Skip to content

Registry: enforce the installed permission manifest at load and run time (follow-up to M7a) #272

Description

@LinuxDevil

Follow-up to #229 (M7a), which enforces a registry item's permission manifest at install time only (a static check of the code, --allow with --yes, and the receipt <agent-dir>/lousho-registry.json).

Goal

Use the receipt to enforce the manifest when the agent loads and runs, so an installed item cannot do more than it declared even if its code hides it from the static check:

  • tools from an item with exec: true (or any item whose needsApproval is true) always require approval;
  • sandbox egress for the item's tools limited to its network hosts (hostPattern / the credential broker allow-list);
  • only the item's declared env variables passed through where the SDK controls the environment;
  • loadAgentDir notices files whose sha256 no longer matches the receipt and reports it (warn or lousho doctor finding), without refusing edits the owner made on purpose.

Notes

  • Receipt format (v1): { "v": 1, "items": { "<name>": { "type", "registry", "installedAt", "permissions", "files": [{ "path", "sha256" }] } } }, written by src/cli/addReceipt.ts.
  • Out of scope in [M7a] lousho add: enforce the permission manifest at install #229 by design ("Enforcing the manifest at load or run time ... open a follow-up issue").

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions