VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head 355d814f5c
Evidence:
Exact PR/branch head verified: 355d814f5c8d7097ebc80b21f04ab63a1f8c4a5e.
PR CI green: ci/woodpecker/pr/ci pipeline 1716 success.
Reviewed TESS-FLT-001 authority boundary: fleet writes/control default-deny before tmux probing unless a write authority permits, then exact-target assertAuthorized runs after roster/socket/runtime verification and before sendMessage/terminate.
Target and identity checks are enforced through roster lookup, exact session target (=<agent>:0.0 / =<agent>), configured roster socket, live pane check, and runtime command match; prefix/unrostered target, unavailable pane, and runtime drift tests fail closed.
Attach is read-only only; control attach is denied before transport, handles are short-lived and immutable-scope-bound, and replay from another actor scope is denied.
Message/terminate cannot escape policy: empty messages are rejected before authority/transport, default writes do not call transport, unverified targets fail before Mos final authorization, and authorized calls use the maintained sender/exact tmux target only.
Gateway registry remains the audit/correlation boundary from M1-002; this PR does not bypass it or introduce a direct raw socket/target path.
git diff --check clean; no credential material or secret values in the PR diff.
VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head 355d814f5c8d7097ebc80b21f04ab63a1f8c4a5e
Evidence:
- Exact PR/branch head verified: `355d814f5c8d7097ebc80b21f04ab63a1f8c4a5e`.
- PR CI green: `ci/woodpecker/pr/ci` pipeline 1716 success.
- Reviewed TESS-FLT-001 authority boundary: fleet writes/control default-deny before tmux probing unless a write authority permits, then exact-target `assertAuthorized` runs after roster/socket/runtime verification and before `sendMessage`/`terminate`.
- Target and identity checks are enforced through roster lookup, exact session target (`=<agent>:0.0` / `=<agent>`), configured roster socket, live pane check, and runtime command match; prefix/unrostered target, unavailable pane, and runtime drift tests fail closed.
- Attach is read-only only; control attach is denied before transport, handles are short-lived and immutable-scope-bound, and replay from another actor scope is denied.
- Message/terminate cannot escape policy: empty messages are rejected before authority/transport, default writes do not call transport, unverified targets fail before Mos final authorization, and authorized calls use the maintained sender/exact tmux target only.
- Gateway registry remains the audit/correlation boundary from M1-002; this PR does not bypass it or introduce a direct raw socket/target path.
- `git diff --check` clean; no credential material or secret values in the PR diff.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Verification
Refs #707
VERIFIED APPROVE reviewer-of-record [W-jarvis:reviewer] head
355d814f5cEvidence:
355d814f5c8d7097ebc80b21f04ab63a1f8c4a5e.ci/woodpecker/pr/cipipeline 1716 success.assertAuthorizedruns after roster/socket/runtime verification and beforesendMessage/terminate.=<agent>:0.0/=<agent>), configured roster socket, live pane check, and runtime command match; prefix/unrostered target, unavailable pane, and runtime drift tests fail closed.git diff --checkclean; no credential material or secret values in the PR diff.