Skip to content

feat(hooks): gate trust grants through action hooks - #37

Merged
TeoSlayer merged 3 commits into
mainfrom
feat/action-hook-gating
Aug 7, 2026
Merged

TeoSlayer merged 3 commits into
mainfrom
feat/action-hook-gating

Conversation

@TeoSlayer

@TeoSlayer TeoSlayer commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Summary

  • expose harness-neutral pre and post action-hook gating on trust-grant paths
  • run anti-flood admission checks before invoking a potentially remote policy hook
  • preserve default handshake behavior when no hook is configured
  • consume the public common actionhook contract rather than private platform source

Verification

  • GOWORK=off go test -race ./...
  • GOWORK=off go vet ./...

teovl and others added 3 commits August 7, 2026 02:55
Preservation snapshot of uncommitted working-tree work (repo survey 2026-08-02).
WIP branch — do NOT push directly; split into reviewed PRs first. Build scratch
excluded via .gitignore.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… amplification)

M1: prepareTrustAction (a synchronous authority round-trip in managed-enforce
mode) ran at the very top of handleRequest/processRelayedRequest, before the
per-source and total pending caps (evaluated only under the lock afterward) and
before the already-trusted fast return. Any node that could reach port 444 or
relay a request thus forced one authority call per handshake and tied up a
handler goroutine — defeating the per-source pending cap and enabling
amplification against the operator's authority.

Add fast pre-checks before the hook: an already-trusted peer (matching key) is
accepted and over-cap/unqueued spam is rejected, both without invoking the hook.
The authoritative trust and cap decisions remain under the lock below, so the
pre-checks are a guard, not the enforcement — no change to who gets trusted. The
relayed path never drops an already-trusted or already-pending peer. Regression
test asserts the hook is not invoked for already-trusted peers or over-cap spam
(direct and relayed); full trust suite green.

SECURITY_REVIEW_v1.14 M1.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@codecov

codecov Bot commented Aug 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@TeoSlayer
TeoSlayer merged commit efae6e8 into main Aug 7, 2026
4 checks passed
@TeoSlayer
TeoSlayer deleted the feat/action-hook-gating branch August 7, 2026 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants