Skip to content

Enforce participant flow policy at final runtime sinks #1003

Description

@Brad-Edwards

Parent: #812

Bounded outcome

Extend RUN-319 so every governed external action or disclosure resolves SEM-233 effective labels, exact policy/state cut, authority, destination, and API-407 support immediately before RuntimeTarget dispatch or serialization. Commit the decision atomically before effect and preserve idempotent, append-only evidence.

Negative cases

  • Enforcement only at planning, schema validation, action admission, gateway, prompt, monitor, or request construction.
  • Backend dispatch or participant-visible output before the durable permit decision.
  • Missing label/provenance, stale cut, unsupported capability, policy denial, failed expected-head check, or failed commit causing any external effect.
  • Streaming chunks, errors, tool arguments, callbacks, or handoffs bypassing the sink policy.
  • Unsafe raw values in diagnostics, logs, audit, or error envelopes.

Evidence required

  • Boundary tests through the real RuntimeControlPlane and instrumented RuntimeTarget.
  • Zero target-call and zero disclosure assertions for every denial class.
  • Atomic store, history-head, idempotency, replay, restart, and both shipped-store evidence.
  • Authenticated identity/target/participant/controller/audience binding tests.
  • Safe bounded diagnostics and audit/evidence assertions.

Explicit nonclaims

  • Reference-runtime enforcement is not backend realization or universal information-flow control.
  • No undeclared timing/covert-channel, opaque apparatus, monitor-honesty, or model-alignment claim.

Dependencies

Requirements

  • SEM-233
  • RUN-319
  • RUN-310
  • API-423
  • API-407

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:runtimeRuntime and control-plane codeenhancementNew feature or requestin-progressAn agent is actively working this issue via /implementsecuritySecurity vulnerabilities and hardening issues

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions