feat(budget,provenance): reasoning budget modes and JOASNSCOPE provenance

Budget (opt-in, unlimited by default so an un-budgeted run is unchanged):
- crates/harness/src/budget.rs — modes, phase shares, Token Governor
- CLI: --budget/--token-limit/--deep-test-limit/--coverage-first/
  --depth-first/--sample-per-route; same controls in the web wizard
- pipeline honours it: vote_n narrows, evidence rounds are capped

Run control parity in the web console:
- /pause in the REPL, backed by a pause gate in the model pool: in-flight
  agents finish, then the run holds with every finding kept
- POST /api/exploit/:id/{pause,continue,report} + GET .../log

Provenance (crates/harness/src/provenance.rs):
- JOASNSCOPE sigil leads every canary, so a marker found in a response,
  a log or someone else's report extracts whole and names its build
- per-build fingerprint, per-run id, optional per-customer build id
- findings.json stamped with _engine; signed provenance.json manifest
- structural signature survives rewording but not a changed result set
- prompts watermarked at the single pool chokepoint
- `neurosploit provenance show|scan|verify`

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 5 committed 2026-09-14 01:14:03 -03:00
1 parent 40b047b9e7
commit 408350539f
16 files changed
+1464 -26

No files matched your search

+5
View File
@@ -274,7 +274,12 @@ a { color: var(--accent); text-decoration: none; }
.btn-primary:hover { background: var(--accent-hover); border-color: var(--accent-hover); }
.btn-danger { background: transparent; border-color: var(--sev-critical-fg); color: var(--sev-critical-fg); }
.btn-danger:hover { background: var(--sev-critical-bg); }
/* A paused run is a state to notice, not an error — the resume button wears
the warning hue so the run never looks quietly stalled. */
.btn-warn { background: var(--sev-medium-bg); border-color: var(--sev-medium-fg); color: var(--sev-medium-fg); }
.btn-warn:hover { background: var(--sev-medium-bg); filter: brightness(1.12); }
.btn:disabled { opacity: .5; cursor: not-allowed; }
a.btn:disabled, a.btn[aria-disabled="true"] { pointer-events: none; }
.btn:focus-visible { outline-offset: 2px; }
/* ============================================================ Wizard */