Skip to content

feat: harden Context Engine agent delivery - #7039

Open
johnpein wants to merge 10 commits into
block:mainfrom
johnpein:feature/stacy-buzz-secure
Open

feat: harden Context Engine agent delivery#7039
johnpein wants to merge 10 commits into
block:mainfrom
johnpein:feature/stacy-buzz-secure

Conversation

@johnpein

Copy link
Copy Markdown

Summary

  • add exact Gabe/Stacy Context Engine harness recognition with one-shot credential stdin and immutable runtime validation
  • sandbox ordinary managed agents in private per-agent workspaces while preserving authenticated Git worktrees
  • make the Stacy first-Save path select the reviewed frozen outer ACP binary
  • add locked, rollback-safe runtime installation and stable-path reproducible ACP release builds
  • tolerate later Gabe commits only when guarded shared-runtime bytes remain identical to Stacy upstream provenance

Validation

  • just ci
  • cargo test -p buzz-acp
  • Desktop strict clippy, focused Context Engine and sandbox tests
  • two cargo-clean trusted ACP builds produced SHA-256 f026d37b61cd9cc5dcc13cd59856301591dcddd7f81ad894680680218f99a97d
  • adversarial security and end-to-end reviews found no remaining Critical, High, or Medium code defects

Release gate

Do not install an unsigned local build. Activation remains gated on a Block Developer-ID-signed and notarized Buzz artifact built from the exact upstream merge commit, followed by the single-Save Stacy DM proof.

Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
Signed-off-by: John Peinhardt <johnpeinhardt@gmail.com>
@johnpein
johnpein requested a review from a team as a code owner August 29, 2026 19:11
@github-actions

Copy link
Copy Markdown

🔐 Codex Security Review

Status: review required for the current range.

The current range is 00e61eafa917d296104006576b7a2ddbfd58bb5a...67cb7f2c45f7c4d9103dce5bc3ade3ea34e1b5da.
A new review must complete for this exact range. When manual authorization
is required, a Block organization member must comment exactly
@buzz-security-review 67cb7f2c45f7c4d9103dce5bc3ade3ea34e1b5da to authorize a new review.
Any previous review applies only to its recorded range.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant