|
|
e56567f7cf
|
wave1: formally close provenance foundation production deployment
|
2026-09-04 20:02:48 +00:00 |
|
root
|
36916a073d
|
phase13.6: formally close hardening repair
|
2026-09-01 10:20:24 +00:00 |
|
root
|
51c03f7ade
|
phase13.5: formally close runner trustgate remediation
|
2026-08-31 23:00:47 +00:00 |
|
root
|
738af54c93
|
phase13.5: verify recreate post-gates against target class
|
2026-08-31 18:54:03 +00:00 |
|
root
|
35bbdd89e7
|
phase13.5: add bounded recreate startup readiness gate
|
2026-08-31 17:29:06 +00:00 |
|
root
|
b61acd3f08
|
phase13.5: fix remediation recreate Gate O runner allowance
|
2026-08-31 16:13:40 +00:00 |
|
root
|
d6394ef327
|
RAIN: Phase 13.5 Emergency Rollback CP Repair - target-image-based rollback pre-gates (current/recovery gold). SoT local, no push.
|
2026-08-31 12:54:03 +00:00 |
|
root
|
a7336c2585
|
RAIN: Phase 13.5 Remediation Recreate Gate Decoupling + fixed-ID rollback-to-current-gold-anchor (SoT)
|
2026-08-31 11:38:41 +00:00 |
|
root
|
41c82f14d3
|
RAIN Hotfix: Partial Archive Cleanup Semantics (PARTIAL statt UNKNOWN fuer image.tar+fehlende Metadaten, fail-closed)
|
2026-08-31 07:51:49 +00:00 |
|
root
|
561133f39b
|
RAIN Hotfix: Remediation Archive Build-Input-Semantik (branch-spezifisch, recovery unveraendert)
|
2026-08-31 07:02:48 +00:00 |
|
root
|
75b594f225
|
Phase 13.5: verify-runner-remediation-image session-binding hotfix (load_remediation_source_state)
|
2026-08-31 05:57:34 +00:00 |
|
root
|
ce58a067ee
|
Phase 13.5: Deploy verified partial-archive control-plane patch (cleanup-partial-remediation-archive + active remediation image state validation)
|
2026-08-30 20:39:13 +00:00 |
|
root
|
3e65c36cce
|
Phase 13.5: Orphan Remediation Staging Cleanup Control-Plane Hotfix (cleanup-partial-remediation-staging)
|
2026-08-30 17:31:47 +00:00 |
|
root
|
f69774e34b
|
Phase 13.5 Remediation Staging Consistency + Active Image ID Hotfix: remediation_staging_matches_expected entfernt fehlerhaftes | sort (SHA-sortiert) das gegen Pfad-sortiertes Staging-Manifest verglich -> Staging-Check FAIL CLOSED trotz identischem Inhalt. Fix: exp ohne | sort (remediation_expected_manifest erzeugt bereits Pfad-sortiert). Active-ID bereits state-basiert (remediation_session/full_image_id), 41e357a1 nur noch dokumentarisch. Verdict A.
|
2026-08-30 16:58:10 +00:00 |
|
root
|
c95fbe6b3c
|
Phase 13.5 Remediation Build-Context Control-Plane Rotation: build-runner-remediation von /opt/historical-v2 auf immutable Gold-Source-Session 20260830_104127 + autorisierter Runner-Overlay 6cca3c55; Guards A/B/C/D/N auf Gold+Overlay; Guard I diagnostisch (No-op-Tag-Loss NON-BLOCKING); verify_runner_remediation_image 62+1 + repository.py Hard Gate; verify_archive/pin/archive aktive Build-Session-Identity; deterministischer REMEDIATION_BUILD_INPUT_SHA
|
2026-08-30 16:36:42 +00:00 |
|
root
|
8161208f1c
|
Phase 13.5 Archive Metadata Variable Hotfix: gen_archive_meta nach write_runtime_config/write_app_manifest + SHA-Validierung (unbound variable Fix)
|
2026-08-30 14:22:14 +00:00 |
|
root
|
9685b616cf
|
Phase 13.5 Recovery Archive Hotfix: Fix A (Reihenfolge-Bug nach docker image save) + cleanup-partial-recovery-archive Command
|
2026-08-30 11:34:11 +00:00 |
|
root
|
a9d7da14f5
|
Phase 13.5 Recovery Rebuild Guard Source Rotation: rebuild_guards Guard A/B/C auf Gold-Source-Session (verify-recovered-gold-build-source + verify_recovery_build_input), Host-SoT-Drift non-blocking Diagnostic, kein /opt/historical-v2 als Recovery-Build-Blocker
|
2026-08-30 11:10:07 +00:00 |
|
Rain Ocampo
|
d7db920116
|
Phase 13.5 Nested Verify Exit Hotfix: verify_deployed_gold_source + verify_recovered_gold_build_source exit 0 -> return 0 (nested-call Guard-Defekt)
|
2026-08-30 10:28:46 +00:00 |
|
Rain Ocampo
|
8f29924ec6
|
Phase 13.5 Recovery Control-Plane Rotation: real recover freigegeben, Build-Context-Rotation (kein /opt/historical-v2), Recovery-Identity-Rotation (CURRENT_RECOVERY_ID statt d2db), READY-Gate, wrapper-sha
|
2026-08-30 09:26:59 +00:00 |
|
root
|
563ed111b9
|
Phase 13.5: Deployed Gold Source Recovery Control Plane - feste Subcommands verify-deployed-gold-source / dry-run recover-gold-build-source / recover-gold-build-source (real blockiert) / verify-recovered-gold-build-source; Gold-Source fest an Container+Image+63-File-Manifest gebunden, kein latest, kein full_sot_backup, immutable Target, FAIL CLOSED
|
2026-08-30 08:46:32 +00:00 |
|
root
|
65c1d57fa7
|
Phase 13.5: Image Retention & Archive Control Plane - feste Subcommands archive/pin/verify-archive/verify-pin/verify-ready/dry-run restore (FAIL CLOSED, kein Overwrite, kein Coolify-Cleanup-Disable, kein coolify.managed-Spoof); Restore nur dry-run (real blockiert)
|
2026-08-30 06:05:56 +00:00 |
|
Rain Ocampo
|
8187a4bc1d
|
Phase 13.5: Authorized Remediation Divergence Verify Fix - verify-runner-remediation-image nutzt gemeinsame authorized_gold_delta-Policy (exakt 1 autorisierte Runner-Divergenz, alles andere FAIL CLOSED); Candidate-vs-Host-SoT direkter Vergleich; verify_critical_files runner-Flag
|
2026-08-29 23:56:14 +00:00 |
|
Rain Ocampo
|
6194868100
|
Phase 13.5: Remediation Build/Deploy Control Plane - build-runner-remediation, verify-runner-remediation-image, recreate-runner-remediation-safe, verify-remediation-build-input; Full/Partial SoT-Backup-Klassifikation (Blocker A)
|
2026-08-29 23:01:57 +00:00 |
|
root
|
223fa33f50
|
Phase 13.5: Persistent Host-SoT Patch Promotion Channel - promote-runner-patch, rollback-runner-patch (SHA-bound, atomic, FAIL CLOSED)
|
2026-08-29 20:59:30 +00:00 |
|
root
|
6bcad03e18
|
Phase 13.5: Final Reproduction Control Plane - pin-current-candidate, verify-candidate-image, recreate-candidate-safe, rollback-to-recovery-gold (Safe Recreate + Rollback Prep)
|
2026-08-29 19:17:23 +00:00 |
|
root
|
9d2bfe3ae4
|
CP2A2: verify-recovery-gold-image PATH-NORMALIZATION-FIX (Image-Manifest app/-Präfix, Container-Pfad /app/app) + Critical-File-Pfadfix
|
2026-08-29 19:08:42 +00:00 |
|
root
|
c6046feaf2
|
CP2A2: rq-historical build-recovery-gold Kanal (fix Context/Dockerfile/Tag, 7 Guards, DIRECT-Tag no-latest, verify-recovery-gold-image, Host-Legacy-Guard)
|
2026-08-29 18:46:00 +00:00 |
|
root
|
efe13ec92d
|
Phase 13.5: Recovery-Gold-Snapshot-Kanal (snapshot-recovery/verify/dry-run, 14 Guards, fail-closed) | Rain Ocampo 2026-08-29
|
2026-08-29 18:12:04 +00:00 |
|
root
|
c9b3dafd9f
|
rq-historical: CONTROLLED NO-OP BUILD/RECREATE Kanal (build-historical, recreate-historical, verify-gold-reproduction) — dry-run Mutation Guard, .dockerignore Build-Pollution-Exclusion, fail-closed, kein echter Build/Recreate
|
2026-08-29 16:50:17 +00:00 |
|
Rain Ocampo
|
64240ea3b1
|
rq-historical: HOST-SOT-RECOVERY Kanal (backup-sot, recover-sot, verify-sot-recovery, restore-sot) — Gold-SHA-gebunden, fail-closed, kein Build
|
2026-08-29 15:56:57 +00:00 |
|
Rain Ocampo
|
9129e76a6d
|
rq-historical: SOT-Discovery read-only Kanal (build-def, build-files, host/container-manifest, host/container-code, tree-diff) — redacted Secrets
|
2026-08-29 15:24:28 +00:00 |
|
root
|
6324c8aaac
|
rq-historical: add dev/test/deploy channel (stage-check,test,deploy,backup,rollback,search-writes,healthcheck)
|
2026-08-29 10:34:59 +00:00 |
|
root
|
bbfd85e472
|
rq-historical: add READ-ONLY code/hashes/code-list (allowlist) for RQ Phase 13.5
|
2026-08-29 09:51:04 +00:00 |
|
root
|
a0c388ab18
|
CP2A2.2B: Fix worker UID/GID to 10000/10000 (hermes user in base image) - non-root hardening correction
|
2026-08-29 07:17:11 +00:00 |
|
root
|
7a4220d86d
|
CP2A2.2B: L1 Red Queen Worker Foundation - separate minimal worker runtime (non-root, read-only rootfs, cap-drop ALL, no-new-privileges, internal-net, credential-zero, inert idle, NO autonomy/heartbeat/scheduler)
|
2026-08-29 07:16:28 +00:00 |
|
root
|
7b58d27fa0
|
CP2A1: Trusted Gate Evaluator (External Gate Enforcement Foundation) - non-productive, no autonomy, CP1-logic reuse, fail-closed, internal-net, no credentials
|
2026-08-28 13:24:58 +00:00 |
|
Red Queen
|
058c92e5d0
|
CP1.1: PRE_HERMES Control Plane SOT closure - 5-control scope (trading_execution removed), RED_QUEEN_TRADING_AUTHORITY=NEVER, reproducible deployment
|
2026-08-28 11:27:31 +00:00 |
|
Rain Ocampo
|
b6c9da3e12
|
CP1.1: Control Plane SoT closure - reader, tests, deploy script, ops contract
|
2026-08-28 09:18:04 +00:00 |
|
Rain Ocampo
|
dcc6d8a098
|
AUTH.4D: P10/P11 test suite + mutation/sensitivity tests
- test_delete_worker.py: 42 tests (T1-T42) against productive delete_* SoT code
(T29 delete_request_id mismatch, T41 second-delete guard, T42 immutable guard)
- test_mutations.py: 15 mutations A-O, all detected (P11 sensitivity)
AUTH.4D P14. No deployment, no token injection, no key provisioning.
|
2026-08-28 02:30:19 +00:00 |
|
Rain Ocampo
|
9c2d6e365a
|
AUTH.4D: DELETE-scoped executor + delete_request_id binding in SoT core
- delete_worker.py: DELETE-scoped worker loop (ApprovalStateStore, fail-closed)
- delete_tolaria_client.py: DELETE-only Tolaria client (fixed /delete endpoint)
- delete_entrypoint.py: DELETE runtime entrypoint (health/status + worker)
- delete_Dockerfile: DELETE executor image (no SAVE code, no credentials)
- delete_executor_core.py: minimal SoT patch — VALID_NONCE replay guard +
VALID_DELETE_REQUEST binding (approval binds delete_request_id, fail-closed
APPROVAL_MISMATCH). Closes P10/T29 security gap in productive SoT.
AUTH.4D P14. No deployment, no token injection, no key provisioning.
|
2026-08-28 02:28:48 +00:00 |
|
|
|
5f3adda73f
|
AUTH.4C3: Dockerfile kopiert save_reconciliation.py ins Image (BUILD_REPRODUCIBLE_FROM_SOT)
|
2026-08-27 16:52:11 +00:00 |
|
|
|
dbc31ad1bb
|
AUTH.4C3: OUTCOME_UNKNOWN read-only reconciliation contract — RECONCILED state, immutable-field guard, provenance recompute, fail-closed classification, 61 isolated tests (reconciliation 30, incident fixture 5, adversarial 14, sensitivity 12)
|
2026-08-27 15:57:06 +00:00 |
|
|
|
2e631fd5fa
|
AUTH.4C2: relative vault path contract repair (OPTION A) — canonical relative path, absolute/traversal fail-closed, no approval_payload dual-semantics, 20 path-contract tests
|
2026-08-27 13:23:56 +00:00 |
|
|
|
2ba503df0e
|
AUTH.4C1: SoT reconciliation — runtime wiring (entrypoint, worker, tolaria_client, forgejo_source_loader, Dockerfile) + Read-Back-Verifikation + SHA1-Korrektur
|
2026-08-27 13:23:43 +00:00 |
|
|
|
9f3ed82cfc
|
AUTH.4C2: First Productive SAVE Canary (tolaria/auth4c2-canary.md)
|
2026-08-27 12:47:50 +00:00 |
|
|
|
373425fc0d
|
AUTH.3E: Audit-Trail trennt REQUESTED/AUTHORIZED/EXECUTED (Fresh Checker Punkt 27)
Fresh Checker identifizierte Defekt: audit_trail() lieferte nur einen Job-Snapshot,
kein persistentes Audit-Event-Log. Design §18 verlangt Trennung der Phasen.
- job_store: audit_events-Tabelle + _record_audit/record_audit_event; REQUESTED bei create_job
- delete_executor_core: AUTHORIZED nach AUTH.3D-Validierung, EXECUTED nach Mutation
- save_executor_core: AUTHORIZED nach Provenance-Validierung, EXECUTED nach Mutation
- test_job_channel: +4 AuditTrailTests (REQUESTED/AUTHORIZED/EXECUTED)
REPAIR_CYCLES=1. Volle Regression 444 PASS (76+50+19+299).
|
2026-08-27 10:09:18 +00:00 |
|
|
|
10761f52b2
|
AUTH.3E: Executor Command Channel + Runtime Boundary Contract
- job_schema: geschlossene Job-Type-Allowlist (C5_SAVE_OBJECT/C5_DELETE_OBJECT), Pfad-/Längen-Validierung
- job_state_machine: deterministische States (CREATED/READY/CLAIMED/EXECUTING/SUCCEEDED/FAILED)
- job_claim: atomare Claim-/Lease-/Recovery-Logik (kein TOCTOU)
- job_store: getrennte SQLite-Inbox-DBs (c5a_save.db/c5a_delete.db), delegiert an job_claim
- save_executor_core: SAVE-only, Content-Rekonstruktion, Provenance-Validierung
- delete_executor_core: DELETE-only, AUTH.3D-Composition, TOCTOU-Defense (Re-Read nach Claim)
- test_job_channel: T1-T40 + adversarial (72 Tests)
- test_job_channel_adversarial: adversarial + Substitution + DB-Manipulation
- sensitivity_proof_auth3e: Mutationen A-L (12/12 Invarianten PRESENT)
- AUTH3B/3C/3D/3E_DESIGN: autoritative Security-Dokumentation (e25 Reconciliation)
COMMAND != AUTHORIZATION. Kein generischer Dispatcher. RQ credential-free.
Keine produktive Mutation. Keine echten Credentials.
|
2026-08-27 10:03:32 +00:00 |
|
|
|
9c8d239ae5
|
AUTH.3D: Human DELETE Approval Authenticity (Ed25519, verify-only)
- approval_payload: kanonischer, deterministischer Approval-Payload
- approval_signature: Ed25519 sign/verify (Christian=Private Key, Executor=Public Key only)
- approval_verifier: verify-only, alle Bindings fail-closed
- approval_state: Lifecycle CREATED->CONSUMED, Single-Use, Reservation, OUTCOME_UNKNOWN
- test_approval_auth3d: T1-T30 + adversarial (50 Tests)
- test_approval_helpers: synthetische Test-Keypairs
- sensitivity_proof: Mutationen A-J machen Tests ROT
Nur synthetische Test-Keypairs. Kein produktives Deployment.
DELETE_OPERATION_ACTIVATION bleibt BLOCKED bis AUTH.3D geprueft.
|
2026-08-27 09:36:21 +00:00 |
|
|
|
a11c1bbe53
|
AUTH.3A: C5 Caller Auth Integration (SAVE/DELETE Credential, fail-closed, Tests, Sensitivity, Gap-Doku)
- rq_c5c.py: TolariaClient save_token/delete_token DI, _require_token fail-closed,
write()/delete() senden Bearer (SAVE/DELETE), read()/list() ohne Credential
- rq_c5_cli.py: _delete_executor liest nur DELETE-Credential (Least Privilege)
- test_c5c.py: write()-Tests injizieren synthetisches SAVE-Token
- test_c5_auth3a.py: isolierte AUTH.3A-Testsuite (19 Tests, Fake/Mock Tolaria)
- auth3a-sensitivity.sh: 8 Sensitivitaets-Mutationen (A-H) -> ROT
- AUTH3A_HUMAN_APPROVAL_AUTHENTICITY_GAP.md: Gap dokumentiert (OPEN, nicht repariert)
Keine echten Tokens. Keine ENV-Mutation. Kein Deployment. Keine produktive Auth-Aktivierung.
|
2026-08-27 08:42:26 +00:00 |
|