feat(sentinel): add authenticated robot policy enforcement - #205
Draft
enkerewpo wants to merge 1 commit into
Draft
feat(sentinel): add authenticated robot policy enforcement#205enkerewpo wants to merge 1 commit into
enkerewpo wants to merge 1 commit into
Conversation
Add the typed Sentinel rule engine and admin management contracts, carry Keystone-authenticated identity through the internal planning path, enforce rules before capability dispatch, and ship a reproducible Webots demo configuration. Assisted-by: Codex:gpt-5.6
Member
Author
|
Companion Client PR: syswonder/robonix-client#9 (targets |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
ListRules/ReplaceRulesmanagement contractsWhy
This provides the minimum end-to-end Sentinel loop for the Keystone demo branch without hard-coding robot predicates such as
movingorgripper_open. Robot state remains generic and typed, so deployments can address boolean, integer-range, and float-range conditions through stable state paths.Security properties
Validation
cargo fmt --all -- --checkcargo test -p robonix-sentinel -p robonix-executor -p robonix-cli(7 Sentinel, 44 Executor, 32 CLI tests)cargo clippy -p robonix-sentinel -p robonix-executor -p robonix-cli --all-targets -- -D warningspython3 -m unittest scripts/tests/test_check_commit_authorship.pypython3 scripts/check_commit_authorship.py --base origin/dev-keystone --head HEADgit diff --checkCompanion change
The admin rule-management page is being published separately from the robonix-client Keystone branch.
This PR intentionally targets
dev-keystone; it does not changedevordev-next.