Commit graph

61 commits

Author SHA1 Message Date
sknr
47336e2c19
refactor(cli): extract subcommands and registry into internal/cli package
- Extract command router registry and modular subcommand handlers into internal/cli
- Isolate CLI argument parsing and flags from public API surface
- Reduce cmd/okf/main.go to a lean entrypoint delegating to cli.Execute
- Remove monolithic subcommand files and obsolete tests from cmd/okf
2026-09-25 12:54:23 +02:00
sknr
651bd04ec7
feat(core): decouple MCP server and hub sync, add query filters and staleness engine
- Move MCP server implementation and tool schemas from cmd/okf into pkg/okf
- Move hub vault operations and lifecycle management from cmd/okf into pkg/sync
- Implement generic frontmatter --filter AST evaluation in pkg/okf/filter.go
- Implement --stale-within temporal horizon staleness engine in pkg/okf
- Introduce okf.SaveOptions and HubOp structures for clean API ergonomics
2026-09-25 12:53:43 +02:00
sknr
7e6fba7d92 fix(security): sanitize multi-line frontmatter blocks and broaden Jules discovery (#36) 2026-09-23 21:06:25 +02:00
sknr
5b5c114abd merge: incorporate Jules cross-platform absolute path evasion fix (PR #37) 2026-09-23 21:05:01 +02:00
sknr
eab108dedf
fix(cli): separate validate findings taxonomy and reconcile summary counts
In non-strict mode, all printed diagnostic lines (warnings, gate findings,
broken links, orphans) are prefixed with 'warn  ' and reconciled 1:1 into
the headline warning(s) counter.

In strict mode (--strict), gate-failing findings are prefixed with 'gate  '
and tracked under a dedicated 'gate finding(s)' summary counter, cleanly
separating them from non-gating advisory 'warn  ' lines and 'error ' spec
violations.

Resolves #35
Reported-by: mattgdrums-cloud <mattgdrums-cloud@users.noreply.github.com>
2026-09-23 20:52:06 +02:00
google-labs-jules[bot]
f9265e05bb fix(security): prevent absolute path traversal evasion cross-platform
* Introduced IsAbsPath helper to securely detect cross-platform absolute paths
* Patched resolveInBundle to explicitly reject absolute paths early before
  they can be evaluated by path.Clean and Join as relative on POSIX systems
* Patched validate method and others to also use IsAbsPath
* Verified with rigorous testing of absolute paths evasion in mutation flow

Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
2026-09-23 04:29:37 +00:00
sknr
05b6fc5fc9
fix(mcp): enforce 4MB max line limit on stdin to prevent streaming OOM 2026-09-19 14:49:40 +02:00
sknr
41682b48dc
fix(mcp): enforce 1KB limit and string type check on bundle argument 2026-09-19 14:49:07 +02:00
sknr
809f521764
fix(mcp): harden argument boundaries and prevent memory cache corruption in okf_update/create 2026-09-19 14:41:19 +02:00
sknr
573c86ed77
fix(security): sanitize Windows-style backslashes across validator and search 2026-09-19 14:26:47 +02:00
sknr
01d8e8c5b7
merge: incorporate Jules security remediation (jules-audit-fix-path-traversal-14703784320229980277) 2026-09-19 14:24:31 +02:00
sknr
bd89454df9
feat: add benchmark results and improve API parameter handling and help documentation in benchmark CLI 2026-09-19 14:18:40 +02:00
google-labs-jules[bot]
53be021b76 fix: harden path resolution against cross-platform backslash traversal
Replaces `filepath.ToSlash` with explicit `strings.ReplaceAll(path, "\\", "/")` when normalizing incoming path inputs and concept IDs. `filepath.ToSlash` is a no-op on POSIX operating systems, which allowed an attacker to bypass directory boundary confinement (CWE-22) using Windows-style backslashes (e.g. `..\..\etc\passwd`). This ensures cross-platform defensive behavior regardless of the host OS executing the agent. Includes negative security test cases.

Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
2026-09-18 09:03:50 +00:00
sknr
2374fd57be
feat(mcp): implement structuredContent and object outputSchema via embedded tools.json (#30) 2026-09-17 21:57:54 +02:00
sknr
84f539959f
fix(mcp): omit non-object outputSchemas and fix rootDir for non-knowledge bundles
- Fix #30: Omit outputSchema from okf_search, okf_create, okf_update, and okf_relate because MCP specification requires outputSchema to be type 'object'
- Fix #31: Use filepath.Dir(cleanBundle) as rootDir for any bundle name, avoiding doubled paths for non-knowledge bundles
- Update TestMCPToolsListOutputSchemas and TestMCPOutputSchemasV02Properties
- Add TestMCPNonKnowledgeBundleResolution
2026-09-17 19:48:08 +02:00
sknr
fc2ec6ac36
test(hub): add real HTTP socket E2E test for embedded hub serve 2026-09-17 15:42:54 +02:00
sknr
b2a35fa8db
fix(hub): use -auth-token flag in hub commands 2026-09-17 15:32:19 +02:00
sknr
a27cd56bd2
feat(hub): add -auth-token flag and cascading token resolution for vault sync 2026-09-17 15:10:13 +02:00
sknr
4858baa78e
Merge branch 'develop' into feat/vault-crypto 2026-09-16 10:47:23 +02:00
sknr
45c63e5732 fix(benchmark): filter empty whitespace lines in mermaid blocks 2026-09-16 10:41:46 +02:00
sknr
7a7d506350 refactor(benchmarks): eliminate dry-run, add pre-flight warmup and mermaid sanitizer 2026-09-16 10:30:09 +02:00
sknr
b7180e2598
Merge branch 'develop' into feat/vault-crypto 2026-09-16 09:23:03 +02:00
sknr
2649a28213 fix(security): sanitize benchmark paths and resolve gosec G304 warnings 2026-09-16 09:19:03 +02:00
sknr
ae4c7e05cf fix(cli): add subcommand help handlers and reject hyphenated concept IDs 2026-09-16 09:19:03 +02:00
sknr
eeae88c148 feat(benchmarks): add DMAA Layer 1 (AAG vs Prose) suite and methodology guide 2026-09-16 09:19:03 +02:00
sknr
f394fdd75f merge: sync develop v0.3.0 into feat/vault-crypto 2026-09-15 15:31:34 +02:00
sknr
f87cb9ef03 fix(security): resolve G703 path taint finding in cmdValidate agentsRoot resolution 2026-09-15 15:00:47 +02:00
sknr
66f34971b9 feat(ci): enforce 'okf validate --agents' across all bundled examples in Makefile and CI 2026-09-15 14:54:17 +02:00
sknr
6a243451e1 fix(security): add nosec annotations and harden http server timeouts in hub and sync engine 2026-09-15 14:47:07 +02:00
sknr
26107066d9 merge: incorporate develop (AAG, DMAA, SSoT symlinks, Jules security hardening) 2026-09-15 14:46:14 +02:00
sknr
cb17b8d402 fix(mcp): resolve duplicate normTarget declaration after security merge 2026-09-15 14:39:25 +02:00
sknr
de991025ca merge: incorporate Jules security hardening PR (jules-14861611321268232439-f34d0d97) 2026-09-15 14:39:05 +02:00
sknr
4942eba1fc
fix(ci): strictly enforce golangci-lint in Makefile and resolve static analysis findings
- Fix Makefile lint target so golangci-lint failure exit code is not swallowed
- Address errcheck in defer os.RemoveAll across test suites
- Replace deprecated filepath.HasPrefix with strings.Contains
- Fix staticcheck QF1012 string formatting in pkg/okf/domains.go
- Remove unused variables in pkg/okf/aag/linter.go
2026-09-15 14:32:13 +02:00
sknr
ee4b812d9a feat(cli): add 'okf agents' subcommand suite (lint, init, link, check)
- Provide CLI subcommands: okf agents lint, okf agents init, okf agents link, and okf agents check
- Add --agents flag to okf validate
- Add CLI integration tests for okf agents commands
2026-09-15 14:18:00 +02:00
sknr
4493be7531 fix(lint): fix make lint fallback logic and resolve errcheck issues 2026-09-14 15:38:07 +02:00
sknr
79cf3b0395 feat(sync): implement CAS client, embedded server, reconcile engine, and okf hub CLI 2026-09-14 15:27:29 +02:00
sknr
b38c60e247
fix(security): sanitize Windows backslash path traversal cross-platform (#27)
Closes #27. Supersedes #26. Normalized Windows backslashes via strings.ReplaceAll cross-platform.
2026-09-13 15:40:11 +02:00
sknr
00cdb022c1
style(mcp): gofmt broken_links property formatting in outputSchema 2026-09-13 15:37:57 +02:00
sknr
eed06c8b98
feat(mcp): advertise outputSchema on all six tools (#22)
Closes #20. Contributed by @yakimoto.
2026-09-13 15:35:26 +02:00
google-labs-jules[bot]
50fd060ea9 fix(security): sanitize Windows backslash path traversal cross-platform
Ensure input paths containing backslashes are normalized to forward slashes before evaluation with filepath.Clean and filepath.Rel across ensureWithinRoot, resolveInBundle, UpdateParentIndex, and MCP resolveBundleDir. Add adversarial tests in mutate_security_test.go and mcp_test.go.

Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
2026-09-13 05:13:40 +00:00
Jake Fineman
f70c77f42f mcp: outputSchema covers v0.2.0 fields (governance, code_refs, body, gate diagnostics) 2026-09-12 13:08:36 -04:00
google-labs-jules[bot]
907ab99232 fix(security): harden path normalization against cross-platform traversal
- Normalize input paths with filepath.ToSlash prior to filepath.Clean across pkg/okf/mutate.go, pkg/okf/validator.go, and cmd/okf/mcp.go.
- Enforce ValidateConceptID checks within SaveConcept to prevent invalid concept ID path traversal.
- Add adversarial unit tests covering Windows-style backslash traversal vectors in concept paths, code_refs, and MCP bundle parameter confinement.

Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
2026-09-12 05:24:42 +00:00
yakimoto
d5f729db03 feat(mcp): advertise outputSchema on all six tools
Clients can now validate structured results without guessing shapes. Schemas mirror the Go result types (SearchResult, Concept, ValidationResult); mutating tools declare string confirmations. Adds TestMCPToolsListOutputSchemas.
2026-09-11 18:04:42 -04:00
sknr
ef4de5a680 fix(security): prevent path traversal in code_refs validation and sanitize CLI path (CWE-22) 2026-09-11 20:02:19 +02:00
sknr
10ba1cb6b5 feat(governance): add 3-tier governance model and code-to-knowledge binding
- Implement 3-tier epistemic governance (constraint, hold, context) with zero-boilerplate implicit inference
- Add code-to-knowledge binding via code_refs supporting exact, directory prefix, glob, and recursive wildcards
- Add pre-edit discovery via 'okf search --for-path <path>' in CLI and MCP server
- Add code_refs drift validation in 'okf validate --drift'
- Formalize architecture decision in knowledge/architecture/governance-model.md
2026-09-11 19:26:45 +02:00
Denis Samatov
a09e04918a fix(cli): preserve flag values without bundle path (#14) 2026-09-11 16:59:01 +02:00
Wu Shuwen
11cb2d18d1
test(mcp): make path fixtures cross-platform (#19) 2026-09-11 15:55:03 +02:00
google-labs-jules[bot]
119d3e39d3 fix(security): enforce search resource limits and control character validation
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
2026-09-11 04:47:11 +00:00
sknr
93d4063e8a fix(security): block drive letter paths in ValidateConceptID and add adversarial test coverage
- Explicitly reject Windows drive letter prefixes in ValidateConceptID across all OSes (CWE-22)
- Add adversarial traversal edge cases (UNC, drive letter, parent escape) to TestValidateConceptID
- Add TestMCPAdversarialIndirectPromptInjectionInputs to verify MCP sanitization and edge limits
- Enable -race detector in Makefile test target for concurrency safety
2026-09-10 09:02:30 +02:00
sknr
63a42da35b refactor: eliminate redundant validation and enforce DRY in SaveConcept and RelateConcepts 2026-09-09 13:10:10 +02:00