Skip to content
Open
Changes from 1 commit
Commits
Show all changes
158 commits
Select commit Hold shift + click to select a range
2f3834e
feat(runtime): add policy-aware tool registry
JoTalbot Aug 26, 2026
9510b30
feat(runtime): add tool execution policy boundary
JoTalbot Aug 26, 2026
57f9249
test(runtime): cover tool permissions and sandbox boundary
JoTalbot Aug 26, 2026
36ccb86
feat(runtime): add structured execution audit trail
JoTalbot Aug 26, 2026
392f48b
feat(runtime): audit tool sandbox executions
JoTalbot Aug 26, 2026
cc497f1
test(runtime): cover tool execution audit trail
JoTalbot Aug 26, 2026
7ab6c3b
feat(runtime): add agent execution adapter
JoTalbot Aug 26, 2026
bc7483e
feat(runtime): connect orchestrator to agent executor
JoTalbot Aug 26, 2026
aeff23d
fix(runtime): pass agent executor through scheduled task
JoTalbot Aug 26, 2026
c7c58b9
feat(kernel): execute scheduled tasks through agent executor
JoTalbot Aug 26, 2026
bc11aca
test(runtime): cover agent executor tool pipeline
JoTalbot Aug 26, 2026
6fbe2b6
feat(runtime): connect orchestrator memory context
JoTalbot Aug 26, 2026
a452bc2
test(runtime): verify orchestrator tool execution path
JoTalbot Aug 26, 2026
532c904
feat(runtime): add typed tool call result protocol
JoTalbot Aug 26, 2026
0133483
feat(runtime): add timeout aware typed tool executor
JoTalbot Aug 26, 2026
c8a4982
test(runtime): cover typed tool results and timeout
JoTalbot Aug 26, 2026
76dc790
refactor(runtime): use typed tool protocol in agent executor
JoTalbot Aug 26, 2026
d22b1d8
test(runtime): verify typed agent execution and retry
JoTalbot Aug 26, 2026
cacf1eb
feat(cognition): bridge tool failures into replanning
JoTalbot Aug 26, 2026
8426821
test(cognition): verify tool failure reflection bridge
JoTalbot Aug 26, 2026
77b5871
refactor(runtime): standardize execution context and correlation id
JoTalbot Aug 26, 2026
fa480e0
feat(runtime): add async event bus
JoTalbot Aug 26, 2026
3a775e7
feat(runtime): add correlated execution event contract
JoTalbot Aug 26, 2026
9c78330
feat(runtime): correlate audit events with execution context
JoTalbot Aug 26, 2026
f05a5cd
feat(runtime): define canonical lifecycle event types
JoTalbot Aug 26, 2026
f70118c
feat(runtime): correlate tool lifecycle events
JoTalbot Aug 26, 2026
8d160ca
feat(runtime): propagate execution context through agent lifecycle
JoTalbot Aug 26, 2026
b441593
feat(runtime): add orchestration lifecycle event publisher
JoTalbot Aug 26, 2026
33907df
feat(runtime): propagate lifecycle events through orchestrator
JoTalbot Aug 26, 2026
a3e0faf
feat(cognition): add orchestrator replan lifecycle
JoTalbot Aug 26, 2026
e193b89
feat(runtime): add bounded autonomous execution loop
JoTalbot Aug 26, 2026
4217560
test(runtime): cover automatic replan execution loop
JoTalbot Aug 26, 2026
525c4e8
feat(runtime): add persistent execution state store
JoTalbot Aug 26, 2026
ff0822f
test(runtime): verify persistent execution recovery
JoTalbot Aug 26, 2026
49bcb58
feat(runtime): persist checkpoints and resume executions
JoTalbot Aug 26, 2026
ca9df87
test(runtime): verify restart-safe autonomous loop
JoTalbot Aug 26, 2026
ccb006a
feat(runtime): complete startup recovery manager
JoTalbot Aug 26, 2026
f5b533e
test(runtime): verify startup recovery manager
JoTalbot Aug 26, 2026
1ea5698
feat(runtime): add startup runtime bootstrap recovery
JoTalbot Aug 26, 2026
75b19fd
test(runtime): verify startup recovery orchestration
JoTalbot Aug 26, 2026
eeb2c64
fix(runtime): resume persisted executions through loop
JoTalbot Aug 26, 2026
685f196
feat(runtime): wire bootstrap to restart-safe loop resume
JoTalbot Aug 26, 2026
49cfced
test(runtime): add end-to-end startup recovery coverage
JoTalbot Aug 26, 2026
1f92585
feat(runtime): add restart recovery execution lease
JoTalbot Aug 26, 2026
dfb1531
test(runtime): verify exclusive execution recovery lease
JoTalbot Aug 26, 2026
dc0e7de
feat(runtime): enforce exclusive leases during startup recovery
JoTalbot Aug 26, 2026
cb4579a
test(runtime): verify exclusive bootstrap recovery leases
JoTalbot Aug 26, 2026
b2d2595
feat(runtime): add execution lease renewal and ownership checks
JoTalbot Aug 26, 2026
1e41129
test(runtime): verify execution lease renewal ownership
JoTalbot Aug 26, 2026
c22e6f7
feat(runtime): add automatic recovery lease heartbeat
JoTalbot Aug 26, 2026
6a96296
test(runtime): verify recovery lease heartbeat lifecycle
JoTalbot Aug 26, 2026
64de1a5
test(runtime): simulate crash and takeover recovery
JoTalbot Aug 26, 2026
4005bd3
feat(runtime): add explicit recovery checkpoint lifecycle
JoTalbot Aug 26, 2026
f3cfded
feat(runtime): integrate recovery checkpoints into execution loop
JoTalbot Aug 26, 2026
c5c925a
test(runtime): add checkpoint integration coverage
JoTalbot Aug 26, 2026
051d200
fix(test): complete checkpoint integration assertions
JoTalbot Aug 26, 2026
beec171
feat(runtime): guard checkpoints with execution lease ownership
JoTalbot Aug 26, 2026
92ffba6
fix(runtime): restore loop compatibility after lease-aware checkpoint
JoTalbot Aug 26, 2026
72e3584
test(runtime): cover stale-owner checkpoint rejection
JoTalbot Aug 26, 2026
f3b89bc
fix(runtime): use RecoveryCheckpoint in lease-aware adapter
JoTalbot Aug 26, 2026
05c14af
feat(runtime): provide lease-aware autonomous runtime factory
JoTalbot Aug 26, 2026
665b790
feat(runtime): add unified runtime lifecycle orchestrator
JoTalbot Aug 26, 2026
0d2d48e
test(runtime): verify unified runtime lifecycle
JoTalbot Aug 26, 2026
25a9912
fix(runtime): make orchestrator startup failure-safe
JoTalbot Aug 26, 2026
a51a83c
test(runtime): verify startup failure rollback
JoTalbot Aug 26, 2026
ecbdcf6
feat(runtime): implement graceful shutdown lifecycle
JoTalbot Aug 26, 2026
043c5ad
test(runtime): verify graceful shutdown lifecycle
JoTalbot Aug 26, 2026
fafa412
feat(runtime): wire graceful shutdown into orchestrator
JoTalbot Aug 26, 2026
122c240
feat(runtime): guarantee lease release during graceful shutdown
JoTalbot Aug 26, 2026
04f51f2
fix(runtime): release owned leases on orchestrator shutdown
JoTalbot Aug 26, 2026
dcf233c
test(runtime): verify shutdown releases recovery leases
JoTalbot Aug 26, 2026
6d1f551
fix(test): remove invalid asyncio dependency from shutdown test
JoTalbot Aug 26, 2026
ed3f0b5
feat(runtime): enforce explicit execution state machine
JoTalbot Aug 26, 2026
4665a2e
test(runtime): add execution state machine coverage
JoTalbot Aug 26, 2026
585f9b8
fix(runtime): route loop lifecycle through validated state transitions
JoTalbot Aug 26, 2026
8c247ea
test(runtime): cover loop state transition integration
JoTalbot Aug 26, 2026
228c6e9
fix(test): assert persisted loop state after validated retry
JoTalbot Aug 26, 2026
9d05c81
feat(runtime): extract execution state machine domain
JoTalbot Aug 26, 2026
2963fd5
refactor(runtime): delegate execution transitions to domain state mac…
JoTalbot Aug 26, 2026
c6037e6
test(runtime): cover domain state machine and store injection
JoTalbot Aug 26, 2026
49fb631
feat(runtime): make execution audit append-only and lifecycle-aware
JoTalbot Aug 26, 2026
08db54b
test(runtime): verify persistent lifecycle audit trail
JoTalbot Aug 26, 2026
7c04741
feat(runtime): emit immutable audit events from state persistence
JoTalbot Aug 26, 2026
98ad15e
fix(runtime): preserve existing audit API alongside lifecycle events
JoTalbot Aug 26, 2026
85f80ee
feat(runtime): add audit event identity and idempotency
JoTalbot Aug 26, 2026
1402e28
feat(runtime): propagate correlation identity through execution persi…
JoTalbot Aug 26, 2026
5d63512
test(runtime): verify audit idempotency and correlation propagation
JoTalbot Aug 26, 2026
81db960
feat(runtime): add durable execution commit coordinator
JoTalbot Aug 26, 2026
d35b58d
feat(runtime): add crash reconciliation for execution commits
JoTalbot Aug 26, 2026
85c0331
test(runtime): cover durable execution commit and crash reconciliation
JoTalbot Aug 26, 2026
cc09b66
feat(runtime): reconcile interrupted commits before startup recovery
JoTalbot Aug 26, 2026
6362b29
feat(runtime): wire commit reconciliation into orchestrator bootstrap
JoTalbot Aug 26, 2026
a723134
feat(runtime): expose reconciliation results in recovery report
JoTalbot Aug 26, 2026
61f1a9e
test(runtime): verify bootstrap reconciliation reporting
JoTalbot Aug 26, 2026
0b56ac0
feat(runtime): make commit journal replay stateful and bounded
JoTalbot Aug 26, 2026
67bbd80
feat(runtime): add commit journal integrity and quarantine
JoTalbot Aug 26, 2026
ffe983d
feat(runtime): add deterministic recovery policy engine
JoTalbot Aug 26, 2026
2a7ce2d
test(runtime): cover recovery policy decisions
JoTalbot Aug 26, 2026
c6324fc
feat(runtime): enforce recovery policy during bootstrap
JoTalbot Aug 26, 2026
7040e19
test(runtime): integrate recovery policy with bootstrap
JoTalbot Aug 26, 2026
47f6ef9
feat(runtime): add persistent recovery operator queues
JoTalbot Aug 26, 2026
f0ef956
feat(runtime): persist quarantine and manual-review recovery queues
JoTalbot Aug 26, 2026
c67a989
test(runtime): persist manual recovery decisions
JoTalbot Aug 26, 2026
12346c6
feat(runtime): add operator recovery queue service
JoTalbot Aug 26, 2026
fc09c60
fix(runtime): make recovery queue resolution durable
JoTalbot Aug 26, 2026
9e35149
fix(runtime): use durable queue resolution in operator service
JoTalbot Aug 26, 2026
7265487
feat(runtime): add operator recovery HTTP transport
JoTalbot Aug 26, 2026
fa97330
feat(api): add FastAPI application factory and operator boundary
JoTalbot Aug 26, 2026
4847993
test(api): verify recovery HTTP authorization boundary
JoTalbot Aug 26, 2026
af99a76
fix(api): enforce request auth and typed recovery payloads
JoTalbot Aug 26, 2026
5a583f9
feat(api): add health readiness and control-plane wiring
JoTalbot Aug 26, 2026
0742f19
test(api): cover health readiness and request-aware auth
JoTalbot Aug 26, 2026
47bd2c6
feat(api): add production control-plane entrypoint
