Skip to content

fix(P1): fail-closed install/settle/X-base/cloud-write + full receipt sha256 - #11

Merged
scrimshawlife-ctrl merged 2 commits into
mainfrom
fix/p1-adversary-fail-closed
Sep 5, 2026
Merged

scrimshawlife-ctrl merged 2 commits into
mainfrom
fix/p1-adversary-fail-closed

Conversation

@scrimshawlife-ctrl

@scrimshawlife-ctrl scrimshawlife-ctrl commented Sep 5, 2026 •

Copy link
Copy Markdown
Contributor

Code-drop envelope

ADVERSARY P1 fail-closed hardening on org SoT (feba4b51). Additive only. No PyPI publish. No new bots/services. No exploit PoCs. No phenomenology. LICENSE / LICENSE_POLICY / AGENTS.md unchanged.

Workflows: anti-slop-code · production-systems · google-developer-style.

Acceptance

P1-1 Claude transactional (a)+(b)

  • hyperlex init --target claude / init_skill: refuse symlink dest; target-keyed backup before overwrite; staged smoke unless --skip-smoke → UNVERIFIED; dry-run writes nothing.
  • ./install.sh --claude and --claude-plugin copy CLAUDE_HELPERS only through scripts/install_transaction.py (hyperlex-helper kind). Unguarded copy_claude_helpers deleted.

P1-2 Settle fail-closed

Gate in settle() / settle_and_log() (not CLI-only). Scored TRUE/FALSE require human token (HYPERLEX_SETTLE_TOKEN / --settle-token) or interactive TTY confirm (SETTLE); authority.ref non-empty; kind ≠ advisory. Piped yes / non-TTY stdin without token is refused. Missing gate → exception, no score_log append. Raw token is never stored.

P1-3 X API base allowlist

Hosts: api.twitter.com, api.x.com — https only. Reject non-https, userinfo, non-default ports, off-allowlist host unless HYPERLEX_X_API_BASE_ALLOW_CUSTOM=1. No request on refuse; bearer never logged.

P1-4 Cloud vector write gate

Writes require HYPERLEX_CLOUD_WRITE=1 or TTY --i-understand-cloud-write. Gate: CloudClient upsert, force_cloud transfers, autoindex cloud stores. Auto-loaded ~/.hermes/.env / ~/.hyperlex/.env keys alone ≠ write permission. Local PersistentClient unchanged.

P1-5 Tip skew doctor marker

hyperlex doctor emits CLAUDE_SOT_CLEARED=true|false from local pin references/claude-sot-cleared.json plus git/install provenance (not live GitHub). Fails when Claude packaging is claimed and uncleared. Pin SHA: feba4b515cf7856dd0cb85cdc24291caf1330e1b (#10 Claude helpers). Shallow clones that lack the pin commit stay uncleared; Skill Validation now fetches full history so ancestry is local.

P1-6 Full receipt sha256

receipt.integrity is the full 64-char digest. emit_receipt(..., validate=True) default; CLI --no-validate escape. Legacy 12-char verify only if HYPERLEX_RECEIPT_LEGACY_INTEGRITY=1. Goldens updated.

Cheap folds

  • http/https scheme allowlist for HYPERLEX_LLM_BASE_URL / embed base (file:// refused).
  • permissions: contents: read on .github/workflows/ci.yml.

Validations (local, this tree)

  • PYTHONPATH=src pytest -q → 303 passed, 5 skipped, 20 subtests (pre-follow-up). Follow-up: tests/test_p1_fail_closed.py 38 passed; doctor/SoT subset 8 passed.
  • tests_audit → 25 passed (pre-follow-up).
  • hyperlex doctor → ok True, CLAUDE_SOT_CLEARED True (HEAD descends from feba4b51; Claude packaging not claimed).
  • install.sh --dry-run and --claude --dry-run write nothing.
  • mkdocs build --strict succeeded (nav warnings only, pre-existing).

CI note

First Skill Validation run failed on 3.10/3.11/3.12 because actions/checkout depth=1 hid pin feba4b51, so merge-base --is-ancestor could not prove descent (honest fail-closed). Follow-up commit sets fetch-depth: 0 and reports missing pin objects without a live GitHub SoT lookup.

Unresolved residuals

  • Score_log remains an unsigned append-only JSONL file (FS rewrite still possible). Hardening only; signing is out of scope.
  • Public scrimshawlife-ctrl tip may still lag org SoT post-feat: mirror Claude Code packaging helpers from personal tip #10 until that tree contains this pin / is a descendant of feba4b51.
  • Chromadb CVE pin not touched.

Do not merge — Boof/Danny auto-land.

Open in Web Open in Cursor 

… sha256

Additive ADVERSARY P1 hardening: transactional Claude init/helpers, settle
API gate, X API host allowlist, cloud vector write gate, doctor
CLAUDE_SOT_CLEARED pin, and full sha256 receipt integrity.

Co-authored-by: Daniel Meyer <scrimshawlife@gmail.com>
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown

CC @Zero-State-LLC/partner-agents. Flagged for shared triage.

Skill Validation used checkout depth=1, so merge-base could not see
feba4b5 and doctor tests failed closed. Fetch the pin's ancestors
locally (still no live GitHub SoT lookup) and report missing pin objects.

Co-authored-by: Daniel Meyer <scrimshawlife@gmail.com>
@scrimshawlife-ctrl
scrimshawlife-ctrl marked this pull request as ready for review September 5, 2026 19:05
@scrimshawlife-ctrl
scrimshawlife-ctrl requested a review from a team as a code owner September 5, 2026 19:05
@scrimshawlife-ctrl
scrimshawlife-ctrl merged commit 3188ef4 into main Sep 5, 2026
8 checks passed
@scrimshawlife-ctrl
scrimshawlife-ctrl deleted the fix/p1-adversary-fail-closed branch September 5, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants