fix(acp): authenticate stored workflow mentions - #36
Merged
Conversation
Backport the focused workflow-owner provenance contract from block#6953 onto the deployed fork without absorbing unrelated upstream divergence. Relay-authored workflow messages now carry canonical owner and stored-template mention provenance, and ACP fails closed unless the receiving agent was explicitly named in that stored template. Co-authored-by: Justin <justin@triumphfw.com> Signed-off-by: Justin <justin@triumphfw.com>
Update compatible transitive releases for yanked spin, async-utility, and chacha20 entries, patch webbrowser and h2 advisories, and carry upstream's narrow informational exception for the retired nostr relay pool until MeshLLM adopts nostr-sdk 0.45. Co-authored-by: Justin <justin@triumphfw.com> Signed-off-by: Justin <justin@triumphfw.com>
Co-authored-by: Justin <justin@triumphfw.com> Signed-off-by: Justin <justin@triumphfw.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
buzz:workflow-ownerprovenance and authority-bearingbuzz:workflow-mentiontags only for agent mentions present in the stored, unrendered workflow step templateactorattribution from workflow messagesThis is intentionally limited to the paired relay and ACP authorization fix. It does not absorb the fork's large unrelated divergence from upstream.
Security properties
respond-to=nobodypolicy checks remain downstream of the authenticated author resolutionVerification
env -u BUZZ_ACP_LAZY_POOL cargo test -p buzz-acp --lib(707 passed)env -u BUZZ_ACP_LAZY_POOL cargo test -p buzz-workflow --lib(159 passed, 5 integration-only ignored)env -u BUZZ_ACP_LAZY_POOL cargo test -p buzz-relay --lib workflow_sink(20 passed, 1 integration-only ignored)cargo fmt --all -- --checkcargo clippy -p buzz-acp -p buzz-workflow -p buzz-relay --all-targets -- -D warningsenv -u BUZZ_ACP_LAZY_POOL just cipassed, including workspace Rust, Desktop, web, and all 1,162 mobile testsRollout boundary
Relay and Desktop ACP must be deployed as a pair. Production deployment and end-to-end verification follow only after this PR is green.
Originating Buzz channel:
7ce21003-c460-4384-a3f3-a95c3623bfe1Originating thread:
87433f24cf3521e0cdd93741ddf4f7eb82c38d554b0c19a69261f65f1c10948c