Release 1.6.0: FlareFlow capability-bounded agent declassification - #14
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
flare-redact/agentwith runtime-owned source/detector/sink/JSON-Pointer capabilities/v1/flowsgateway endpoints plus Python and Go remote clientsSecurity properties
A token is restored only when a live same-flow record and the first matching capability agree on trusted source, detector, runtime-resolved sink, and destination path, with all projected budgets valid. One failure denies the complete graph without partial plaintext or budget consumption. Forged, expired, foreign-flow, wrong-path, cross-sink, and key-position tokens fail closed. Gateway clients cannot supply policy, and typoed flow routes cannot fall through to an upstream.
Evaluation
The checked-in deterministic corpus runs 700 exact-token attack trials and 300 utility trials. FlareFlow records 0 plaintext exposures, 680 explicit denials, 20 harmless percent-encoded opaque-token passes, and 300/300 utility passes. This is deliberately scoped evidence for exact protected-value restoration, not a general prompt-injection benchmark.
Local Node 22 / Apple A18 Pro microbenchmark, median of nine 100,000-iteration samples: 220,964 FlareFlow authorizations/s. The raw snapshot is checked in under
paper/results/.Verification
go vet ./...andgo test ./...npm run spec:checknpm pack, clean tarball install/import/security smoke, andnpm audit(0 vulnerabilities)No existing API changes behavior. FlareFlow and its gateway endpoints are opt-in.