Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
9440ced
feat(cli): implement single-command agent provisioning and autostash …
bordumb Jul 23, 2026
c5d82d8
feat(cli): add interactive guided wizard flow and optional flags for …
bordumb Jul 23, 2026
fffb0fc
fix(cli): streamline AUTHS-E4203 passphrase error suggestion
bordumb Jul 23, 2026
638e6a5
fix(sdk): clean up temporary staging keys on provisioning failure and…
bordumb Jul 23, 2026
b61bfd5
fix(core): distinguish software keys in SecureEnclaveKeyStorage durin…
bordumb Jul 23, 2026
9c24503
fix(core): route SecureSigner::sign_with_alias for SecureEnclaveKeySt…
bordumb Jul 23, 2026
23db5b8
fix(core): delegate StorageSigner::sign_with_alias to sign_with_key a…
bordumb Jul 23, 2026
b26db3f
fix(core): add is_hardware_key to KeyStorage to prevent fallback pass…
bordumb Jul 23, 2026
0a05e15
test(e2e): add test_agent_provision_recursive_subagent to test_agent_…
bordumb Jul 23, 2026
15dd31c
fix(cli): implement AgentProvisionPassphraseProvider and clean stale …
bordumb Jul 23, 2026
3b17646
fix(agent): correctly quote AUTHS_PASSPHRASE in env.sh to enable head…
bordumb Jul 23, 2026
7441974
fix(core): forward is_hardware_key, rebind_identity, export_public_ke…
bordumb Jul 23, 2026
a3e2835
test(core): add unit test for Arc and Box KeyStorage trait method for…
bordumb Jul 23, 2026
18b1d28
fix(sdk): replace cp -R with pure Rust copy_dir_clean to filter sockets
bordumb Jul 23, 2026
b9f30b1
fix(e2e): isolate test_agent_provisioning working directory to tmp_pa…
bordumb Jul 23, 2026
f13a33d
test(cli): add comprehensive unit tests for handle_provision_cmd
bordumb Jul 23, 2026
d2e13a8
fix(cli,sdk): resolve AUTHS_REPO and AUTHS_SIGNING_KEY for agent comm…
bordumb Jul 23, 2026
d83f706
chore(ci): update identity bundle with delegated agent anchors
Jul 23, 2026
0653650
style: apply cargo fmt to crates
bordumb Jul 23, 2026
3a97cf9
fix: update ci-bundle
bordumb Jul 23, 2026
605b399
fix: formatting
bordumb Jul 23, 2026
f1143fd
Delete claims/claim-cbe93daa3a36463c.json
bordumb Jul 23, 2026
bcb211b
feat: implement strongly typed SigningKeyRef
bordumb Jul 23, 2026
d5ef807
fix: resolve SDK boundary and clippy issues
bordumb Jul 23, 2026
8a0ce83
style: apply cargo fmt
bordumb Jul 23, 2026
6c637b1
feat: add auths agent prompt command
bordumb Jul 23, 2026
950b1be
Merge branch 'dev-agenticSigningErgonomics' of github.com:auths-dev/a…
bordumb Jul 23, 2026
5de4214
refactor: Decouple daemon from agent in auths-cli
bordumb Jul 23, 2026
4ce9ccb
style: cargo fmt
bordumb Jul 23, 2026
9873c53
docs: add AI instructions to auths agent help
bordumb Jul 24, 2026
12c4e64
Fix command drift violations for deprecated agent start
bordumb Jul 24, 2026
37bdc9e
Remove deprecated agent commands
bordumb Jul 24, 2026
04f9a19
test(cli): add e2e git hook integration tests
bordumb Jul 24, 2026
7659c11
fix(agent): remove test hack and fix clippy error
bordumb Jul 24, 2026
eca55b5
fix: clippy and xtask
bordumb Jul 24, 2026
3a45dd6
fix(cli): headless fail-fast, command-drift formatting, and primary h…
bordumb Jul 24, 2026
b114413
fix(docs): update error strings to resolve command-drift for agent cmds
bordumb Jul 24, 2026
19e9e37
style: run cargo fmt on error.rs
bordumb Jul 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
435 changes: 73 additions & 362 deletions .auths/ci-bundle.json

Large diffs are not rendered by default.

