Compare commits
100
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
205adc54dc | ||
|
|
32799e6025 | ||
|
|
ba74ce4e48 | ||
|
|
bd5afb0711 | ||
|
|
6d92234422 | ||
|
|
9f4b3716db | ||
|
|
1fa2d2ab21 | ||
|
|
806b763d97 | ||
|
|
4c1b2a1fda | ||
|
|
e01cfd44cb | ||
|
|
8f02b55b03 | ||
|
|
aa4b584764 | ||
|
|
2a9360407b | ||
|
|
2922aa152d | ||
|
|
7fc7fa1a25 | ||
|
|
b66d1858e1 | ||
|
|
673fbdb978 | ||
|
|
8fe14d8e1a | ||
|
|
dde38717dd | ||
|
|
d9207d4c1a | ||
|
|
33caf78744 | ||
|
|
1aedf32523 | ||
|
|
0d5aae2c84 | ||
|
|
08f706b675 | ||
|
|
eae62a598a | ||
|
|
267b58deb3 | ||
|
|
e2058d4e84 | ||
|
|
4430e60d84 | ||
|
|
4520d2f672 | ||
|
|
09875143c0 | ||
|
|
08cb73fde3 | ||
|
|
24a7915633 | ||
|
|
e1a3806292 | ||
|
|
72b577eb85 | ||
|
|
52114dd4eb | ||
|
|
8f70b1bc63 | ||
|
|
32384dab02 | ||
|
|
777a8f7f5b | ||
|
|
995f8b6a24 | ||
|
|
d0a510d28d | ||
|
|
8cef39f924 | ||
|
|
f3c100f814 | ||
|
|
2750cc4842 | ||
|
|
553474e4c8 | ||
|
|
0de8ccb52c | ||
|
|
37402e9770 | ||
|
|
01831814b6 | ||
|
|
86cd1a0f46 | ||
|
|
249335e515 | ||
|
|
d9ab6026c8 | ||
|
|
50c0340add | ||
|
|
345d152790 | ||
|
|
f11f257368 | ||
|
|
6c779595e1 | ||
|
|
cc097f36c5 | ||
|
|
56d8e8a3d5 | ||
|
|
4589659bc1 | ||
|
|
357a636a3a | ||
|
|
9e205e8201 | ||
|
|
73a313301b | ||
|
|
eddf718a5c | ||
|
|
c83a3cd3e2 | ||
|
|
bf8c6f4a89 | ||
|
|
bdf8932328 | ||
|
|
16d11cd6cd | ||
|
|
8ce77fcb0d | ||
|
|
cdd5568adb | ||
|
|
ff4b45b025 | ||
|
|
f47cf45b0c | ||
|
|
e7c9160c7b | ||
|
|
2d58779675 | ||
|
|
cbbe3e1ce2 | ||
|
|
9a7ab73952 | ||
|
|
2b85afe4ea | ||
|
|
eabe04bc5e | ||
|
|
36018be8d1 | ||
|
|
8c496993e4 | ||
|
|
e85a088f85 | ||
|
|
8a795df0ce | ||
|
|
f5a0566198 | ||
|
|
1e7a0701fd | ||
|
|
43f69bf167 | ||
|
|
f9435c2a03 | ||
|
|
3b191b6b34 | ||
|
|
85bdbe3383 | ||
|
|
ae4baf145d | ||
|
|
4512312b9f | ||
|
|
e233f196b5 | ||
|
|
3477e933df | ||
|
|
d0ad6e942b | ||
|
|
7f686aaf6d | ||
|
|
f13222b76b | ||
|
|
d1e7ba19ca | ||
|
|
0ffdcf14bd | ||
|
|
be10bdc828 | ||
|
|
2201c30284 | ||
|
|
75dfe2fa75 | ||
|
|
409bf23e6a | ||
|
|
31c3191305 | ||
|
|
6a067174ed |
@@ -8,7 +8,6 @@ coverage
|
|||||||
.env.local
|
.env.local
|
||||||
*.tsbuildinfo
|
*.tsbuildinfo
|
||||||
.pnpm-store
|
.pnpm-store
|
||||||
__pycache__/
|
|
||||||
docs/reports/
|
docs/reports/
|
||||||
|
|
||||||
# Step-CA dev password — real file is gitignored; commit only the .example
|
# Step-CA dev password — real file is gitignored; commit only the .example
|
||||||
|
|||||||
+1
-1
@@ -1 +1 @@
|
|||||||
pnpm preflight && pnpm typecheck && pnpm lint && pnpm format:check
|
pnpm typecheck && pnpm lint && pnpm format:check
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
@mosaicstack:registry=https://git.mosaicstack.dev/api/packages/mosaicstack/npm/
|
@mosaicstack:registry=https://git.mosaicstack.dev/api/packages/mosaicstack/npm/
|
||||||
# HOME resolves to /root in the ci-base image, preserving its warmed-store path.
|
# Pin the pnpm store to the same path the ci-base image warms (Dockerfile.ci),
|
||||||
# Non-root checkouts use their own HOME. Override without editing this file via
|
# so the pipeline `pnpm install --prefer-offline` consumes the baked store
|
||||||
# NPM_CONFIG_STORE_DIR (pnpm's environment form of the store-dir setting).
|
# instead of repopulating a fresh one.
|
||||||
store-dir=${HOME}/.local/share/pnpm/store
|
store-dir=/root/.local/share/pnpm/store
|
||||||
|
|||||||
@@ -201,21 +201,8 @@ git clone [email protected]:mosaicstack/stack.git
|
|||||||
cd stack
|
cd stack
|
||||||
|
|
||||||
# Install dependencies. The local tier uses in-process PGlite; leave DATABASE_URL unset.
|
# Install dependencies. The local tier uses in-process PGlite; leave DATABASE_URL unset.
|
||||||
# The pnpm store defaults to $HOME/.local/share/pnpm/store. Override it without
|
|
||||||
# editing the checkout with NPM_CONFIG_STORE_DIR=$HOME/another-store if needed.
|
|
||||||
pnpm install
|
pnpm install
|
||||||
|
|
||||||
# Verify dependencies and generated state before running source-quality gates.
|
|
||||||
# Missing dependencies exit 42; stale/foreign apps/web/.next state exits 43.
|
|
||||||
# The web build certifies its exact standalone symlink manifest; added, removed,
|
|
||||||
# retargeted, or manifest-only-tampered generated links also exit 43. This detects
|
|
||||||
# accidental, independent, stale, and foreign-residue mutation—the class exposed by
|
|
||||||
# a five-month-stale .next that produced 19 phantom TS2307 errors.
|
|
||||||
# It does NOT defend against a same-UID actor that can rewrite both manifest and
|
|
||||||
# marker consistently (CWE-345). RM-59 tracks the required executor/spine-side
|
|
||||||
# trust anchor outside worktree authority.
|
|
||||||
pnpm preflight
|
|
||||||
|
|
||||||
# Optional local queue service only. This does not start PostgreSQL.
|
# Optional local queue service only. This does not start PostgreSQL.
|
||||||
docker compose up -d valkey
|
docker compose up -d valkey
|
||||||
|
|
||||||
@@ -243,7 +230,6 @@ Gateway start command until KBN-101-02 makes that state fail closed.
|
|||||||
### Quality Gates
|
### Quality Gates
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
pnpm preflight # Checkout/dependency/generated-state validation
|
|
||||||
pnpm typecheck # TypeScript type checking (all packages)
|
pnpm typecheck # TypeScript type checking (all packages)
|
||||||
pnpm lint # ESLint (all packages)
|
pnpm lint # ESLint (all packages)
|
||||||
pnpm test # Vitest (all packages)
|
pnpm test # Vitest (all packages)
|
||||||
|
|||||||
@@ -3,7 +3,7 @@
|
|||||||
"version": "0.0.2",
|
"version": "0.0.2",
|
||||||
"private": true,
|
"private": true,
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"build": "node ../../scripts/build-web.mjs",
|
"build": "next build",
|
||||||
"dev": "next dev",
|
"dev": "next dev",
|
||||||
"lint": "eslint src",
|
"lint": "eslint src",
|
||||||
"typecheck": "tsc --noEmit",
|
"typecheck": "tsc --noEmit",
|
||||||
|
|||||||
-53
@@ -437,59 +437,6 @@ Canonical checkpoint/handoff payloads, exactly-once connector receipts, concrete
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Governed fleet credential lifecycle (`mosaic cred`, #1045)
|
|
||||||
|
|
||||||
### Problem and objective
|
|
||||||
|
|
||||||
Fleet credentials are issued, wired, resolved, granted, validated, rotated, and revoked through unrelated scripts and manual provider actions. The split has produced silent fallback to a human/shared principal, missing runtime identity, cross-estate login resolution, incomplete permission checks, and non-auditable grants. The objective is one mechanical, durable, systemic `mosaic cred` path that decides both what a fleet seat may do and which provider identity it acts as.
|
|
||||||
|
|
||||||
### Scope
|
|
||||||
|
|
||||||
Phase 1 governs the existing per-identity Gitea token store and Tea login registration. VaultWarden is explicitly out for the agent tier and is not a backend option in this workstream. Certificate-backed identity and short-lived broker-issued credentials remain later phases behind the same caller contract.
|
|
||||||
|
|
||||||
### Normative requirements
|
|
||||||
|
|
||||||
1. `CRED-REQ-01`: The CLI SHALL expose `provision`, `wire`, `grant`, `get`, `validate`, `whoami`, `list`, `rotate`, `revoke`, and `audit`. Grant and validate SHALL conform to [`docs/credentials/GRANT-VALIDATE-CONTRACT.md`](./credentials/GRANT-VALIDATE-CONTRACT.md).
|
|
||||||
2. `CRED-REQ-02`: Every provider operation SHALL carry an explicit identity, estate, and host. Estate-to-host mapping SHALL come from strict non-secret configuration. Missing, ambiguous, inferred, or mismatched values SHALL refuse before credential resolution. Machine location SHALL grant no estate authority.
|
|
||||||
3. `CRED-REQ-03`: Token capability and Tea login identity are inseparable. Provisioning SHALL create/register both or neither. At mint time, delegated Basic authority SHALL read its provider principal back, the minted token object SHALL read back exact scopes, and both the token binding and exact host-bound Tea record SHALL contain that same minted credential. Rollback SHALL read provider, token-store, and Tea state back and may report complete only when the pre-operation state is established exactly; failed or unverified cleanup is `indeterminate`/`rollback-incomplete`. Provision, rotate, and revoke SHALL serialize the complete provider/token-store/Tea transaction between cooperating `mosaic cred` processes under one fixed estate/host/identity advisory lock that caller-selected state roots cannot bypass. That same-UID-replaceable filesystem lock and the file-store generation preconditions provide optimistic concurrency only for cooperating `mosaic cred` mutators; neither is an authorization boundary nor atomic CAS against a hostile same-UID filesystem writer. Provider authority is the authorization boundary. Hostile same-UID direct filesystem mutation is explicitly out of scope for this phase and deferred. Runtime `/user` identity remeasurement is required only when the seat token already carries `read:user`; least-privilege tokens SHALL NOT be widened to service the instrument. A wrong-host or absent Tea login SHALL never fall back to a host default.
|
|
||||||
4. `CRED-REQ-04`: Under fleet context, unset or unresolvable identity SHALL fail closed identically in the git credential helper and API resolver. Interactive shared credentials remain available only through an explicit non-fleet/shared selection; absence SHALL never select them.
|
|
||||||
5. `CRED-REQ-05`: Token scope, repository permission, and organization/team role are independent layers. Provision, grant, and validate SHALL report each separately from provider evidence. No layer substitutes for another, and a permission widening at one layer SHALL not be described as least privilege because another layer is narrow.
|
|
||||||
6. `CRED-REQ-06`: Gitea token creation SHALL use an explicit delegated provisioning step because this provider requires Basic Auth. Password-equivalent provisioning material SHALL enter only through a protected control-plane runtime credential channel, never caller bearer storage, argv, ordinary environment, logs, or output.
|
|
||||||
7. `CRED-REQ-07`: Permission grants SHALL be accepted only after provider read-back of the named direct collaborator permission or, for team grants, organization membership, team membership, team-repository attachment, and subject effective permission.
|
|
||||||
8. `CRED-REQ-08`: `validate --repo` SHALL compute a side-effect-free write differential by result. One immutable credential resolution SHALL bind the declared subject's provider identity read-back, repository permission, and authenticated Git receive-pack advertisement. A distinct provider-confirmed read-only principal and an unauthenticated caller SHALL both be refused receive-pack in the same evaluation. Principal/handle disagreement SHALL be indeterminate, never refusal or success. The check SHALL create no ref or artifact and SHALL state that it does not prove a particular update will pass branch protection, hooks, races, or content policy.
|
|
||||||
9. `CRED-REQ-09`: All provider HTTP calls SHALL share one transport implementation for URL/host binding, TLS, User-Agent, content-type, JSON-shape validation, redaction, and bounded responses. A 2xx status alone SHALL never establish identity, scope, permission, grant, or revocation.
|
|
||||||
10. `CRED-REQ-10`: Operations SHALL return stable machine outcomes `ok`, `refused`, `error`, or `indeterminate`. Policy refusal, local operational failure, and incomplete/inconsistent evidence SHALL remain distinguishable. `provider-unavailable`, `identity-not-measured`, `identity-not-visible`, `identity-not-found`, and `credential-rejected` SHALL remain distinct diagnoses. Validation SHALL report capability from an in-scope probe separately from identity measurement. `/user` 401 is `credential-rejected`/refused; `/user` 403/404 plus successful in-scope capability is `identity-not-measured`, never a dead credential. A returned login mismatch is a binding refusal. No implemented operation may emit `identity-not-found`; that diagnosis requires a separately approved visibility-authorized inventory capability. Security callers SHALL fail closed on every outcome except `ok` without relabelling indeterminate evidence as a denial.
|
|
||||||
11. `CRED-REQ-11`: No command SHALL print a token, password, authorization header, fingerprint, partial secret, or secret-bearing provider body, including error paths. Secrets SHALL not appear in process argv. Phase-1 file storage SHALL remain private, symlink-safe, regular-file-only, test-overridable, and compatible with existing managed token consumers.
|
|
||||||
12. `CRED-REQ-12`: Every issue, provision, grant, rotate, revoke, and credential access SHALL be journaled with actor, subject, estate, host, repo/scope, operation, time, and non-secret provider evidence. The durable journal SHALL be opened and fsynced before the first mutation, append each mutation/read-back, and seal only after acceptance. Credential access SHALL durably record issuance start immediately before protected-fd disclosure; any partial write or post-write audit failure SHALL remain visibly `indeterminate` with mutation `unknown` or `applied`, never be relabelled as a pre-disclosure destination error. A journal seal SHALL remain staged and recovery-visible until its final rename and directory durability succeed; a final seal-commit fault SHALL revert to open classification and cannot leave an acceptance-bearing sealed-success object. Journal/audit write failure SHALL be fatal; an unsealed journal means incomplete/indeterminate work.
|
|
||||||
13. `CRED-REQ-13`: `wire` SHALL be idempotent and SHALL update the exact roster-derived `<identity>.env.generated` fleet projection so both identity axes survive restart. It SHALL authenticate the same explicit seat through a protected delegated credential channel and provider identity read-back before mutation, refuse actor/identity/path/roster disagreements, and never authorize from the shared Unix account. It SHALL not write linked-worktree git configuration or silently infer identity from pane/session names.
|
|
||||||
14. `CRED-REQ-14`: Rotate SHALL verify the new credential/provider identity before retiring the old credential. Revoke SHALL read back provider revocation/denial and preserve an auditable recovery record. A local file deletion or successful HTTP status is not revocation evidence.
|
|
||||||
15. `CRED-REQ-15`: Before the #1044 fail-closed resolver change is eligible to land, `mosaic cred validate` SHALL resolve every live HOMELAB mosaic-lane seat from `git.mosaicstack.dev` by provider read-back. Any unresolved seat HOLDS the fail-closed change; the implementation may not widen or restore shared fallback.
|
|
||||||
16. `CRED-REQ-16`: Provider claims SHALL record the estate, instance, endpoint, asserted content type, and decision-relevant object fields. Append-only provider status history SHALL be reduced to latest-per-context where current state is required.
|
|
||||||
|
|
||||||
### Acceptance criteria
|
|
||||||
|
|
||||||
1. `AC-CRED-01`: Red-first tests prove unset identity, missing token, wrong estate, wrong host, wrong Tea login, and out-of-estate identity produce the same structured refusal class/reason on git and API resolution, with no shared credential read and no provider mutation.
|
|
||||||
2. `AC-CRED-02`: Provisioning against a provider fixture proves Basic Auth is required, bearer-only token minting is refused, both identity axes are established together or every completed provider/token-store/Tea change is compensated and read back to the exact pre-operation state, and exact token scopes are read back from the provider token object. Injected Tea cleanup failure returns `indeterminate`/`rollback-incomplete` and cannot claim mutation `none`; no cross-system atomic commit is claimed. A second cooperating same-identity transaction is refused across caller-selected state roots. A code-level security-model assertion pins that advisory flock as cooperative serialization, provider authority as the authorization boundary, generation preconditions as optimistic protection for cooperating mutators rather than atomic CAS, and hostile same-UID filesystem mutation as explicitly deferred.
|
|
||||||
3. `AC-CRED-03`: Direct and team grant tests read all applicable permission layers back from provider objects. Deliberately divergent token scope and repo grant cases cannot return `ok`; organization/team membership and team-repository attachment are additionally acceptance-bearing for team grants. A direct collaborator grant reports organization membership but does not require it, because direct collaborator permission and organization membership are intentionally independent provider layers.
|
|
||||||
4. `AC-CRED-04`: Validate proves provider identity and the write differential on the intended repository through one credential handle. The subject is accepted, a separately resolved provider-confirmed read-only principal is refused, and an unauthenticated caller is refused in the same invocation. A shared/wrong-principal fallback, independent subject lookups, invalid read-only control, evidence disagreement, unexpected content type/shape, or provider outage returns `indeterminate`, never success or policy refusal. Runtime exact scope is reported independently as `not-measured` when the current seat credential is not authorized to read its provider token object; NOT-MEASURED is neither pass nor failure and does not erase confirmed repository capability. Exact scope is acceptance-bearing at provision/rotate time, where delegated mint authority can read the token object.
|
|
||||||
5. `AC-CRED-05`: Audit/journal fault injection before and after each mutation proves write failure is fatal, open journals remain visible/recoverable, and no operation can claim success without a sealed journal and provider read-back. Protected credential output fault injection covers partial write, post-write append, and seal failure and preserves possibly-issued/applied truth in both DTO and durable journal.
|
|
||||||
6. `AC-CRED-06`: Adversarial output/argv tests seed distinct secret values through success, refusal, provider-error, parser-error, rollback, rotate, and revoke paths and find zero secret/partial/fingerprint occurrences in stdout, stderr, logs, audit, and child argv.
|
|
||||||
7. `AC-CRED-07`: Storage tests reject symlinked roots/files, non-regular files, permissive modes, traversal, stale generations from cooperating concurrent mutators, and production-store leakage into fixture tests. They do not claim atomic exclusion against hostile same-UID direct filesystem mutation. Existing canonical per-seat token consumers continue through the governed adapter.
|
|
||||||
8. `AC-CRED-08`: `wire` repeated twice is byte-idempotent, produces both required identity-axis values in the exact roster-derived generated environment, survives a fresh fleet projection/restart path, and leaves shared linked-worktree git config untouched. An unauthenticated caller, a caller authenticated as another seat, a caller-selected filename, or a file whose roster identity differs is refused before mutation.
|
|
||||||
9. `AC-CRED-09`: Rotate validates new identity/capabilities before retiring old material; injected failure leaves the previously valid credential usable and the journal open. Revoke is accepted only when provider read-back proves the credential no longer authenticates/authorizes.
|
|
||||||
10. `AC-CRED-10`: Every live HOMELAB mosaic-lane seat resolves from `git.mosaicstack.dev` before the #1044 fallback closes. The evidence names the complete seat population, provider endpoint/content type, and unresolved count; non-zero unresolved count blocks landing.
|
|
||||||
11. `AC-CRED-11`: Baseline typecheck/lint/format/tests, focused auth/permission abuse cases, independent code review, independent security review, and terminal-green HOMELAB Woodpecker CI pass on the exact reviewed head.
|
|
||||||
12. `AC-CRED-12`: Interim delivery to `next` is reported only as **believed-fixed, pending validation AND pending promotion to `main`**. Issues stay open until #1037 promotes the work and constitutional completion is independently verified.
|
|
||||||
|
|
||||||
### Constraints and dependencies
|
|
||||||
|
|
||||||
- C1 install-state-machine work merges first. This lane then re-takes base/head-bound measurements without redesigning or reworking code.
|
|
||||||
- MB-BRAIN-01 (#1051) consumes the grant/validate contract and may proceed against the published interface before implementation merge.
|
|
||||||
- The branch-model compatibility question for `next` remains escalated. No `done` claim, issue closure, or self-initiated promotion is permitted at the `next` checkpoint.
|
|
||||||
- `ASSUMPTION:` Phase-1 Gitea support is the only provider implementation in this slice; provider-neutral types preserve later adapters without pretending unimplemented providers are supported.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
|
|
||||||
### High-Level System Diagram
|
### High-Level System Diagram
|
||||||
|
|||||||
@@ -1,204 +0,0 @@
|
|||||||
# `mosaic cred grant` / `validate` caller contract v1.5
|
|
||||||
|
|
||||||
**Status:** early binding contract for MC-CRED-01 and MB-BRAIN-01. v1.3's anonymous absence classifier was withdrawn as unsound for private users. v1.4 adopted subject-credential validation without admin visibility. v1.5 separates in-scope capability from identity measurement so correctly least-privileged tokens are not widened to service the instrument. This contract may evolve before implementation merge; incompatible changes require an explicit change notice.
|
|
||||||
|
|
||||||
## Security model
|
|
||||||
|
|
||||||
- Every call carries both `--estate` and `--host`. The configured estate-to-host mapping must match exactly. Host inference, host-adjacent fallback, and cross-estate resolution are forbidden.
|
|
||||||
- `<identity>` is always explicit. The CLI never substitutes a pane, roster, login, Unix user, or other plausible ambient identity.
|
|
||||||
- The identity token and the host-bound Tea login are one provisioning unit. Minting authority reads the principal back when the invariant is created and records that binding with the token registration. Runtime validation re-measures identity only when the token already holds `read:user`; it never widens scopes to make the instrument green.
|
|
||||||
- Grant authority is broker/delegated-provisioner material. It is never supplied as a CLI value, environment value, or bearer token readable by the requesting agent. The broker obtains it from its protected runtime credential channel.
|
|
||||||
- Commands never print token, password, authorization header, fingerprint, partial secret, or secret-bearing error text. Structured evidence contains provider object fields and endpoint metadata only.
|
|
||||||
- Every operation opens and fsyncs a durable journal before the first mutation. Journal/audit write failure is fatal. A grant is successful only after provider read-back and a sealed journal.
|
|
||||||
|
|
||||||
## Commands
|
|
||||||
|
|
||||||
```text
|
|
||||||
mosaic cred grant <identity> \
|
|
||||||
--estate <estate> \
|
|
||||||
--host <host> \
|
|
||||||
--repo <owner/repo> \
|
|
||||||
--permission <read|write|admin> \
|
|
||||||
[--via <collaborator|team>] \
|
|
||||||
[--team <team>] \
|
|
||||||
[--read-only-control <identity>] \
|
|
||||||
[--json]
|
|
||||||
|
|
||||||
mosaic cred validate <identity> \
|
|
||||||
--estate <estate> \
|
|
||||||
--host <host> \
|
|
||||||
[--repo <owner/repo>] \
|
|
||||||
[--require <read|write|admin>] \
|
|
||||||
[--read-only-control <identity>] \
|
|
||||||
[--json]
|
|
||||||
```
|
|
||||||
|
|
||||||
Rules:
|
|
||||||
|
|
||||||
- `--via collaborator` is the default. It grants a direct repository permission and still reports the organization-membership layer.
|
|
||||||
- `--via team` requires `--team`; `--team` with collaborator mode is invalid.
|
|
||||||
- `validate --repo` reports two independent axes: capability from an in-scope repository probe, and identity binding from `/user` only when authorized. Capability may be `confirmed` while identity is `not-measured`; NOT-MEASURED is neither pass nor failure.
|
|
||||||
- Write validation requires a distinct known-read-only control identity, supplied explicitly or configured in the declared estate. The control identity and its read-only permission are read back from the provider on every invocation; the configured name alone is not evidence.
|
|
||||||
- `grant` invokes the same validation after mutation. HTTP 2xx and process exit status are never acceptance evidence.
|
|
||||||
|
|
||||||
## Machine result
|
|
||||||
|
|
||||||
`--json` writes exactly one non-secret JSON object to stdout. Human diagnostics go to stderr. Callers must decide from `outcome`, never by parsing prose.
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"schemaVersion": 1,
|
|
||||||
"operation": "grant",
|
|
||||||
"outcome": "ok",
|
|
||||||
"exitCode": 0,
|
|
||||||
"retryable": false,
|
|
||||||
"subject": {
|
|
||||||
"identity": "seat-name",
|
|
||||||
"estate": "estate-name",
|
|
||||||
"host": "git.example.invalid",
|
|
||||||
"repo": "owner/repo"
|
|
||||||
},
|
|
||||||
"mutation": "applied",
|
|
||||||
"reason": {
|
|
||||||
"code": "grant-verified",
|
|
||||||
"message": "Grant matched all provider read-backs."
|
|
||||||
},
|
|
||||||
"evidence": {
|
|
||||||
"providerIdentity": {
|
|
||||||
"login": "seat-name",
|
|
||||||
"endpoint": "GET /api/v1/user",
|
|
||||||
"contentType": "application/json"
|
|
||||||
},
|
|
||||||
"tokenCapabilities": {
|
|
||||||
"state": "not-measured",
|
|
||||||
"scopes": [],
|
|
||||||
"source": "runtime-not-authorized"
|
|
||||||
},
|
|
||||||
"repositoryPermission": {
|
|
||||||
"requested": "write",
|
|
||||||
"effective": "write",
|
|
||||||
"endpoint": "GET /api/v1/repos/owner/repo",
|
|
||||||
"contentType": "application/json"
|
|
||||||
},
|
|
||||||
"organizationMembership": {
|
|
||||||
"state": "present"
|
|
||||||
},
|
|
||||||
"teamMembership": {
|
|
||||||
"state": "not-applicable"
|
|
||||||
},
|
|
||||||
"writeDifferential": {
|
|
||||||
"state": "can-write",
|
|
||||||
"credentialBinding": "same-resolution",
|
|
||||||
"transportPrincipal": "seat-name",
|
|
||||||
"authenticatedReceivePack": "advertised",
|
|
||||||
"readOnlyControl": {
|
|
||||||
"identity": "read-only-control",
|
|
||||||
"providerPermission": "read",
|
|
||||||
"receivePack": "refused"
|
|
||||||
},
|
|
||||||
"unauthenticatedReceivePack": "refused",
|
|
||||||
"artifactCreated": false,
|
|
||||||
"proves": "One immutable credential resolution authenticated both the subject identity read-back and write transport; a provider-confirmed read-only principal and an unauthenticated caller were both refused.",
|
|
||||||
"doesNotProve": "A particular ref update will pass branch protection, hooks, races, or content policy."
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"audit": {
|
|
||||||
"journalId": "opaque-id",
|
|
||||||
"state": "sealed"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
Fields may be `null` only when their enclosing evidence state explains why. Missing decision-relevant fields make the result `indeterminate`, never `ok`.
|
|
||||||
|
|
||||||
## Terminal classes
|
|
||||||
|
|
||||||
| Outcome | Exit | Meaning | Mutation guarantee | Caller action |
|
|
||||||
| --------------- | ---: | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
|
|
||||||
| `ok` | `0` | Requested property was established from provider objects and all required layers agree. | `validate`: `none`; `grant`: `applied` and read back. | Continue. |
|
|
||||||
| `refused` | `10` | A complete, authoritative policy/access decision denied the request. Examples: estate-host mismatch, missing explicit identity, provider identity mismatch, explicit permission denial, or cross-estate subject. | `none`; refusal occurs before mutation. | Treat as a stable denial. Do not retry without changing authority/configuration. |
|
|
||||||
| `error` | `20` | The command contract or local control failed before an access verdict. Examples: invalid arguments, malformed estate registry, insecure credential path, journal cannot be opened/fsynced, or internal invariant failure. | `none` unless `mutation` explicitly says `unknown`; `unknown` is never success. | Repair the tool/configuration. Do not reinterpret as access denial. |
|
|
||||||
| `indeterminate` | `30` | The requested security property could not be evaluated completely or evidence disagreed. Examples: provider unavailable, wrong content type/shape, permission and receive-pack disagreement, missing post-grant read-back, or unknown mutation acknowledgement. Runtime scope `not-measured` remains a separately reported axis and is neither pass nor failure. | `none`, `applied`, or `unknown`, stated explicitly. Never infer. | Fail closed at the calling gate. Investigate/re-evaluate; do not label the subject refused. |
|
|
||||||
|
|
||||||
Parsing/usage errors emitted by Commander remain exit `2` and do not produce a broker verdict. Callers should treat them as integration defects, not access decisions.
|
|
||||||
|
|
||||||
## Refusal object
|
|
||||||
|
|
||||||
A refusal is intentionally recognizable without prose:
|
|
||||||
|
|
||||||
```json
|
|
||||||
{
|
|
||||||
"schemaVersion": 1,
|
|
||||||
"operation": "validate",
|
|
||||||
"outcome": "refused",
|
|
||||||
"exitCode": 10,
|
|
||||||
"retryable": false,
|
|
||||||
"subject": {
|
|
||||||
"identity": "external-seat",
|
|
||||||
"estate": "homelab",
|
|
||||||
"host": "git.example.invalid",
|
|
||||||
"repo": "owner/repo"
|
|
||||||
},
|
|
||||||
"mutation": "none",
|
|
||||||
"reason": {
|
|
||||||
"code": "no-token-for-identity",
|
|
||||||
"message": "The explicit identity has no credential in the declared estate."
|
|
||||||
},
|
|
||||||
"evidence": {
|
|
||||||
"providerIdentity": null,
|
|
||||||
"tokenCapabilities": {
|
|
||||||
"state": "not-measured",
|
|
||||||
"scopes": [],
|
|
||||||
"source": "runtime-not-authorized"
|
|
||||||
},
|
|
||||||
"repositoryPermission": null,
|
|
||||||
"organizationMembership": null,
|
|
||||||
"teamMembership": null,
|
|
||||||
"writeDifferential": null
|
|
||||||
},
|
|
||||||
"audit": {
|
|
||||||
"journalId": "opaque-id",
|
|
||||||
"state": "sealed"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
```
|
|
||||||
|
|
||||||
The git credential helper and API resolver must map the same subject/estate/host failure to the same `reason.code` and terminal class. MB-BRAIN-01 may assert this parity. A caller does not need to know which resolver path was used.
|
|
||||||
|
|
||||||
## Required reason codes
|
|
||||||
|
|
||||||
Stable v1 codes:
|
|
||||||
|
|
||||||
- refusal: `identity-required`, `estate-required`, `estate-host-mismatch`, `cross-estate-resolution`, `no-token-for-identity`, `tea-login-missing`, `tea-login-host-mismatch`, `provider-identity-mismatch`, `credential-rejected`, `permission-denied`, `organization-membership-required`, `team-membership-required`
|
|
||||||
- error: `invalid-input`, `estate-registry-invalid`, `insecure-credential-source`, `journal-unavailable`, `internal-invariant`
|
|
||||||
- indeterminate: `provider-unavailable`, `identity-not-visible`, `identity-not-measured`, `identity-not-found`, `unexpected-content-type`, `unexpected-provider-shape`, `scope-not-evaluable`, `permission-evidence-disagrees`, `transport-principal-mismatch`, `read-only-control-invalid`, `readback-missing`, `mutation-state-unknown`, `concurrent-mutation`, `mutation-lock-unavailable`, `mutation-lock-release-failed`, `team-scope-changed-during-grant`, `wire-audit-incomplete`
|
|
||||||
|
|
||||||
`provider-unavailable` means no usable provider answer was available. `identity-not-measured` means `/user` was scope-forbidden while an in-scope repository probe confirmed the credential capability; it is `indeterminate` only for the identity axis and must not be represented as a dead credential. `identity-not-visible` and `identity-not-found` are reserved for the unimplemented external inventory capability. `credential-rejected` means the provider rejected the credential itself (Gitea 401), which is a stable `refused` outcome. A 403 on `/user` is not credential rejection when an in-scope probe succeeds.
|
|
||||||
|
|
||||||
No anonymous or visibility-unprivileged 404 is admissible evidence of absence. `identity-not-found` requires, in the same invocation: (1) the visibility credential's own `/user` object read back as the configured authority with provider-admin visibility; (2) target lookup performed with that same authority; (3) a known-present PRIVATE control returning JSON 200 with matching login and `visibility=private`; and (4) a generated absent negative control returning JSON 404 under that same authority. Missing authority or any non-discriminating control yields `identity-not-visible`, never absence. A public positive control cannot certify private subjects.
|
|
||||||
|
|
||||||
No currently implemented operation may emit `identity-not-found`: the required governed inventory capability was deliberately declined and runtime validation must not acquire standing admin visibility. For `validate`, `/user` 401 means `credential-rejected`; `/user` 403/404 triggers the in-scope capability probe and, when that succeeds, identity is `identity-not-measured`; JSON 200 with a mismatched login is a binding refusal. A future inventory operation must meet every precondition above and receive an explicit privilege decision before making `identity-not-found` reachable.
|
|
||||||
|
|
||||||
Unknown future reason codes must still carry one of the four stable `outcome` values.
|
|
||||||
|
|
||||||
## Side-effect-free write differential
|
|
||||||
|
|
||||||
For Gitea v1, `validate --repo` resolves the subject credential exactly once into an immutable in-memory credential handle. The provider `/user` read-back, authenticated repository object, and Git smart-HTTP `git-receive-pack` advertisement all consume that same handle; callers may not perform independent lookups for those steps. The command also probes a separately resolved, provider-confirmed read-only control principal and repeats the request unauthenticated.
|
|
||||||
|
|
||||||
`can-write` requires all of the following:
|
|
||||||
|
|
||||||
1. provider `/user` login obtained with the subject credential handle equals `<identity>`;
|
|
||||||
2. authenticated repository object obtained with that same handle reports write-capable permission;
|
|
||||||
3. receive-pack obtained with that same handle returns the exact advertisement content type and protocol preamble;
|
|
||||||
4. the transport evidence records the same declared principal as the identity read-back; any handle/principal seam disagreement is `transport-principal-mismatch` and therefore `indeterminate`, never refused;
|
|
||||||
5. a distinct known-read-only credential resolves to its declared control identity, its provider repository object reports no write permission, and receive-pack is refused;
|
|
||||||
6. the unauthenticated control is refused and does not return a receive-pack advertisement;
|
|
||||||
7. estate, host, and repository in every request equal the declared subject.
|
|
||||||
|
|
||||||
The read-only control varies the mechanism under accusation: principal selection. The unauthenticated arm remains as a separate control proving authentication is required; it cannot establish which principal authenticated the subject probe. A missing, write-capable, identity-mismatched, or otherwise invalid read-only control makes the result `indeterminate`.
|
|
||||||
|
|
||||||
No ref is updated and no repository artifact is created. This proves that the declared subject credential—not merely some authenticated credential—can enter the write transport for that repository, while a provider-confirmed read-only principal and an unauthenticated caller cannot. It does not prove any specific branch update would survive branch protection, hooks, concurrent changes, or content policy.
|
|
||||||
|
|
||||||
## Grant read-back
|
|
||||||
|
|
||||||
A collaborator grant is accepted only when the provider returns the named collaborator permission and the subject credential independently reads the repository with matching effective permission. A team grant uses a same-UID-replaceable advisory lock to serialize cooperating `mosaic cred` mutations per provider team; this is optimistic coordination, not an authorization boundary or atomic CAS against direct filesystem mutation. Provider authority remains the authorization boundary. While holding that cooperative lock, the grant enumerates the team's complete repository attachment set both before and after mutation. It refuses before mutation when the team is already attached outside the one explicitly requested repository (`team-scope-exceeds-request`). If the post-mutation set is not exactly the requested repository, it returns `indeterminate` (`team-scope-changed-during-grant`) and compensates only state proven absent before the locked invocation: a newly introduced subject membership and/or requested repository attachment. Both compensations require provider absence read-back and are journaled; this is explicit all-or-verified-compensation behavior, not a cross-system atomic commit, and the operation never reports success from the stale pre-check. The grant then requires provider read-back of organization membership, team membership, team repository attachment, and effective subject permission. Token capability, repository permission, and organization/team role are reported as separate layers; no layer substitutes for another.
|
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
# RM-02 / PR #1030 — PRE-REGISTERED RE-REVIEW: the merge-base anchor round
|
||||||
|
|
||||||
|
**Subject head (exact):** `fbb61912981abb250d289ec7aafd4316db6fdb11`
|
||||||
|
**Supersedes:** the second NO-GO at `32b490a7` (D-45/D-46/D-47). That verdict is VOID.
|
||||||
|
**Registered by:** `mos-remediation` **before any reviewer read the diff.** **Reviewer:** `rev-974`.
|
||||||
|
|
||||||
|
## What the orchestrator already reproduced (do not re-spend the review here)
|
||||||
|
|
||||||
|
- Derived boundary `f4fd5967` **equals** an independently computed `git merge-base HEAD origin/main`.
|
||||||
|
- Emptying `criteria`/`gates`/`proseClaims`/`compatibilityScenarios` now fails with
|
||||||
|
_"population must be non-empty and anchored before evaluation"_.
|
||||||
|
- The both-directions bootstrap statement is present in `gate-history.mjs` with the Builds 1–2 residual.
|
||||||
|
|
||||||
|
## A — attack the ANCHOR (highest value)
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **A1** | `targetRef` is the literal `refs/remotes/origin/main`. **Who controls that ref in the environment where the gate runs?** Can a PR author influence it — a `remote.origin.url` rewrite, a crafted `refs/remotes/origin/main` in their own clone, a push to a fork's `main`? If the gate trusts a locally-writable ref, the anchor moved from the manifest into git config. |
|
||||||
|
| **A2** | **Absent/stale target:** if `refs/remotes/origin/main` is missing, stale, or the fetch is shallow, does it fail CLOSED (line 57 suggests it does) or silently derive a narrower range? |
|
||||||
|
| **A3** | **Delayed introduction — the round-2 attack, re-run.** Commit a gate change BEFORE adding the manifest. Does it now stay in range and fail the own-tree read? |
|
||||||
|
| **A4** | **Branch from an old main:** branch from a point far behind `origin/main`, so merge-base is old. Does the range widen correctly (safe) or include unrelated main commits that cannot carry manifests (a new false-red)? Over-inclusion is the natural failure mode of this fix. |
|
||||||
|
| **A5** | Is the **bootstrap residual** recorded as a **tracked dependency on Builds 1–2**, not prose? (D-19's third mandatory move.) |
|
||||||
|
|
||||||
|
## P — the non-empty/anchored precondition
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **P1** | Does the precondition run **before** every quantified check, on **every** path — or only the ones the author enumerated? Find a quantified check that still runs before its precondition. |
|
||||||
|
| **P2** | **Seven required gate IDs anchored to canonical sources** — can that anchor list itself be emptied, shrunk, or pointed elsewhere? An anchor list the author edits is D-45 again, one level in. |
|
||||||
|
| **P3** | The author reports finding and REMOVING a **production CLI fixture-profile bypass** in their own pre-commit review. **Verify it is gone from the shipped CLI path**, that the remaining relaxation is test-support only and non-executable in production, and that the CLI rejection is tested. This was self-disclosed — confirm it independently. |
|
||||||
|
|
||||||
|
## Q — clauses quantified over the population (D-47)
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **Q1** | `gateRefs` **exactly spans** every registered gate. Can a gate be added WITHOUT a corresponding ref — i.e. does adding a gate to the population escape the clause? |
|
||||||
|
| **Q2** | Deleting `gateRefs`, or shrinking gates and refs **together**, must fail. Shrink-together is the D-46 shape; verify it is a genuine control and not a regression guard mislabelled. |
|
||||||
|
| **Q3** | Do the population controls **iterate all seven gates** and mutate evidence-subject and comparison-type **per gate**, or only a representative one? |
|
||||||
|
| **Q4** | Honest labelling: author claims delayed-introduction, empty-populations, fixture-profile bypass and removable gateRefs as **genuine red-first**, and shrink-together/exact-span as **regression guards**. Verify each claim against pre-fix code (D-8). |
|
||||||
|
|
||||||
|
## C — head, CI, integrity
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **C1** | Head `fbb61912` on git and provider; `Closes #1029` present. |
|
||||||
|
| **C2** | Exact-head CI terminal-green, full `-f json`, counts stated incl. `clone`; machine-checked with `verify-terminal-green.py --expect-commit fbb61912981abb250d289ec7aafd4316db6fdb11`. |
|
||||||
|
| **C3** | Nothing weakened: `32b490a7` → `fbb61912` removes/relaxes no existing case, test, or assertion. |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Verdict bound to `fbb61912981abb250d289ec7aafd4316db6fdb11`, evidence enumerated, posted durably under
|
||||||
|
your own identity. If a check is unrunnable, **say so**.
|
||||||
|
|
||||||
|
**A1 and P2 are the ones I most want answered** — both ask whether the fix moved the author's control
|
||||||
|
point again rather than removing it, which is now the mission's named first-class principle and has
|
||||||
|
recurred three times. **Attack outside this set.**
|
||||||
|
|
||||||
|
**No one dispatching this review may state a conclusion on an open check (D-39).**
|
||||||
@@ -0,0 +1,67 @@
|
|||||||
|
# RM-02 / PR #1030 — PRE-REGISTERED RE-REVIEW: the four-blocker hardening pass
|
||||||
|
|
||||||
|
**Subject head (exact):** `32b490a712a5e8e77f13c40c60099b51feb38994`
|
||||||
|
**Supersedes:** the NO-GO at `83d2ecb2` (D-44, four silent-defeat paths). That verdict is VOID.
|
||||||
|
**Registered by:** `mos-remediation` **before any reviewer read the diff.** **Reviewer:** `rev-974`.
|
||||||
|
|
||||||
|
## Framing — attack the FIX, not the original bug
|
||||||
|
|
||||||
|
Every round on this mission, **the remediation introduced the next hole**: the commit-binding fix
|
||||||
|
shipped a type confusion; the type-strict fix was clean but the registry around it had four defeats.
|
||||||
|
So the highest-value checks here are **not** "was each blocker fixed" — the orchestrator already
|
||||||
|
reproduced three of the four attacks as dead — but **"is the NEW mechanism itself defeatable?"**
|
||||||
|
|
||||||
|
Blocker 1's fix replaced an author-settable field with a **derivation**. A derivation has inputs. **The
|
||||||
|
question is who controls them.**
|
||||||
|
|
||||||
|
## H — the new derivation (highest value)
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **H1** | `deriveHistoryBoundary` = parent of the first first-parent commit introducing `gates/gates.manifest.json`. **Are its inputs author-controlled?** Can a PR author influence the derived value by adding, moving, renaming, deleting-and-recreating, or symlinking that path — or by adding a SECOND manifest earlier in history? If the derivation is gameable, blocker 1 is not fixed, only relocated. |
|
||||||
|
| **H2** | **First-parent traversal:** what happens on a merge commit, an octopus merge, a squash, a rebase that reorders, or a branch where the introducing commit is not on the first-parent chain? Does the boundary silently move, or fail closed? |
|
||||||
|
| **H3** | **Shallow/partial clone:** the branch previously needed an unshallow fix (`e8959975` "unshallow gate replay history"). If history is shallow, does the derivation fail CLOSED or silently derive a wrong/empty boundary? |
|
||||||
|
| **H4** | **Path deletion:** if `gates/gates.manifest.json` is absent at HEAD, or was deleted and re-added, what is derived? Fail closed, or a boundary that excludes the deletion window? |
|
||||||
|
| **H5** | Are the **three registered seam controls (HEAD, HEAD^, introduction) genuinely RED-FIRST** — do they fail against the PRE-fix code for their own stated reason? A control that was always green is a regression guard, not a must-fail control (D-8). |
|
||||||
|
|
||||||
|
## S — the recursive schema closure
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **S1** | **Is closure COMPLETE or enumerated?** The author lists the objects they closed. Find one they did **not** — any nested object anywhere in the manifest — and inject an unknown key there. If it is accepted, the fix covers instances, not the class. |
|
||||||
|
| **S2** | **Wrong-type, not just unknown-key:** `outputPattern` as a number/array/object/null rather than misspelled. Does the closed schema type-check values, or only key names? |
|
||||||
|
| **S3** | **Empty/degenerate values:** `outputPattern: ""` — does an empty regex match everything and silently neuter the assertion the same way a typo did? The author claims an empty-pattern control; verify it is bound. |
|
||||||
|
| **S4** | Confirm the registered typo/wrong-type/empty-pattern controls are **genuine red-first** against pre-fix code, and that anything labelled a regression guard is honestly labelled as one. |
|
||||||
|
|
||||||
|
## E — provider evidence (blocker 4)
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **E1** | Global validation runs **before** per-commit filtering **on every path**, including the HEAD-only path the author calls out. Is there any code path that reaches per-commit assessment without it? |
|
||||||
|
| **E2** | **Duplicate identity by another key:** the fix makes pipeline NUMBER globally unique. Can two records still collide on a different identity dimension — same commit + different number, same URL, same step-id — and certify the wrong subject? |
|
||||||
|
| **E3** | "Exactly one gate-verify step per record" — what if a record has zero, or two with different outcomes? Fail closed? |
|
||||||
|
|
||||||
|
## C — clauses, integrity, CI
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **C1** | The three new criteria (`RM02-EVIDENCE-SUBJECT-BINDING`, `RM02-TYPE-STRICT-SCHEMA`, `RM02-HISTORY-BOUNDARY`) are **checked criteria with bidirectionally bound cases**, not prose. Orchestrator observed caseRefs 1 / 3 / 3 — verify the bindings actually run and can fail. |
|
||||||
|
| **C2** | **B1/B2 satisfied in substance:** does `RM02-EVIDENCE-SUBJECT-BINDING` express D-38 generally ("does this gate bind its evidence to its subject?") or only the one pipeline-number instance? Same for D-40 vs the one typo instance. **A clause that only covers its originating instance is not a clause.** |
|
||||||
|
| **C3** | **Nothing weakened:** diff `83d2ecb2` → `32b490a7` removes/relaxes no existing case, test, or assertion. |
|
||||||
|
| **C4** | Exact-head CI terminal-green, full `-f json`, counts stated **including `clone`**; machine-checked with `verify-terminal-green.py --expect-commit 32b490a712a5e8e77f13c40c60099b51feb38994`. |
|
||||||
|
| **C5** | `Closes #1029` still present (D-38c). |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Verdict bound to `32b490a712a5e8e77f13c40c60099b51feb38994`, evidence enumerated, posted durably under
|
||||||
|
your own identity. If a check is unrunnable, **say so** — never substitute a passing variant.
|
||||||
|
|
||||||
|
**H1 and S1 are the two I most want answered**, because they ask whether each fix closed a **class** or
|
||||||
|
an **instance**. Attack outside this set: four of the last five blockers on this PR came from mutating
|
||||||
|
something nobody had registered.
|
||||||
|
|
||||||
|
**Environment note:** `pnpm gate:verify` fails on `checkout-preflight` with outcome 42 (bubblewrap
|
||||||
|
class) in at least one worktree. If you hit it, report it as an environment limitation — do not treat it
|
||||||
|
as a finding, and do not let it mask one.
|
||||||
|
|
||||||
|
**No one dispatching this review may state a conclusion on an open check (D-39).**
|
||||||
@@ -0,0 +1,59 @@
|
|||||||
|
# RM-02 / PR #1030 — PRE-REGISTERED RE-REVIEW: honest narrowing + (d)-strict
|
||||||
|
|
||||||
|
**Subject head (exact):** `e910a45ab3578a9c77ad3eeaa52b31b72611f6c6`
|
||||||
|
**Supersedes:** the third NO-GO at `fbb61912` (D-45/D-46/D-47) and the D-52 stop. Those are VOID.
|
||||||
|
**Registered by:** `mos-remediation` before any reviewer read the diff. **Reviewer:** `rev-974`.
|
||||||
|
|
||||||
|
## Already reproduced by the orchestrator (do not re-spend here)
|
||||||
|
|
||||||
|
- The required narrowing sentence is **verbatim** in `gates/required-gates.baseline.json` and in
|
||||||
|
`scripts/gate-inventory-claim-control.mjs`: _"Detects accidental and incompetent inventory drift
|
||||||
|
within a checkout; does NOT survive an adversary who rewrites baseline, manifest, and verifier
|
||||||
|
consistently — that guarantee requires RM-60's external boundary."_
|
||||||
|
- **The overclaim control FIRES**: clean ⇒ exit 0; injecting "protected, independently anchored" into
|
||||||
|
the baseline purpose ⇒ **exit 84**, `INVENTORY_CLAIM_OVERSTATED`.
|
||||||
|
- CI #2201 at the exact head, 10/10 incl. `clone`; machine check bound, `exempted_steps 0`, no anomalies.
|
||||||
|
|
||||||
|
## N — the narrowing (D-52's ruling is the wording)
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **N1** | ★ Is the narrowed claim **honest EVERYWHERE**, or only where the control looks? Find any place — docs, comments, observations, manifest prose, CLI output — that still implies the baseline is protected or independently anchored. **The control only checks the files it checks.** |
|
||||||
|
| **N2** | ★ Can the **overclaim control itself** be defeated? It is PR-controlled like everything else. Weaken/skip/reword it so an overstatement passes. If it can be trivially neutered, D-52 is re-armed one level down — the exact recursion this PR keeps producing. |
|
||||||
|
| **N3** | Does the control detect **semantic** overclaim or only the literal strings it greps? An artifact could assert protection in different words and pass. |
|
||||||
|
| **N4** | Is the narrowed claim **TRUE**? Verify the baseline genuinely catches accidental/inconsistent drift — not just that it says so. A narrowed claim that is still overstated is D-48 again. |
|
||||||
|
|
||||||
|
## H — (d)-strict history removal
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **H1** | Is the verifier **structurally incapable** of reporting history-provenance-verified, or merely not currently doing so? The manifest says "structurally incapable" — test the claim. |
|
||||||
|
| **H2** | ★ **TRAP 1 re-check:** nothing emits the unverifiable state as an OBSERVATION (which exits 0). Confirm no path yields exit 0 while implying provenance was considered. |
|
||||||
|
| **H3** | ★ **TRAP 2 re-check:** the exclusion is **enforced**, not merely declared in `coverageBoundary.excluded`. Re-enable history provenance without a trustworthy anchor — does a registered case go RED? |
|
||||||
|
| **H4** | The residual is stated **correctly** — no local git state is trustworthy because PR code executes before the gate — **NOT** the D-48 wording ("compromised main"). |
|
||||||
|
|
||||||
|
## B3 / R — evidence-subject and renderer
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **B1** | Subject is on the **EVIDENCE side** and compared **at consumption**, not `gate.evidenceSubject === gate.id` metadata-vs-itself. Mutate the evidence-side subject **per gate**. |
|
||||||
|
| **B2** | Can evidence still be moved or misbound while every gate satisfies its check? |
|
||||||
|
| **R1** | Renderer now covers the **final success stdout/stderr** paths. |
|
||||||
|
|
||||||
|
## C — integrity + CI
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ----------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **C1** | Head `e910a45a` on git + provider; `Closes #1029` present. |
|
||||||
|
| **C2** | Exact-head CI terminal-green, `-f json`, counts incl. `clone`; machine-checked with `--expect-commit e910a45ab3578a9c77ad3eeaa52b31b72611f6c6`. |
|
||||||
|
| **C3** | Nothing weakened `fbb61912` → `e910a45a`. Red-first labels honest (D-8). |
|
||||||
|
| **C4** | **NO fourth local anchor was invented.** Blocker 1 and blocker 2's adversarial guarantee both track RM-60. |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Verdict bound to `e910a45ab3578a9c77ad3eeaa52b31b72611f6c6`, evidence enumerated, posted durably.
|
||||||
|
Unrunnable ⇒ **say so**. **N1 and N2 are the sharp ones** — this PR's history is that every fix
|
||||||
|
relocates the defect one level down, and N2 asks whether the control that enforces honesty is itself
|
||||||
|
honest. **Attack outside the set: six for six so far.**
|
||||||
|
|
||||||
|
**No one dispatching this review may state a conclusion on an open check (D-39).**
|
||||||
@@ -0,0 +1,71 @@
|
|||||||
|
# RM-02 / PR #1030 — PRE-REGISTERED ACCEPTANCE CHECKS (post-rebase, keystone)
|
||||||
|
|
||||||
|
**Subject head (exact):** `83d2ecb2243f1b0987ef2bc14de47f444285a684`
|
||||||
|
**Rebased onto:** `main` @ `f4fd5967fc5d4cbc72d680b199d88224aa855131` (post-RM-61)
|
||||||
|
**Registered by:** `mos-remediation` **BEFORE the reviewer read the diff.** **Reviewer:** `rev-974`
|
||||||
|
(author ≠ reviewer; branch commits are `f10-coder`'s and `coder-mos1`'s).
|
||||||
|
**Prior reviews 63 / 65 are SUPERSEDED; this head carries NO live review of any kind.**
|
||||||
|
|
||||||
|
RM-02 is the **keystone**: it is the anti-inert-gate registry every downstream gate is measured against.
|
||||||
|
A defect that survives here propagates into every gate this mission ships.
|
||||||
|
|
||||||
|
## ★ CRUX — the one non-mechanical change, made by the author, that turned a red green
|
||||||
|
|
||||||
|
The rebase was clean. One further commit was **not** purely mechanical and the author disclosed it
|
||||||
|
unprompted (`83d2ecb2` — advance registry activation seam):
|
||||||
|
|
||||||
|
gates/gates.manifest.json
|
||||||
|
- "activationCommit": "f65e9ea656ec466e12640bf6ab5d46fe07ff160c"
|
||||||
|
+ "activationCommit": "f4fd5967fc5d4cbc72d680b199d88224aa855131"
|
||||||
|
|
||||||
|
Stated rationale: after the rebase, `pnpm gate:verify` correctly failed because the newly-merged
|
||||||
|
pre-registry RM-61 commit was treated as _prospective_ and required a manifest that could not exist.
|
||||||
|
|
||||||
|
`activationCommit` sets the lower bound of `activationCommit..HEAD` — **the set of commits required to
|
||||||
|
carry own-tree registry provenance** (`gate-history.mjs:314` → `listProspectiveCommits`). Advancing it
|
||||||
|
**shrinks that set**.
|
||||||
|
|
||||||
|
**Determine, do not assume — and I have deliberately formed and stated no verdict (D-39):**
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **A1** | **Is the advance JUSTIFIED?** Can a pre-registry commit on `main` (e.g. `f4fd5967`) satisfy the provenance requirement at all, or is requiring it impossible-by-construction? If impossible, is advancing the seam the _correct_ remedy, or does a correct remedy exist that does not move an author-controlled field? |
|
||||||
|
| **A2** | **Is the advance MINIMAL?** Was it advanced exactly to the new parent baseline, or beyond it? Does any commit that _should_ remain covered fall outside the new range? |
|
||||||
|
| **A3** | **Are all 7 branch commits still PROSPECTIVE under the new seam?** Enumerate them and show each is still required to carry provenance. The author claims "own-tree provenance over every registry-era branch commit" — verify the claim, do not accept it. |
|
||||||
|
| **A4** | ★★ **IS THE SEAM ITSELF CONSTRAINED?** The only validation found is `merge-base --is-ancestor activationCommit head` (`gate-history.mjs:288`). **A commit is its own ancestor.** Determine what `activationCommit = HEAD` does: is the prospective range empty, does the per-commit loop iterate zero times, and does the history check therefore PASS VACUOUSLY? If so, the anti-inert-gate registry contains an author-settable field that can inert its own history check. **Run it. Report the observed exit and whether any failure is raised.** |
|
||||||
|
| **A5** | **If A4 shows vacuity is reachable, is there a registered MUST-FAIL negative control for it?** RM-02's own founding rule is that a gate with no proven failure path manufactures evidence. Does the registry hold a case that goes RED when the seam is over-advanced? If not, that is a hole in the registry's coverage of itself. |
|
||||||
|
| **A6** | **Self-verification shape (charter / D-19 / D-39b):** the field was advanced by the change's own author to make the author's gate pass. Independent of whether the value is correct, determine whether the _mechanism_ permits an audited party to relax its own audit, and whether that needs a constraint, an owner, or an escalation. |
|
||||||
|
|
||||||
|
## Registry substance — the clauses this PR must now carry
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **B1** | **D-38 clause present and enforced:** the registry asks of every gate _"does this gate BIND its evidence to the subject under review?"_ Ruled in-scope for THIS PR by Mos. Verify it exists as a checked clause, not prose. |
|
||||||
|
| **B2** | **D-40 clause present and enforced:** _"discriminator and comparison inputs must be TYPE-STRICT."_ Also ruled in-scope for THIS PR. `== 0` matching `False`/`0.0` is the banked instance; the clause is the general form. |
|
||||||
|
| **B3** | **D-42's clause is CORRECTLY ABSENT** — provider-side negative control tracks separately (Mos: landing it now would give the registry a clause with nothing to satisfy it, going red on its own clause). Confirm its absence is deliberate and recorded, not forgotten. |
|
||||||
|
| **B4** | **The four founding clauses still hold** (`MISSION.md`): every check proven **right** (red for its own stated reason), the set **covers**, no two criteria **conflict**, and criterion evolution **retains original text + restatement + reason**. |
|
||||||
|
| **B5** | **Nothing was weakened, skipped, or deleted by the rebase.** Diff `f9746b23` → `83d2ecb2` and confirm no registered case, test, or assertion was removed or relaxed to make the rebase land. |
|
||||||
|
| **B6** | **`coverageBoundary.excluded[]` is honest in BOTH directions** (charter principle 4): what it does NOT cover is stated beside what it DOES, and the gap is tracked (`trackedBy: RM-54`) rather than implied-fixed. |
|
||||||
|
| **B7** | **The RM-02 execution boundary** (`gate-history.mjs`, DOES / DOES NOT, owner RM-60, xref RM-59) states its limits in both directions and names a tracked owner — not a documented gap with no owner. |
|
||||||
|
|
||||||
|
## Head + CI (re-run these; do not carry them forward from the author's report)
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
|
||||||
|
| **C1** | Head `83d2ecb2…` on **both** git and provider; `Closes #1029` present in the body (delivery-issue rule, D-38c). |
|
||||||
|
| **C2** | Exact-head CI terminal-green by **full `-f json` scan**, counts stated **including `clone`**. Note the count changed 9 → **10** (this PR adds `gate-verify`) — confirm the new step is real, not a miscount. |
|
||||||
|
| **C3** | **Machine-check it, do not assert it:** `verify-terminal-green.py --expect-commit 83d2ecb2243f1b0987ef2bc14de47f444285a684`. Report exit, `exempted_steps`, `commit == expected_commit`. |
|
||||||
|
| **C4** | `exempted_steps=0` is expected here — `ci-postgres` succeeded, so the #1000 exemption was **not needed**. Confirm the exemption is present-but-unused rather than silently inapplicable. |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Verdict bound to `83d2ecb2243f1b0987ef2bc14de47f444285a684`, evidence enumerated per check, posted
|
||||||
|
durably under your own identity. If a check is unrunnable, **say so** — never substitute a variant that
|
||||||
|
passes. Scan CI from `-f json`, never default text (D-33); state your counts.
|
||||||
|
|
||||||
|
**A4 is the check I most want an answer to and the one I have least confidence about.** Attack outside
|
||||||
|
this set as well: every blocker found on this mission so far came from mutating something nobody had
|
||||||
|
registered a check for.
|
||||||
|
|
||||||
|
**No one dispatching this review may state a conclusion on an open check (D-39).** Observations may be
|
||||||
|
relayed to you; verdicts may not. The ruling is yours.
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
# RM-03 / PR #1032 — PRE-REGISTERED RE-REVIEW (post-freshening)
|
||||||
|
|
||||||
|
**Subject head (exact):** `868b9b871a5118762aa5b8aafecd2f0592f7ab5c`
|
||||||
|
**Rebased onto:** `main` @ `f4fd5967` **Registered by:** `mos-remediation` before the reviewer read the
|
||||||
|
diff. **Reviewer:** `rev-974`.
|
||||||
|
|
||||||
|
**Why this exists:** review 66 APPROVED and the merge-gate GO were bound to `78ec47cd`; `main` drifted
|
||||||
|
under a long hold and the PR went `mergeable=false` (**D-50 — a GO has a shelf life**). Both verdicts
|
||||||
|
are VOID at the new head. Jason's merge approval is **standing** and executes once this re-gates.
|
||||||
|
|
||||||
|
## What the orchestrator already verified (do not re-spend here)
|
||||||
|
|
||||||
|
- `git range-diff 78ec47cd...868b9b87`: commits **2–5 are `=` (patch-equivalent)**; only commit 1 differs.
|
||||||
|
- That single difference is the `test:framework-shell` chain, resolved as a **UNION** — main's
|
||||||
|
`test-terminal-green-contract.sh` **and** RM-03's `tristate`, `github-checks`, `merge-queue-branch`,
|
||||||
|
`merge-head-pin`, plus the pre-existing `branch-absent`. **Nothing dropped from either side.**
|
||||||
|
- CI #2199 at the exact head: 9 children, 9 success incl. `clone`; machine check exit 0, bound, no anomalies.
|
||||||
|
- `mergeable` is now **true**.
|
||||||
|
|
||||||
|
## Checks
|
||||||
|
|
||||||
|
| id | check |
|
||||||
|
| ------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
|
| **R1** | ★ **THE GUARD CAN FAIL.** RM-03 exists because the queue guard is ZERO-INFORMATION (D-23) — it returns pass for every possible input. Prove the rebased head's guard **actually fails** on asserted non-readiness, not merely that its tests pass. This is the whole deliverable. |
|
||||||
|
| **R2** | ★ **NO QUEUE-GUARD SEMANTIC MOVED IN THE REBASE.** Confirm the range-diff equivalence independently. A queue-guard semantic resolved quietly re-breaks the thing this PR fixes. |
|
||||||
|
| **R3** | **Union is complete in BOTH directions:** no RM-03 suite lost to main's version, no main suite (esp. `test-terminal-green-contract.sh`) lost to RM-03's. Enumeration count reconciles. |
|
||||||
|
| **R4** | **Tri-state is real** (`verified` / `written-unverified` / `failed`) — P-WRAPPER-001. Verify an indeterminate result cannot present as a pass; that is the exact defect (`state=unknown exit 0`). |
|
||||||
|
| **R5** | The guard's **exit-asserting non-null-case** tests are genuine — each fails for its own stated reason against pre-fix code, not merely present (D-8). |
|
||||||
|
| **R6** | `test:framework-shell` is **runnable to completion in CI** (canonical env). Known: it exits 97 on some hosts via a Bash 5.2.15 `BASH_LINENO` assertion — if you hit that, report it as an environment limitation, do not treat it as a finding and do not let it mask one. |
|
||||||
|
| **R7** | Exact-head CI terminal-green, full `-f json`, counts stated incl. `clone`; machine-checked with `--expect-commit 868b9b871a5118762aa5b8aafecd2f0592f7ab5c`. |
|
||||||
|
| **R8** | `Closes #1019` present in the body (D-38c delivery-issue rule). |
|
||||||
|
| **R9** | Nothing weakened by the rebase: no test, case, or assertion removed or relaxed to make it land. |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Verdict bound to `868b9b871a5118762aa5b8aafecd2f0592f7ab5c`, evidence enumerated, posted durably under
|
||||||
|
your own identity. If a check is unrunnable, **say so**.
|
||||||
|
|
||||||
|
**R1 is the deliverable and R2 is the risk.** Attack outside this set. **Do not cite the queue guard's
|
||||||
|
own green as evidence of anything** — it remains inert until this very PR lands (D-23).
|
||||||
|
|
||||||
|
**No one dispatching this review may state a conclusion on an open check (D-39).**
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
# RM-61 / PR #1033 — PRE-REGISTERED RE-REVIEW ACCEPTANCE CHECKS
|
||||||
|
|
||||||
|
**Subject head (exact):** `033b2ffb46674b2c0bcc5197273c109b461f62d9`
|
||||||
|
**Supersedes:** review 67 / comment 20403 @ `e7b29219` (NO GO). That verdict is VOID — the head moved.
|
||||||
|
**Registered by:** `mos-remediation` (orchestrator). **Reviewer:** `rev-974` (author ≠ reviewer).
|
||||||
|
**Registered BEFORE the reviewer read the diff.** Any head move after this file is committed voids the
|
||||||
|
re-review and requires re-registration.
|
||||||
|
|
||||||
|
## Scope discipline
|
||||||
|
|
||||||
|
The prior review passed AC1–AC8 and still found a blocker, because the registered set tested whether the
|
||||||
|
signature DISCRIMINATES and never tested whether the evidence was BOUND TO ITS SUBJECT (Finding 3 /
|
||||||
|
coverage-failure-mode-2, D-17 class). This set therefore carries the binding property as a first-class
|
||||||
|
check, and **RR7 explicitly invites the reviewer to attack outside the set** — a registered set is
|
||||||
|
protection against retrofitting only, never a ceiling on scrutiny.
|
||||||
|
|
||||||
|
## Checks
|
||||||
|
|
||||||
|
| id | check | verdict form |
|
||||||
|
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------- |
|
||||||
|
| **RR1** | The full 12-case contract harness passes at the exact head: `bash test-terminal-green-contract.sh` | ⇒0, and states 12 cases |
|
||||||
|
| **RR2** | ★CRUX — the ORIGINAL ATTACK IS DEAD. Take the real `#2188` record, mutate ONLY `commit` to an unrelated 40-hex value, verify against the true expected head | ⇒1, `exempted_steps == 0`, anomaly naming expected vs actual |
|
||||||
|
| **RR3** | Missing `--expect-commit` cannot be defaulted, inferred, or skipped | ⇒2 (not 0, not 1) |
|
||||||
|
| **RR4** | Malformed expected commit (short SHA, non-hex, empty) is rejected — no silent normalisation into a pass | ⇒2 |
|
||||||
|
| **RR5** | A record with the `commit` key ABSENT (not merely different) is rejected — fail-closed on missing, not just on mismatch | ⇒1, `exempted_steps == 0` |
|
||||||
|
| **RR6** | The genuine artifact still passes when correctly bound: real `#2188` + its true head | ⇒0, `exempted_steps == 1`, exactly one `WP-K8S-1000-CI-POSTGRES-TEARDOWN` |
|
||||||
|
| **RR7** | ★RED-FIRST, PROVED RETROACTIVELY. The four new cases must FAIL against the OLD verifier at `e7b29219` — otherwise they do not test what they claim (D-8 class). Run the new cases against the previous implementation | new cases ⇒≠0 under `e7b29219` |
|
||||||
|
| **RR8** | AC2 OF THE PRIOR SET DID NOT REGRESS: both REAL controls stay terminal red — `#2189` (`ci-postgres` exit 1) and `#2191` (exit 137, `test` exit 61) | both ⇒1, `exempted_steps == 0` |
|
||||||
|
| **RR9** | Still NO fetch / trigger / retry / re-roll / sleep / network of any kind in the verifier or harness. The coin flip must remain removed, not codified (D-21) | grep ⇒ no such call sites |
|
||||||
|
| **RR10** | The doc/baseline changes REQUIRE the current provider PR head to be passed — they must not merely mention it. Check `merge-gate.md`, `CI-CD-PIPELINES.md`, `woodpecker/README.md` state it as a requirement a gate operator cannot satisfy by omission | reviewer judgement, quote the lines |
|
||||||
|
| **RR11** | Exemption remains bound to #1000 and retires with it; signature conjunction unchanged and not widened by this fix | diff-scoped, ⇒ no widening |
|
||||||
|
| **RR12** | Case-sensitivity: an uppercase-hex record commit against a lowercase expected head must NOT silently pass by accident of comparison. State which way it resolves and whether it fails closed | state the observed behaviour |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Report the verdict **bound to `033b2ffb46674b2c0bcc5197273c109b461f62d9`** and state each check's
|
||||||
|
observed result, including counts read from `pipeline-status.sh -f json` (never default text — it omits
|
||||||
|
`clone`, D-33). If any check is unrunnable, **say so** — never substitute a passing variant. Attack
|
||||||
|
outside this set and report anything it finds; RR7 and RR12 exist because the last blocker was found
|
||||||
|
exactly that way.
