ollie/cmd/toolsrv/internal/server
Levi Neely d65c06f27b implement namespace-bounded capability model
Per-agent file ownership with Unix permission enforcement:
- Agent directories owned by agent ID (UID), group 'agent' (GID)
- Private files (plan, ctl, fifo): mode 0600 - owner only
- Group-readable (chat, log): mode 0440 - owner + agent group
- World-readable (state, id): mode 0444 - observable by all
- Prompt: mode 0220 - CLI and owner can write

virtfs: fix UID/GID inheritance through nested paths
- Added findChildWithInheritance() to accumulate inherited UID/GID
- Stat now correctly shows agent ID as owner for nested files

server: admin bypass for server owner
- serverAdmin variable captures the Unix user running olliesrv
- Admin bypass includes empty uname, 'admin', or server owner

Documentation updates:
- fs/doc.go: 'The Namespace IS the Security Model'
- registry/doc.go: capability-based tool access
- peer.go: capability-based peer access
- lessons-learned.md: 'Model compliance is not a security boundary'
- architecture-9p.md: per-agent file ownership section

Security evaluation:
- Added experiments/security-eval/ with NERV attack corpus adaptation
- Test scripts for Landlock sandbox validation
- RESULTS.md documenting 0% ASR on hostile operations

This implements the NERV thesis: 'An agent can only access resources
explicitly bound into its namespace.' Enforcement is structural via
file permissions, not behavioral via model compliance.
2026-10-06 17:41:27 +02:00
..
doc.go add doc.go files; decompose agent package 2026-08-27 10:03:58 +02:00
pathlock.go toolsrv: add path-based lock table for cross-agent serialization 2026-08-14 14:27:21 +02:00
pathlock_test.go toolsrv: add path-based lock table for cross-agent serialization 2026-08-14 14:27:21 +02:00
proc.go implement namespace-bounded capability model 2026-10-06 17:41:27 +02:00
proc_test.go Code quality fixes from review 2026-08-21 19:16:44 +02:00
server.go Code quality fixes from review 2026-08-21 19:16:44 +02:00
state_test.go toolsrv: rename internal/fs → internal/server 2026-08-11 21:15:03 +02:00