28 changes: 3 additions & 25 deletions .auths/roots
Original file line number Diff line number Diff line change
@@ -1,25 +1,3 @@
did:keri:EB5cPHY0t-ejNC_rUzPS1dclTvd6kG-R9mQzjozCuGgd
did:keri:EMCu26JE1Jm40kuNyWtCyTJu3CwC_2MBmiiFCIp6XN7t
did:keri:ECorK2R66hdj9W3wzV0JYYPVm37iL_48lHnWF-_zXtfJ
did:keri:EHZu-FvRR0yJF3tId3iJVN_XXlsNZdXg-ZSRchZHCcTS
did:keri:EA-toxTnhpWcjgDGonNgzRRsHgyatvu4GXp8vQ9RZMD6
did:keri:EJRwo0DQdzF6ggeznDh6113KlfMy-_KUF_9WfZ5Gh28e
did:keri:EJR9zlO6FtsjRULj07wynEEUcN0AD1MmKI6A1U_uD10l
did:keri:EN6HZUkHvWsaSgFKPKEDR8nMVV1Ef9zw1gbdtxOtLWDP
did:keri:EGAeM5vBmzcFEzf3MVbOD_VKjMxC4GsoUarWUjz5J6li
did:keri:ED-k2LMn90EN5DUQGCCGKGn-Bf9BXWLiao-nyLp9LAjH
did:keri:ELiyxeCLBDgNKtYG_bfpnpCy2Lohqyv8M3TyMS8Zn9Tm
did:keri:EL1CaAKTd-I7l6v8FO8FvWbFrgK_UMAUk5MQ-7YjPeHr
did:keri:EJzyWbcg-u6v_4nc-R1XwfbblLqz1wBQpIHx_WNUTZgL
did:keri:EJ35ubEJO6ZT4HDeFxKqcoAH1VE0MnA4Y_Mk_rniD_ku
did:keri:ELS_t_TDI2vfNPkUjcatCqA8tSgQwYOv_h9OKvp5rvER
did:keri:ENv6JMgfYFbr3J4nBOtcNNgpVZ5lmd6dUr_25wK4MJUM
did:keri:EKHawavyEruvh0v3A2H5zLoLnOE2L3lAqzivN0kjZil3
did:keri:EHMeiHXhVedvGhvFf5O71HoPskHArJXokxnx08PEr_CM
did:keri:EF9goneG7pezrfCzYvEhEp_gSct_BZLmSZfrngNWxTqM
did:keri:EC7fQlCP19mPRMx-lIpHhWCjKF12Z1aZ6VYYwUa8ZZ-M
did:keri:EDa0hFOowB7PYAkUeiuRQiV1zaa1mpFbxQYf61r73Pii
did:keri:EPsk0PCEQpa3ALIG1Oyiuxg8UfLbgma4QV16I-O6TnOc
did:keri:EAZG0HqAzbydr1iAbnEPUhVC_IuB6vZXYBJagVXS2k9a
did:keri:EKh1onK1bubyaWxHIWzr_yeOAtBm36ZGn0AXDYsBhrsq
did:keri:EPmp6Nav8Z-_prJg0EShHnB396yJJtXmBr6hG647PxwJ
did:keri:EGfg3puqwCzBD3rBSiMhO1HpDM26pmotVreI41Jl_1Eq
did:keri:EMN-WRXNAkLfavKsaFHS0ehP7eB1s8a1alktBJoDhI7b
did:keri:EAswoxxXY6-kXqYcc3mUngY8GOiwhDwXxFfjWXzCvuW6
2 changes: 2 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions crates/auths-cli/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ gethostname = "1.1.0"
glob.workspace = true
auths-policy.workspace = true
auths-index.workspace = true
auths-core.workspace = true
auths-crypto.workspace = true
auths-sdk = { workspace = true, features = ["backend-git", "witness-server", "witness-client", "indexed-storage", "keychain-secure-enclave"] }
auths-transparency = { workspace = true, features = ["native"] }
Expand Down
2 changes: 1 addition & 1 deletion crates/auths-cli/src/adapters/agent.rs
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ use auths_sdk::crypto::{construct_sshsig_pem, construct_sshsig_signed_data};
use auths_sdk::ports::agent::{AgentSigningError, AgentSigningPort};

#[cfg(unix)]
use crate::commands::agent::{ensure_agent_running, get_default_socket_path};
use crate::commands::daemon::{ensure_agent_running, get_default_socket_path};

/// CLI adapter that delegates signing to the Unix SSH agent.
///
Expand Down
13 changes: 7 additions & 6 deletions crates/auths-cli/src/bin/sign.rs
Original file line number Diff line number Diff line change
Expand Up @@ -111,19 +111,20 @@ fn validate_verify_option(opt: &str) -> Result<()> {
}

fn parse_key_identifier(key_file: &str) -> Result<String> {
if let Some(alias) = key_file.strip_prefix("auths:") {
if alias.is_empty() {
bail!("Invalid Auths key format: alias cannot be empty. Use 'auths:<alias>'");
}
Ok(alias.to_string())
} else {
let key_ref =
auths_sdk::keychain::SigningKeyRef::parse(key_file).map_err(|e| anyhow::anyhow!(e))?;

if !matches!(key_ref, auths_sdk::keychain::SigningKeyRef::Uri { ref scheme, .. } if scheme == "auths")
{
bail!(
"Unsupported key format: '{}'. \
Auths keys should be specified as 'auths:<alias>' \
(e.g., 'auths:default' or 'auths:my-signing-key')",
key_file
);
}

Ok(key_ref.bare_alias().as_str().to_string())
}

fn build_signing_context(alias: &str) -> Result<CommitSigningContext> {
Expand Down
4 changes: 3 additions & 1 deletion crates/auths-cli/src/cli.rs
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ use crate::commands::approval::ApprovalCommand;
use crate::commands::artifact::ArtifactCommand;
use crate::commands::audit::AuditCommand;
use crate::commands::auth::AuthCommand;
use crate::commands::daemon::DaemonCommand;

use crate::commands::commit::CommitCmd;
use crate::commands::completions::CompletionsCommand;
Expand Down Expand Up @@ -101,6 +102,7 @@ pub enum RootCommand {
Verify(UnifiedVerifyCommand),
Status(StatusCommand),
Whoami(WhoamiCommand),
Agent(AgentCommand),

// ── Setup & Troubleshooting ──
Demo(DemoCommand),
Expand Down Expand Up @@ -162,7 +164,7 @@ pub enum RootCommand {
#[command(hide = true)]
Emergency(EmergencyCommand),
#[command(hide = true)]
Agent(AgentCommand),
Daemon(DaemonCommand),
/// Aggregate treasury cap across a manager's sub-delegated agents.
Treasury(TreasuryCommand),
/// Verify witness-network anchor evidence (duplicity proofs) offline.
Expand Down
19 changes: 19 additions & 0 deletions crates/auths-cli/src/commands/agent/agent_prompt.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
<auths_delegated_identity>
You have been granted a delegated cryptographic identity ({{LABEL}}) to sign your git commits in this workspace.

# Core Directive
Whenever you execute a `git commit` on behalf of the user, you MUST sign it using this identity.

# Activation Instructions
Before running ANY git commands that require signing, you MUST activate your signing environment for the current shell session by sourcing your environment script:
`source {{ENV_PATH}}`

This script automatically handles:
- Injecting your `AUTHS_PASSPHRASE` into the environment so you do not need to prompt the user.
- Setting up temporary `GIT_CONFIG_COUNT` overrides to force git to use the `auths-sign` binary.

# Constraints & Rules
1. NEVER attempt to manually modify the repository's `.git/config` file to configure signing. The `env.sh` script handles this cleanly via environment variables.
2. NEVER attempt to run `ssh-agent`, `ssh-add`, or interact with standard GPG tools. `auths-sign` is a custom headless signer that replaces them.
3. If a commit fails with a signing error, verify that you sourced the `env.sh` file in the EXACT same bash session/subshell as the `git commit` command.
</auths_delegated_identity>
Loading
Loading