Repository navigation
Authenticate live handoff responses and preserve timeout diagnostics - #187
Merged
Merged
Conversation
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
imran-siddique
marked this pull request as ready for review
September 17, 2026 23:35
imran-siddique
requested review from
a team,
carloshvp and
zohebk8s
as code owners
September 17, 2026 23:35
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
The reference caller appraised the peer before sending a task but accepted the returned HTTP body without authenticating it against that peer or request. Add opt-in
require_authenticated_response=True: a fresh caller X25519 key and the appraised peer key derive a session MAC bound to the complete request, recipient and occurrence ID. The caller verifies provenance or denial before exposing its contents and refuses unsigned or substituted replies without fallback.Each pending response expires and can be consumed once, including under concurrent delivery. Timeout, invalid proof and lost reply preserve an unknown execution outcome; no automatic retry is introduced. The legacy path remains available and strips reserved verification metadata so a remote peer cannot manufacture local assurance.
The PR also retains operation timing for the historical mutual-SNP burst timeout. That failure remains unexplained; the diagnostics add no retry or new hardware result.
Related: #188 and agentrust-io/.github#41. This is the implementation follow-up on the existing PR, following merged #186.
Security impact and limits
The versioned profile uses the existing integer-only JCS subset, X25519, HKDF-SHA256 and domain-separated HMAC-SHA256. It rejects duplicate/unknown envelope fields, malformed keys, ambiguous JSON, oversized messages, wrong peer/request/session, altered status and unsupported response kinds. Request context validation precedes task admission. POST redirects and ambient proxies are disabled on the authenticated submission.
Both session parties can compute the MAC. This is live-caller authentication, not portable signed evidence or the signed lineage tracked in #168. It does not encrypt provenance, introduce confidential outputs, or deduplicate server execution. Restart loses pending state; whole-process snapshot rollback and protected clocks require deployment controls. Hardware assurance still requires
require_hardware=Trueand a pinned verifier. No live hardware run is claimed.The chosen contract, wire bytes, compatibility rules, key rotation, replay lifetime and acceptance matrix are documented in the response profile. The new path needs security review before merge.
Validation
DCO