Skip to content

feat(rds-core): grant v3 — tenant/policy binding + per-path sync scopes - #46

Merged
rldyourmnd merged 2 commits into
mainfrom
w2-3-grant-v3
Sep 27, 2026
Merged

rldyourmnd merged 2 commits into
mainfrom
w2-3-grant-v3

Conversation

@rldyourmnd

Copy link
Copy Markdown
Contributor

Summary

W2.3 module-side scope. GrantPayload advances to v3:

  • tenant + policy_revision claims — bind a grant to an estate tenant and record the policy revision it was minted under. Bounded and lexically validated at decode.
  • constraints.sync_paths — signed allowlist of relative subtrees (≤64 entries) scoping Sync reads and writes. Enforced in the sync engine after check_rel_path normalization and before any filesystem handle/manifest/journal work; refusal is sync path outside granted scope with no filesystem detail.
  • Version-dispatched decode — v2 and v3 both verify; v2 payloads verify with all v3 claims absent so estate-minted grants survive the cutover. v3 uses its own signature domain (rds/capability-grant/v3); a v3 payload signed under the v2 domain fails.
  • Agent binding — authority.tenant / policy_min_revision settings (--tenant, --policy-min-revision) pin the deployment; post-verify authorization refuses unscoped, mismatched or below-floor grants with typed errors. Binding without trusted issuers is refused at preflight.
  • Renewal cannot change either claim or the path scope (InvalidRenewal).

Deferred (cross-repository)

Account-level scopes, automatic GDS issuance/renewal, policy reconciliation — tracked in the ledger.

Test plan

  • grant unit tests: v3 verify+scope, v2 decode, version-relabel rejection, unsupported-version refusal, claim bounds, renewal preservation
  • settings tests: tenant/revision parse, issuer requirement, flag-over-file merge
  • grant_scopes e2e on a real pinned agent: unscoped/mismatched/stale-revision refused; in-scope pull succeeds; out-of-scope read + write refused by name incl. traversal and docsx boundary; zero filesystem side effects
  • cargo fmt --check, clippy default + x11 lanes -D warnings, cargo test --workspace (103 suites) — all green

Generated with Devin

… scopes

GrantPayload advances to version 3. The signature domain tracks the
payload version (rds/capability-grant/v3), the decoder dispatches on the
leading version varint and still accepts v2 bytes — estate-minted v2
grants verify with all new claims absent, so the format cutover does not
strand outstanding leases.

New claims: tenant binds a grant to an estate tenant identifier (<=64
bytes, no control/whitespace), policy_revision records the estate policy
revision the issuer minted under, and constraints.sync_paths scopes Sync
reads and writes to <=64 normalized relative subtree entries (relative,
nonempty, no traversal or NUL — checked at decode). Renewal cannot
change either claim or the path scope: a change is an InvalidRenewal and
requires fresh authorization.

Agents pin the deployment binding with authority.tenant /
policy_min_revision (flags --tenant/--policy-min-revision). Post-verify
authorization refuses unscoped, mismatched or below-floor grants with
typed TenantMismatch/PolicyRevisionStale errors; pinning a binding with
no trusted issuers is refused at preflight since it could never
evaluate. Access carries the signed path scope into the sync engine:
both Offer and Request check the normalized rel_path as a subtree match
after check_rel_path and before any filesystem handle, manifest or
journal work, refusing by name without filesystem detail.

Tests pin the version contract (v3 verify, genuine v2 decode, a v3
payload relabeled v2 rejected, unsupported versions refused, claim
bounds, renewal preservation), the settings merge/validation rules, and
a real-agent e2e lane covering tenant refusal, revision floor, read and
write scope denial (including traversal and component-boundary
lookalikes), no filesystem side effects, and an in-scope pull.
grant-leases documents the v3 claims, the version-dispatched signature
domain, v2 compatibility and the sync_paths subtree semantics; the
agent-configuration reference gains the authority.tenant /
policy_min_revision fields and CLI flags. Architecture, conventions,
releases and local-sessions references are updated to the v3 contract,
the capability matrix gains a grants-v3 row, and the ledger records the
wave with the explicitly deferred cross-repository remainder (account
scopes, automatic GDS issuance/renewal, policy reconciliation).
@rldyourmnd
rldyourmnd merged commit 8a63450 into main Sep 27, 2026
18 checks passed
@rldyourmnd
rldyourmnd deleted the w2-3-grant-v3 branch September 27, 2026 05:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant