Commit Graph

20 Commits

Author SHA1 Message Date
Levi Neely d65c06f27b implement namespace-bounded capability model
Per-agent file ownership with Unix permission enforcement:
- Agent directories owned by agent ID (UID), group 'agent' (GID)
- Private files (plan, ctl, fifo): mode 0600 - owner only
- Group-readable (chat, log): mode 0440 - owner + agent group
- World-readable (state, id): mode 0444 - observable by all
- Prompt: mode 0220 - CLI and owner can write

virtfs: fix UID/GID inheritance through nested paths
- Added findChildWithInheritance() to accumulate inherited UID/GID
- Stat now correctly shows agent ID as owner for nested files

server: admin bypass for server owner
- serverAdmin variable captures the Unix user running olliesrv
- Admin bypass includes empty uname, 'admin', or server owner

Documentation updates:
- fs/doc.go: 'The Namespace IS the Security Model'
- registry/doc.go: capability-based tool access
- peer.go: capability-based peer access
- lessons-learned.md: 'Model compliance is not a security boundary'
- architecture-9p.md: per-agent file ownership section

Security evaluation:
- Added experiments/security-eval/ with NERV attack corpus adaptation
- Test scripts for Landlock sandbox validation
- RESULTS.md documenting 0% ASR on hostile operations

This implements the NERV thesis: 'An agent can only access resources
explicitly bound into its namespace.' Enforcement is structural via
file permissions, not behavioral via model compliance.
2026-10-06 17:41:27 +02:00
Levi Neely 13831fb9f3 experiments: remove accidentally committed binary 2026-10-06 12:31:53 +02:00
Levi Neely 9a66944859 ollie-9p: add rdwrs command for streaming rdwr
rdwrs writes stdin then streams reads (does not wait for EOF).
Use for event subscription: echo filter | rdwrs event

Also adds prototype in experiments/streamrdwr demonstrating:
- Write topic filter, stream matching events
- Glob-style filtering: * (single segment), > (rest)
2026-10-06 12:31:06 +02:00
Ollie Agent acfeacc555 remove proven experiments 2026-08-16 18:37:31 +02:00
Levi Neely 9bb3cd76b8 Remove sudo mechanism from bypass system
The sudo credential broker was never functional and added complexity
without value. This removes:

- Sudo field from bypass Request structs (broker, client, toolsrv)
- Sudo parameter from EvaluateRequest interface and implementations
- Sudo/ResetsCounter fields from MetaFile and Variant structs
- sudo: true from system_logs.meta variants
- All sudo documentation from writing-tools.md, tool-registry.md,
  core.md, evolution.md, and misc.md

Bypass remains fully functional for sandbox escapes. Tools that need
elevated privileges should handle that internally or be run manually.
2026-08-12 08:58:41 +02:00
Levi Neely 6b3913a524 Remove experiments/ - concept proven 2026-08-04 16:39:15 +02:00
Levi Neely c39149ca3e 9P streaming: add chat file, rename chat→log, rewrite acme frontend
- Rename 'chat' to 'log': returns last 64KB sliding window (static read).
  Tail still works via Qid.Vers. Full history persisted to disk per turn.

- Add 'chat' streaming file: blocking read that delivers new output as
  the agent produces it. Per-fid offset tracked via waitBase. Blocks
  indefinitely between turns (no EOF). EOF only on kill/session death.

- Add LongBlock interface to File: streaming files bypass the 5s read
  timeout. Server returns content directly (ignores Tread offset for
  streaming files since waitBase tracks position).

- Add 'kill'/'.'' ctl aliases with FIXME: currently kills entire session.
  When multi-agent-per-session lands, kill should kill agent only.

- Rewrite acme frontend (cmd/Ollie) to use 9P client directly instead
  of FUSE mount. streamChat() is a blocking read loop — no polling.
  All file operations (read, write, ls) go through plan9/client.

- Add 9P streaming prototype in experiments/9p-stream demonstrating
  the blocking-read pattern for token delivery.

The key insight: 9P's request-response model gives natural streaming.
Server holds the Tread until data arrives, client blocks on Read().
No polling, no signals, no offset tracking needed.
2026-07-31 19:52:27 +02:00
Ollie Agent 9b6ddb7df1 flatten: absorb submodules into single Go module
- Remove submodules: core, 9p, acme, httpgw, remote, el
- Keep submodules: kde, webui (separate build systems)
- Collapse core/ packages into root: agent/, backend/, detach/, elevate/,
  env/, log/, paths/, sandbox/, session/, skills/, tools/, toolsrv/
- Collapse 9p/ packages: fs/session/, mount/, dbus/, cmd/olliesrv/
- Move binaries: acme/ → cmd/Ollie/, httpgw/ → cmd/ollie-httpgw/,
  remote/ → cmd/ollie-remote/, 9p/cmd/ollie-9p/ → cmd/ollie-9p/
- Move data: agents/, prompts/, tools/, scripts/, skills/ → contrib/
- Move services/ → contrib/services/, experiments/ → doc/experiments/
- Delete .beads/, .claude/, .kiro
- Single go.mod at root (module ollie)
- Fix all import paths, merge fs/ + session/ packages
- Extract dbus/ and elevate/notify.go from 9p server package
- Update justfile for new paths and single-module build
2026-07-30 18:57:51 +02:00
Levi Neely b0be365f88
Clarify Identity-Specific Rigor description
Refine the phrasing in the Future Work section to enhance clarity.
2026-05-02 14:30:21 +02:00
Levi Neely 2bd0a45271
Revise TRIAL_2.md for weather.GetWeather updates
Update documentation to reflect changes in weather.GetWeather return type and future work steps.
2026-05-02 14:29:34 +02:00
Levi Neely 491bec350e add Future Work section to TRIAL_2.md 2026-05-02 14:28:09 +02:00
Levi Neely 14a602d948 document failed subagent trial (TRIAL_2) and update coordination protocol guidance 2026-05-02 14:27:30 +02:00
Levi Neely d8508d650d
Update TRIAL_1.md 2026-05-01 12:59:26 +02:00
Levi Neely 26f868b399
Update TRIAL_1.md 2026-05-01 12:53:37 +02:00
Levi Neely 8186e2cbf2
Revise recovery procedures and clarify agent interactions
Updated the recovery procedures section to clarify human intervention steps and technical debt resolution processes.
2026-05-01 12:39:15 +02:00
Levi Neely aca064e810
Document recovery procedures for agent issues
Added details on recovery procedures for agent states and hallucination detection.
2026-05-01 12:37:58 +02:00
Levi Neely c2b50509a8
Revise TRIAL_1.md with orchestration insights
Updated the documentation to clarify issues encountered during the agent orchestration process, including notification failures, state desynchronization, and hallucination of unnecessary files. Added proposed recovery procedures and future work suggestions to enhance agent performance.
2026-05-01 12:35:59 +02:00
Levi Neely 645b37753c Document identifier slippage in Trial 1 2026-05-01 12:09:51 +02:00
Levi Neely d75c7a5cf0 Relocate Trial 1 research ideas to TRIAL_1.md under Future Work 2026-05-01 12:07:58 +02:00
Levi Neely 79395ef450 Add Experiment Trial 1: Multi-agent coordination analysis 2026-05-01 11:57:47 +02:00