feat(wake): W3 — cumulative-state digest renderer + non-circular HMAC signer
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
All checks were successful
ci/woodpecker/pr/ci Pipeline was successful
Builds on the merged W2 store/ack (EPIC #892). Adds A3 (digest.sh) and A5 (sign.sh) under packages/mosaic/framework/tools/wake/, honoring CONVERGED-DESIGN. A3 — digest.sh (cumulative-state digest renderer), §2.1: - CUMULATIVE-STATE: renders the FULL unacked set since consumed_seq from the durable pending-inbox (state-since-CONSUMED, not an event delta). - TWO-TIER TRUST: orientation tier (who/lane/board-head + changed-obligation list with observed_seq + locators) decides the no-op case with ZERO tool calls; actionable tier renders every consequential fact ONLY as a CLAIM-TO-VERIFY, point-in-time-at-seq — never auto-actioned. - HARD LOCATORS: every actionable claim must carry repo+issue#/40-char SHA/ file:anchor; a missing locator is fail-loud (exit 4, nothing emitted). - BOUNDING/INJECTION/SECRETS: source free-text is quoted only inside a delimited, length-capped, ANSI/bidi/zero-width-stripped untrusted block; secret-canary redaction over any inlined content; embeds the W2 ack line. A5 — sign.sh (non-circular HMAC signer), §2.5: - wake_id generated INDEPENDENTLY at emit (not derived from, and not a member of, the signed field-tuple); wake_mac = HMAC(key, wake_id || agent_identity || mission_generation || observed_seq || emit_ts || content_hash) — over wake_id PLUS the fields, genuinely non-circular (the MAC is never its own input). Fills the `hmac` placeholder W2 left in store entries. - Key resolved BY NAME from the credential store, never inlined, never echoed; no flag accepts key material. Same-uid threat boundary documented; off-uid signer named as a future gate. RED-FIRST tests (test-wake-digest-hmac.sh, wired into test:framework-shell): cumulative-state, hard-locator fail-loud, two-tier (zero-call orientation + claim-to-verify), scrub (secret-canary + ANSI/bidi/zero-width), non-circular HMAC (independent wake_id + tamper-breaks-MAC), key-by-name-never-inline. Each verified to go RED on a targeted regression. shellcheck clean; operator-agnostic (XDG/env only). manifest.txt bumped to 0.2.0. Part of #892 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0158NZqN2n2ymKFeJAZ4GUCb
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# Mosaic wake component — VERSION metadata manifest (Gate B).
|
||||
#
|
||||
# EPIC #892, W2 of the wake/heartbeat canon.
|
||||
# EPIC #892, W2 + W3 of the wake/heartbeat canon.
|
||||
#
|
||||
# SCOPE — THIS FILE IS VERSION METADATA ONLY. It declares the wake component's
|
||||
# semantic version and the RANGE of watch-list schema versions it supports. It
|
||||
@@ -10,9 +10,11 @@
|
||||
#
|
||||
# Format: KEY=VALUE, one per line. '#' and blank lines ignored.
|
||||
|
||||
# Component identity + semantic version (the store+drain lib + ack-wrapper).
|
||||
# Component identity + semantic version.
|
||||
# 0.1.0 W2 — store+drain lib + ack-wrapper.
|
||||
# 0.2.0 W3 — cumulative-state digest renderer + non-circular HMAC signer.
|
||||
component=wake
|
||||
version=0.1.0
|
||||
version=0.2.0
|
||||
|
||||
# Watch-list schema this component consumes, and the INCLUSIVE range of
|
||||
# schema_version values it supports. A wake-watch-list.json whose schema_version
|
||||
@@ -22,8 +24,12 @@ schema=wake-watch-list
|
||||
schema_min=1
|
||||
schema_max=1
|
||||
|
||||
# W2 pieces shipped by this component version (informational):
|
||||
# store.sh A2 — three-cursor durable store + drain lib.
|
||||
# ack.sh A4 — RECEIVED/CONSUMED ack-wrapper (local-write + async ship).
|
||||
# Out of W2 scope (later waves): detector (W4), digest renderer/HMAC (W3),
|
||||
# FN-oracle/reconciler (W5), beacon (W6), installer (W7).
|
||||
# Pieces shipped by this component version (informational):
|
||||
# store.sh A2 — three-cursor durable store + drain lib. (W2)
|
||||
# ack.sh A4 — RECEIVED/CONSUMED ack-wrapper (local-write + ship). (W2)
|
||||
# digest.sh A3 — cumulative-state digest renderer (hard locators,
|
||||
# two-tier trust, injection/secret scrub). (W3)
|
||||
# sign.sh A5 — non-circular HMAC signer (independent wake_id,
|
||||
# load_credentials by-name; fills the hmac placeholder). (W3)
|
||||
# Out of scope (later waves): detector (W4), FN-oracle/reconciler (W5),
|
||||
# beacon (W6), installer (W7).
|
||||
|
||||
Reference in New Issue
Block a user