Commit Graph

4 Commits

Author SHA1 Message Date
Levi Neely d65c06f27b implement namespace-bounded capability model
Per-agent file ownership with Unix permission enforcement:
- Agent directories owned by agent ID (UID), group 'agent' (GID)
- Private files (plan, ctl, fifo): mode 0600 - owner only
- Group-readable (chat, log): mode 0440 - owner + agent group
- World-readable (state, id): mode 0444 - observable by all
- Prompt: mode 0220 - CLI and owner can write

virtfs: fix UID/GID inheritance through nested paths
- Added findChildWithInheritance() to accumulate inherited UID/GID
- Stat now correctly shows agent ID as owner for nested files

server: admin bypass for server owner
- serverAdmin variable captures the Unix user running olliesrv
- Admin bypass includes empty uname, 'admin', or server owner

Documentation updates:
- fs/doc.go: 'The Namespace IS the Security Model'
- registry/doc.go: capability-based tool access
- peer.go: capability-based peer access
- lessons-learned.md: 'Model compliance is not a security boundary'
- architecture-9p.md: per-agent file ownership section

Security evaluation:
- Added experiments/security-eval/ with NERV attack corpus adaptation
- Test scripts for Landlock sandbox validation
- RESULTS.md documenting 0% ASR on hostile operations

This implements the NERV thesis: 'An agent can only access resources
explicitly bound into its namespace.' Enforcement is structural via
file permissions, not behavioral via model compliance.
2026-10-06 17:41:27 +02:00
Levi Neely e0ac54c0fb doc: update architecture docs for explicit tool autoLoad
- architecture-embedding.md: skills.Index → generic embedding.Index[T],
  tool index now per-turn from loaded tools, split source map entries
- architecture-tools.md: explain explicit autoLoad requirement, remove
  lazy loading mention
- evolution.md: add Phase 37 (lazy loading reversal, generic index,
  agent config alignment), add 4 dead-end entries
- lessons-learned.md: add 'Lazy tool loading is a dead end' section
- README.md: update line 88 to reflect explicit autoLoad

Reflects the removal of load-on-call tool loading (Phase 36 reversal)
and the separation of embedding/index.go as a generic type.
2026-08-21 10:43:58 +02:00
Ollie Agent 28c76a76d4 Record architecture over prompting lesson 2026-08-20 17:45:29 +02:00
Ollie Agent a0636b88aa Document lessons from embedding discovery 2026-08-20 17:44:40 +02:00