Skip to content

Add native Guardian permission policy (DCO-clean) - #4333

Open
gagan114662 wants to merge 1 commit into
block:mainfrom
gagan114662:repair/guardian-dco-clean
Open

Add native Guardian permission policy (DCO-clean)#4333
gagan114662 wants to merge 1 commit into
block:mainfrom
gagan114662:repair/guardian-dco-clean

Conversation

@gagan114662

Copy link
Copy Markdown

Summary

  • add owner-configurable Monitor and Lockdown permission policies for managed agents
  • enforce fail-closed ACP permission handling with redacted decision evidence and unsupported-runtime fallback
  • integrate local Numbat findings, lifecycle retention, race-safe turn cancellation, and accessible owner-facing policy controls
  • replace Add native Guardian permission policy #4155 with one DCO-clean signed commit directly based on upstream main; no shared history was rewritten

Exact candidate

091998ca357043dea2c0cc3831a575740dfcd6b6

Verification at exact candidate

  • cargo fmt --manifest-path desktop/src-tauri/Cargo.toml --all -- --check
  • cargo check --manifest-path desktop/src-tauri/Cargo.toml
  • full Tauri suite: 2,106 passed, 0 failed, 14 intentional OS-keychain ignores
  • mixer diagnostics: 3/3 passed
  • desktop repository checks: passed
  • desktop tests: 3,911 passed, 0 failed
  • desktop TypeScript: passed
  • desktop production build: passed
  • git diff --check: passed
  • matching human Co-authored-by and Signed-off-by trailers

The first sandboxed Tauri run reported 17 localhost-bind permission failures; the unchanged suite passed completely when rerun with localhost permission. Stale reproducible build caches were removed after an out-of-disk interruption; no source or commit was deleted.

Originating Buzz channel: 2db0f46d-71e4-46c2-9798-3b248dac5fff

Co-authored-by: gagan114662 <gagan@designgaga.ca>
Signed-off-by: gagan114662 <gagan@designgaga.ca>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant