a2edaf8694
Implements PRD prd-new-trusted-agent-forge-identity. Moves author identity and named forge configurations onto the trusted, host-only agent definition, and lets a bottle repository optionally associate a git-gate repo with one of the agent's forge aliases. - Agent-owned identity: new `author` (name/email) and `forge-accounts` (alias -> canonical Gitea /api/v1 origin + host `token_secret` ref) on the agent manifest. `author` populates the bottle's git user.name/user.email. - Remove `git-gate.user` from both agents and bottles; fail with a migration pointer to `author`. `git-gate` is no longer accepted on an agent. - Bottle git-gate repos gain optional `forge: <alias>`, resolved against the selected agent's forge-accounts at composition (fail-closed on unknown). - Fail-closed Gitea API URL validation (https, no userinfo/query/fragment, /api/v1 base, host lowercased, trailing slash normalized, host dedup). - Proxy-held credential: synthesize one inspected, token-authenticated egress route per referenced forge alias, scoped to the origin + API prefix. The token is resolved from the host env at launch into the egress proxy only — never the bottle env, prompt, gitconfig, or workspace. - Generated, non-secret forge workflow guidance appended to the agent prompt for associated repos (API base, branch-backed PR flow, AGit-ref prohibition, mutation verification); omitted when no repo declares a forge. - Agents become home-only: cwd `.bot-bottle/agents` no longer contributes, overrides, or is selectable; warned-and-ignored like cwd bottles. - Docs: README examples, PRD 0011 supersession note, manifest schema docstring. - Tests: new test_forge_identity suite; legacy git-gate.user/cwd tests updated to the agent-owned identity model. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
56 lines
1.9 KiB
Plaintext
56 lines
1.9 KiB
Plaintext
# Critical security/logic core held to the >=85% coverage bar by
|
|
# docs/decisions/0004-coverage-policy.md.
|
|
#
|
|
# SINGLE SOURCE OF TRUTH: scripts/coverage.sh (the `critical` report) and
|
|
# .gitea/workflows/update-badges.yml (the "core coverage" badge) both read
|
|
# this file. Add a module here when it becomes part of the core; a coverage
|
|
# number that silently stops measuring a module is worse than no badge.
|
|
#
|
|
# One module path per line, relative to the repo root. Blank lines and
|
|
# `#` comments are ignored. scripts/critical_modules.py rejects missing,
|
|
# duplicate, non-Python, and out-of-repository entries before coverage runs.
|
|
|
|
# Host-side egress planning and secret preparation.
|
|
bot_bottle/egress/plan.py
|
|
bot_bottle/egress/service.py
|
|
|
|
# Gateway egress policy, matching, and DLP enforcement.
|
|
bot_bottle/gateway/egress/addon.py
|
|
bot_bottle/gateway/egress/addon_core.py
|
|
bot_bottle/gateway/egress/context.py
|
|
bot_bottle/gateway/egress/dlp.py
|
|
bot_bottle/gateway/egress/dlp_config.py
|
|
bot_bottle/gateway/egress/dlp_detectors.py
|
|
bot_bottle/gateway/egress/matching.py
|
|
bot_bottle/gateway/egress/schema.py
|
|
bot_bottle/gateway/egress/types.py
|
|
|
|
# Manifest trust boundary and schema.
|
|
bot_bottle/manifest/agent.py
|
|
bot_bottle/manifest/bottle.py
|
|
bot_bottle/manifest/egress.py
|
|
bot_bottle/manifest/extends.py
|
|
bot_bottle/manifest/forge.py
|
|
bot_bottle/manifest/git.py
|
|
bot_bottle/manifest/index.py
|
|
bot_bottle/manifest/loader.py
|
|
bot_bottle/manifest/schema.py
|
|
bot_bottle/manifest/util.py
|
|
|
|
# Host-side and gateway-side git policy enforcement.
|
|
bot_bottle/git_gate/host_key.py
|
|
bot_bottle/git_gate/plan.py
|
|
bot_bottle/git_gate/provision.py
|
|
bot_bottle/git_gate/service.py
|
|
bot_bottle/gateway/git_gate/render.py
|
|
bot_bottle/gateway/git_gate/http_backend.py
|
|
|
|
# Supervise proposal protocol and data plane.
|
|
bot_bottle/supervisor/plan.py
|
|
bot_bottle/supervisor/types.py
|
|
bot_bottle/gateway/supervisor/server.py
|
|
|
|
# Shared parsers and state validation.
|
|
bot_bottle/yaml_subset.py
|
|
bot_bottle/bottle_state.py
|