|
||||||
@@ -0,0 +1,60 @@
|
|||||||
|
# RM-61 / PR #1033 — PRE-REGISTERED ACCEPTANCE CHECKS: `exit_code` TYPE-STRICTNESS (D-40)
|
||||||
|
|
||||||
|
**Registered by:** `mos-remediation` (orchestrator) — **BEFORE the fix was pushed and before any
|
||||||
|
reviewer read a diff.** At registration time the fix existed only as an unpushed local commit
|
||||||
|
(`6e7a336d`) on coder-mos1's machine which **I have not read**. There is therefore no diff for these
|
||||||
|
checks to have been retrofitted to.
|
||||||
|
|
||||||
|
**Subject head:** TBD — binds to the NEW head once coder-mos1 pushes. The prior head
|
||||||
|
`033b2ffb46674b2c0bcc5197273c109b461f62d9` and its review 69 / pipeline #2193 go VOID on that push;
|
||||||
|
that cost was accepted deliberately by Mos's BLOCKING ruling on D-40.
|
||||||
|
|
||||||
|
**Ruling being enforced (Mos, 2026-08-01):** `exit_code` must be accepted ONLY as a real integer.
|
||||||
|
`false`, `0.0`, `"0"`, and `null` must all fail to satisfy the exemption. Wrong-ACCEPT is the
|
||||||
|
disqualifying direction; this hole sits inside the load-bearing discriminator.
|
||||||
|
|
||||||
|
## ⚠ Read this before writing the tests — RED-FIRST HERE IS NOT UNIFORM
|
||||||
|
|
||||||
|
Two of the four near-miss values **already block** at `033b2ffb`. Demanding "all four observed RED
|
||||||
|
first" would be demanding an impossible red for two of them, and the predictable response to an
|
||||||
|
impossible demand is a fudge — weakening something real to manufacture the red. So state it precisely:
|
||||||
|
|
||||||
|
| value | behaviour at `033b2ffb` (pre-fix) | what the new case is |
|
||||||
|
| ------- | --------------------------------- | ------------------------- |
|
||||||
|
| `false` | **WRONGLY EXEMPTS** (exit 0) | **genuine RED-FIRST** |
|
||||||
|
| `0.0` | **WRONGLY EXEMPTS** (exit 0) | **genuine RED-FIRST** |
|
||||||
|
| `"0"` | correctly blocks (exit 1) | **regression guard** only |
|
||||||
|
| `null` | correctly blocks (exit 1) | **regression guard** only |
|
||||||
|
|
||||||
|
Claiming red-first for `"0"` or `null` would be a false claim about your own evidence. Say which is
|
||||||
|
which. **Do not weaken anything to make a green case go red** (D-8).
|
||||||
|
|
||||||
|
## Checks
|
||||||
|
|
||||||
|
| id | check | verdict form |
|
||||||
|
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
|
||||||
|
| **TS1** | ★RED-FIRST. `exit_code: false` on the real #2188 record is **observed wrongly exempting at `033b2ffb`** (exit 0, `exempted_steps 1`), then blocks after the fix | pre-fix ⇒0/exempt 1 · post-fix ⇒1/exempt 0 |
|
||||||
|
| **TS2** | ★RED-FIRST. Same for `exit_code: 0.0` | pre-fix ⇒0/exempt 1 · post-fix ⇒1/exempt 0 |
|
||||||
|
| **TS3** | REGRESSION GUARD. `exit_code: "0"` blocked before AND after — state honestly that it was already green | both ⇒1, `exempted_steps 0` |
|
||||||
|
| **TS4** | REGRESSION GUARD. `exit_code: null` blocked before AND after | both ⇒1, `exempted_steps 0` |
|
||||||
|
| **TS5** | ★NOT OVER-TIGHTENED. The genuine artifact — real #2188, real integer `exit_code: 0`, correctly bound head — still passes | ⇒0, `exempted_steps 1`, exactly one `WP-K8S-1000-CI-POSTGRES-TEARDOWN` |
|
||||||
|
| **TS6** | The strictness sits on the value the EXEMPTION rests on, not on a cosmetic sibling. Show the guarded comparison is the one feeding `exemption_applies` | reviewer quotes the line |
|
||||||
|
| **TS7** | `bool` is excluded EXPLICITLY, not incidentally. A bare `isinstance(x, int)` still admits `True`/`False` — verify the `not isinstance(x, bool)` clause exists | ⇒ clause present; `true` also blocks |
|
||||||
|
| **TS8** | Negative control unaffected: a genuine failed step with a real integer non-zero exit still blocks | ⇒1, `exempted_steps 0` |
|
||||||
|
| **TS9** | NO REGRESSION ON THE PRIOR ROUND'S BINDING WORK: mutated record commit ⇒1; `--expect-commit` omitted ⇒2; record `commit` absent ⇒1 | ⇒1 / ⇒2 / ⇒1 |
|
||||||
|
| **TS10** | Signature conjunction NOT widened elsewhere by this fix — `POD_NOT_FOUND` / name / type / state untouched | diff-scoped ⇒ no widening |
|
||||||
|
| **TS11** | Still no fetch / trigger / retry / re-roll / sleep / network | grep ⇒ no call sites |
|
||||||
|
| **TS12** | Full harness passes at the new head; **state the case count** (12 previously, expected 16 — confirm the actual number rather than the expected one) | ⇒0, count stated |
|
||||||
|
|
||||||
|
## Reviewer instruction
|
||||||
|
|
||||||
|
Verdict bound to the NEW head, evidence enumerated per check, CI counts from `pipeline-status.sh -f json`
|
||||||
|
(never default text — it omits `clone`, D-33). If a check is unrunnable, **say so**; never substitute a
|
||||||
|
passing variant.
|
||||||
|
|
||||||
|
**Attack outside this set and report what you find.** Both blockers on this PR so far — the missing
|
||||||
|
commit binding, and this type confusion — were found outside the registered set, by mutating a field
|
||||||
|
nobody had registered a check for. That is now the expectation, not a bonus.
|
||||||
|
|
||||||
|
**Nobody dispatching this review may state a conclusion on an open check here (D-39).** If you are sent
|
||||||
|
an observation, it is an observation; the ruling is yours.
|
||||||
@@ -23,3 +23,68 @@ Merged PR #868 (`b79336a8`) shipped a file that FAILS `pnpm format:check` ⇒ th
|
|||||||
### **D-4 / P-LIFECYCLE + hygiene — a dispatched agent silently IGNORED an in-message context reset.**
|
### **D-4 / P-LIFECYCLE + hygiene — a dispatched agent silently IGNORED an in-message context reset.**
|
||||||
|
|
||||||
planner-sol was at 64.3%/372k; the brief asked it to reset first; it began work on dirty context anyway. Only an out-of-band `/new` driven by the orchestrator guaranteed clean state. Confirms the postmortem thesis: **instructions are not enforcement.** Reset must be a mechanical pre-dispatch step, not a request.
|
planner-sol was at 64.3%/372k; the brief asked it to reset first; it began work on dirty context anyway. Only an out-of-band `/new` driven by the orchestrator guaranteed clean state. Confirms the postmortem thesis: **instructions are not enforcement.** Reset must be a mechanical pre-dispatch step, not a request.
|
||||||
|
|
||||||
|
<!-- board-roll: 2 entries rolled from BOARD.md -->
|
||||||
|
|
||||||
|
### **D-7 / P-FLEET-001 — stale-GC-on-disk: shared 30G /tmp hit 100% ENOSPC, degrading two seats.**
|
||||||
|
|
||||||
|
~5.2G was session scratch dead 8-9 days (this session's own footprint: 88K). Same missing capability as orphaned-tmux-session GC, applied to disk — not a quota or discipline problem. Resolved manually by Mos (lead coordinator) after independent verification; `/tmp` now 79%. **The gap IS the finding:** the authority to reap exists, the deterministic reaper does not. Folded into RM-50 with explicit requirements (mechanical liveness, age threshold, dry-run, audit event per reap — never a heuristic sweep). Refusing to unilaterally delete another session's scratch was correct doctrine; the fix is a reaper, not braver agents.
|
||||||
|
|
||||||
|
### **D-6 / P-QUEUE-001 — the mandated queue guard returned PASS on an UNKNOWN state, live, today.**
|
||||||
|
|
||||||
|
Running the required `ci-queue-wait.sh --purpose push` before pushing produced `state=unknown ... exit 0` — the exact defect at `ci-queue-wait.sh:282-288` that PR #1023 is parked on. It also evaluated `branch=main` rather than the branch being pushed. The mission's own required pre-push gate passed me on an indeterminate result. Third independent live instance of the class.
|
||||||
|
|
||||||
|
<!-- board-roll: 1 entry rolled from BOARD.md -->
|
||||||
|
|
||||||
|
### **D-8 / P-CONFORMANCE-001 — a PRE-REGISTERED acceptance check that was not runnable as written.**
|
||||||
|
|
||||||
|
PR #1025 AC2's fixture `mkdir -p apps/*/venv/lib` creates a literal `apps/*/venv/lib` dir when the glob is unmatched — it did not test what it claimed. rev-974 ran it exactly as written, caught it, re-ran the intended assertion at an explicit path, and **disclosed** rather than silently substituting a working fixture and reporting PASS. **Pre-registration protects a check from being retrofitted to the implementation; it does not make the check correct.** An unverified gate appeared inside the mechanism built to catch unverified gates. Hard requirement on RM-02: the registry must self-verify that every registered case runs AND can fail — presence is not evidence.
|
||||||
|
|
||||||
|
<!-- board-roll: Decisions-log narrative rolled from BOARD.md 2026-08-01 (D-43: meet the
|
||||||
|
byte budget by ROLLING OUT, never by rewording what stays) -->
|
||||||
|
|
||||||
|
### Decisions log — full record in [`TASKS.md`](./TASKS.md)
|
||||||
|
|
||||||
|
All 44 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-43 + D-38c in `TASKS.md`) and every ruling with its
|
||||||
|
rationale live there. **Not duplicated here** — a second copy is a second thing to go stale, which this
|
||||||
|
board had done three times in one night (gate list, capability registry, DECISION-1 status), and three
|
||||||
|
more times by the next rotation seam (RM-61 "building", "nothing implemented yet", DECISION-1/2/3
|
||||||
|
"must be ruled"). The rulings a fresh seat needs are items 4–7 above; they are **not** repeated here,
|
||||||
|
because that repetition is what went stale.
|
||||||
|
|
||||||
|
<!-- board-roll: Sequencing section rolled verbatim from BOARD.md 2026-08-01 (D-43: meet the
|
||||||
|
byte budget by ROLLING OUT, never by rewording what stays). Canonical: MISSION.md + TASKS.md §5 -->
|
||||||
|
|
||||||
|
### Sequencing — see [`MISSION.md`](./MISSION.md)
|
||||||
|
|
||||||
|
Builds 1-5, the cross-cutting retirements, and DECISION-1's corrected wire-in target are stated once in
|
||||||
|
the charter and `TASKS.md` §5. **Not repeated here** — the previous copy of DECISION-1's status on this
|
||||||
|
board is one of the six stale restatements below.
|
||||||
|
|
||||||
|
<!-- board-roll: capability/seat-identity bullets rolled verbatim from BOARD.md 2026-08-01
|
||||||
|
(D-43: roll out, never reword). Authoritative home: TASKS.md D-11 / D-11a / D-11b. -->
|
||||||
|
|
||||||
|
- Capability is **per-path** (D-11b → **superseded in part by D-13/D-15**): a token file is **necessary,
|
||||||
|
not sufficient**. Three layers — token file (raw-API), `tea` login (tea paths), **repository permission**
|
||||||
|
(writes). Before dispatch, assert `permissions.push == true` **as that seat**, not token existence and
|
||||||
|
not a 200 on a read. Mos owns provisioning; escalate missing pairs.
|
||||||
|
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
|
||||||
|
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
|
||||||
|
|
||||||
|
<!-- board-roll: D-26 gate-restatement rationale rolled verbatim from BOARD.md 2026-08-01 -->
|
||||||
|
|
||||||
|
### Why the board must not restate the delivery gates (D-26)
|
||||||
|
|
||||||
|
Restating the gate from memory is how the merge-gate step went missing from mission setup twice,
|
||||||
|
once inside the correction for it (**D-26**).
|
||||||
|
|
||||||
|
<!-- board-roll: Fleet seats rolled verbatim from BOARD.md 2026-08-01 (D-43: roll out, never
|
||||||
|
reword). NOTE: all these seats are UNMANAGED per D-41; `mosaic fleet ps` is live truth. -->
|
||||||
|
|
||||||
|
## Fleet seats
|
||||||
|
|
||||||
|
- mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket `mosaic-fleet`) — ACTIVE
|
||||||
|
- planner-opus — adversarial planner (robustness), Opus 5, socket `default` — DELIVERED, idle
|
||||||
|
- planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket `default` — DELIVERED, idle
|
||||||
|
- rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
|
||||||
|
- Mos (mos-claude) — lead coordinator, socket `default` — relay path to Jason
|
||||||
|
|||||||
+65
-73
@@ -1,93 +1,85 @@
|
|||||||
# mos-remediation — LIVE BOARD (keep < 8 KB)
|
# mos-remediation — LIVE BOARD (keep < 8 KB)
|
||||||
|
|
||||||
**Phase:** EXECUTING — P0 open. RM-01 MERGED; RM-02 (keystone gate registry) is next.
|
**Phase:** EXECUTING — **RM-02 keystone is the front**.
|
||||||
**Updated:** 2026-07-31 (mos-remediation orchestrator; seat active on `mosaic-fleet`).
|
**Updated:** 2026-08-05 — successor seat live. D-56 state correction applied (lost round-5 dispatch,
|
||||||
|
4 idle days); round-5 review then ran same day: verdict id 88 REQUEST_CHANGES @ `e910a45a`,
|
||||||
|
remediation dispatched to `coder-mos2`. Review dispatches now always leave a durable PR comment.
|
||||||
|
⚠ That was a **MANUAL pane respawn** (prior seat ~803k tokens): it validates the checkpoint+rehydration
|
||||||
|
**design**, NOT a lifecycle **mechanism** — P-LIFECYCLE rotation does not exist yet (**D-41 / RM-62**).
|
||||||
|
|
||||||
## Head
|
## Head
|
||||||
|
|
||||||
- Mission charter + 15 decisions + 4-build plan: PERSISTED (`docs/remediation/MISSION.md`).
|
- Charter + 15 decisions + 4-build plan: `MISSION.md`. Backlog + all findings: `TASKS.md`.
|
||||||
- HOLD lifted for this workstream (Jason 2026-07-31). Nothing implemented yet — planning first.
|
- Planning DONE (58 tasks, P0–P5). **DECISION-1/2/3 all RULED by Mos 2026-07-31** (`TASKS.md` §5) —
|
||||||
- Orchestrator seat `mos-remediation` is LIVE and owns the mission. Residency attestation: PASS.
|
nothing is waiting on a decision. D-2's availability _target_ is Jason-pending and non-blocking.
|
||||||
- **TASK-0 DONE** — checkout repaired, all three gates green HONESTLY (no `--no-verify`), branch pushed.
|
- **Executing, not planning.** RM-01 is MERGED; three lanes are live (see In-flight).
|
||||||
- **TASK-1 DONE** — both planners delivered independently on clean context; reconciled into `TASKS.md`
|
- Orchestrator seat `mos-remediation` LIVE, owns the mission, resumed across the rotation seam
|
||||||
(58 tasks across P0–P5, 7 convergences, 7 adjudicated disagreements, 3 escalated decisions).
|
2026-08-01 and re-attested to Mos from the files. Residency attestation: PASS.
|
||||||
- **NEXT ACTION IS NOT MINE:** DECISION-1/2/3 (`TASKS.md` §5) must be ruled before P0 dispatch.
|
|
||||||
RM-01 is dispatchable immediately regardless — it depends on nothing and blocks everything.
|
|
||||||
|
|
||||||
## In-flight
|
## In-flight
|
||||||
|
|
||||||
| Task | Owner | State |
|
| Task | Owner | State |
|
||||||
| ----------------------------------- | --------------- | ------------------------------------------------------------------------- |
|
| ------------------- | --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||||
| RM-01 reproducible checkout | — | **MERGED** `f58b3699` (PR #1027) — rev-974 APPROVE + CI #2172 8/8 green |
|
| RM-01 checkout | — | **MERGED** `f58b3699` (#1027) |
|
||||||
| RM-02 gate registry ★keystone | unassigned | **READY** — depends only on RM-01; not held by RM-03 |
|
| RM-03 queue guard | Jason (re-sync) | ✅ **MERGED** `58b971ab` (#1032), #1019 closed. ⚠ **NOT DELIVERED**: installed guard still the broken one (291 lines / 0 `ASSERTED_NOT_READY` vs main 482 / 5). Re-sync via `mosaic upgrade`, then **prove it blocks a KNOWN-RED pipeline** — **D-51** |
|
||||||
| RM-03 queue guard (3 defects) | — | HOLD — #1023 SUPERSEDED-PENDING-JASON |
|
| RM-02 registry ★key | coder-mos2 | **ROUND-5 VERDICT id 88 REQUEST_CHANGES @ `e910a45a` (2026-08-05T22:37Z, live).** 2 blockers left: renderer accepts manifest-controlled `COMPATIBILITY `-prefixed provenance-success payloads; overclaim control is lexical-not-semantic vs docs claims. Shrink-together + evidence-subject CONFIRMED CLOSED — do not weaken. Remediation dispatched to `coder-mos2` 22:5xZ (PR comment + verified tmux); context guard: checkpoint at 85%. ⚠ **MERGE PRECONDITIONS (D-55/D-55f, measured):** poster=f10-coder (1 of 3 authors); (1) explicit `-m squash` (repo default `merge` discards ALL authorship); (2) **merger ≠ f10-coder** (self-merge suppresses the trailer generator → all 3 lost); (3) **the EXECUTING pr-merge.sh must contain `MergeMessageField` — merging #1066 is NOT sufficient** (deployed wrapper `08a65e85` = 0 refs, physically cannot emit; D-51's merged≠effective class inside the remedy; Mos-as-merger verifies wrapper sha256 before ANY trailer-dependent merge and refuses on `08a65e85`); (4) ✅ **CLOSED ON MEASUREMENT** — N=2 supplied non-poster trailers BOTH land, order preserved, poster line appended last (fixture prmerge-trailer-fixture#2 → `39db9d13`, #1030's exact shape; N=3+/poster-dup-dedup/Co-committed-by absence remain unmeasured but #1030 needs N=2). Merge decision resolved: all-land ⇒ merge as planned, three authors preserved. Trade in body; **branch MUST NOT be deleted**. ACs @ `dde38717` |
|
||||||
| RM-59 close D-19 residual risk | — | BLOCKED by RM-12/RM-21/RM-25 (spine + executor) — tracked edge, not prose |
|
| RM-61 CI exemption | — | ✅ **MERGED** `f4fd5967` (#1033). #1034 closed; **#1000 stays OPEN** (retirement trigger). Exemption is on `main` |
|
||||||
| `remediation/state` snapshot → main | mos-remediation | opening at this mission seam |
|
| RM-59 / RM-60 | Jason (infra) | tracked deps; RM-60 option **B** |
|
||||||
|
| #1023 queue attempt | Jason | SUPERSEDED-PENDING-JASON — live REQUEST_CHANGES, do **not** merge |
|
||||||
|
|
||||||
|
### For the incoming orchestrator — read this before acting
|
||||||
|
|
||||||
|
1. **Lane state lives in the In-flight table above — this item does NOT restate it.** It went stale
|
||||||
|
three times in one session by duplicating that table (D-26's class). Read the table. ⚠ **And
|
||||||
|
re-derive any board claim from the provider before load-bearing use (D-43)** — the board is
|
||||||
|
sole-written and has no independent verifier.
|
||||||
|
2. **`docs/remediation/TASKS.md` is authoritative**, not the newest voice in a chat. It holds 58 findings
|
||||||
|
(D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-55c + D-38c in TASKS.md), every ruling with its rationale, and the
|
||||||
|
requirements each finding placed on RM-02/RM-34/RM-50/RM-55.
|
||||||
|
3. **`MISSION.md` carries the first-class principles** — read them there, they are not listed here.
|
||||||
|
Two added 2026-08-01: **the anchor must live outside the audited party's authority** (D-19/D-25/D-45,
|
||||||
|
third arrival) and **no universally-quantified check may pass over an empty set** (D-44/D-46).
|
||||||
|
4. **Seat identity:** `export MOSAIC_GIT_IDENTITY=<seat>` is stripped by a context reset (**D-34**) —
|
||||||
|
every dispatch/rehydration brief must re-export it, or the seat cannot use its credentials.
|
||||||
|
5. **Scan CI from `-f json`, never default text** — text mode omits `clone` (**D-33**). State counts.
|
||||||
|
6. **The queue guard is zero-information until RM-03 merges** (**D-23**) — never cite its green.
|
||||||
|
7. **The bounded CI re-roll used on RM-02 was a one-time stopgap, NOT policy.** A per-PR free re-roll is
|
||||||
|
D-21 normalisation. Do not repeat it; RM-61 is the fix.
|
||||||
|
|
||||||
|
## Delivery gates — REFERENCE, do not restate
|
||||||
|
|
||||||
|
Canonical: `~/.config/mosaic/fleet/roles.local/merge-gate.md` (verdict authority) +
|
||||||
|
`~/.config/mosaic/fleet/roles/validator.md`. Order and the freeze/zero-information rules: `MISSION.md`
|
||||||
|
and `KICKSTART.md`. **Read them there** (why: **D-26**, in `BOARD-LEDGER.md`).
|
||||||
|
|
||||||
## Fleet seats
|
## Fleet seats
|
||||||
|
|
||||||
- mos-remediation — project orchestrator (Claude, /src/mosaic-stack, socket `mosaic-fleet`) — ACTIVE
|
Roster rolled verbatim to [`BOARD-LEDGER.md`](./BOARD-LEDGER.md); live truth is `mosaic fleet ps`.
|
||||||
- planner-opus — adversarial planner (robustness), Opus 5, socket `default` — DELIVERED, idle
|
|
||||||
- planner-sol — adversarial planner (pragmatic), gpt-5.6-sol, socket `default` — DELIVERED, idle
|
|
||||||
- rev-974 — mosaicstack reviewer identity (id 16, write:repository) — idle, on call
|
|
||||||
- Mos (mos-claude) — lead coordinator, socket `default` — relay path to Jason
|
|
||||||
|
|
||||||
## Gate status
|
## Gate status
|
||||||
|
|
||||||
- Delivery gates active: author≠reviewer, diff-blind pre-registered checks, CI-green, merged-PR completion.
|
|
||||||
- Freeze: LIFTED for this workstream only.
|
- Freeze: LIFTED for this workstream only.
|
||||||
- Git identity: `MOSAIC_GIT_IDENTITY=mos-dt-0` INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what
|
- Git identity: orchestrator runs `MOSAIC_GIT_IDENTITY=mos-dt-0` INTERIM. Mos ruled gate-16 HOLDS (author≠reviewer is what
|
||||||
gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
|
gate-16 protects; rev-974 reviews, mos-dt-0 never self-reviews). Dedicated identity TRACKED, Mos provisions.
|
||||||
- Capability check (D-11b): before dispatching seat X to provider Y, verify
|
- Capability + seat identity (**D-11b / D-11a**, incl. the false-NEGATIVE twin): authoritative in
|
||||||
`~/.config/mosaic/secrets/gitea-tokens/gitea-<Y>-<X>.token` exists. Token-file set = authoritative
|
`TASKS.md`. Short form — **assert the DIFFERENTIAL as that seat** (authenticated `push:true` vs
|
||||||
capability registry. Mos owns provisioning; escalate missing pairs to him.
|
unauthenticated `push:false`); a single endpoint can be true for anyone or 403 for an unrelated
|
||||||
- Seat identity (D-11a): token identity AND `git config user.name`/`user.email` must BOTH be set and
|
scope. Full text rolled to [`BOARD-LEDGER.md`](./BOARD-LEDGER.md).
|
||||||
agree. Exporting `MOSAIC_GIT_IDENTITY` alone does NOT fix commit authorship.
|
- ⚠ **LIVE HAZARD (D-37) — one shared `.git/config` re-identifies EVERY worktree at once.** Every seat,
|
||||||
- Standing worker-brief doctrine (accreted, mandatory in every brief): don't weaken a RED test to make
|
including `rev-974`'s review worktree, currently authors as **`coder-mos1`**; `MOSAIC_GIT_IDENTITY`
|
||||||
it pass; if a check is unrunnable as written SAY SO, never silently substitute; `agent-send -f` never
|
does **not** override it. **STANDING ORDER: commit with explicit
|
||||||
`-m`; heavy artifacts off shared `/tmp`.
|
`git -c user.name=<seat> -c user.email=<seat>@…`, and NOBODY rewrites the shared config mid-flight.**
|
||||||
|
Real fix authorised, Mos owns it, sequenced at a quiet seam. **#1024 implicated.** Detail: D-37.
|
||||||
|
- Standing worker-brief doctrine (mandatory in EVERY brief): re-export `MOSAIC_GIT_IDENTITY` (**D-34**);
|
||||||
|
commit early/WIP (**D-31**); don't weaken a RED test to pass; if a check is unrunnable SAY SO, never
|
||||||
|
substitute; `agent-send -f` never `-m`; artifacts off shared `/tmp`; scan CI from `-f json` (**D-33**);
|
||||||
|
**relay observations into an open review, NEVER your own conclusion on an open check (D-39)**; the
|
||||||
|
**author never adjudicates their own PR's blocker status** — surface evidence, prepare the fix, hold.
|
||||||
- Remote control: native `/remote-control` NOT wired in this runtime. Path is **Mos-relay**
|
- Remote control: native `/remote-control` NOT wired in this runtime. Path is **Mos-relay**
|
||||||
(Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.
|
(Jason ↔ mos-claude via Discord ↔ mos-remediation via agent-send). Not a blocker.
|
||||||
|
|
||||||
## Sequencing (from MISSION.md)
|
## Decisions log — full record in [`TASKS.md`](./TASKS.md)
|
||||||
|
|
||||||
1. Spine + choke-point service (MACP wiring @ mosaic_orchestrator.py::run_single_task) + PG/Redis
|
All 58 findings (D-1…D-6 in `BOARD-LEDGER.md`, D-7…D-55c + D-38c in `TASKS.md`) and every ruling with
|
||||||
⚠ **CONTESTED — see DECISION-1.** Both planners independently reject this wire-in point: that
|
its rationale live there. **Not duplicated here.** The history of _why_ this board must not restate —
|
||||||
controller is `"enabled": false` and references a dispatcher that does not exist here. Charter text
|
six stale copies across two seams — is rolled verbatim into [`BOARD-LEDGER.md`](./BOARD-LEDGER.md).
|
||||||
left UNCHANGED pending Mos/Jason ruling; do not treat it as settled.
|
|
||||||
2. Rotation daemon (finish Mission Control Plane, reuse packages/coord)
|
|
||||||
3. Comms service (envelope→service→PG/Redis→adapters)
|
|
||||||
4. Hygiene + conformance harness
|
|
||||||
Cross-cutting retirements: flat-file tracking, 3 MACP islands, silent MOSAIC BYPASS.
|
|
||||||
|
|
||||||
## Dogfood evidence — live failure classes, not hypotheticals
|
|
||||||
|
|
||||||
> Newest first. Oldest entries roll to `BOARD-LEDGER.md` via `board-roll.sh` when this file
|
|
||||||
> exceeds its 8 KB cap. Keystone detail is duplicated in `TASKS.md` §1a, so rolling loses nothing.
|
|
||||||
|
|
||||||
<!-- BOARD-ROLL:START -->
|
|
||||||
|
|
||||||
### **D-8 / P-CONFORMANCE-001 — a PRE-REGISTERED acceptance check that was not runnable as written.**
|
|
||||||
|
|
||||||
PR #1025 AC2's fixture `mkdir -p apps/*/venv/lib` creates a literal `apps/*/venv/lib` dir when the glob is unmatched — it did not test what it claimed. rev-974 ran it exactly as written, caught it, re-ran the intended assertion at an explicit path, and **disclosed** rather than silently substituting a working fixture and reporting PASS. **Pre-registration protects a check from being retrofitted to the implementation; it does not make the check correct.** An unverified gate appeared inside the mechanism built to catch unverified gates. Hard requirement on RM-02: the registry must self-verify that every registered case runs AND can fail — presence is not evidence.
|
|
||||||
|
|
||||||
### **D-7 / P-FLEET-001 — stale-GC-on-disk: shared 30G /tmp hit 100% ENOSPC, degrading two seats.**
|
|
||||||
|
|
||||||
~5.2G was session scratch dead 8-9 days (this session's own footprint: 88K). Same missing capability as orphaned-tmux-session GC, applied to disk — not a quota or discipline problem. Resolved manually by Mos (lead coordinator) after independent verification; `/tmp` now 79%. **The gap IS the finding:** the authority to reap exists, the deterministic reaper does not. Folded into RM-50 with explicit requirements (mechanical liveness, age threshold, dry-run, audit event per reap — never a heuristic sweep). Refusing to unilaterally delete another session's scratch was correct doctrine; the fix is a reaper, not braver agents.
|
|
||||||
|
|
||||||
### **D-6 / P-QUEUE-001 — the mandated queue guard returned PASS on an UNKNOWN state, live, today.**
|
|
||||||
|
|
||||||
Running the required `ci-queue-wait.sh --purpose push` before pushing produced `state=unknown ... exit 0` — the exact defect at `ci-queue-wait.sh:282-288` that PR #1023 is parked on. It also evaluated `branch=main` rather than the branch being pushed. The mission's own required pre-push gate passed me on an indeterminate result. Third independent live instance of the class.
|
|
||||||
|
|
||||||
<!-- BOARD-ROLL:END -->
|
|
||||||
|
|
||||||
## Decisions log
|
|
||||||
|
|
||||||
- 2026-07-31 — Mission set up by Mos post-postmortem (15/15 decided). Dogfood posture active.
|
|
||||||
- 2026-07-31 — Mos: stale `.mosaic/orchestrator/mission.json` is RESIDUE of the disabled Python
|
|
||||||
orchestrator rail that this plan RETIRES. Do NOT invest in it; do NOT build on that rail. The 0/0
|
|
||||||
milestone banner is cosmetic. (Supersedes any plan to repair it.)
|
|
||||||
- 2026-07-31 — Mos: planners must be dispatched with GUARANTEED clean context, not requested-clean.
|
|
||||||
Prior default-socket planner sessions predate this mission; dirty context is the indicted hygiene.
|
|
||||||
- 2026-07-31 — mos-remediation: worker briefs forbid all git ops and restrict each worker to a single
|
|
||||||
named output file, so two planners can share one checkout without a branch race (M2-era incident doctrine).
|
|
||||||
|
|||||||
@@ -25,8 +25,18 @@ mechanically until Build 3 (rotation) makes it automatic.
|
|||||||
## Standing invariants (never violate)
|
## Standing invariants (never violate)
|
||||||
|
|
||||||
- **North star:** deterministic-right-answer → code/gate; LLM only for judgment.
|
- **North star:** deterministic-right-answer → code/gate; LLM only for judgment.
|
||||||
- **Delivery gates:** author≠reviewer; PRE-REGISTERED diff-blind checks committed before reading the diff;
|
- **Delivery gates — REFERENCE the canonical files, never restate them:**
|
||||||
CI terminal-green; completion = merged PR + closed issue. rev-974 = the mosaicstack reviewer identity.
|
`~/.config/mosaic/fleet/roles.local/merge-gate.md` (verdict authority) and
|
||||||
|
`~/.config/mosaic/fleet/roles/validator.md` (validator role). Order:
|
||||||
|
independent review (author ≠ reviewer, `rev-974`; pre-registered diff-blind checks committed before the
|
||||||
|
diff is read) → remediation → **CI terminal-green at the exact head by full step scan** →
|
||||||
|
**merge-gate verdict `GO`/`NO-GO`/`HOLD`**, commit-bound and **void the instant the head moves**, posted
|
||||||
|
durably with enumerated evidence under its own minted identity → **coordinator head-pinned merge**.
|
||||||
|
The queue guard runs but is **zero-information until RM-03 lands** (D-23) and must not be cited as evidence.
|
||||||
|
**After a `GO`, freeze pushes** — even a doc tweak voids the verdict. The coordinator assigns the gate seat.
|
||||||
|
- **Query for refutation, never for confirmation.** A subordinate asked to confirm a hypothesis will
|
||||||
|
agree — the bias is in the question, not the answerer, and agent seats are agreeable by construction.
|
||||||
|
State the hypothesis as yours, ask for the evidence that KILLS it, and reproduce when it matters.
|
||||||
- **Dogfooding:** every fix validated against its live seed case (MISSION.md lists them).
|
- **Dogfooding:** every fix validated against its live seed case (MISSION.md lists them).
|
||||||
- **Tracking → DB** (hard cutover); do NOT re-invest in flat-file tracking. jarvis-brain PDA is off-limits.
|
- **Tracking → DB** (hard cutover); do NOT re-invest in flat-file tracking. jarvis-brain PDA is off-limits.
|
||||||
- **Git identity:** export `MOSAIC_GIT_IDENTITY=<your-seat>` so wrappers author correctly and survive respawn.
|
- **Git identity:** export `MOSAIC_GIT_IDENTITY=<your-seat>` so wrappers author correctly and survive respawn.
|
||||||
|
|||||||
+143
-2
@@ -91,6 +91,99 @@ gate/program; the LLM handles only genuine judgment.
|
|||||||
> seat in the loop. Residual risk bound to **RM-59** (`depends_on: RM-12, RM-21, RM-25`), where the
|
> seat in the loop. Residual risk bound to **RM-59** (`depends_on: RM-12, RM-21, RM-25`), where the
|
||||||
> choke-point executor and spine verify from _outside_ the worktree's authority.
|
> choke-point executor and spine verify from _outside_ the worktree's authority.
|
||||||
|
|
||||||
|
### First-class principle — query for refutation, never for confirmation
|
||||||
|
|
||||||
|
> **A subordinate asked to confirm a hypothesis will agree. Ask it to refute, with evidence.**
|
||||||
|
>
|
||||||
|
> The bias is induced by the **query**, not by the answerer's diligence. _"The DB flaked — please
|
||||||
|
> confirm"_ and _"confirm or refute this, with the log line that proves it"_ are different instruments,
|
||||||
|
> and they return different answers to the same question. The first harvests agreement; only the second
|
||||||
|
> can return **"you are wrong, and here is why."**
|
||||||
|
>
|
||||||
|
> This matters most with agent subordinates, which are **agreeable by construction**: fluent, eager to
|
||||||
|
> be useful, and structurally disinclined to tell the dispatcher their premise is false. A confirmation
|
||||||
|
> query aimed at one is close to a guaranteed yes — so the discipline cannot rest on the answerer being
|
||||||
|
> rigorous. **It has to be built into how the question is asked.**
|
||||||
|
>
|
||||||
|
> Promoted to the charter by Mos (2026-08-01). Origin: the orchestrator hypothesised that a coincident
|
||||||
|
> `ci-postgres` failure caused a CI test failure and asked the implementing seat to **confirm or refute**
|
||||||
|
> it. The seat **refuted it** with the log (`ci-postgres:5432 - accepting connections`, migrations
|
||||||
|
> completed) and identified the real cause. Reproduction on an identical head then settled it. Had the
|
||||||
|
> query been phrased for confirmation, the agreement would have been returned, **D-21 would have been
|
||||||
|
> re-classified on a false premise**, and a banked finding would have been silently corrupted.
|
||||||
|
>
|
||||||
|
> **Operationally:** state your hypothesis explicitly, mark it as yours, ask for _evidence that kills
|
||||||
|
> it_, and say what evidence would change your mind. A hypothesis you cannot describe how to falsify is
|
||||||
|
> not yet a hypothesis. Where the answer is consequential, **reproduce** rather than accept — two
|
||||||
|
> independent runs beat one confident report.
|
||||||
|
|
||||||
|
### First-class principle — the anchor must live outside the audited party's authority
|
||||||
|
|
||||||
|
> **You cannot fix "the author controls X" by deriving X from something the author ALSO controls.**
|
||||||
|
> Deriving merely **moves** the control point; it does not remove it.
|
||||||
|
>
|
||||||
|
> Promoted to the charter by Mos (2026-08-01) on the **THIRD INDEPENDENT ARRIVAL** of the same
|
||||||
|
> conclusion, each reached while trying to ship something else, each from a different direction:
|
||||||
|
>
|
||||||
|
> | arrival | the audited party controls… | found as |
|
||||||
|
> | ----------------- | ------------------------------------------------------------------- | -------- |
|
||||||
|
> | manifest | the tree that certifies its own generated state (same-UID, CWE-345) | **D-19** |
|
||||||
|
> | sandbox | the code that enters the sandbox, before the boundary exists | **D-25** |
|
||||||
|
> | **registry seam** | **WHEN the tracked path is introduced, hence the derived boundary** | **D-45** |
|
||||||
|
>
|
||||||
|
> Round 1 the value was an author-settable **field**, so it was **derived**. Round 2 the derivation
|
||||||
|
> depended on **when the author introduces the path**. Same authority, new costume. **Three
|
||||||
|
> impossibility-derivations of one conclusion is not a coincidence to note — it is the strongest
|
||||||
|
> architectural evidence this mission has produced**, and it is precisely what **forces Builds 1–2**
|
||||||
|
> rather than making them a preference.
|
||||||
|
>
|
||||||
|
> **Operationally:** anchor to a reference the audited party cannot move. A git **merge-base against
|
||||||
|
> `main`** is such a reference for a PR author (they own their branch; they do not own `main`).
|
||||||
|
> **State the bootstrap in BOTH directions (D-19):** that anchor is sound against an author who cannot
|
||||||
|
> rewrite `main` — the threat in scope — and **NOT** sound against an attacker who can. **That residual
|
||||||
|
> is what Builds 1–2 close, and it must be recorded as a tracked dependency, never implied.**
|
||||||
|
|
||||||
|
### First-class principle — no universally-quantified check may pass over an empty set
|
||||||
|
|
||||||
|
> **"All registered cases ran" is VACUOUSLY TRUE when there are no registered cases.**
|
||||||
|
> **Non-emptiness and anchoring are PRECONDITIONS asserted before the quantified check runs — not
|
||||||
|
> properties hoped for after it.**
|
||||||
|
>
|
||||||
|
> Promoted by Mos (2026-08-01) after the identical vacuity appeared **twice, at two different levels**:
|
||||||
|
> `activationCommit = HEAD` emptied the **commit range** (D-44), and an emptied manifest — `criteria`,
|
||||||
|
> `gates`, `proseClaims`, `compatibilityScenarios` all `[]` — emptied the **registry population**
|
||||||
|
> (D-46), each yielding **exit 0**. The first was fixed **as an instance**; the principle was never
|
||||||
|
> extracted, **so it returned one level up.**
|
||||||
|
>
|
||||||
|
> **Delete every gate and every criterion TOGETHER and no remaining reference complains — because every
|
||||||
|
> reference went with them.** A check that quantifies over a population must actually **range** over it,
|
||||||
|
> and that population must be **provably complete and non-empty**.
|
||||||
|
>
|
||||||
|
> **Corollary (same disease):** a clause written for the instance that produced it is not a clause.
|
||||||
|
> **Do not relabel the originating instances as the general clauses** — quantify over the population.
|
||||||
|
|
||||||
|
### First-class principle — redundant observation on evidence-bearing steps
|
||||||
|
|
||||||
|
> **Two observers of the same evidence, disagreeing, catch what neither catches alone.** Apply redundancy
|
||||||
|
> not only to judgement calls but to **evidence gathering itself** — the step everyone assumes is
|
||||||
|
> mechanical and therefore skips.
|
||||||
|
>
|
||||||
|
> Promoted by Mos (2026-08-01) from **D-33**. A seat scanned a pipeline with `-f json` and reported 9
|
||||||
|
> steps; the orchestrator scanned the same pipeline in the wrapper's default text mode and reported 8.
|
||||||
|
> **The default output omits `clone`.** Every "full step scan" that night had been 8-of-9 and was stated
|
||||||
|
> as complete in good faith. No verdict changed — but the _method_ was wrong, invisibly, and **only the
|
||||||
|
> disagreement between two counts surfaced it.**
|
||||||
|
>
|
||||||
|
> The reason it survived: **a summary that resembles an enumeration is more dangerous than one that
|
||||||
|
> obviously summarises.** A labelled list of named steps with states _looks_ like the artifact, so nobody
|
||||||
|
> checks it against the record. Compare D-24 — `mergeable` was a _true answer to a different question_;
|
||||||
|
> this was a _true answer to a smaller one_. Neither is a lie; both pass every sniff test.
|
||||||
|
>
|
||||||
|
> **Operationally:** where a step _produces evidence a decision rests on_, have it produced twice by
|
||||||
|
> different means, and treat **any divergence as a finding rather than as noise to reconcile**. Prefer the
|
||||||
|
> machine-readable record over the human-readable rendering — _read the artifact, not the summary_ — and
|
||||||
|
> state the counts observed so a divergence is detectable at all.
|
||||||
|
|
||||||
## Decision record (authoritative, immutable)
|
## Decision record (authoritative, immutable)
|
||||||
|
|
||||||
- **15/15 proposals decided: 13 accept, 2 modify (P-AUTHORITY-001, P-INBOX-001), 0 reject.**
|
- **15/15 proposals decided: 13 accept, 2 modify (P-AUTHORITY-001, P-INBOX-001), 0 reject.**
|
||||||
@@ -109,6 +202,31 @@ gate/program; the LLM handles only genuine judgment.
|
|||||||
| **4. Comms service** | AUTHORITY, INBOX (+ versioning roadmap) | Envelope (comms/v1) → sole-path service → PG/Redis → pluggable adapters (tmux→Matrix/Discord/Slack/Telegram). Version the protocol, not participants. |
|
| **4. Comms service** | AUTHORITY, INBOX (+ versioning roadmap) | Envelope (comms/v1) → sole-path service → PG/Redis → pluggable adapters (tmux→Matrix/Discord/Slack/Telegram). Version the protocol, not participants. |
|
||||||
| **+ Hygiene & proof** | FLEET, WORKFLOW, CONFORMANCE | One roster-owned socket/host + stale GC; allowlist auto-sync; the conformance harness that fault-injects the failure classes and proves builds 1–4 hold. |
|
| **+ Hygiene & proof** | FLEET, WORKFLOW, CONFORMANCE | One roster-owned socket/host + stale GC; allowlist auto-sync; the conformance harness that fault-injects the failure classes and proves builds 1–4 hold. |
|
||||||
|
|
||||||
|
## Why Builds 1–2 are necessary — two independent impossibility proofs
|
||||||
|
|
||||||
|
**The choke-point executor and PG spine are not a design preference. They are forced.** Twice during
|
||||||
|
the mission's own first deliveries, work stopped against a security property that **cannot exist** at
|
||||||
|
the layer that needed it — and both times the only resolution was an authority _outside_ the audited
|
||||||
|
party's control, which is precisely what Builds 1–2 provide.
|
||||||
|
|
||||||
|
| | the audited party controls… | so what fails | found as |
|
||||||
|
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------- | --------------- | -------- |
|
||||||
|
| **Artifact integrity** | the manifest that certifies its own generated tree (same-UID write ⇒ regenerate manifest _and_ marker consistently, CWE-345) | tamper-evidence | **D-19** |
|
||||||
|
| **Execution integrity** | the code that enters the sandbox (PR-controlled config executes _before_ the boundary exists) | isolation | **D-25** |
|
||||||
|
|
||||||
|
Both reduce to one sentence:
|
||||||
|
|
||||||
|
> **Self-verification by the audited party is not verification.**
|
||||||
|
|
||||||
|
And to one consequence: **the anchor must live outside the audited party's authority.** A local check
|
||||||
|
cannot defend against an actor who can rewrite the check; a repo cannot grant a capability to
|
||||||
|
PR-controlled config and simultaneously prevent that config from using it.
|
||||||
|
|
||||||
|
**An architecture forced by two independent impossibility proofs is stronger evidence than one argued
|
||||||
|
for.** Neither proof was sought — both arrived while trying to ship something else, from different
|
||||||
|
directions (a symlink manifest; a CI sandbox), at different layers. RM-59 and RM-60 are the two tracked
|
||||||
|
dependencies this creates, and they are the same dependency in different clothes.
|
||||||
|
|
||||||
## The finding that sets the cost
|
## The finding that sets the cost
|
||||||
|
|
||||||
**Built-but-unwired disease.** `@mosaicstack/macp` is stranded (nothing calls it); `packages/coord` primitives
|
**Built-but-unwired disease.** `@mosaicstack/macp` is stranded (nothing calls it); `packages/coord` primitives
|
||||||
@@ -161,6 +279,29 @@ orphaned context loader, a fail-open bypass. **Work = wire + consolidate + retir
|
|||||||
- **Project orchestrator** `mos-remediation` (this seat) owns the mission; coordinates under Mos (lead).
|
- **Project orchestrator** `mos-remediation` (this seat) owns the mission; coordinates under Mos (lead).
|
||||||
- **Adversarial task decomposition:** `planner-opus` (robustness) + `planner-sol` (pragmatic) each decompose
|
- **Adversarial task decomposition:** `planner-opus` (robustness) + `planner-sol` (pragmatic) each decompose
|
||||||
the plan independently; orchestrator reconciles into `TASKS.md`/DB tasks. Oppositional by design.
|
the plan independently; orchestrator reconciles into `TASKS.md`/DB tasks. Oppositional by design.
|
||||||
- **Delivery gates (non-negotiable):** author≠reviewer, PRE-REGISTERED diff-blind acceptance checks committed
|
- **Delivery gates — REFERENCE, do not restate.** The authoritative definitions live at
|
||||||
before reading the diff, CI terminal-green, completion = merged PR + closed issue. rev-974 = mosaicstack reviewer.
|
[`~/.config/mosaic/fleet/roles.local/merge-gate.md`](file:///home/hermes/.config/mosaic/fleet/roles.local/merge-gate.md)
|
||||||
|
(verdict authority) and
|
||||||
|
[`~/.config/mosaic/fleet/roles/validator.md`](file:///home/hermes/.config/mosaic/fleet/roles/validator.md)
|
||||||
|
(validator/certificate role). **Read them; do not paraphrase them.** Restating an authoritative source
|
||||||
|
is lossy every time — see D-26, where a subset restated from memory dropped a security precondition.
|
||||||
|
|
||||||
|
**Gate order** (the sequence only; the definitions are in the files above):
|
||||||
|
1. Independent review, **author ≠ reviewer** (`rev-974` on mosaicstack), with PRE-REGISTERED diff-blind
|
||||||
|
acceptance checks committed before the diff is read
|
||||||
|
2. Remediation of findings
|
||||||
|
3. **CI terminal-green** at the exact full-40 head, by **full step scan**
|
||||||
|
4. **Merge-gate verdict — `GO` / `NO-GO` / `HOLD`** (class `merge-gate`; "Ultron" is an _instance name_,
|
||||||
|
display data, never an authority source). **Bound to a commit and VOID the instant the head moves.**
|
||||||
|
`HOLD` persists until replaced; a `NO-GO` answered by an empty commit must be re-issued as `NO-GO`.
|
||||||
|
Posted durably on the PR under the gate's own minted identity, **enumerating** its evidence — a bare
|
||||||
|
"GO — gates verified" is non-conforming.
|
||||||
|
5. **Coordinator merge**, head-pinned. The gate never merges; it holds `push=False` by design.
|
||||||
|
|
||||||
|
⚠ **The CI queue guard runs but is ZERO-INFORMATION until RM-03 lands** (D-23: it returns pass for every
|
||||||
|
possible input). It must not be cited as evidence by any gate, including the coordinator's own merge path.
|
||||||
|
|
||||||
|
**Assignment:** the coordinator assigns the merge-gate seat; the orchestrator does not. The orchestrator
|
||||||
|
owns getting a PR _gate-ready_.
|
||||||
|
|
||||||
- **Compaction survival:** see `KICKSTART.md` in this dir — the resume procedure. Persist typed state, not transcript.
|
- **Compaction survival:** see `KICKSTART.md` in this dir — the resume procedure. Persist typed state, not transcript.
|
||||||
|
|||||||
+2090
-12
File diff suppressed because it is too large
Load Diff
@@ -1,118 +0,0 @@
|
|||||||
# RM-61 — CI contract exemption for #1000 teardown artifact
|
|
||||||
|
|
||||||
**Tracking:** RM-61 / issue #1000
|
|
||||||
|
|
||||||
**Branch:** `fix/rm-61-ci-contract-exemption`
|
|
||||||
**Owner:** `coder-mos1`
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Determine, by red-first provider controls, whether the `ci-postgres` pod-not-found teardown signature discriminates from a real PostgreSQL failure. Only if it discriminates may a named, bounded CI-contract exemption be implemented. The exemption must retire when #1000 is fixed; fixing #1000 is the closure path.
|
|
||||||
|
|
||||||
## Pre-registered kill criterion
|
|
||||||
|
|
||||||
If an injected real `ci-postgres` failure also yields `pods "wp-svc-<ULID>-ci-postgres" not found` as the service's provider-visible failure, the signature does not discriminate. Option B is unsafe; stop exemption implementation and fall to Option A (#1000).
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
1. Capture full `-f json` records for the 11 supplied observations and state counts.
|
|
||||||
2. Run one startup-failure control using the real pgvector/PostgreSQL image with an invalid `initdb` argument.
|
|
||||||
3. Run one post-readiness crash control using real PostgreSQL, `pg_isready`, and a deliberate postmaster kill while a DB-dependent probe is active.
|
|
||||||
4. Compare the raw `ci-postgres` service record independently of failures in dependent steps.
|
|
||||||
5. Investigate runner/time/head clustering only as a hypothesis; never encode incidental correlates or retries into policy.
|
|
||||||
6. If and only if the controls discriminate, implement and test the exact exemption, document its two-way boundary, and track retirement at #1000.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
No explicit token cap supplied. Working estimate: 20K–30K tokens. Limit provider controls to the two pre-registered runs; no retries or re-roll policy.
|
|
||||||
|
|
||||||
## Initial evidence
|
|
||||||
|
|
||||||
Historical JSON saved locally under `.evidence/rm-61/` (not for commit). Supplied pipelines: 11 total. Child-step counts: five pipelines with 9 children and six with 10 children. Seven contain the `ci-postgres` pod-not-found failure (#2170, #2175, #2180, #2181, #2182, #2187, #2188); four do not (#2158, #2167, #2184, #2186). Every observed workflow reports `agent_id=44`, so the available JSON does not separate clean and artifact runs by runner. This refutes runner identity as a discriminator in the sampled record.
|
|
||||||
|
|
||||||
## Progress
|
|
||||||
|
|
||||||
- [x] Requirements and kill criterion recorded before control implementation.
|
|
||||||
- [x] Historical full-JSON records captured.
|
|
||||||
- [x] Startup-failure control observed terminal.
|
|
||||||
- [x] Post-readiness crash control observed terminal.
|
|
||||||
- [x] Discrimination verdict recorded: Option B may proceed.
|
|
||||||
- [x] Conditional exemption implementation.
|
|
||||||
|
|
||||||
## Tests / evidence
|
|
||||||
|
|
||||||
### Control 1 — real startup failure
|
|
||||||
|
|
||||||
- Commit: `3931b0e29eb834914f7b17e4db7e221481d436fa`
|
|
||||||
- Pipeline: #2189, exact commit match.
|
|
||||||
- Full JSON child scan: 9 total — 7 success, 2 failure, 0 skipped/pending/running.
|
|
||||||
- `ci-postgres`: `state=failure`, `exit_code=1`, `error=null`, with a five-second execution window.
|
|
||||||
- `test`: `state=failure`, `exit_code=1` after the readiness budget expired.
|
|
||||||
- Pipeline/workflow: terminal `failure`.
