Skip to content

Authenticate live handoff responses and preserve timeout diagnostics - #187

Merged
imran-siddique merged 4 commits into
mainfrom
agent/handoff-timeout-diagnostics
Sep 18, 2026
Merged

imran-siddique merged 4 commits into
mainfrom
agent/handoff-timeout-diagnostics

Conversation

@imran-siddique

@imran-siddique imran-siddique commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

What and why

The reference caller appraised the peer before sending a task but accepted the returned HTTP body without authenticating it against that peer or request. Add opt-in require_authenticated_response=True: a fresh caller X25519 key and the appraised peer key derive a session MAC bound to the complete request, recipient and occurrence ID. The caller verifies provenance or denial before exposing its contents and refuses unsigned or substituted replies without fallback.

Each pending response expires and can be consumed once, including under concurrent delivery. Timeout, invalid proof and lost reply preserve an unknown execution outcome; no automatic retry is introduced. The legacy path remains available and strips reserved verification metadata so a remote peer cannot manufacture local assurance.

The PR also retains operation timing for the historical mutual-SNP burst timeout. That failure remains unexplained; the diagnostics add no retry or new hardware result.

Related: #188 and agentrust-io/.github#41. This is the implementation follow-up on the existing PR, following merged #186.

Security impact and limits

The versioned profile uses the existing integer-only JCS subset, X25519, HKDF-SHA256 and domain-separated HMAC-SHA256. It rejects duplicate/unknown envelope fields, malformed keys, ambiguous JSON, oversized messages, wrong peer/request/session, altered status and unsupported response kinds. Request context validation precedes task admission. POST redirects and ambient proxies are disabled on the authenticated submission.

Both session parties can compute the MAC. This is live-caller authentication, not portable signed evidence or the signed lineage tracked in #168. It does not encrypt provenance, introduce confidential outputs, or deduplicate server execution. Restart loses pending state; whole-process snapshot rollback and protected clocks require deployment controls. Hardware assurance still requires require_hardware=True and a pinned verifier. No live hardware run is claimed.

The chosen contract, wire bytes, compatibility rules, key rotation, replay lifetime and acceptance matrix are documented in the response profile. The new path needs security review before merge.

Validation

  • Full unit/conformance suite: 691 passed, two existing private hardware-fixture skips; 89.91% coverage on Windows/Python 3.12.
  • 57 focused response tests, including real HTTP success, authenticated denial, legacy behavior, substitution, replay, redirect refusal and reply loss after execution.
  • Public language-neutral vector with synthetic keys; HKDF/MAC cross-checked by direct HMAC extract/expand independently of the production helper.
  • Removing MAC verification, single-use enforcement or deadline checks causes the relevant regressions to fail; original source restored before the full suite.
  • Ruff, formatting, mypy (46 files), Bandit and strict staged MkDocs passed.
  • Hosted checks on 4f2fcab completed: 12 successful, two expected skips (main-only benchmark and image publication), none pending. CI run.

DCO

  • Commits are signed off.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique imran-siddique changed the title Add diagnostics for incomplete hardware handoffs Add handoff timeout diagnostics and authenticated-response requirements Sep 18, 2026
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique imran-siddique changed the title Add handoff timeout diagnostics and authenticated-response requirements Authenticate live handoff responses and preserve timeout diagnostics Sep 18, 2026
Qiang-Xu
Qiang-Xu previously approved these changes Sep 18, 2026

@Qiang-Xu Qiang-Xu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique
imran-siddique merged commit 762f329 into main Sep 18, 2026
12 checks passed
@imran-siddique
imran-siddique deleted the agent/handoff-timeout-diagnostics branch September 18, 2026 20:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants