Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-dev reprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if (!key && NODE_ENV === "production") throw;   // no silent throwaway key
    // dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-dev reprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-tools Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercel Bot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
c-api Error Error Aug 3, 2026 11:34pm
veklom-id-59uw Error Error Aug 3, 2026 11:34pm

@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s) Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s) Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s) Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Caller
  participant EvidenceGenerator
  participant AgentEvidenceChain
  participant EvidenceStorage
  Caller->>EvidenceGenerator: submit execution evidence
  EvidenceGenerator->>AgentEvidenceChain: record envelope hash
  AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
  EvidenceGenerator->>EvidenceStorage: store signed evidence
  EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
  participant DelegationRegistry
  participant validateAttenuation
  participant Ed25519
  DelegationRegistry->>validateAttenuation: validate delegated capabilities
  validateAttenuation-->>DelegationRegistry: return validation result
  DelegationRegistry->>Ed25519: sign delegation
  Ed25519-->>DelegationRegistry: return signature
  DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
  participant Client
  participant ManagedIntermediary
  participant DownstreamServer
  participant ReceiptStorage
  Client->>ManagedIntermediary: process request
  ManagedIntermediary->>DownstreamServer: forward eligible request
  DownstreamServer-->>ManagedIntermediary: return response
  ManagedIntermediary->>ReceiptStorage: store signed receipt
  ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into main Aug 3, 2026
1 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants