feat(rds-core): grant v3 — tenant/policy binding + per-path sync scopes - #46
Merged
Merged
Conversation
… scopes GrantPayload advances to version 3. The signature domain tracks the payload version (rds/capability-grant/v3), the decoder dispatches on the leading version varint and still accepts v2 bytes — estate-minted v2 grants verify with all new claims absent, so the format cutover does not strand outstanding leases. New claims: tenant binds a grant to an estate tenant identifier (<=64 bytes, no control/whitespace), policy_revision records the estate policy revision the issuer minted under, and constraints.sync_paths scopes Sync reads and writes to <=64 normalized relative subtree entries (relative, nonempty, no traversal or NUL — checked at decode). Renewal cannot change either claim or the path scope: a change is an InvalidRenewal and requires fresh authorization. Agents pin the deployment binding with authority.tenant / policy_min_revision (flags --tenant/--policy-min-revision). Post-verify authorization refuses unscoped, mismatched or below-floor grants with typed TenantMismatch/PolicyRevisionStale errors; pinning a binding with no trusted issuers is refused at preflight since it could never evaluate. Access carries the signed path scope into the sync engine: both Offer and Request check the normalized rel_path as a subtree match after check_rel_path and before any filesystem handle, manifest or journal work, refusing by name without filesystem detail. Tests pin the version contract (v3 verify, genuine v2 decode, a v3 payload relabeled v2 rejected, unsupported versions refused, claim bounds, renewal preservation), the settings merge/validation rules, and a real-agent e2e lane covering tenant refusal, revision floor, read and write scope denial (including traversal and component-boundary lookalikes), no filesystem side effects, and an in-scope pull.
grant-leases documents the v3 claims, the version-dispatched signature domain, v2 compatibility and the sync_paths subtree semantics; the agent-configuration reference gains the authority.tenant / policy_min_revision fields and CLI flags. Architecture, conventions, releases and local-sessions references are updated to the v3 contract, the capability matrix gains a grants-v3 row, and the ledger records the wave with the explicitly deferred cross-repository remainder (account scopes, automatic GDS issuance/renewal, policy reconciliation).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
W2.3 module-side scope.
GrantPayloadadvances to v3:tenant+policy_revisionclaims — bind a grant to an estate tenant and record the policy revision it was minted under. Bounded and lexically validated at decode.constraints.sync_paths— signed allowlist of relative subtrees (≤64 entries) scopingSyncreads and writes. Enforced in the sync engine aftercheck_rel_pathnormalization and before any filesystem handle/manifest/journal work; refusal issync path outside granted scopewith no filesystem detail.rds/capability-grant/v3); a v3 payload signed under the v2 domain fails.authority.tenant/policy_min_revisionsettings (--tenant,--policy-min-revision) pin the deployment; post-verify authorization refuses unscoped, mismatched or below-floor grants with typed errors. Binding without trusted issuers is refused at preflight.InvalidRenewal).Deferred (cross-repository)
Account-level scopes, automatic GDS issuance/renewal, policy reconciliation — tracked in the ledger.
Test plan
grant_scopese2e on a real pinned agent: unscoped/mismatched/stale-revision refused; in-scope pull succeeds; out-of-scope read + write refused by name incl. traversal anddocsxboundary; zero filesystem side effectscargo fmt --check, clippy default + x11 lanes-D warnings,cargo test --workspace(103 suites) — all greenGenerated with Devin