Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules by reprewindai-dev · Pull Request #26 · reprewindai-dev/cAPI · GitHub
Skip to content

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules - #26

Merged
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard
Aug 3, 2026
Merged

feat(covenant): signed evidence, capability attenuation, accountable-intermediary modules#26
reprewindai-dev merged 1 commit into
mainfrom
devin/1785799722-capi-evidence-standard

Conversation

@reprewindai-dev

@reprewindai-devreprewindai-dev commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

Adds three additive, standards-hardened Covenant modules under src/lib/covenant/ — extracted/hardened from reference drafts — plus vitest suites. This is Phase 1: land + prove the primitives. Nothing in the live 9-phase runtime (runtime.ts), routes, governance.ts, safety.ts, or types.ts is touched, so /api/request is unchanged. Wiring these into the pipeline (and any trust-score model change) is a deliberate, design-gated Phase 2.

Each reference draft had a real Ed25519 bug — crypto.createSign('sha256') / key.export({format:'hex'}), which Node rejects for Ed25519. All three modules now reuse the existing ./crypto primitives (generateKeyPair, signMessage, verifyMessage, sha256) with base64-DER keys/signatures, and share one recursive canonical encoder.

evidence-standard.ts

Server-signed, per-agent evidence envelopes (the current runtime uses HMAC/SHA-256 with a single global lastEvidenceHash).

  • canonicalEncode() — recursive, lexicographically key-sorted, whitespace-free JSON (the existing hmacHashObject only sorts top-level keys); rejects non-finite numbers, normalizes -0.
  • EvidenceGenerator signs each envelope hash with an Ed25519 server key from COVENANT_EVIDENCE_SIGNING_KEY. Fail-closed:
    if(!key&&NODE_ENV==="production")throw;// no silent throwaway key// dev only: ephemeral keypair + one warning
  • AgentEvidenceChain — one independent chain head per agent (removes the global-head race), plus verifyEvidence, getEvidenceChain, queryEvidenceByAgent/ByTime.

capability-attenuation.ts

Deterministic, signed delegation as an explicit Capability {resource, action, constraints} model — offered alongside the existing trust-score delegation, not replacing it.

  • validateAttenuation() proves delegatee ⊆ delegator (and can't loosen max_amount); hasCapability() enforces grant/exclude/constraint/expiry/revocation.
  • DelegationRegistry signs delegations (signMessage over canonicalEncode) and does cascading revocation (guards against re-processing already-revoked to terminate cycles).

accountable-intermediary.ts

Signed gateway/proxy decision receipts (new capability — no equivalent today).

  • ManagedIntermediary.processRequest() emits a signed IntermediaryReceipt for forwarded | cached | denied(429/403) | queued, committing to the request hash + decision; verifyReceipt() recomputes hash and checks the Ed25519 signature (any field tamper ⇒ invalid).

Testing

  • npm test: 42 passed (was 29 on main) — 13 new tests, no new failures. Covers deterministic canonicalization, verify-true, prod fail-closed, tamper-every-section, per-agent chains, attenuation escalation rejection, denial codes, cascade revocation, receipt tamper detection.
  • tsc --noEmit, npm run build, npm run lint: the only failures (route-context typegen error; ESLint 10 vs legacy next lint config) reproduce identically on clean main — pre-existing, not introduced here.

Follow-up (Phase 2, not in this PR)

Wire EvidenceGenerator into Phase 7 sealing + forwardEvidence; decide whether capability attenuation supersedes trust-score delegation (data migration); source COVENANT_EVIDENCE_SIGNING_KEY via Coolify. These need design sign-off before touching the live path.

Link to Devin session: https://app.devin.ai/sessions/325c5e1802984dcd9189080f1493b466
Requested by: @reprewindai-dev

Summary by CodeRabbit

  • New Features
    • Added verifiable accountability receipts for requests, including forwarding, caching, rate limits, and policy denials.
    • Added delegated permissions with support for constrained capabilities, expiration, verification, and cascading revocation.
    • Added signed execution evidence with request and response integrity checks, authorization details, and chain tracking.
    • Added verification tools to detect tampering and confirm the authenticity of receipts, permissions, and evidence.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@reprewindai-devreprewindai-dev self-assigned this Aug 3, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment, CI, and merge conflict monitoring

@ecc-tools

ecc-toolsBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ECC bundle files are already tracked in this repository. Skipping generation of another bundle PR.

@vercel

vercelBot commented Aug 3, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
c-apiErrorErrorAug 3, 2026 11:34pm
veklom-id-59uwErrorErrorAug 3, 2026 11:34pm

@coderabbitai

coderabbitaiBot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: f3ac3e6b-b429-47e6-9105-d3daa7f47710

📥 Commits

Reviewing files that changed from the base of the PR and between b44ac31 and d61d122.

📒 Files selected for processing (6)
  • src/lib/covenant/accountable-intermediary.test.ts
  • src/lib/covenant/accountable-intermediary.ts
  • src/lib/covenant/capability-attenuation.test.ts
  • src/lib/covenant/capability-attenuation.ts
  • src/lib/covenant/evidence-standard.test.ts
  • src/lib/covenant/evidence-standard.ts

📝 Walkthrough

Walkthrough

Adds three Covenant modules: signed execution evidence with agent chains, signed intermediary receipts, and attenuated capability delegation. Each module includes verification logic and focused Vitest coverage for tampering, expiry, denial, revocation, and retrieval behavior.

Changes

Evidence standard

Layer / File(s)Summary
Evidence contracts and canonical commitments
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Defines evidence types, signing-key handling, deterministic canonical encoding, and envelope hashing.
Evidence generation and agent chains
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Generates and signs evidence, records per-agent chain state, stores records, and tests key exposure and chain linkage.
Evidence verification and queries
src/lib/covenant/evidence-standard.ts, src/lib/covenant/evidence-standard.test.ts
Verifies hashes and signatures and supports chain, agent, and time-range queries with tamper tests.

Capability attenuation

Layer / File(s)Summary
Capability models and attenuation checks
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Defines capabilities and delegated authority and checks grants, exclusions, expiry, and amount limits.
Signed delegation registry
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Registers agent keys, creates signed delegations, and verifies delegation signatures and validity.
Revocation and effective capabilities
src/lib/covenant/capability-attenuation.ts, src/lib/covenant/capability-attenuation.test.ts
Cascades revocation to downstream delegations and aggregates effective capabilities by agent and audience.

Accountable intermediary

Layer / File(s)Summary
Receipt schema and request processing
src/lib/covenant/accountable-intermediary.ts, src/lib/covenant/accountable-intermediary.test.ts
Produces signed receipts for forwarding, denials, cache hits, and queued requests.
Receipt verification and retrieval
src/lib/covenant/accountable-intermediary.ts
Validates receipt algorithms, keys, hashes, and signatures and returns stored receipts.

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
participant Caller
participant EvidenceGenerator
participant AgentEvidenceChain
participant EvidenceStorage
Caller->>EvidenceGenerator: submit execution evidence
EvidenceGenerator->>AgentEvidenceChain: record envelope hash
AgentEvidenceChain-->>EvidenceGenerator: return chain metadata
EvidenceGenerator->>EvidenceStorage: store signed evidence
EvidenceStorage-->>Caller: return evidence
Loading
sequenceDiagram
participant DelegationRegistry
participant validateAttenuation
participant Ed25519
DelegationRegistry->>validateAttenuation: validate delegated capabilities
validateAttenuation-->>DelegationRegistry: return validation result
DelegationRegistry->>Ed25519: sign delegation
Ed25519-->>DelegationRegistry: return signature
DelegationRegistry->>Ed25519: verify delegation signature
Loading
sequenceDiagram
participant Client
participant ManagedIntermediary
participant DownstreamServer
participant ReceiptStorage
Client->>ManagedIntermediary: process request
ManagedIntermediary->>DownstreamServer: forward eligible request
DownstreamServer-->>ManagedIntermediary: return response
ManagedIntermediary->>ReceiptStorage: store signed receipt
ReceiptStorage-->>Client: return receipt and response
Loading

Possibly related PRs

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch devin/1785799722-capi-evidence-standard

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

src/lib/covenant/accountable-intermediary.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/accountable-intermediary.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

src/lib/covenant/capability-attenuation.test.ts

Oops! Something went wrong! :(

ESLint: 10.8.0

TypeError [ERR_IMPORT_ATTRIBUTE_MISSING]: Module "file:///.eslintrc.json?mtime=1785801415162" needs an import attribute of "type: json"
at validateAttributes (node:internal/modules/esm/assert:88:15)
at defaultLoadSync (node:internal/modules/esm/load:164:3)
at #loadAndMaybeBlockOnLoaderThread (node:internal/modules/esm/loader:776:12)
at #loadSync (node:internal/modules/esm/loader:796:49)
at ModuleLoader.load (node:internal/modules/esm/loader:762:26)
at ModuleLoader.loadAndTranslate (node:internal/modules/esm/loader:504:31)
at #getOrCreateModuleJobAfterResolve (node:internal/modules/esm/loader:555:36)
at afterResolve (node:internal/modules/esm/loader:603:52)
at ModuleLoader.getOrCreateModuleJob (node:internal/modules/esm/loader:609:12)
at node:internal/modules/esm/loader:628:32

  • 3 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@reprewindai-dev
reprewindai-dev marked this pull request as ready for review August 3, 2026 23:56
@reprewindai-dev
reprewindai-dev merged commit 0a16af4 into mainAug 3, 2026
1 of 5 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@reprewindai-dev@anthonymillwater2-creator