Skip to content

Add Parmana as a TRACE external evidence source - #294

Open
pavancharak wants to merge 1 commit into
agentrust-io:mainfrom
pavancharak:add-parmana-server
Open

pavancharak wants to merge 1 commit into
agentrust-io:mainfrom
pavancharak:add-parmana-server

Conversation

@pavancharak

Copy link
Copy Markdown

Parmana as a TRACE external evidence source
Follows #286. Adds integrations/parmana-server/: Parmana's signed authorization decisions mapped to TRACE references, with an offline checker and the fixtures from one evaluation run.
Per your answers on #286 (trace-spec at db95328):
Role: external-evidence-source, no conformance level. No TRACE Trust Record is issued, so no placeholder subject, model, data_class or build_provenance.
Signing: Parmana keeps its own canonical form and signatures. A runtime's Trust Record points at them: authorized-intent to the Execution Trust Record or Refusal Record, and approval-outcome to the signed approval (retained inside the Trust Record, at #/transaction/signals/approvalArtifact).
Unit: one Parmana record per decision, refusals included.
Mocks: nothing is referenced as observed-effect. The mock label stays in fixtures/report.json, the README and a test.
Re-pinned: the fixtures are one unedited run at pavancharak/parmana commit ac22a7ed594b4a527504ce43841595c1a62f3046. That commit includes the Refusal Record policy content hash (all three records carry it) and the release workflow that publishes the server image with SLSA provenance.
Reproduction

cd integrations/parmana-server
pip install -e ".[test]"
python examples/emit_references.py
python -m pytest tests

18 tests check:
every signature, with Parmana's public key only;
that a changed amount, outcome or approval limit fails;
that the approval is the one the Trust Record was signed over;
that all three decisions name one policy content hash;
that references.json is exactly what the records produce and validates as agentrust_trace.Reference (0.11.0).
To regenerate the fixtures from Parmana itself: npm run evaluate:agentrust-refund at that commit (no network, keys or accounts).
Licence
I, Pavan Dev Singh Charak, for Parmana Systems Private Limited, the copyright holder, license everything in integrations/parmana-server/ under the Apache License 2.0: the code, the README and the fixtures, which are records generated by Parmana in that run. The parmana Python SDK it depends on is Apache-2.0 on PyPI.
Not claimed:
Any downstream effect: the connector in the run is a mock.
That the two caller-declared facts were checked: they can only refuse.
That the policy was approved through governance in the run: the governance anchor reads NO_APPROVAL_RECORD.
The README says the same.

@pavancharak

Copy link
Copy Markdown
Author

The server image with SLSA provenance is published: ghcr.io/pavancharak/parmana-api@sha256:f82c0076ebff847c5ae0afb5f9e3728e49c9dd819f8e52ba0d8659a960753865 (release server-v1.0.0, built at f95f786e).

slsa-verifier verify-image ghcr.io/pavancharak/parmana-api@sha256:f82c0076ebff847c5ae0afb5f9e3728e49c9dd819f8e52ba0d8659a960753865 --source-uri github.com/pavancharak/parmana --source-tag server-v1.0.0

returns PASSED, builder generator_container_slsa3.yml@v2.1.0. f95f786e is the fixtures’ commit ac22a7ed plus only the commit that records the evaluation report and fixtures, so the image runs the same code that produced the fixtures. The hosted API is built by Vercel and carries no provenance.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant