Repository navigation
Conversation
…te example Extends the confinement documentation to address issue agentrust-io#736's execution-scope question by defining a path-set model for protected effects. The model distinguishes: - Agent-side paths: originating from the agent/runtime, enforceable and testable by confinement machinery (e.g., gateway path, alternate endpoint, filesystem/subprocess) - Deployment-side paths: outside agent's enforcement domain, requiring independent deployment-level observation (e.g., external service writing to DB) Implements a worked example for order_create as the protected effect, demonstrating four distinct paths (P1-P4) with clear coverage status: - P1: ENFORCED/TESTED (gateway path, validated by test_confinement_and_fresh_restart) - P2: ENFORCED/TESTED (alternate endpoint, validated by network mutation tests) - P3: ENFORCED/TESTED (filesystem/subprocess, validated by filesystem mutation tests and network namespace inheritance blocking subprocess network escape) - P4: DECLARED/NOT ESTABLISHED (deployment-side, requires independent observation) Adds documentation linking this to EABC's NON_BYPASSABILITY(B,E) claim while explicitly noting that gateway mediation alone does not prove universal complete mediation. Updates test docstrings to map existing confinement tests to the path-set model, clarifying that test_linux.py validates agent-side path coverage (P1-P3) while deployment-side paths require separate deployment-level evidence. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
omwei-org
requested review from
a team,
carloshvp,
qubeena07,
rajnisht7 and
zohebk8s
as code owners
October 8, 2026 20:14
Contributor
|
Thanks for this, @omwei-org. Closing it for now, and it is not about the change itself. This repository asks first-time contributors to be vouched by a maintainer before opening a pull request. That is because agent-written contributions are easy to produce and expensive to review, and we would rather talk to you first than review something neither of us can explain. To get vouched: open an issue saying what you want to change and why, in your own words. A maintainer will reply, and add you with See CONTRIBUTING.md for the detail. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This change introduces an explicit protected-effect path-set model and makes execution-scope coverage visible for the confinement documentation.
Key changes
Design rationale
The model explicitly distinguishes four different claims:
This avoids conflating authorization with universal complete mediation. The model supports a scoped NON_BYPASSABILITY claim; it does NOT establish universal complete mediation.
Test plan
Related issues
Generated with Devin: https://devin.ai