You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Tracking issue for making Astrid's audit log externally verifiable: its
history anchored on an independent ledger (AOS uses the Unicity aggregator),
and its contents complete and precise enough to support claims about what an
agent did.
Motivation
Astrid's audit log is signed and hash-linked, which makes it tamper-evident
only to parties who do not hold the runtime key. External anchoring removes
that limit for history already written. It is only as useful as what the log
records, and how completely and precisely it records it. The steps below are
ordered by how much they add.
Capsule access. A capsule-based anchoring service calling audit.heads
and audit.export under a capability grant (distro-level grant or admin
routing change).
Waiting for the native audit root (#1759). It is the long-term root of trust
for the native kernel, but it doesn't cover the hosted runtime AOS ships today.
The steps above apply to the hosted runtime and would carry over.
Summary
Tracking issue for making Astrid's audit log externally verifiable: its
history anchored on an independent ledger (AOS uses the Unicity aggregator),
and its contents complete and precise enough to support claims about what an
agent did.
Motivation
Astrid's audit log is signed and hash-linked, which makes it tamper-evident
only to parties who do not hold the runtime key. External anchoring removes
that limit for history already written. It is only as useful as what the log
records, and how completely and precisely it records it. The steps below are
ordered by how much they add.
Proposed Implementation
interface for anchoring and verification)
calls, approvals, capability changes, capsule loads
verification
anchored
Later, to be discussed:
audit.headsand
audit.exportunder a capability grant (distro-level grant or adminrouting change).
capsule steps: wasmtime determinism settings, host-call record/replay,
instance model, persistent bus order. Relates to Proof-carrying execution receipts over causal observations and state transitions #1367.
Alternatives Considered
Waiting for the native audit root (#1759). It is the long-term root of trust
for the native kernel, but it doesn't cover the hosted runtime AOS ships today.
The steps above apply to the hosted runtime and would carry over.
Related: #678, #683, #693, #675, #1367, #1542, #1759.