refactor(kernel): AgentDelete always reclaims a deleted principal's footprint (#1217) - #1383
Merged
joshuajbouw merged 5 commits intoAug 12, 2026
Conversation
Contributor
Author
|
@joshuajbouw ready for review — opt-in |
Member
|
Review outcome: valuable direction, but hold for changes. CI reports a public API break because adding |
jvsteiner
added a commit
to jvsteiner/astrid
that referenced
this pull request
Aug 5, 2026
…reclaiming-delete teardown (astrid-runtime#1217) Addresses the review on astrid-runtime#1384: - Remove the --group flag. The throwaway is always created with the fixed least-privilege group (empty groups -> default agent group -> empty capsule allow-list -> no invocable tool can egress), so "locked down" is an invariant of spawn, not a default a caller can flip off. - Teardown calls AgentDelete { principal }, which now always reclaims the footprint (astrid-runtime#1383) -- dropped the removed purge_home plumbing. - Doc/CHANGELOG updated. Live end-to-end evidence against a running daemon is the remaining item; PR stays draft until captured. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
joshuajbouw
force-pushed
the
fix/1217-agent-delete-purge-home
branch
from
August 12, 2026 16:30
b3a1bc4 to
4c2a02a
Compare
Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com>
joshuajbouw
added a commit
that referenced
this pull request
Aug 13, 2026
…#1384) ## Linked Issue Closes #1217 (built on #1383). ## Summary Adds `astrid agent spawn`: one bounded job under a newly derived, restricted principal, followed by reclaiming teardown. The derived runtime receives only explicitly named WASM capsule installs, capsule-scoped state, user-invocable capsule grants, and outbound endpoints. Nothing else is inherited implicitly. ## Changes - Add `astrid agent spawn --job ...` with explicit `--load-capsule`, `--allow-capsule`, `--inherit-capsule-state`, and `--allow-egress` controls. - Make restricted authority an invariant: spawn exposes no arbitrary capability-grant flag and always provisions the built-in `restricted` group. - Add a dedicated additive `admin.agent.derive` request topic and client method rather than adding a variant to the exhaustive public `AdminRequestKind` enum. - Reject duplicate or inconsistent capsule selections, malformed egress, residual target state, and host-MCP/native-process capsule installs. - Materialize only selected capsule installs and copy env, KV, and declared secrets only for explicitly selected capsule namespaces. - Enforce restricted-principal network and process policy again at host-call time. - Authenticate the job uplink as the derived principal, auto-deny approval requests, apply a wall-clock timeout, and send cooperative cancellation before teardown. - Roll failed provisioning back through the ownership deletion guard so concurrent fleet assignment cannot leave ownership pointing at deleted identity state. - Drain admitted host effects and terminate principal-owned process groups before reclamation, while preserving peer runtimes. - Reclaim KV before removing the profile needed by the production quota resolver, retaining the retirement fence throughout teardown. - Tear down through #1383's reclaiming `AgentDelete`; `--keep` remains an explicit debugging escape hatch. ## Verification - `cargo fmt --all -- --check` - `cargo test -p astrid-kernel --lib -- --quiet`: 309 passed - `cargo test -p astrid-capabilities --lib -- --quiet`: 78 passed - Native deletion and restricted derive regressions - Retirement drain, late-admission, KV/FS/secret denial, and secret-read barrier regressions - Process-group descendant cancellation with peer continuity - Strict non-default profile loading and registration-versus-unload serialization - Wasm portability script - Exact CI clippy package surface with all targets/features and `-D warnings` - `git diff --check` The live spawn-run-teardown proof passed against a fresh restricted principal derived from `gemma-code`: the real React and OpenAI-compatible provider capsule set warmed, the provider returned exactly `PR1384_LIVE_OK`, teardown succeeded, and the principal disappeared from `agent list`. Its profile, home, key, secrets, and isolated test homes were absent afterward. ## AI / Tool Assistance Assisted-by: OpenAI Codex: GPT-5 Codex helped reconstruct and adversarially review the patch on current code, remove capability-escalation paths, preserve public Rust API compatibility, integrate fleet-ownership-safe rollback, harden retirement and teardown ordering, add focused regressions, and execute the live provider-backed spawn-run-teardown proof. I reviewed the final changes, risks, and validation and created each GPG-signed, DCO-compliant commit. ## Checklist - [x] Linked to an issue - [x] CHANGELOG.md updated - [x] I understand every change in this PR and can explain its design, risks, and validation. - [x] I reviewed and tested any meaningful tool-generated output included in this PR. - [x] Every non-bot, non-merge commit has a matching `Signed-off-by` trailer. --------- Signed-off-by: Joshua J. Bouw <jjb@unicity-labs.com> Co-authored-by: Joshua J. Bouw <jjb@unicity-labs.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linked Issue
Closes #1217.
Summary
Deleting an agent must retire an authority generation, not merely remove files. This makes deletion fail closed across identity, tokens, allowances, capsule state, signing material, and crash recovery.
Changes
Verification
Regression coverage includes cleanup failure followed by recreate and retry, legacy alias tombstones, orphan KV reclamation, retirement fences, revocation preservation, and peer-principal isolation.
AI / Tool Assistance
Assisted-by: OpenAI Codex: GPT-5
Codex performed adversarial review, implemented the fail-closed deletion and recovery fixes, added regression coverage, and validated the affected crates. Human-authored DCO and GPG signatures remain on every commit.
Checklist