Repository navigation
chore(security): PR A — critical hygiene batch (C1, C2, C3, C6, C7, C8, C9) - #324
Merged
Merged
Conversation
…8, C9) Address 7 of 9 Critical findings from the 2026-05-15 OSS-readiness audit. - C1: CSPRNG for gateway-token + admin-token (controller/src/reconciler/mod.rs). Was RandomState + SystemTime nanos; now rand::rng().fill_bytes via OsRng. Wire format (32-char / 64-char hex) preserved for lazy migration. - C2: Honest comment on inference-router 0.0.0.0:8443 bind — explains the cross-pod controller caller requirement and the three defense layers in front of the bind (NetworkPolicy, admission pod-exec ban, bearer auth). - C3: Rewrite mesh-plugin identity store docstring + deriveEncryptionKey comment to describe the on-disk envelope as obfuscation, not encryption. On-disk format unchanged. - C6: HEALTHCHECK in inference-router/Dockerfile and sandbox-images/openclaw/Dockerfile (curl added to the router runtime image). - C7: Reconcile version drift — README, cli/package.json, cli/package-lock.json, deploy/helm/azureclaw/Chart.yaml all → 0.1.0. - C8: Drop stale vendor/agentmesh-sdk overlay claim from README + docs/architecture.md (overlay retired in Phase 5.2). - C9: Remove dangling docs/internal/* pointers from 13 user-facing docs. Either inlined a prose summary or removed the trailing 'see also' line. Bonus: 11 broken Mermaid blocks across docs/use-cases.md, docs/api/lifecycle.md, docs/architecture/a2a-gateway.md, docs/agt-vs-vendored-sdk.md, docs/architecture-diagrams.md all fixed. All 46 Mermaid blocks in docs/ + README.md now validate against mmdc v11. Out of scope (deferred — require Azure-side provisioning first): - C4 (ACR OIDC swap) — needs federated credential staged first. - C5 (Bicep diagnosticSettings) — needs Log Analytics workspace target. Verification: - cargo build --release --package azureclaw-controller --package azureclaw-inference-router: clean - cargo clippy --all-targets -- -D warnings: clean - cargo fmt --all: clean - cd cli && npm run build / typecheck / lint: clean - cd cli && npm test: 769 passed / 2 skipped / 771 total - Mermaid validator: 46/46 blocks pass Audit doc: docs/internal/security-audits/2026-05-15-audit-critical-batch-a.md (force-added; two Signed-off-by lines per ci/security-audit-required.sh). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 16, 2026
…#325) * docs: OSS-readiness pass — strip internal jargon + correct overclaims Doc + comment-only audit across user-facing docs ahead of OSS launch. No code paths touched. Factual corrections (the heaviest changes): - docs/security.md headline guarantee #4: drop 'signed by the router' claim. The audit log is hash-chained and detects modification but is not signed today; signing is on the v1.1 roadmap. - docs/security.md Layer 6 inference-safety table: * Content Safety: 'Always on, server-side' → 'Always on for Foundry-provider requests; Copilot/GitHub-Models providers do not return prompt_filter_results'. * Token budget: was 'not yet aggregated'; the router DOES aggregate per-tenant daily and monthly UTC counters with on-disk persistence (inference-router/src/budget.rs:200-260). * New 'Operator escape hatches' subsection documents the two env-var knobs (AZURECLAW_SUPPRESS_CONTENT_FLAGS, AZURECLAW_CONTENT_FLAG_MIN_SEVERITY) honestly. - README hero: 'agent never sees an Azure key' softened to call out that this is the AKS guarantee; dev mode co-locates agent + router in one container. - README/architecture: '31 commands' → '30+ commands'; remove unverified '18 Foundry API groups' count. - docs/architecture.md design goal #1 + #4: explicit dev-vs-prod scoping; 'same code path' → 'same data-path code with documented AZURECLAW_DEV_MODE branches'. - docs/architecture/a2a-gateway.md: port 8445 is config-locked but the mTLS listener itself is still being wired; operators should set A2A_GATEWAY_UPSTREAM_URL explicitly until the listener is GA. - mesh-plugin/src/agt-identity.ts comment: replace 'encrypted at rest with per-host KEK' claim with honest 'chmod 0600 is the real boundary' note (mirrors PR #324 identity-store fix). - .github/copilot-instructions.md: '__AGT_INITIALIZED env guard' → 'Symbol.for(agt-mesh-client)' (matches current code in runtimes/openclaw/src/index.ts:458-480). Internal-jargon strip in user-facing docs: - docs/api/lifecycle.md: remove 'Slice 4', 'Slice 4d.3/4d.4', 'Slice 0', 'Slice 1c', 'Slice 2a/2b/2c/2d.1', 'Slice 2d.2', 'Slice 3a' references — replaced with descriptive prose. - docs/api/conditions.md: drop 'Slice 1c invariant' and 'principles.md §3' references. - docs/architecture/agt-boundary.md, docs/security-mcp-top10.md, docs/cli-reference.md: drop 'Phase 5.2' shibboleth — keep the facts (vendored AgentMesh fork was retired upstream). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: deep-dive diagram audit — fix CRD field-name labels + signing/latency overclaims Second pass of the OSS-readiness audit, focused on the architecture diagrams (the first pass missed factual errors here). architecture-diagrams.md: - Diagram #3: audit record is hash-chained, append-only (NOT signed today — cryptographic signing of the chain head is on the roadmap, see security.md). Tamper-detection vs tamper-proof is a real distinction. - Diagram #6: 8 CRDs → 9 CRDs (EgressApproval was missing from the list), prose says nine + mentions ClawPairing as the controller-internal 10th. - Diagram #7: CRD relationship arrows were wrong against the actual Rust structs. Corrected: - policyRef → spec.governance.toolPolicyRef - mcpRefs → spec.governance.mcpServerRefs - inferenceRef → spec.inferenceRef (top-level, was already correct) - memoryRef → spec.memoryRef (top-level, was already correct) - A2A 'sandboxRef' arrow was fake — A2AAgent has no sandboxRef. Real link is A2A -> ToolPolicy via spec.policyRefs.toolPolicy. - CE 'sandboxRef' → spec.targetSandboxRef. - TG 'trustRef' was fake — TrustGraph is cluster-scoped and projected to every sandbox by the controller (no ref). Noted in prose. - EgressApproval added (it was missing from the diagram entirely); links to ClawSandbox via spec.sandbox (string name, not ref object). security.md: - Headline #1 'agent does not see Azure credentials. Period.' — softened with a dev-mode footnote matching the README hero. In azureclaw dev, agent+router share a container with separate UIDs but a kernel-level container escape defeats the boundary; the hard guarantee is the AKS path. Anchor points at architecture.md#two-modes. - Layer 7: 'Sub-µs evaluation latency' → 'sub-millisecond evaluation latency on the router hot path.' Microsecond was an overclaim without a benchmark to back it. architecture.md: - Controller row in the components table: 'watches the eight peer CRDs' → 'nine peer CRDs (plus controller-internal ClawPairing)'. All 9 mermaid blocks pass a bracket-balance sanity check. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Addresses 7 of 9 Critical findings from the 2026-05-15 OSS-readiness audit. Low-risk hygiene batch: token entropy, comment honesty, dockerfile health probes, version reconciliation, doc cleanup.
Findings landed
rand::rng().fill_bytes) for gateway-token + admin-token (wasRandomState+SystemTimenanos). Wire format preserved — 32/64-char hex — for lazy migration.0.0.0.0:8443is required (cross-pod controller caller via Service DNS) + the three defense layers in front of it.deriveEncryptionKeycomment to describe the on-disk envelope as obfuscation, not encryption. On-disk format unchanged.HEALTHCHECKoninference-router/Dockerfile(curl added to runtime image) +sandbox-images/openclaw/Dockerfile.cli/package.json,cli/package-lock.json,deploy/helm/azureclaw/Chart.yamlall reconciled to0.1.0(was 3-way drift between1.0.0-rc.1,0.1.0-alpha.1,1.0.0-rc.1).vendor/agentmesh-sdkoverlay claim from README +docs/architecture.md(overlay retired in Phase 5.2; SDK now installed via npm only).docs/internal/*pointers from 13 user-facing docs. Strategy: prose summary where load-bearing, deletion where it was a 'see also' list line.Bonus
Fixed 11 broken Mermaid blocks across 5 doc files (use-cases, lifecycle, a2a-gateway, agt-vs-vendored-sdk, architecture-diagrams). Root causes:
\nescapes in flowchart labels, HTML entities in sequence messages, unquoted parens /@-prefixed package names / semicolons. All 46 Mermaid blocks indocs/+README.mdnow validate againstmmdcv11.Out of scope (deferred — require Azure-side provisioning)
diagnosticSettings) — needs a Log Analytics workspace target.Verification
cargo build --release --package azureclaw-controller --package azureclaw-inference-routercargo clippy --all-targets -- -D warningscargo fmt --allcd cli && npm run build / typecheck / lintcd cli && npm test— 769 passed / 2 skipped / 771 totalcheck-loc,no-stubs,security-audit-required,no-custom-crypto,a2a-module-isolation,check-copyright-headersAudit doc
docs/internal/security-audits/2026-05-15-audit-critical-batch-a.md(force-added; twoSigned-off-bylines as required byci/security-audit-required.sh).