Skip to content

Define multi-identity workload security contract - #63

Open
omry wants to merge 1 commit into
pr62from
pr63
Open

Define multi-identity workload security contract#63
omry wants to merge 1 commit into
pr62from
pr63

Conversation

@omry

@omry omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner

Select Podman for exact and bounded-range mapping profiles, define exclusive per-installation private mappings and the trusted supervisor capability boundary, and record identity-policy, sandbox, isolation, capability, and lifecycle conformance requirements before product integration.

Require Docker Engine rejection, reject external bind mounts until safe input and ownership contracts exist, and require identifiable seccomp-policy evidence while deferring public schema and production runtime behavior to later reviewed slices.

@omry
omry changed the base branch from main to pr62 August 14, 2026 03:53
@omry
omry marked this pull request as ready for review August 14, 2026 03:59
Copilot AI lite review requested due to automatic review settings August 14, 2026 03:59

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review 64a1263

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

Reviewed commit: 64a12632ce

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@omry omry added the approved PR reviewed and approved label Aug 14, 2026
@omry
omry force-pushed the pr63 branch 2 times, most recently from 2222795 to fb4dac1 Compare August 14, 2026 10:24
@omry omry removed the approved PR reviewed and approved label Aug 14, 2026
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review fb4dac1

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fb4dac1e2d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review 5c01ea7

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5c01ea7ef8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review eb6cb2e

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eb6cb2e209

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review c7faf41

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c7faf4182e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review 10c05fb

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 10c05fb703

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review f4e7ca9

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f4e7ca98ce

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review b709b28

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b709b28c6e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review d8f2ef9

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d8f2ef9816

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md
Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md
Comment thread docs/FUTURE_DIRECTIONS.md
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review f831885

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f831885c82

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/MULTI_IDENTITY_SECURITY_CONTRACT.md Outdated
Select Podman for exact and bounded-range mapping profiles, define exclusive per-installation private mappings and the trusted supervisor capability boundary, and record identity-policy, sandbox, isolation, capability, and lifecycle conformance requirements before product integration.

Require Docker Engine rejection, reject external bind mounts until safe input and ownership contracts exist, and require identifiable seccomp-policy evidence while deferring public schema and production runtime behavior to later reviewed slices.
@omry

omry commented Aug 14, 2026

Copy link
Copy Markdown
Owner Author

@codex review 3210a48

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3210a486d4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +219 to +223
10. **Bounded resource use.** Where the selected host and runtime support the
corresponding controls, every application workload has explicit process,
memory, CPU, temporary-storage, and output bounds. The resolved and
effective policy agree, and exceeding a bound is contained without
exhausting host or peer-workload capacity.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject hosts missing required resource controls

When a selected Podman host lacks even one control—such as rootless cgroup delegation or temporary-storage quotas—the amended conditional wording imposes no fail-closed outcome, and SB-03 likewise tests only hosts where controls are supported. An implementation could therefore admit an untrusted workload without that bound and still satisfy the ledger, despite resource exhaustion being in the threat model; require admission to fail before mutation when every required bound cannot be enforced, or explicitly exclude such hosts from this profile.

Useful? React with 👍 / 👎.

| ID-01 | Every mapped identity has exclusively delegated subordinate host authority only; it does not alias host root, a local or NSS-provided host principal, or a subordinate range delegated to another host principal. | 1 | Host-side mapping inspection and authoritative collision checks against the host identity inventory and every other subordinate UID/GID delegation, plus explicit collision-failure cases and an in-container identity probe for each profile. | Unproven; repeated conformance probe pending |
| ID-02 | The trusted supervisor can perform every required declared transition and rejects mapped-but-undeclared UIDs, GIDs, and supplementary groups; every application child's final supplementary-group vector contains exactly its declared groups; a separate raw bounded-range mechanism probe permits representative other in-range transitions. | 1 | Positive declared-identity and negative mapped-but-undeclared tests through the production supervisor policy, final `Groups:` inspection that excludes inherited privileged, runtime-required, and otherwise undeclared groups, plus an independently identified raw range-mechanism probe. | Unproven; repeated conformance probe pending |
| ID-03 | Exact mappings reject every unmapped transition; bounded ranges reject every out-of-range transition; capability-dropped children cannot change identity or regain authority through set-ID or file-capability execution. | 1 | Profile-specific boundary and post-drop tests for `setuid`, `setreuid`, `setresuid`, `setfsuid`, `setgid`, `setregid`, `setresgid`, `setfsgid`, `setgroups`, set-user/group-ID execution, and file-capability execution. | Unproven; repeated conformance probe pending |
| ID-04 | Two installations using the same container IDs have distinct host mappings, PID and IPC namespaces, and private `/dev/shm` mounts; they cannot observe, signal, or ptrace each other's processes, use each other's System V or named POSIX shared-memory and semaphore objects, use each other's System V message queues, or read each other's private state. | 1 | Concurrent two-workload probe with host mapping, PID-namespace, IPC-namespace, and `/dev/shm` mount inspection plus negative process visibility, signaling, ptrace, System V IPC, POSIX `shm_open`/`sem_open`, and private-state access tests. | Unproven; repeated conformance probe pending |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Test abstract Unix sockets across workload boundaries

If an implementation shares a network namespace between workloads but filters IP traffic, the required PID/IPC namespace checks and negative TCP/UDP probes can all pass while both workloads still share Linux's abstract Unix-domain socket namespace. That permits an undeclared cross-workload channel despite the narrow-sharing requirement; require distinct network-namespace inspection and a negative abstract-socket connection probe.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Firewall support will come later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants