Skip to content

chore(security): PR A — critical hygiene batch (C1, C2, C3, C6, C7, C8, C9) - #324

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
mainfrom
audit/critical-batch-a
May 15, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
mainfrom
audit/critical-batch-a

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

Addresses 7 of 9 Critical findings from the 2026-05-15 OSS-readiness audit. Low-risk hygiene batch: token entropy, comment honesty, dockerfile health probes, version reconciliation, doc cleanup.

Findings landed

# Area Change
C1 controller bootstrap CSPRNG (rand::rng().fill_bytes) for gateway-token + admin-token (was RandomState + SystemTime nanos). Wire format preserved — 32/64-char hex — for lazy migration.
C2 inference-router bind Replaced misleading bind comment with honest explanation of why 0.0.0.0:8443 is required (cross-pod controller caller via Service DNS) + the three defense layers in front of it.
C3 mesh-plugin identity Rewrote docstring + deriveEncryptionKey comment to describe the on-disk envelope as obfuscation, not encryption. On-disk format unchanged.
C6 dockerfiles HEALTHCHECK on inference-router/Dockerfile (curl added to runtime image) + sandbox-images/openclaw/Dockerfile.
C7 versions README, cli/package.json, cli/package-lock.json, deploy/helm/azureclaw/Chart.yaml all reconciled to 0.1.0 (was 3-way drift between 1.0.0-rc.1, 0.1.0-alpha.1, 1.0.0-rc.1).
C8 docs Removed stale vendor/agentmesh-sdk overlay claim from README + docs/architecture.md (overlay retired in Phase 5.2; SDK now installed via npm only).
C9 docs Removed dangling docs/internal/* pointers from 13 user-facing docs. Strategy: prose summary where load-bearing, deletion where it was a 'see also' list line.

Bonus

Fixed 11 broken Mermaid blocks across 5 doc files (use-cases, lifecycle, a2a-gateway, agt-vs-vendored-sdk, architecture-diagrams). Root causes: \n escapes in flowchart labels, HTML entities in sequence messages, unquoted parens / @-prefixed package names / semicolons. All 46 Mermaid blocks in docs/ + README.md now validate against mmdc v11.

Out of scope (deferred — require Azure-side provisioning)

  • C4 (ACR OIDC swap) — needs federated credential staged on Azure side first; in-band swap would be cosmetic since both old and proposed new secrets are unprovisioned in the repo today.
  • C5 (Bicep diagnosticSettings) — needs a Log Analytics workspace target.

Verification

  • ✅ cargo build --release --package azureclaw-controller --package azureclaw-inference-router
  • ✅ cargo clippy --all-targets -- -D warnings
  • ✅ cargo fmt --all
  • ✅ cd cli && npm run build / typecheck / lint
  • ✅ cd cli && npm test — 769 passed / 2 skipped / 771 total
  • ✅ Local CI gates: check-loc, no-stubs, security-audit-required, no-custom-crypto, a2a-module-isolation, check-copyright-headers
  • ✅ Mermaid: 46/46 blocks pass

Audit doc

docs/internal/security-audits/2026-05-15-audit-critical-batch-a.md (force-added; two Signed-off-by lines as required by ci/security-audit-required.sh).

…8, C9)

Address 7 of 9 Critical findings from the 2026-05-15 OSS-readiness audit.

- C1: CSPRNG for gateway-token + admin-token (controller/src/reconciler/mod.rs).
  Was RandomState + SystemTime nanos; now rand::rng().fill_bytes via OsRng.
  Wire format (32-char / 64-char hex) preserved for lazy migration.
- C2: Honest comment on inference-router 0.0.0.0:8443 bind — explains the
  cross-pod controller caller requirement and the three defense layers
  in front of the bind (NetworkPolicy, admission pod-exec ban, bearer auth).
- C3: Rewrite mesh-plugin identity store docstring + deriveEncryptionKey
  comment to describe the on-disk envelope as obfuscation, not encryption.
  On-disk format unchanged.
- C6: HEALTHCHECK in inference-router/Dockerfile and
  sandbox-images/openclaw/Dockerfile (curl added to the router runtime image).
- C7: Reconcile version drift — README, cli/package.json,
  cli/package-lock.json, deploy/helm/azureclaw/Chart.yaml all → 0.1.0.
- C8: Drop stale vendor/agentmesh-sdk overlay claim from README +
  docs/architecture.md (overlay retired in Phase 5.2).
- C9: Remove dangling docs/internal/* pointers from 13 user-facing docs.
  Either inlined a prose summary or removed the trailing 'see also' line.

Bonus: 11 broken Mermaid blocks across docs/use-cases.md,
docs/api/lifecycle.md, docs/architecture/a2a-gateway.md,
docs/agt-vs-vendored-sdk.md, docs/architecture-diagrams.md all fixed.
All 46 Mermaid blocks in docs/ + README.md now validate against mmdc v11.

Out of scope (deferred — require Azure-side provisioning first):
- C4 (ACR OIDC swap) — needs federated credential staged first.
- C5 (Bicep diagnosticSettings) — needs Log Analytics workspace target.

Verification:
- cargo build --release --package azureclaw-controller --package azureclaw-inference-router: clean
- cargo clippy --all-targets -- -D warnings: clean
- cargo fmt --all: clean
- cd cli && npm run build / typecheck / lint: clean
- cd cli && npm test: 769 passed / 2 skipped / 771 total
- Mermaid validator: 46/46 blocks pass

Audit doc: docs/internal/security-audits/2026-05-15-audit-critical-batch-a.md
(force-added; two Signed-off-by lines per ci/security-audit-required.sh).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit fc8feda into main May 15, 2026
32 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the audit/critical-batch-a branch May 15, 2026 22:37
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 16, 2026
…#325)

* docs: OSS-readiness pass — strip internal jargon + correct overclaims

Doc + comment-only audit across user-facing docs ahead of OSS launch.
No code paths touched.

Factual corrections (the heaviest changes):

- docs/security.md headline guarantee #4: drop 'signed by the router'
  claim. The audit log is hash-chained and detects modification but
  is not signed today; signing is on the v1.1 roadmap.
- docs/security.md Layer 6 inference-safety table:
  * Content Safety: 'Always on, server-side' → 'Always on for
    Foundry-provider requests; Copilot/GitHub-Models providers do
    not return prompt_filter_results'.
  * Token budget: was 'not yet aggregated'; the router DOES aggregate
    per-tenant daily and monthly UTC counters with on-disk persistence
    (inference-router/src/budget.rs:200-260).
  * New 'Operator escape hatches' subsection documents the two env-var
    knobs (AZURECLAW_SUPPRESS_CONTENT_FLAGS,
    AZURECLAW_CONTENT_FLAG_MIN_SEVERITY) honestly.
- README hero: 'agent never sees an Azure key' softened to call out
  that this is the AKS guarantee; dev mode co-locates agent + router
  in one container.
- README/architecture: '31 commands' → '30+ commands'; remove
  unverified '18 Foundry API groups' count.
- docs/architecture.md design goal #1 + #4: explicit dev-vs-prod
  scoping; 'same code path' → 'same data-path code with documented
  AZURECLAW_DEV_MODE branches'.
- docs/architecture/a2a-gateway.md: port 8445 is config-locked but the
  mTLS listener itself is still being wired; operators should set
  A2A_GATEWAY_UPSTREAM_URL explicitly until the listener is GA.
- mesh-plugin/src/agt-identity.ts comment: replace 'encrypted at rest
  with per-host KEK' claim with honest 'chmod 0600 is the real
  boundary' note (mirrors PR #324 identity-store fix).
- .github/copilot-instructions.md: '__AGT_INITIALIZED env guard' →
  'Symbol.for(agt-mesh-client)' (matches current code in
  runtimes/openclaw/src/index.ts:458-480).

Internal-jargon strip in user-facing docs:

- docs/api/lifecycle.md: remove 'Slice 4', 'Slice 4d.3/4d.4',
  'Slice 0', 'Slice 1c', 'Slice 2a/2b/2c/2d.1', 'Slice 2d.2',
  'Slice 3a' references — replaced with descriptive prose.
- docs/api/conditions.md: drop 'Slice 1c invariant' and 'principles.md
  §3' references.
- docs/architecture/agt-boundary.md, docs/security-mcp-top10.md,
  docs/cli-reference.md: drop 'Phase 5.2' shibboleth — keep the
  facts (vendored AgentMesh fork was retired upstream).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: deep-dive diagram audit — fix CRD field-name labels + signing/latency overclaims

Second pass of the OSS-readiness audit, focused on the architecture
diagrams (the first pass missed factual errors here).

architecture-diagrams.md:
- Diagram #3: audit record is hash-chained, append-only (NOT signed today —
  cryptographic signing of the chain head is on the roadmap, see
  security.md). Tamper-detection vs tamper-proof is a real distinction.
- Diagram #6: 8 CRDs → 9 CRDs (EgressApproval was missing from the list),
  prose says nine + mentions ClawPairing as the controller-internal 10th.
- Diagram #7: CRD relationship arrows were wrong against the actual Rust
  structs. Corrected:
    - policyRef → spec.governance.toolPolicyRef
    - mcpRefs → spec.governance.mcpServerRefs
    - inferenceRef → spec.inferenceRef (top-level, was already correct)
    - memoryRef → spec.memoryRef (top-level, was already correct)
    - A2A 'sandboxRef' arrow was fake — A2AAgent has no sandboxRef. Real
      link is A2A -> ToolPolicy via spec.policyRefs.toolPolicy.
    - CE 'sandboxRef' → spec.targetSandboxRef.
    - TG 'trustRef' was fake — TrustGraph is cluster-scoped and projected
      to every sandbox by the controller (no ref). Noted in prose.
    - EgressApproval added (it was missing from the diagram entirely);
      links to ClawSandbox via spec.sandbox (string name, not ref object).

security.md:
- Headline #1 'agent does not see Azure credentials. Period.' — softened
  with a dev-mode footnote matching the README hero. In azureclaw dev,
  agent+router share a container with separate UIDs but a kernel-level
  container escape defeats the boundary; the hard guarantee is the AKS
  path. Anchor points at architecture.md#two-modes.
- Layer 7: 'Sub-µs evaluation latency' → 'sub-millisecond evaluation
  latency on the router hot path.' Microsecond was an overclaim without
  a benchmark to back it.

architecture.md:
- Controller row in the components table: 'watches the eight peer CRDs'
  → 'nine peer CRDs (plus controller-internal ClawPairing)'.

All 9 mermaid blocks pass a bracket-balance sanity check.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants