Skip to content

docs(confinement): add execution-scope path-set model with order_create example - #740

Closed
omwei-org wants to merge 1 commit into
agentrust-io:mainfrom
omwei-org:eabc-order-create-path-set
Closed

omwei-org wants to merge 1 commit into
agentrust-io:mainfrom
omwei-org:eabc-order-create-path-set

Conversation

@omwei-org

Copy link
Copy Markdown

Summary

This change introduces an explicit protected-effect path-set model and makes execution-scope coverage visible for the confinement documentation.

Key changes

  • New section: Execution scope and path sets in docs/confinement.md
  • Path classification: Distinguishes agent-side (enforceable/testable through confinement) vs deployment-side (declared boundaries whose coverage remains NOT ESTABLISHED unless independently observed) paths
  • Worked example: Uses order_create as the protected effect with four declared paths (P1-P4)
  • Coverage model: P1-P3 (agent-side) are ENFORCED/TESTED via existing confinement fixtures; P4 (deployment-side) is DECLARED/NOT ESTABLISHED (requires deployment-level observation)
  • Test documentation: Maps existing confinement tests to the path-set model

Design rationale

The model explicitly distinguishes four different claims:

  1. Authorization (existing cMCP mechanism)
  2. Correlation (existing cMCP mechanism)
  3. Observation (existing cMCP mechanism)
  4. Complete mediation (new: addressed by path-set declaration)

This avoids conflating authorization with universal complete mediation. The model supports a scoped NON_BYPASSABILITY claim; it does NOT establish universal complete mediation.

Test plan

  • Code compiles successfully
  • Synchronous unit tests pass (25/25 in test_adapter.py)
  • Async test failures are pre-existing infrastructure issue (missing pytest-asyncio)
  • Linux Docker tests require CMCP_CONFINEMENT_IMAGE environment variable
  • No new test files added; existing tests mapped to path-set model via docstrings

Related issues

Generated with Devin: https://devin.ai

…te example

Extends the confinement documentation to address issue agentrust-io#736's execution-scope
question by defining a path-set model for protected effects. The model distinguishes:

- Agent-side paths: originating from the agent/runtime, enforceable and testable
  by confinement machinery (e.g., gateway path, alternate endpoint, filesystem/subprocess)
- Deployment-side paths: outside agent's enforcement domain, requiring
  independent deployment-level observation (e.g., external service writing to DB)

Implements a worked example for order_create as the protected effect,
demonstrating four distinct paths (P1-P4) with clear coverage status:
- P1: ENFORCED/TESTED (gateway path, validated by test_confinement_and_fresh_restart)
- P2: ENFORCED/TESTED (alternate endpoint, validated by network mutation tests)
- P3: ENFORCED/TESTED (filesystem/subprocess, validated by filesystem mutation tests
  and network namespace inheritance blocking subprocess network escape)
- P4: DECLARED/NOT ESTABLISHED (deployment-side, requires independent observation)

Adds documentation linking this to EABC's NON_BYPASSABILITY(B,E) claim
while explicitly noting that gateway mediation alone does not prove universal
complete mediation.

Updates test docstrings to map existing confinement tests to the path-set model,
clarifying that test_linux.py validates agent-side path coverage (P1-P3) while
deployment-side paths require separate deployment-level evidence.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Thanks for this, @omwei-org. Closing it for now, and it is not about the change itself.

This repository asks first-time contributors to be vouched by a maintainer before opening a pull request. That is because agent-written contributions are easy to produce and expensive to review, and we would rather talk to you first than review something neither of us can explain.

To get vouched: open an issue saying what you want to change and why, in your own words. A maintainer will reply, and add you with /vouch. After that, reopen this pull request or open a new one.

See CONTRIBUTING.md for the detail.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant