PRE-EXECUTION AUTHORIZATION RUNTIME
An autonomous agent decides what it wants to do. VAREK decides whether it may — and proves it against declared policy before the action reaches the kernel.
Verified before the first action. Enforced at the kernel.
A policy declares what an agent may do. The Warden holds every file open, lookup, connect and launch at the kernel boundary and resolves it against that policy before it runs.
# Rules are evaluated in order. First match wins. # No match -> UNKNOWN -> suppressed -> DENY. allow path /tmp/varek_allowed_ allow path /etc/ld.so.cache deny path /etc/shadow deny path /root/ allow host 127.0.0.1:8080
# one line per mediated call (condensed; timings illustrative) file.open /tmp/varek_allowed_demo raw=ALLOW final=ALLOW 242us file.open /etc/shadow raw=DENY final=DENY 20us file.open /tmp/not_in_policy raw=UNKNOWN final=DENY 21us # the agent sees: Permission denied