feat(agent-team): P3-flip Phase 1 — CI trust-boundary hardening (WIP, gated) #34

Merged
amoussa1229 merged 5 commits from feature/agent-team-p3-flip-phase1 into main 2026-06-22 22:51:53 +00:00
amoussa1229 commented 2026-06-22 21:34:26 +00:00 (Migrated from github.com)

Draft / WIP — accumulates the P3-live-flip Phase 1 CI hardening from docs/provisioning/P3-LIVE-FLIP-PLAN.md. The apply/verify workflow stays INERT (if: ${{ false }}); this only tightens the trust boundary. The whole Phase-1 surface is gated by /sh-security-review + a GPT-4.1 cross-family review before any flip or merge — do not merge until those pass on the complete surface.

In this PR so far

  • §4.2 denylist vectors — added direct code-execution / supply-chain vectors to the trust-control denylist, kept byte-identical across all 3 copies (canonical ci_gate.DENYLIST_GLOBS + the guard & post-build inline DENY_GLOBS), drift-guarded: .gitmodules, .husky/**, .githooks/**, .gitattributes, .npmrc, __generated__/**, *.generated.*, dist/**, build/**, *.min.js.
    • Deliberate: lockfiles are NOT wholesale denied — lockfile-postinstall RCE is contained by the credential-less, egress-blocked build sandbox, and the Tier-3 dep-CVE fixer rewrites lockfiles to ship draft PRs. Flagged in-code for the security gate.
  • §4.1 runner-trust — test asserting no job (esp. privileged gate-and-pr) can run on a self-hosted/user-provided runner.

Remaining Phase-1 items (to add to this PR before the gate)

  • Diff-transport integrity: concretize + threat-model (content-addressed signed artifact w/ shared HMAC, or short-lived branch-only token) + per-task nonce anti-replay (§4.3)
  • Gate-weakening detector (fails on noqa/type: ignore/skip/xfail/excludes/--no-verify/gate-config edits) (§4.5)
  • PR-metadata sanitization (§4.6) + ledger anti-tamper (§4.7)
  • ci_fetcher required-check-name discovery + cross-target test
  • Deploy-before-merge required-status-check gate (B1) + no-write-token-on-box audit
  • Then: /sh-security-review + GPT-4.1 cross-review on the full surface (hard stop)

998 tests pass, ruff clean. Pre-push scanners: PASS.

**Draft / WIP** — accumulates the P3-live-flip **Phase 1** CI hardening from `docs/provisioning/P3-LIVE-FLIP-PLAN.md`. The apply/verify workflow stays **INERT** (`if: ${{ false }}`); this only tightens the trust boundary. The **whole Phase-1 surface is gated by `/sh-security-review` + a GPT-4.1 cross-family review before any flip or merge** — do not merge until those pass on the complete surface. ## In this PR so far - **§4.2 denylist vectors** — added direct code-execution / supply-chain vectors to the trust-control denylist, kept byte-identical across all 3 copies (canonical `ci_gate.DENYLIST_GLOBS` + the guard & post-build inline `DENY_GLOBS`), drift-guarded: `.gitmodules`, `.husky/**`, `.githooks/**`, `.gitattributes`, `.npmrc`, `__generated__/**`, `*.generated.*`, `dist/**`, `build/**`, `*.min.js`. - **Deliberate:** lockfiles are NOT wholesale denied — lockfile-postinstall RCE is contained by the credential-less, egress-blocked build sandbox, and the Tier-3 dep-CVE fixer rewrites lockfiles to ship draft PRs. Flagged in-code for the security gate. - **§4.1 runner-trust** — test asserting no job (esp. privileged `gate-and-pr`) can run on a self-hosted/user-provided runner. ## Remaining Phase-1 items (to add to this PR before the gate) - [ ] Diff-transport integrity: concretize + threat-model (content-addressed signed artifact w/ shared HMAC, or short-lived branch-only token) + per-task nonce anti-replay (§4.3) - [ ] Gate-weakening detector (fails on `noqa`/`type: ignore`/skip/xfail/excludes/`--no-verify`/gate-config edits) (§4.5) - [ ] PR-metadata sanitization (§4.6) + ledger anti-tamper (§4.7) - [ ] `ci_fetcher` required-check-name discovery + cross-target test - [ ] Deploy-before-merge required-status-check gate (B1) + no-write-token-on-box audit - [ ] **Then:** `/sh-security-review` + GPT-4.1 cross-review on the full surface (hard stop) 998 tests pass, ruff clean. Pre-push scanners: PASS.
This repo is archived. You cannot comment on pull requests.
No description provided.