JoTalbot Aug 26, 2026
cb0f67c
feat(runtime): add durable operator audit trail
JoTalbot Aug 26, 2026
7b37a63
test(api): verify production operator authentication boundary
JoTalbot Aug 26, 2026
2559236
feat(runtime): audit operator recovery actions
JoTalbot Aug 26, 2026
091837a
fix(runtime): audit durable recovery resolution result
JoTalbot Aug 26, 2026
84eb62b
feat(api): expose operator audit endpoint
JoTalbot Aug 26, 2026
e7c8b02
feat(api): wire operator audit and dependency readiness
JoTalbot Aug 26, 2026
8e28bdf
feat(api): add control-plane security context and RBAC
JoTalbot Aug 26, 2026
e7ff7dd
feat(api): enforce viewer RBAC on operator audit endpoint
JoTalbot Aug 26, 2026
a9d21ab
feat(runtime): type operator audit actions and outcomes
JoTalbot Aug 26, 2026
b3ee5a4
fix(runtime): preserve correlation ids in operator audit
JoTalbot Aug 26, 2026
df4537d
feat(api): add unified operator security context and RBAC
JoTalbot Aug 26, 2026
bd903d2
feat(api): add role dependencies for recovery control plane
JoTalbot Aug 26, 2026
a9588d4
feat(api): inject unified operator context into control plane
JoTalbot Aug 26, 2026
6bf8ea5
feat(api): enforce RBAC and propagate operator context
JoTalbot Aug 26, 2026
1fc0063
fix(api): use canonical security context for recovery
JoTalbot Aug 26, 2026
3de591c
test(api): add recovery RBAC matrix and audit propagation
JoTalbot Aug 26, 2026
d1b7570
refactor(api): make SecurityContext canonical with correlation id
JoTalbot Aug 26, 2026
61115ee
refactor(api): remove duplicate operator context model
JoTalbot Aug 26, 2026
53eba10
fix(api): use canonical SecurityContext in app factory
JoTalbot Aug 26, 2026
50c3317
fix(api): remove stale recovery RBAC context types
JoTalbot Aug 26, 2026
272d917
fix(api): use canonical authentication at uvicorn entrypoint
JoTalbot Aug 26, 2026
c0ef54a
test(api): cover canonical context and correlation propagation
JoTalbot Aug 26, 2026
eaa841e
security(api): prevent header-based identity and role escalation
JoTalbot Aug 26, 2026
0324ea3
test(security): harden identity, role and correlation handling
JoTalbot Aug 26, 2026
1b17e32
ci(security): add control-plane security regression workflow
JoTalbot Aug 26, 2026
ee0a84d
test(security): add authentication hardening regression coverage
JoTalbot Aug 26, 2026
2442e04
feat(api): add fail-closed control-plane auth config
JoTalbot Aug 26, 2026
07eedce
test(api): cover fail-closed auth configuration
JoTalbot Aug 26, 2026
218d8cb
refactor(api): authenticate through validated control-plane config
JoTalbot Aug 26, 2026
3667c66
feat(api): fail closed at control-plane app startup
JoTalbot Aug 26, 2026
45d3c43
fix(runtime): classify tool failures for safe retry
JoTalbot Aug 26, 2026
9109411
fix(runtime): classify retryable tool execution failures
JoTalbot Aug 26, 2026
9833b0e
fix(runtime): retry only explicitly retryable tool failures
JoTalbot Aug 26, 2026
e9bdae8
fix(runtime): isolate event subscriber failures
JoTalbot Aug 26, 2026
f6cf2c6
fix(kernel): preserve execution context through scheduler
JoTalbot Aug 26, 2026
7c97fb6
fix(runtime): enforce agent authorization at tool sandbox boundary
JoTalbot Aug 26, 2026
205b3d7
test(runtime): verify agent authorization boundary
JoTalbot Aug 26, 2026
1127026
test(runtime): isolate event subscriber failures
