feat(rds-agent): unified role/service policy, agent settings file, timeout policy (W2.1) - #45
Merged
Merged
Conversation
rldyourmnd
force-pushed
the
w2-1-agent-policy-settings
branch
from
September 27, 2026 04:24
94b5026 to
fc4948b
Compare
…licy Add a deployment-level service gate to AgentPolicy: an explicit gateable set (tcp/desktop/sync) on top of the always-on ping/info control plane, refused by name in serve_stream before grant machinery runs. Info and directory announcements now advertise exactly the effective set. Replace the hard-coded handshake/hello constants with a validated TimeoutPolicy (1s..=1h) and validate the whole policy before the agent accepts connections. Add crates/rds-agent/src/settings.rs: a versioned (schema_version 1) AgentSettings JSON document — role xor explicit services, disabled services, peers, authority, limits, timeouts — with strict parsing (16 KiB bound, deny_unknown_fields), preflight validation before any identity/binding side effects, and EndpointSettings-style file-then-flag precedence. Wire --agent-config/--role/--service/--no-service and the timeout flags through main.rs, converting defaulted options to Option so file values survive when flags are absent. Tests: settings units (parse/validate/roles/precedence), binary preflight (invalid config fails before key creation and bind), and an e2e service-policy suite covering refusal, Info honesty, and DesktopV2.
Add docs/agent-configuration.md covering the v1 settings schema — roles, explicit/disabled services, peers, authority, limits, timeouts — with bounds, file/flag precedence and examples, plus examples/agent-access.json. Update the capability matrix (deployment-gated services), endpoint and deployment docs (cross-references, systemd/config usage), README feature summary, and mark W2.1 implemented in the remediation ledger with this wave's entry.
rldyourmnd
force-pushed
the
w2-1-agent-policy-settings
branch
from
September 27, 2026 04:25
fc4948b to
affc8ea
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
W2.1 closure — the agent's policy surface moves from implicit flag-soup to a unified, versioned settings model.
AgentPolicy.services— explicit gateable set (tcp/desktop/sync) over the always-on ping/info control plane. Disabled services are refused by name inserve_streambefore grant machinery runs;Infoand directory announcements advertise exactly the effective set.AgentSettingsv1 JSON (--agent-config):rolexor explicitservices,disabled_services,peers,authority,limits,timeouts. Strict parsing (16 KiB,deny_unknown_fields), validation before identity creation/binding, file-then-flag precedence mirroringEndpointSettings. New flags:--role, repeatable--service/--no-service,--handshake-timeout,--hello-timeout.TimeoutPolicy: handshake/hello deadlines are validated policy fields (1s..=1h), not hard-coded constants.Docs: new
agent-configuration.md+examples/agent-access.json; capability matrix, endpoint/deployment docs, README and remediation ledger updated.Test plan
cargo fmt --checkcargo clippy --workspace --all-targets -- -D warningscargo clippy --workspace --all-targets --features rds-desktop/x11 -- -D warningscargo test --workspace— 0 failurescargo deny check— not installed locally; covered by CI supply-chain laneGenerated with Devin