Skip to content

feat(security): vendor TinySecurity and migrate filesystem authorization - #7331

Draft
senamakel wants to merge 21 commits into
tinyhumansai:mainfrom
senamakel:security-bus-7328
Draft

senamakel wants to merge 21 commits into
tinyhumansai:mainfrom
senamakel:security-bus-7328

Conversation

@senamakel

@senamakel senamakel commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

OpenHuman vendors TinySecurity and routes asynchronous filesystem authorization through its attested native module when security-module is enabled. Immutable per-agent scopes translate trusted roots, acting grants, and application-state reservations. Missing, untrusted, faulted, or timed-out modules deny access. The host links only tinysecurity-bus; the feature forwards through every product host.

The registry and gitlinks now pin published TinySecurity v0.2.2 and TinyBox v0.1.17. All 11 supported host digests are copied verbatim from each published checksum.toml. The pin gate passes; reconciled TinyWallet/TinyChannels exemptions are removed. The branch includes current main and its TinyBox Windows portability fix.

Native CI now loads the real released TinySecurity archive through the compiled digest pin, then tests confidential policy calls, scope persistence after reinit, denials, and latency on Linux, macOS, and Windows. Explicit local fixtures remain available only for development.

Dependency draft: tinyhumansai/tinysecurity#4 fixes the two late policy findings from #3 (ancestor metadata errors and forbidden-root alias precedence), plus the release verifier's invalid empty initialization fixture. It must merge and release, then this PR must repin that release before shipping. The published v0.2.2 archive passes TinySecurity's configured verifier; its final release job failed because the generic loader supplied unsupported {} config.

Validation:

  • Upstream follow-up: 152 tests plus the compile-fail API test, build, Clippy, formatting, native verification, and >90% source coverage pass; Linux/macOS/Windows CI passes.
  • Published v0.2.2 archive: digest loading, policy calls, malformed request checks, reinit, and latency pass in the configured native verifier.
  • TinyBox v0.1.17 release workflow passes, including published-archive verification.
  • Module pins, bus-only dependency check, crate chain, feature forwarding, Rust layout, and script tests pass.
  • Fresh OpenHuman published-archive integration passes all 13 tests; 500 samples yield p99 0.80ms (budget 50ms). Default workspace cargo check, documentation generation, and documentation checks pass. Linux native CI and all six artifact-staging jobs pass; macOS/Windows native and full hosted CI are still running.
  • The follow-up review incorrectly requested denying a broad forbidden ancestor; the documented workspace-precedence contract and existing nested-denial test justify retaining this behavior. The thread has a reasoned reply, the specification names aliases explicitly, and automated re-review is pending.

This implements the filesystem slice of phases 1–2 and retains the characterization work already in this PR. It does not close #7328: shell/config consolidation, redaction/egress, approvals, sandbox routing, middleware, audit, crypto, and their cross-OS coverage remain required.

…dencies

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@senamakel

senamakel commented Oct 10, 2026 •

Copy link
Copy Markdown
Member Author

TinySecurity is now vendored, and the filesystem validators route through immutable native policy scopes under security-module. The latest OpenHuman head is 16b44cf387; upstream scope implementation is in tinyhumansai/tinysecurity#3 at 5e90937. Earlier TinySecurity #2 and TinyBox #28 prerequisites have merged.

Fresh verification: 144 upstream Linux tests plus a compile-fail API regression, Clippy, native admission verification and every source file above 90% coverage pass. An independent host verifier passed 13 adapter/config/native tests, five translation tests and the public missing-module regression. The real native fixture also passes from Cargo’s crate working directory, with p99 0.571 ms against the 50 ms budget. Dependency, forwarding and layout checks pass. The encrypted RPC fixture, 158 hosted tests, all three embed integration targets and all 2,427 storage-domain tests pass. The final scope-constructor patch also passes the host’s real-loader fixture at p99 0.740 ms.

The release-URL parser regression is fixed. All six published-artifact staging jobs now correctly fail on TinySecurity’s absent release URL. This remains a dependency draft until the upstream change merges and releases, its published tag and all 11 checksum entries are pinned, and positive public-validator parity plus the three-OS released-artifact matrix pass. Locally hashed test fixtures do not populate production pins. This PR implements filesystem migration preparation; the remaining phases of #7328 are still open.

Hosted candidate-source three-OS native jobs are still running. Markdown CI encountered 205 GitHub HTTP 503 responses; the final push triggers another run. CodeRabbit skipped the draft OpenHuman PR and rate-limited upstream, so its status is not evidence of a completed review.

Final follow-up native checks reject unresolved paths, preserve directory reads while rejecting filename-less parent writes, normalize Windows trailing-dot/space denial aliases, and fail closed for unresolved grant roots. Native 144-test workspace, compile-fail API, Clippy, coverage and rebuilt host fixture pass.

Windows follow-up also rejects drive-relative/rooted ambiguous inputs before action-directory joining and normalizes alternate-data-stream denial aliases without broadening grants. Native Windows regressions are in the upstream matrix; Unix colon filenames remain valid. The rebuilt module passes the OpenHuman loader fixture.

Final metadata checks treat only NotFound as a prospective target. The latest upstream snapshot has zero unresolved threads; four historical changes-requested reviews await re-review, with no dismissals. All local verification passes; hosted matrices and published-release pins remain outstanding.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel senamakel changed the title test(security): characterize RPC contracts and enforce bus-only dependencies feat(security): vendor TinySecurity and migrate filesystem authorization Oct 10, 2026
senamakel and others added 9 commits October 10, 2026 19:51
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
# Conflicts:
#	crates/openhuman-core/src/security/keyring/encrypted_file_backend.rs
#	crates/openhuman-embed/tests/common/mod.rs
#	crates/openhuman-embed/tests/saas_profiles.rs
senamakel and others added 9 commits October 10, 2026 22:03
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tracker: consolidate security, policy, approvals and sandboxing into the tinysecurity bus module (+ tinybox audit)

1 participant