Forward-merge release/0.8 into main - #936
Merged
Merged
Conversation
#### Overview Implements API-, ABI-, configuration-, and data-compatible hardening for the gateway, permission, dynamic-plugin, observability, and adaptive-cache threat-model findings. - [x] I confirm this contribution is my own work, or I have the right to submit it under this project license. - [x] I searched existing issues and open pull requests, and this does not duplicate existing work. #### Details - Add hidden authentication for managed, transparent, and generated hook clients; bind sessions to authenticated client identities; strip internal credentials before events and forwarding; and reject unsafe explicit-daemon exposure. - Route final permission requests through the existing tool conditional-execution chain and bind decisions to the exact active tool call, name, and arguments. Claude Code permission requests intentionally omit the call identifier, so Relay resolves it only when exactly one active pre-tool record matches and denies ambiguous or changed requests. - Preserve Claude Code host permission semantics: `PreToolUse` no longer pre-authorizes the action, and Relay returns Claude's event-specific permission decision shape only after final evaluation. - Preserve user settings while ensuring the transparent Relay gateway overlay has final precedence for the launched Claude process. - Require signed, trusted dynamic plugins at runtime startup by default while preserving existing manifest schemas, lifecycle management APIs, and conditional-middleware fail-open semantics. - Minimize inherited worker-process environment variables. - Confine ATOF and ATIF output beneath configured destinations, reject traversal and symlink targets, and use private files, private directories, and atomic ATIF replacement. - Document cache namespace tenancy and add partitioning coverage for namespaces, providers, and allowlisted tenant headers. - Preserve all Rust, Python, Node.js, Go, C, hook, provider, event, cache, ATOF, and ATIF interfaces and schemas. There are no breaking API or ABI changes. Validation: - `RELAY_E2E_TRANSPARENT_ONLY=1 just test-codex-plugin-e2e` — real Codex CLI tool-call round trip, second provider turn, lifecycle hooks, and balanced ATOF tool scope - `RELAY_E2E_TRANSPARENT_ONLY=1 just test-claude-plugin-e2e` — real interactive Claude Code `PreToolUse` → `PermissionRequest` allow → tool execution → `PostToolUse` round trip and balanced ATOF tool scope - `just test-rust` — 4,407 workspace tests plus native-plugin, worker-plugin, and language-binding example suites - `just test-python` - `just test-node` - `just test-go` - `cargo clippy --workspace --all-targets -- -D warnings` - `just docs` - `uv run pre-commit run --all-files` - Targeted changed-file pre-commit validation after the E2E follow-up #### Where should the reviewer start? Start with `crates/cli/src/server/mod.rs` for the hidden ingress-authentication boundary and Claude permission response, `crates/cli/src/sessions/mod.rs` for session ownership and exact permission binding, and `crates/core/src/observability/private_file.rs` for trace-path confinement and private writes. The live client scenarios are in `scripts/test-codex-plugin-e2e.sh` and `scripts/test-claude-plugin-e2e.sh`. The dynamic-plugin compatibility boundary is in `crates/cli/src/plugins/policy.rs` and `crates/cli/src/plugins/lifecycle/mod.rs`. #### Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to) - Relates to: none ## Summary by CodeRabbit * **Security** * Strengthened gateway and hook authentication with client ownership checks, browser-origin blocking, and secure client tokens. * Restricted gateway binding and dynamic-plugin runtime environments with secure defaults. * Protected local observability files with private permissions, safe paths, symlink rejection, and atomic writes. * **New Features** * Added validated permission-request handling and session-scoped authorization for Claude and Codex. * Improved Claude plugin argument handling and transparent tool-use workflows. * **Documentation** * Clarified response-cache tenant configuration and dynamic-plugin runtime behavior. Authors: - Will Killian (https://github.com/willkill07) - Maryam Najafian (https://github.com/mnajafian-nv) Approvers: - Maryam Najafian (https://github.com/mnajafian-nv) URL: #934
Author
|
SUCCESS - forward-merge complete. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Forward-merge triggered by push to release/0.8 that creates a PR to keep main up-to-date. If this PR is unable to be immediately merged due to conflicts, it will remain open for the team to manually merge. See forward-merger docs for more info.