeps.access.posix

import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }

// External-authority anchor (promotes the Source citation above to the structured carrier
// that v2.lens.extdeps_external_authority gates on — DESIGN §3).
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "pubs.opengroup.org/onlinepubs/9699919799/basedefs/sys_stat.h.html"
}
}

// The three permission bits applied per class (e.g. S_IRUSR / S_IWUSR / S_IXUSR for the owner).
type PermissionBits {
read: Bool // r
write: Bool // w
execute: Bool // x (search, for directories)
read: Bool
write: Bool
execute: Bool
}

// A file's mode: the three classes plus the special bits.
type FileMode {
owner: PermissionBits // user class (S_IRWXU)
group: PermissionBits // group class (S_IRWXG)
other: PermissionBits // other class (S_IRWXO)
setuid: Bool // S_ISUID — execute as the file's owner
setgid: Bool // S_ISGID — execute as the file's group / dir group inheritance
sticky: Bool // S_ISVTX — restricted deletion (e.g. /tmp)
owner: PermissionBits
group: PermissionBits
other: PermissionBits
setuid: Bool
setgid: Bool
sticky: Bool
}

// The owning identities the mode's classes resolve against.
type FileOwnership {
uid: Int // owning user id
gid: Int // owning group id
uid: Int
gid: Int
}

type FilePermissions {
Expand Down
32 changes: 5 additions & 27 deletions dsl/extdeps/access/rbac.dag
Original file line number Diff line number Diff line change
@@ -1,67 +1,45 @@
// extdeps/access/rbac.dag -- "What is (NIST) Role-Based Access Control?"
//
// Permissions are assigned to roles, roles to users; a senior role inherits a junior role's
// permissions (role hierarchy); a session activates a subset of a user's roles. Faithful model
// of Core + Hierarchical RBAC, keeping the standard's relation names (UA, PA, RH, PRMS = OPS×OBS).
//
// Source: ANSI INCITS 359-2004, "Role Based Access Control" (Ferraiolo, Sandhu, Gavrila, Kuhn,
// Chandramouli) — the NIST RBAC standard.
// https://csrc.nist.gov/projects/role-based-access-control
//
// One of several access-control systems in extdeps/access; the std abstraction is derived from
// their commonality and validated against each (DESIGN §3), not re-coined from one.

module extdeps.access.rbac

import std.types { NonEmptyStr }
import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }

// External-authority anchor (promotes the Source citation above to the structured carrier
// that v2.lens.extdeps_external_authority gates on — DESIGN §3).
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "csrc.nist.gov/projects/role-based-access-control"
}
}

// PRMS ⊆ OPS × OBS — a permission is an operation on an object.
type Permission {
operation: NonEmptyStr // OPS, e.g. "read", "write", "approve"
object: NonEmptyStr // OBS, e.g. a resource name
operation: NonEmptyStr
object: NonEmptyStr
}

// UA ⊆ USERS × ROLES — a user is assigned a role.
type UserAssignment {
user: NonEmptyStr
role: NonEmptyStr
}

// PA ⊆ PRMS × ROLES — a permission is assigned to a role.
type PermissionAssignment {
permission: Permission
role: NonEmptyStr
}

// RH ⊆ ROLES × ROLES (a partial order): `senior` inherits the permissions of `junior`.
type RoleInheritance {
senior: NonEmptyStr
junior: NonEmptyStr
}

// SESSIONS / session_roles — a session activates a subset of a user's authorized roles.
type Session {
user: NonEmptyStr
active_roles: List<NonEmptyStr>
}

// A full Core+Hierarchical RBAC policy. (Constrained RBAC adds SSD/DSD separation-of-duty
// constraints — omitted here; this is the assignment core the std abstraction is derived from.)
type RbacPolicy {
users: List<NonEmptyStr>
roles: List<NonEmptyStr>
user_assignments: List<UserAssignment> // UA
permission_assignments: List<PermissionAssignment> // PA
role_hierarchy: List<RoleInheritance> // RH
user_assignments: List<UserAssignment>
permission_assignments: List<PermissionAssignment>
role_hierarchy: List<RoleInheritance>
}
30 changes: 0 additions & 30 deletions dsl/extdeps/access/zanzibar.dag
Original file line number Diff line number Diff line change
@@ -1,62 +1,36 @@
// extdeps/access/zanzibar.dag -- "What is Zanzibar?"
//
// Google's global authorization system: a relation-tuple data model plus a per-namespace
// userset-rewrite configuration. Faithful model of the data model + config language in the
// paper (§2), keeping its real names.
//
// Source: Ruoming Pang, Ramón Cáceres, Mike Burrows, et al., "Zanzibar: Google's Consistent,
// Global Authorization System," 2019 USENIX Annual Technical Conference (USENIX ATC '19).
// https://www.usenix.org/conference/atc19/presentation/pang
//
// One of several access-control systems modeled in extdeps/access so the std/ access
// abstraction can be DERIVED from their commonality and validated against each (DESIGN §3),
// not re-coined from any single one.

module extdeps.access.zanzibar

import std.types { NonEmptyStr }
import extdeps.external_authority { ExternalAuthority }
import extdeps.uri { Uri, Https }

// External-authority anchor (promotes the Source citation above to the structured carrier
// that v2.lens.extdeps_external_authority gates on — DESIGN §3).
data extdeps_external_authority_anchor: ExternalAuthority = ExternalAuthority {
uri: Uri {
scheme: Https
locator: "www.usenix.org/conference/atc19/presentation/pang"
}
}

// ⟨object⟩ ::= ⟨namespace⟩ ':' ⟨object id⟩ (e.g. "doc:readme")
type Object {
namespace: NonEmptyStr
id: NonEmptyStr
}

// ⟨userset⟩ ::= ⟨object⟩ '#' ⟨relation⟩ (e.g. "group:eng#member")
type Userset {
object: Object
relation: NonEmptyStr
}

// ⟨user⟩ ::= ⟨user id⟩ | ⟨userset⟩
type User
= UserId { id: NonEmptyStr }
| UsersetUser { userset: Userset }

// ⟨tuple⟩ ::= ⟨object⟩ '#' ⟨relation⟩ '@' ⟨user⟩ (e.g. "doc:readme#viewer@group:eng#member")
type RelationTuple {
object: Object
relation: NonEmptyStr
user: User
}

// Userset rewrite rules (§2.3) — a namespace relation's config. Leaf rules:
// This -- `_this`: tuples stored directly for this object#relation
// ComputedUserset -- another relation on the SAME object (e.g. editor implies viewer)
// TupleToUserset -- follow `tupleset` to other objects, then `computed` relation there
// (e.g. "viewer of the parent folder" — inheritance)
// combined by Union / Intersection / Exclusion.
type UsersetRewrite
= This
| ComputedUserset { relation: NonEmptyStr }
Expand All @@ -70,19 +44,15 @@ type RelationConfig {
rewrite: UsersetRewrite
}

// A namespace configuration: its relations and their rewrite rules (§2.3).
type NamespaceConfig {
namespace: NonEmptyStr
relations: List<RelationConfig>
}

// Zookie (§2.2): opaque consistency token (a snapshot timestamp) for read-after-write.
type Zookie {
token: NonEmptyStr
}

// The Check decision (§2.4.1): is `user` related to `object` via `relation`, evaluated at a
// consistency snapshot? Modeled as the request shape (the boolean answer is the dependent fact).
type CheckRequest {
object: Object
relation: NonEmptyStr
Expand Down
23 changes: 0 additions & 23 deletions dsl/extdeps/audit/cloudevents.dag
Original file line number Diff line number Diff line change
@@ -1,22 +1,7 @@
// extdeps/audit/cloudevents.dag -- CloudEvents audit emission target surface.
//
// Specs:
// CloudEvents 1.0.2 core event attributes
// https://github.com/cloudevents/spec/blob/v1.0.2/cloudevents/spec.md
// RFC 3339 timestamp profile
// https://www.rfc-editor.org/rfc/rfc3339
//
// Ctrl-Migration Phase 3 authority for emitted audit event facts. The target
// describes stable event records; it does not decide storage backend, queueing,
// retention, or alerting policy.

module extdeps.audit.cloudevents

import std.types { NonEmptyStr, Timestamp }

// CloudEvents core attribute carriers. They intentionally stay separate from
// ctrl audit convenience fields so emitted audit records preserve the external
// wire vocabulary until a generated emitter owns the final serialization.
type CloudEventId = NonEmptyStr where brand("CloudEventId")
type CloudEventSource = NonEmptyStr where brand("CloudEventSource")
type CloudEventSpecVersion = NonEmptyStr where brand("CloudEventSpecVersion")
Expand All @@ -25,17 +10,11 @@ type CloudEventSubject = NonEmptyStr where brand("CloudEventSubject")
type CloudEventExtensionName = NonEmptyStr where brand("CloudEventExtensionName")
type CloudEventExtensionValue = NonEmptyStr where brand("CloudEventExtensionValue")

// Coproduct dissolution classification:
// GREEN (terminal). Actor source changes authorization and attribution
// semantics; collapsing to a string would lose the external audit dimension.
type AuditActorKind
= HumanActor
| ServiceActor
| SystemActor

// Coproduct dissolution classification:
// GREEN (terminal). Outcome is part of the externally reported audit fact
// and drives different downstream compliance interpretations.
type AuditOutcome
= AuditSucceeded
| AuditDenied
Expand Down Expand Up @@ -63,8 +42,6 @@ type AuditEventRecord {
fields: List<AuditEventField>
}

// STAGED. Ctrl subsystem projections emit into this target only after parity
// tests prove the event stream matches the existing TypeScript implementation.
type AuditEventEmissionTarget {
stream_name: NonEmptyStr
events: List<AuditEventRecord>
Expand Down
5 changes: 0 additions & 5 deletions dsl/extdeps/bmc.dag
Original file line number Diff line number Diff line change
@@ -1,8 +1,3 @@
// extdeps/bmc.dag — BMC telemetry projections over Redfish resource shapes.
//
// Types: extdeps.bmc.types. Per-firmware cited facts: extdeps.bmc.<family>.
// Redfish projections: extdeps.bmc.redfish.

module extdeps.bmc

import extdeps.bmc.types { BmcGroundedHostObservations, BmcTelemetrySnapshot }
Expand Down
Loading
Loading