JoTalbot Aug 26, 2026
182f1eb
test(pr252): pin down API and execution contracts
JoTalbot Aug 26, 2026
2ed54c7
test(pr252): verify scheduler to sandbox tool integration
JoTalbot Aug 26, 2026
d0ea9a4
test(pr252): enforce sandbox authorization at agent boundary
JoTalbot Aug 26, 2026
52c0b0f
fix(ci): satisfy operator token length contract
JoTalbot Aug 26, 2026
6593a78
fix(test): import execution transition error from state machine
JoTalbot Aug 26, 2026
5fce4a7
fix(test): align sandbox authorization and execution contracts
JoTalbot Aug 26, 2026
8fd83f3
fix(test): align recovery audit assertions with durable log contract
JoTalbot Aug 26, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
test(api): cover canonical context and correlation propagation
  • Loading branch information
JoTalbot committed Aug 26, 2026
commit c0ef54aeb2f16555e26dfeeb96d33d36eac06661
25 changes: 10 additions & 15 deletions tests/test_recovery_rbac_matrix.py
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,10 @@
from runtime.recovery_queue import RecoveryQueue, RecoveryQueueItem


def context(role, correlation_id="corr-test"):
return SecurityContext(actor="alice", role=role, correlation_id=correlation_id)


@pytest.mark.parametrize("role,mutation_status", [
(OperatorRole.VIEWER, 403),
(OperatorRole.OPERATOR, 200),
Expand All @@ -18,29 +22,20 @@ def test_recovery_mutation_rbac(role, mutation_status, tmp_path):
queue = RecoveryQueue(str(tmp_path / "queue.jsonl"))
queue.enqueue(RecoveryQueueItem("e1", "manual_review", "operator action", 3, "corr-1"))
service = RecoveryOperatorService(queue=queue)
app = create_app(
recovery_service=service,
operator_validator=lambda request: SecurityContext(actor="alice", role=role),
)
client = TestClient(app)
response = client.post("/recovery/resolve", json={"execution_id": "e1", "action": "manual_review", "reason": "approved"})
app = create_app(recovery_service=service, operator_validator=lambda request: context(role))
response = TestClient(app).post("/recovery/resolve", json={"execution_id": "e1", "action": "manual_review", "reason": "approved"})
assert response.status_code == mutation_status
if response.status_code == 200:
assert response.json()["execution_id"] == "e1"


def test_actor_and_correlation_are_propagated(tmp_path):
def test_correlation_propagates_to_audit(tmp_path):
queue = RecoveryQueue(str(tmp_path / "queue.jsonl"))
queue.enqueue(RecoveryQueueItem("e2", "manual_review", "needs review", 3, "corr-77"))
audit_path = tmp_path / "audit.jsonl"
from runtime.operator_audit import OperatorAuditLog
service = RecoveryOperatorService(queue=queue, audit_log=OperatorAuditLog(str(audit_path)))
app = create_app(
recovery_service=service,
operator_validator=lambda request: SecurityContext(actor="alice", role=OperatorRole.OPERATOR),
)
service = RecoveryOperatorService(queue=queue, audit_log=OperatorAuditLog(str(tmp_path / "audit.jsonl")))
app = create_app(recovery_service=service, operator_validator=lambda request: context(OperatorRole.OPERATOR, "corr-99"))
response = TestClient(app).post("/recovery/resolve", json={"execution_id": "e2", "action": "manual_review"})
assert response.status_code == 200
event = service.audit_events()[-1]
assert event.actor == "alice"
assert event.correlation_id == "corr-99"
assert event.outcome == "resolved"