root
223fa33f50
Phase 13.5: Persistent Host-SoT Patch Promotion Channel - promote-runner-patch, rollback-runner-patch (SHA-bound, atomic, FAIL CLOSED)
2026-08-29 20:59:30 +00:00
root
6bcad03e18
Phase 13.5: Final Reproduction Control Plane - pin-current-candidate, verify-candidate-image, recreate-candidate-safe, rollback-to-recovery-gold (Safe Recreate + Rollback Prep)
2026-08-29 19:17:23 +00:00
root
9d2bfe3ae4
CP2A2: verify-recovery-gold-image PATH-NORMALIZATION-FIX (Image-Manifest app/-Präfix, Container-Pfad /app/app) + Critical-File-Pfadfix
2026-08-29 19:08:42 +00:00
root
c6046feaf2
CP2A2: rq-historical build-recovery-gold Kanal (fix Context/Dockerfile/Tag, 7 Guards, DIRECT-Tag no-latest, verify-recovery-gold-image, Host-Legacy-Guard)
2026-08-29 18:46:00 +00:00
root
efe13ec92d
Phase 13.5: Recovery-Gold-Snapshot-Kanal (snapshot-recovery/verify/dry-run, 14 Guards, fail-closed) | Rain Ocampo 2026-08-29
2026-08-29 18:12:04 +00:00
root
c9b3dafd9f
rq-historical: CONTROLLED NO-OP BUILD/RECREATE Kanal (build-historical, recreate-historical, verify-gold-reproduction) — dry-run Mutation Guard, .dockerignore Build-Pollution-Exclusion, fail-closed, kein echter Build/Recreate
2026-08-29 16:50:17 +00:00
Rain Ocampo
64240ea3b1
rq-historical: HOST-SOT-RECOVERY Kanal (backup-sot, recover-sot, verify-sot-recovery, restore-sot) — Gold-SHA-gebunden, fail-closed, kein Build
2026-08-29 15:56:57 +00:00
Rain Ocampo
9129e76a6d
rq-historical: SOT-Discovery read-only Kanal (build-def, build-files, host/container-manifest, host/container-code, tree-diff) — redacted Secrets
2026-08-29 15:24:28 +00:00
root
6324c8aaac
rq-historical: add dev/test/deploy channel (stage-check,test,deploy,backup,rollback,search-writes,healthcheck)
2026-08-29 10:34:59 +00:00
root
bbfd85e472
rq-historical: add READ-ONLY code/hashes/code-list (allowlist) for RQ Phase 13.5
2026-08-29 09:51:04 +00:00
root
a0c388ab18
CP2A2.2B: Fix worker UID/GID to 10000/10000 (hermes user in base image) - non-root hardening correction
2026-08-29 07:17:11 +00:00
root
7a4220d86d
CP2A2.2B: L1 Red Queen Worker Foundation - separate minimal worker runtime (non-root, read-only rootfs, cap-drop ALL, no-new-privileges, internal-net, credential-zero, inert idle, NO autonomy/heartbeat/scheduler)
2026-08-29 07:16:28 +00:00
root
7b58d27fa0
CP2A1: Trusted Gate Evaluator (External Gate Enforcement Foundation) - non-productive, no autonomy, CP1-logic reuse, fail-closed, internal-net, no credentials
2026-08-28 13:24:58 +00:00
Red Queen
058c92e5d0
CP1.1: PRE_HERMES Control Plane SOT closure - 5-control scope (trading_execution removed), RED_QUEEN_TRADING_AUTHORITY=NEVER, reproducible deployment
2026-08-28 11:27:31 +00:00
Rain Ocampo
b6c9da3e12
CP1.1: Control Plane SoT closure - reader, tests, deploy script, ops contract
2026-08-28 09:18:04 +00:00
Rain Ocampo
dcc6d8a098
AUTH.4D: P10/P11 test suite + mutation/sensitivity tests
...
- test_delete_worker.py: 42 tests (T1-T42) against productive delete_* SoT code
(T29 delete_request_id mismatch, T41 second-delete guard, T42 immutable guard)
- test_mutations.py: 15 mutations A-O, all detected (P11 sensitivity)
AUTH.4D P14. No deployment, no token injection, no key provisioning.
2026-08-28 02:30:19 +00:00
Rain Ocampo
9c2d6e365a
AUTH.4D: DELETE-scoped executor + delete_request_id binding in SoT core
...
- delete_worker.py: DELETE-scoped worker loop (ApprovalStateStore, fail-closed)
- delete_tolaria_client.py: DELETE-only Tolaria client (fixed /delete endpoint)
- delete_entrypoint.py: DELETE runtime entrypoint (health/status + worker)
- delete_Dockerfile: DELETE executor image (no SAVE code, no credentials)
- delete_executor_core.py: minimal SoT patch — VALID_NONCE replay guard +
VALID_DELETE_REQUEST binding (approval binds delete_request_id, fail-closed
APPROVAL_MISMATCH). Closes P10/T29 security gap in productive SoT.
AUTH.4D P14. No deployment, no token injection, no key provisioning.
2026-08-28 02:28:48 +00:00
5f3adda73f
AUTH.4C3: Dockerfile kopiert save_reconciliation.py ins Image (BUILD_REPRODUCIBLE_FROM_SOT)
2026-08-27 16:52:11 +00:00
dbc31ad1bb
AUTH.4C3: OUTCOME_UNKNOWN read-only reconciliation contract — RECONCILED state, immutable-field guard, provenance recompute, fail-closed classification, 61 isolated tests (reconciliation 30, incident fixture 5, adversarial 14, sensitivity 12)
2026-08-27 15:57:06 +00:00
2e631fd5fa
AUTH.4C2: relative vault path contract repair (OPTION A) — canonical relative path, absolute/traversal fail-closed, no approval_payload dual-semantics, 20 path-contract tests
2026-08-27 13:23:56 +00:00
2ba503df0e
AUTH.4C1: SoT reconciliation — runtime wiring (entrypoint, worker, tolaria_client, forgejo_source_loader, Dockerfile) + Read-Back-Verifikation + SHA1-Korrektur
2026-08-27 13:23:43 +00:00
9f3ed82cfc
AUTH.4C2: First Productive SAVE Canary (tolaria/auth4c2-canary.md)
2026-08-27 12:47:50 +00:00
373425fc0d
AUTH.3E: Audit-Trail trennt REQUESTED/AUTHORIZED/EXECUTED (Fresh Checker Punkt 27)
...
Fresh Checker identifizierte Defekt: audit_trail() lieferte nur einen Job-Snapshot,
kein persistentes Audit-Event-Log. Design §18 verlangt Trennung der Phasen.
- job_store: audit_events-Tabelle + _record_audit/record_audit_event; REQUESTED bei create_job
- delete_executor_core: AUTHORIZED nach AUTH.3D-Validierung, EXECUTED nach Mutation
- save_executor_core: AUTHORIZED nach Provenance-Validierung, EXECUTED nach Mutation
- test_job_channel: +4 AuditTrailTests (REQUESTED/AUTHORIZED/EXECUTED)
REPAIR_CYCLES=1. Volle Regression 444 PASS (76+50+19+299).
2026-08-27 10:09:18 +00:00
10761f52b2
AUTH.3E: Executor Command Channel + Runtime Boundary Contract
...
- job_schema: geschlossene Job-Type-Allowlist (C5_SAVE_OBJECT/C5_DELETE_OBJECT), Pfad-/Längen-Validierung
- job_state_machine: deterministische States (CREATED/READY/CLAIMED/EXECUTING/SUCCEEDED/FAILED)
- job_claim: atomare Claim-/Lease-/Recovery-Logik (kein TOCTOU)
- job_store: getrennte SQLite-Inbox-DBs (c5a_save.db/c5a_delete.db), delegiert an job_claim
- save_executor_core: SAVE-only, Content-Rekonstruktion, Provenance-Validierung
- delete_executor_core: DELETE-only, AUTH.3D-Composition, TOCTOU-Defense (Re-Read nach Claim)
- test_job_channel: T1-T40 + adversarial (72 Tests)
- test_job_channel_adversarial: adversarial + Substitution + DB-Manipulation
- sensitivity_proof_auth3e: Mutationen A-L (12/12 Invarianten PRESENT)
- AUTH3B/3C/3D/3E_DESIGN: autoritative Security-Dokumentation (e25 Reconciliation)
COMMAND != AUTHORIZATION. Kein generischer Dispatcher. RQ credential-free.
Keine produktive Mutation. Keine echten Credentials.
2026-08-27 10:03:32 +00:00
9c8d239ae5
AUTH.3D: Human DELETE Approval Authenticity (Ed25519, verify-only)
...
- approval_payload: kanonischer, deterministischer Approval-Payload
- approval_signature: Ed25519 sign/verify (Christian=Private Key, Executor=Public Key only)
- approval_verifier: verify-only, alle Bindings fail-closed
- approval_state: Lifecycle CREATED->CONSUMED, Single-Use, Reservation, OUTCOME_UNKNOWN
- test_approval_auth3d: T1-T30 + adversarial (50 Tests)
- test_approval_helpers: synthetische Test-Keypairs
- sensitivity_proof: Mutationen A-J machen Tests ROT
Nur synthetische Test-Keypairs. Kein produktives Deployment.
DELETE_OPERATION_ACTIVATION bleibt BLOCKED bis AUTH.3D geprueft.
2026-08-27 09:36:21 +00:00
a11c1bbe53
AUTH.3A: C5 Caller Auth Integration (SAVE/DELETE Credential, fail-closed, Tests, Sensitivity, Gap-Doku)
...
- rq_c5c.py: TolariaClient save_token/delete_token DI, _require_token fail-closed,
write()/delete() senden Bearer (SAVE/DELETE), read()/list() ohne Credential
- rq_c5_cli.py: _delete_executor liest nur DELETE-Credential (Least Privilege)
- test_c5c.py: write()-Tests injizieren synthetisches SAVE-Token
- test_c5_auth3a.py: isolierte AUTH.3A-Testsuite (19 Tests, Fake/Mock Tolaria)
- auth3a-sensitivity.sh: 8 Sensitivitaets-Mutationen (A-H) -> ROT
- AUTH3A_HUMAN_APPROVAL_AUTHENTICITY_GAP.md: Gap dokumentiert (OPEN, nicht repariert)
Keine echten Tokens. Keine ENV-Mutation. Kein Deployment. Keine produktive Auth-Aktivierung.
2026-08-27 08:42:26 +00:00
40bbc40a49
PRE_HERMES_SECURITY_GATE AUTH.1: Tolaria Write Auth Contract + isolierte Test-Suite
...
- Contract (ADR): Auth-Modell (SAVE/DELETE-Scope getrennt), Credential-Modell
(RQ/Hermes NO SAVE/DELETE; C5C Writer SAVE only; DeleteExecutor DELETE only),
FAIL-CLOSED-Regeln, Human-DELETE-Gate (2 unabhaengige Ebenen AUTH+APPROVAL),
Logging/Secret-Regeln, Rotation/Revocation, Path-Safety-Contract (Defense-in-Depth).
- Isolierte Test-Suite (47 Tests): T1-T20 Auth-Matrix, Human-Approval-Composition A-G,
Adversarial, Sensitivitaet (Mutationen -> ROT). KEIN Produktionscode geaendert.
- KEINE produktive Mutation, KEINE echten Tokens, nur synthetische Fixture-Werte.
2026-08-27 05:57:22 +00:00
9402a92cc3
C5G.1: Acceptance/Exit-Criteria test (17 tests, 12/12 adversarial sensitivity)
2026-08-27 04:12:20 +00:00
951868dda9
C5F: Remove controlled canary object (c5f-controlled-canary.md)
...
Human-gated cleanup of the C5F canary object/6edb6869-0dfd-4046-993a-a727a8cab029.
Authorized exclusively for this single canary (C5F PRODUCTIVE CANARY CLEANUP AUTHORIZATION).
2026-08-26 19:26:28 +00:00
3db1c71b68
C5: Human-Gated DELETE Execution Contract (Todo 7-13)
...
- DeleteExecutor (rq_c5_delete.py): Pre-Gates, Read-Back, idempotenter replay
- TolariaClient.delete() (rq_c5c.py): kontrollierter DELETE, keine Probes
- Approval-Store + Reason Codes RC_DELETE_APPROVAL_MISSING/MISMATCH (rq_c5a.py)
- CLI: c5-delete-approve/execute/replay/status (rq_c5_cli.py)
- C5E: recover()/replay() DELETE-Integration
- C5D: verify_integrity prueft secret_blocked_objects (FAIL CLOSED)
- Security: Path-Traversal-Block in _normalize_vault_path
- Drift nach DELETE -> FAIL CLOSED zurueck zu HUMAN_REVIEW_REQUIRED
- Tests: test_c5_delete (19), test_c5_delete_integration (22),
test_c5_delete_fresh_checker (17) — alle gruen
- ADR: C5_DELETE_EXECUTION_ARCHITECTURE_DECISION.md (ACCEPTED)
2026-08-26 19:22:44 +00:00
363f27327b
fix(tolaria): C5D source_provenance persistence contract (OPTION A)
...
Persistiert die Search-Source-Provenance commit-spezifisch im C5-State
(meta-KV-Key search_source_provenance:<workflow_commit_sha>), WRITE POINT
nach validiertem Source-Build. Adoption prueft ausschliesslich gegen die
persistierte source_provenance, nie gegen workflow_commit_sha oder
current_repo_head. FAIL CLOSED ohne persistierte Provenance. Generischer,
evidence-validierter Recovery-Pfad fuer extern abgeschlossene Builds.
14 neue Contract-Tests (A-N); volle Regression gruen.
2026-08-26 16:07:49 +00:00
76512ddd48
fix(tolaria): C5A reason-code closed-set accepts C5D build code
...
RC_SEARCH_SOURCE_BUILD_FAILURE (added in 5e41915 , C5D search-source
pipeline) was missing from test_reason_codes_closed_set, so the C5A
suite falsely FAILed (18 vs 17). Pre-existing defect exposed by the
C5D adoption fresh-checker regression gate; not introduced by 747376e .
Harden the assertion to the real closed set (len 18).
2026-08-26 15:24:03 +00:00
747376ebb0
fix(tolaria): adopt externally completed search rebuild
...
C5F P5 Option A: C5DEngine.apply_commit() uebernimmt einen extern
bereits vollstaendig korrekt rebuildeten Suchzustand bei UPDATING_SEARCH
idempotent (ADOPT_ALREADY_AT_TARGET) ohne zweiten Rebuild.
- Neues evaluate_external_adoption(): read-only, exakte Set-Gleichheit
(ids, paths, count, source_head), kein object_count-only shortcut
- apply_commit(): UPDATING_SEARCH -> Adoption-Check -> bei exaktem Match
direkt VERIFYING_SEARCH ohne rebuild() -> verify -> APPLIED
- Neuer Report-Feld 'adoption' mit Status + rebuild_count
- Testsuite test_c5d_adoption.py (Faelle A-O, 15 Tests)
Kein zweiter Rebuild, kein manueller State-Set, kein Tolaria-/Forgejo-Write.
2026-08-26 15:18:27 +00:00
12635e8672
fix(tolaria): C5F Phase B — search-source indexability path-independent (valid C3 object_id suffices; LEGACY kept; out-of-scope dirs no longer auto-exclude indexable knowledge)
2026-08-26 13:05:13 +00:00
5e4191578a
fix(tolaria): C5D search-source pipeline — build+verify source from current Tolaria before rebuild
...
- SearchSourceBuilder: deterministischer Vault->Source-Snapshot (read-only),
atomar (temp->validate->fsync->replace), Secret-Scan fail-closed
- verify_integrity: exakte object_id/path Set-Equality (stale Source kann
nie APPLIED), Canary implizit ueber erwartetes Objekt-Set
- apply_commit: Source-Build+Verification vor Rebuild; VERIFYING_SEARCH-Resume
(kein Doppel-Rebuild) — C5E-Replay-Crash-Fall abgedeckt
- Fix: source_object_count ist keine 0-Fehlerbedingung (echter Defekt)
- SearchSourceBuildError + RC_SEARCH_SOURCE_BUILD_FAILURE (Human Gate)
- c4b: source_path env-konfigurierbar, indexed_object_ids/paths Read-Back
- Testsuite: 17 neue Tests (Test-Plan A-O + Realistic C4-Integration)
2026-08-26 12:12:45 +00:00
f451283276
fix(tolaria): allow propagate_commit resume from PROPAGATING_TOLARIA crash-window
...
C5F canary commit parked in PROPAGATING_TOLARIA with objects already written
to Tolaria (real write before crash). C5EEngine.replay() delegates the pending
case to propagate_commit, whose entry guard only accepted READY/RETRY_PENDING,
so the commit could never resume past the crash window and the ALREADY_AT_TARGET
idempotency (pre_write_drift_check) was never reached.
Minimal fix: accept PROPAGATING_TOLARIA as a resume entry state (idempotency
still determined per-object via pre_write_drift_check -> no double write; read-back
verify() remains the mandatory gate) and skip the READY->PROPAGATING_TOLARIA
transition on resume (no self-transition entry exists in _ALLOWED_TRANSITIONS).
Adds 2 regression tests covering the crash-window resume (already-at-target and
pending-create). Full C5A-E suite: 190 tests, 0 failures.
2026-08-26 10:48:10 +00:00
c5b3db153a
fix(tolaria): handle null success response from vault save
2026-08-26 10:23:14 +00:00
238536710a
fix(tolaria): handle missing vault object in C5C read path
2026-08-26 10:03:40 +00:00
63f957f4fb
c5f: add controlled canary object (C5F CONTROLLED CANARY)
2026-08-26 08:11:42 +00:00
Rain Ocampo
3289098040
C5E: Fix replay crash-window (PROPAGATING_TOLARIA/READY + all objects propagated) via formal VERIFYING_TOLARIA path
...
FRESH CHECKER-VERDICT (deleg_3ea8ed5a): FAIL.
Defekt: rq_c5e.py Replay 'alle Objekte bereits propagated' rief
transition_commit(ST_UPDATING_SEARCH) aus PROPAGATING_TOLARIA/READY direkt auf,
was InvalidTransitionError warf (Transition nicht in _ALLOWED_TRANSITIONS).
Reparatur (invarianten-treu): statt den VERIFYING_TOLARIA-Schritt zu ueberspringen
(wuerde Read-Back/DRIFT-Check verletzen), wird der formale State-Pfad
READY->PROPAGATING->VERIFYING->UPDATING_SEARCH durchlaufen. Nutzt nur bereits
erlaubte Transitions; keine _ALLOWED_TRANSITIONS-Aenderung, kein C5A/C5C-Risiko.
Kein Tolaria-Doppel-Write (prop_calls=0), kein verfrühter Search (search_calls=0).
+ 2 Regressionstests (test_c5e.py): crash-window + ready-edge-case.
Volle Suite: C5A 25/0 + B/C/D/E 170/0 = 195 OK. Guarantees true.
2026-08-26 07:06:50 +00:00
22e1cd0d44
C5E: FAILURE/REPLAY/RECOVERY + OBSERVABILITY (fail-closed Library)
...
- rq_c5e.py: C5EEngine (Recovery-Entscheidung RESUME/RETRY/WAIT/HUMAN_REVIEW/ALREADY_APPLIED,
deterministisches Replay, Partial-Commit-Recovery via object_progress), C5EReconciler
(read-only, kein blindes Repair), observability(), health_contract() (HEALTHY/DEGRADED/BLOCKED),
failure_evidence(). FAIL-CLOSED: Standard allow_writes=False, kein Polling/Daemon.
- rq_c5a.py: +4 Reason-Codes (SEARCH_UNAVAILABLE, NETWORK_TIMEOUT, MALFORMED_RESPONSE,
INTEGRITY_FAILURE) -> REASON_CODES 13->17 (minimal, dokumentiert, regressionsgetestet).
- rq_c5_cli.py: +7 C5E-Befehle (recover, replay, reconcile, observability, health,
evidence, guarantees), alle fail-closed.
- test_c5a.py: Assertions auf 17 Reason-Codes angehoben.
- test_c5e.py: 58 Tests (Restart/Retry/Replay/Partial/Ordering/Drift/Health/
Observability/Persistence/Reconciliation/No-Doppel-Writes).
Regression: C5A 25/25, C5B 40/40, C5C 35/35, C5D 35/35, C5E 58/58. Alle gruen.
Keine produktive Aktivierung.
2026-08-26 06:54:10 +00:00
1404e78cb9
c5d: search integration + commit completion (UPDATING_SEARCH->VERIFYING_SEARCH->APPLIED)
2026-08-26 06:15:33 +00:00
8d7647b113
fix(tolaria): repair C5C retry state transitions and add retry tests
2026-08-26 05:57:55 +00:00
763f1ca9da
feat(tolaria): add C5 Tolaria propagation and drift verification
2026-08-26 05:55:38 +00:00
ed374ac4ce
fix(c5b): persist human-review object changes + read content_before from parent commit
...
- C5A objects table: object_id nullable + reason_code column so HUMAN_REVIEW/
SECRET_DETECTED object changes (object_id=None) are persisted, not silently
dropped (was: object_id TEXT NOT NULL, no reason_code field)
- C5B poll_once: content_before now read from parent_sha (state BEFORE the
change) instead of sha, so MODIFIED changes classify as CONTENT_UPDATE
instead of being misclassified (Checker-Befund)
- test_c5b: add test_modified_content_reads_parent regression test
C5B 40/40, C5A 25/25, real-repo dry run: 233 object changes (109 IN_SCOPE
with valid id, 124 HUMAN_REVIEW), idempotent.
2026-08-26 05:20:38 +00:00
091c1828c7
feat(tolaria): add C5 Forgejo polling and change detection
2026-08-26 05:13:33 +00:00
183afed1d6
feat(tolaria): add C5 sync state machine
2026-08-26 05:03:19 +00:00
68db35f55c
docs(tolaria): add C5 sync architecture design
2026-08-26 04:31:56 +00:00
Rain Ocampo
4122bdd408
fix(tolaria-search): repair admin rebuild source path
...
server.py resolved SOURCE_JSON to ../c4a_evidence/index_source.json which does not exist in the deployed container. The C4B service ships index_source.json in its own directory. Fix resolves robustly relative to the service root.
2026-08-26 03:37:26 +00:00
29cbca9357
docs(tolaria): add C4 Search v1 production deployment plan (C4B)
2026-08-26 02:45:34 +00:00