|
|
||||||
|
|
||||||
This control is red and its service record differs from #1000 (`exit_code=0` plus pod-not-found). It proves the startup-failure direction only. It does not settle the dangerous post-readiness crash/garbage-collection path.
|
|
||||||
|
|
||||||
### Control 2 — real post-readiness crash
|
|
||||||
|
|
||||||
- Commit: `25ac59715a94dd1b52ef42577472eb44ecc4b446`
|
|
||||||
- Pipeline: #2191, exact commit match.
|
|
||||||
- Full JSON child scan: 9 total — 7 success, 2 failure, 0 skipped/pending/running.
|
|
||||||
- Service log proves PostgreSQL reached `database system is ready to accept connections`, the test created the arm table, and the service then killed postmaster PID 7.
|
|
||||||
- Test log proves a successful `SELECT 1` followed by `Connection refused`; it exited the pre-registered control code 61.
|
|
||||||
- `ci-postgres`: `state=failure`, `exit_code=137`, `error=null`, with a 203-second execution window.
|
|
||||||
- `test`: `state=failure`, `exit_code=61`.
|
|
||||||
- Pipeline/workflow: terminal `failure`.
|
|
||||||
|
|
||||||
This is the dangerous post-readiness crash path. Its service record is not pod-not-found and therefore differs from #1000 independently of the dependent test failure.
|
|
||||||
|
|
||||||
### Discrimination verdict
|
|
||||||
|
|
||||||
Both real failures are provider-visible as process exits (`exit_code=1` startup; `exit_code=137` crash) with no pod-not-found error. The seven observed #1000 artifacts are provider reconciliation misses (`exit_code=0` plus the exact pod-not-found error). The declared kill criterion did not fire, so Option B may proceed with a matcher requiring the full conjunction. This evidence does **not** prove every future Kubernetes failure is distinguishable; it proves these two concrete real-failure classes remain blocking and bounds the exemption to the observed reconciliation shape.
|
|
||||||
|
|
||||||
### Unit red-first checkpoint
|
|
||||||
|
|
||||||
The nine-case contract harness was written before the verifier. First execution exited 1 because `verify-terminal-green.py` did not exist; no exemption implementation was live. Cases pre-register ordinary green, the exact artifact, both provider controls, near-miss signatures, an independent failure, and a skipped step.
|
|
||||||
|
|
||||||
### Control 2 setup attempt — invalid, excluded from evidence
|
|
||||||
|
|
||||||
- Commit: `9455cd6a2650b2b7e70f746c07933d96e5cb3d20`
|
|
||||||
- Pipeline: #2190, exact commit match.
|
|
||||||
- Full JSON child scan: 9 total — 7 success, 2 failure, 0 skipped/pending/running.
|
|
||||||
- Service log: `/bin/sh: 0: -c requires an argument`.
|
|
||||||
- Root cause: Woodpecker service `commands` did not become the third `sh -c` argument. PostgreSQL never started, so this run is **not** the post-readiness crash control and provides no discrimination evidence.
|
|
||||||
- Focused remediation: place the script directly in the third `entrypoint` element and supply `PGPASSWORD` for the marker query. This is a control-fixture correction, not a retry of #1000 and not evidence for either verdict.
|
|
||||||
|
|
||||||
## Implementation evidence
|
|
||||||
|
|
||||||
- `verify-terminal-green.py` consumes only the full JSON/API record; it performs no fetch, retry, or trigger.
|
|
||||||
- Exact #2188 record: exit 0, 10 children, 9 success + 1 named exemption.
|
|
||||||
- Historical set: #2158/#2167/#2184/#2186 pass with no exemption; #2170/#2175/#2182/#2187/#2188 pass with one named exemption; #2180/#2181 remain red because independent failures exist.
|
|
||||||
- Provider controls: #2189 and #2191 both exit 1 under the verifier; neither is exempted.
|
|
||||||
- Unit harness: initial 9/9 cases passed after the red-first checkpoint; review remediation expands this to 12 cases with expected-head match/missing/mismatch coverage.
|
|
||||||
- Test-membership guard: PASS, population 45; 26 enumerated, 19 signed exclusions; all 39 surface paths present.
|
|
||||||
- Python compile: PASS.
|
|
||||||
- `pnpm typecheck`: PASS, 45/45 tasks.
|
|
||||||
- `pnpm lint`: PASS, 25/25 tasks.
|
|
||||||
- `pnpm format:check`: PASS after moving local evidence outside the repository tree.
|
|
||||||
- `test:framework-shell`: RM-61 and all preceding suites passed, then the pre-existing wake assertion aborted with exit 97 because this host's Bash 5.2.15 reports `BASH_LINENO [3 5]` where that suite requires `[3 4]`. RM-61 does not modify the wake suite; the command is not fully runnable on this host as written and no substitute result is claimed.
|
|
||||||
|
|
||||||
## Independent review
|
|
||||||
|
|
||||||
- Review 67 / comment 20403 at exact head `e7b29219e11efd0a19395156ac0b154bec0c3a73`: **REQUEST CHANGES**.
|
|
||||||
- Blocker: the verifier echoed the pipeline commit but did not bind it to the current PR head; mutating only #2188's commit still returned terminal-green.
|
|
||||||
- Remediation: require `--expect-commit <full-40>`, add a pipeline anomaly on missing/mismatched record commits, emit expected and observed values, wire both CI documentation and the merge-gate baseline to pass provider PR head, and add match/missing/mismatch tests.
|
|
||||||
- This binding is not prohibited head-based clustering policy: it proves the evidence belongs to the commit under verdict. Runner/node/time/head correlation remains excluded from the teardown signature itself.
|
|
||||||
- Review 69 later approved the commit-binding remediation at exact head `033b2ffb46674b2c0bcc5197273c109b461f62d9`; pipeline #2193 was 9/9 success. Before merge-gate, an independent adjudicator found that Python treats JSON `false == 0`, allowing a non-integer exit value to match. The prior gate-ready state was withdrawn. The type-strict set distinguishes genuine red-first controls (`false`, `0.0`, which wrongly exempted) from regression guards (`true`, `"0"`, `null`, which already blocked). Remediation requires the decoded type to be exactly `int` and excludes `bool` explicitly.
|
|
||||||
|
|
||||||
## Documentation checklist
|
|
||||||
|
|
||||||
- [x] CI contract documented in the canonical framework CI/CD guide.
|
|
||||||
- [x] Operator command documented in the Woodpecker tool README.
|
|
||||||
- [x] Merge-gate baseline points to the deterministic verifier and named retirement.
|
|
||||||
- [x] Tracking and retirement cite issue #1000.
|
|
||||||
- [x] Both positive and negative guarantee boundaries are stated.
|
|
||||||
- [x] No API/auth/schema/user-facing navigation change; OpenAPI, user guide, and sitemap are not applicable.
|
|
||||||
|
|
||||||
## Risks
|
|
||||||
|
|
||||||
The controls establish discrimination for deterministic startup failure and an armed post-readiness postmaster crash on the current Woodpecker Kubernetes provider. They cannot prove that every future Kubernetes failure mode will preserve a non-zero exit before reconciliation. The exact matcher minimizes that residual risk, and issue #1000 remains the mandatory provider-seam closure and retirement trigger.
|
|
||||||
@@ -1,71 +0,0 @@
|
|||||||
# #1019 — Zero-timeout queue-guard harness race
|
|
||||||
|
|
||||||
- **Issue:** #1019 (parent status remains `believed-fixed, pending jarvis validation`; do not close)
|
|
||||||
- **Branch:** `fix/1019-ci-queue-timeout-harness`
|
|
||||||
- **Owner:** `be-coder-08`
|
|
||||||
- **Base:** `origin/main` at `5916aeefd6ed12bcac086c6834c7f6c4ae38e1bc`
|
|
||||||
- **Charter:** `/home/hermes/agent-work/tl-mosaic/CHARTER-1019-HARNESS-FIX.md`
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Make `test-ci-queue-wait-tristate.sh` deterministic without changing any asserted outcome. Remove the indiscriminate zero-timeout race, require every status-classification case to prove the provider was observed, and prove the harness-controlled virtual clock is active.
|
|
||||||
|
|
||||||
## Scope
|
|
||||||
|
|
||||||
- In scope: `packages/mosaic/framework/tools/git/test-ci-queue-wait-tristate.sh` only, plus this evidence scratchpad.
|
|
||||||
- Out of scope: guard parsers, D2/D3 behavior, installer/reseed staleness, PR #1060, and issue closure.
|
|
||||||
|
|
||||||
## Acceptance criteria
|
|
||||||
|
|
||||||
1. RED deterministically reproduces deadline pre-emption before the provider call.
|
|
||||||
2. Every case that intends status classification positively proves provider observation.
|
|
||||||
3. Pending observes `pending` before deterministic virtual-time expiration.
|
|
||||||
4. The virtual clock has a positive interception control; a broken-clock mutant makes the suite red.
|
|
||||||
5. The exact CI-base image passes the final harness repeatedly with zero failures.
|
|
||||||
6. Baseline gates, independent code/security review, exact-head CI, and coordinator-authorized squash merge pass.
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
1. Add deterministic RED instrumentation for the known merge/provider-unreachable pre-emption.
|
|
||||||
2. Replace global `-t 0` with a nonzero timeout interpreted under an event-driven virtual clock; stub sleep without wall waiting.
|
|
||||||
3. Add provider-observation and virtual-clock positive controls without changing outcome assertions.
|
|
||||||
4. Run focused shell checks, repeat in exact CI-base image, baseline gates, and independent reviews.
|
|
||||||
5. Commit with both identity layers, queue-guard plus direct Woodpecker terminal-state verification, push, self-post PR, verify poster/head/CI, obtain coordinator merge authorization, then squash merge without closing #1019.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
- No explicit token cap supplied. Keep scope to one harness file and one scratchpad; stop/report at the charter's 60% context gate.
|
|
||||||
|
|
||||||
## Evidence
|
|
||||||
|
|
||||||
- RED, deterministic pre-provider expiry: `evidence/1019-harness-fix/red-pre-provider-expiry.log` — rc 1; merge/provider-unreachable got rc 124 instead of 75, omitted CANNOT_ASSERT, did not observe the status provider, and wrote no additional audit record (four named failures).
|
|
||||||
- GREEN host focused harness: `evidence/1019-harness-fix/green-host.log` — rc 0, all outcome classes passed.
|
|
||||||
- Load-bearing clock negative control: a temporary same-directory mutant replaced the virtual `date` body with `/bin/date`; `evidence/1019-harness-fix/red-clock-not-intercepted.log` — rc 1 with named `virtual clock interception did not run` failures. The mutant file was removed after the run.
|
|
||||||
- Exact CI-base repeat: `git.mosaicstack.dev/mosaicstack/stack/ci-base:latest`, repository mounted read-only, harness work under container `/tmp`; `evidence/1019-harness-fix/ci-image-repeat/summary.log` — **100 pass / 0 fail / 100 total**.
|
|
||||||
- Synchronization design: provider-status observation creates the event marker; virtual time is 1000 before the event and 1002 afterward. Pending alone reaches the stubbed no-op sleep and a post-observation deadline check. `-t 1` is uniquely load-bearing because removing it restores the 900-second default deadline at virtual time 1900, which 1002 does not cross. The numeric timeout is subject semantics under virtual time, not a wall-clock synchronization duration.
|
|
||||||
|
|
||||||
## Review remediation — semantic timeout vs. liveness bound
|
|
||||||
|
|
||||||
Security review found that virtual time remained at 1000 forever before provider observation and stubbed sleep never waited. A regression looping before the status endpoint—or blocking in the first provider call—therefore could prevent `run_guard` from returning, so the post-return provider assertion could never fire.
|
|
||||||
|
|
||||||
**General rule:** A timeout usually serves two purposes: semantics and liveness. Removing wall time from semantic synchronization can silently remove the only independent hang bound. Preserve deterministic virtual time for subject semantics, but provide a separately implemented real-clock liveness watchdog and prove that watchdog fires.
|
|
||||||
|
|
||||||
Remediation:
|
|
||||||
|
|
||||||
- Every guard subject invocation is launched by absolute `/usr/bin/python3` in a new session. Python's internal monotonic `wait(timeout=...)` provides real-clock liveness independently of PATH; expiry kills the entire isolated process group, so neither PATH-front shims nor a blocked provider descendant can retain the capture pipe.
|
|
||||||
- Watchdog expiry returns distinct harness rc 90 plus `FAIL HANG watchdog`, separate from subject timeout rc 124.
|
|
||||||
- A first attempt using absolute `/usr/bin/timeout -s KILL` passed on GNU coreutils but failed in the exact Alpine CI-base image: BusyBox killed the immediate wrapper while the guard/provider descendants survived and retained the command-substitution pipe. The process-group kill is therefore required behavior, not portability polish.
|
|
||||||
- A committed positive control hangs the branch-provider stub before the status endpoint. It must terminate through the watchdog, emit the hang-specific diagnostic, return rc 90, and prove the status provider was never reached.
|
|
||||||
- RED before remediation: a temporary ordinary-success mutant hung before provider observation; only an external control could kill the suite (rc 137), and there was no internal hang-specific diagnostic (`red-watchdog-absent.log`).
|
|
||||||
- The watchdog mutant/control is load-bearing: removing the internal watchdog leaves the control unable to produce its required rc 90 and diagnostic.
|
|
||||||
|
|
||||||
Post-review evidence:
|
|
||||||
|
|
||||||
- Host focused harness with process-group watchdog: rc 0 (`green-watchdog-process-group-host.log`).
|
|
||||||
- Exact Alpine CI-base focused harness with process-group watchdog: rc 0 (`green-watchdog-ci-image.log`).
|
|
||||||
- Hanging ordinary-success mutant: suite rc 1; success returned rc 90, emitted `FAIL HANG watchdog`, and loudly reported that provider/clock observation did not occur (`red-watchdog-fires.log`).
|
|
||||||
- Removed-`-t 1` mutant: suite rc 1; pending was terminated by the watchdog instead of producing `ASSERTED_NOT_READY`, proving the explicit timeout is load-bearing (`red-timeout-argument-removed.log`).
|
|
||||||
|
|
||||||
## 60% context hold
|
|
||||||
|
|
||||||
Stopped before baseline/review/commit as required by the charter. Remaining: inspect final diff, shell/static/baseline gates, independent code/security review, remediation if any, identity-bound commit/trailer verification, mandatory queue guard plus direct terminal Woodpecker `mosaic` enumeration, push, self-posted PR/provider poster read-back, exact-head terminal-green CI, coordinator merge authorization, squash merge, main CI verification, and leave #1019 unclosed as `believed-fixed, pending jarvis validation`.
|
|
||||||
@@ -1,110 +0,0 @@
|
|||||||
# MC-CRED-01 / stack #1045 scratchpad
|
|
||||||
|
|
||||||
Last updated: 2026-08-05
|
|
||||||
|
|
||||||
## Successor remediation (`be-coder-07`, PR #1059 review id 89)
|
|
||||||
|
|
||||||
Objective: close the four exact-head `rev-974` blockers without weakening any assertion, repair canonical-image test portability, and refresh the narrowed cooperative-concurrency claims and PR metadata. The provider-fetched starting head is `12958610cbafaa54a3db95327a7c3453d9111669` at merge-base `85d2108e4ed15c744ad3b87a5b629e7b2d39405a`.
|
|
||||||
|
|
||||||
Plan:
|
|
||||||
|
|
||||||
1. Preserve the journal-lock release assertion while replacing Alpine-invalid `/usr/bin/true` with canonical `/bin/true`.
|
|
||||||
2. Replace cross-system atomicity claims with exact all-or-verified-compensation semantics; retain atomic wording only for explicitly scoped single-file rename/replacement primitives and qualify team locking as cooperative advisory serialization.
|
|
||||||
3. Add red-first controls for complete journal writes under one-byte progress, rejection of zero/invalid progress, Tea generation equivalence under recursive key reorder, and durable indeterminate classification when team-lock release cannot be verified.
|
|
||||||
4. Implement bounded journal write-all, recursive canonical generation serialization, and release-before-seal team-lock cleanup classification; then run focused and baseline gates plus code/security advisories.
|
|
||||||
5. Commit with explicit `be-coder-07` identity, rebase rather than merge onto current `origin/main`, prove stable patch identity, run the required queue/direct-CI guards, and make one force-with-lease push pinned to the measured starting head.
|
|
||||||
|
|
||||||
Budget: hard context ceiling is 60%. Reuse predecessor evidence and avoid re-deriving unrelated 41-file history. Non-blocking secret zeroization is included only after all blockers are green. Stop and write a seam/report before the ceiling.
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Deliver the governed `mosaic cred` identity boundary for issue, scope, validation, rotation, and revocation across explicitly declared estates. The trunk-only ruling superseded the original `next` checkpoint: the branch is rebased onto `origin/main` and its PR target is `main`. Linked issues remain **believed-fixed, pending jarvis validation** after merge.
|
|
||||||
|
|
||||||
## Requirements sources
|
|
||||||
|
|
||||||
- Charter: `/home/hermes/agent-work/tl-mosaic/CHARTER-MC-CRED-01-be-coder-06.md`
|
|
||||||
- Stack issues: #1045, #1043, #1044, #1047, #1049, #1013, #1007; promotion #1037; consumer #1051
|
|
||||||
- Remote spec: `jason.woltje/jarvis-brain` origin/main `b7687d51f4efe52e43dbcd6dc95b5554b3332957`
|
|
||||||
- Greenfield PRD v3 addenda: INV-B durable journal, INV-C visible failure diagnostics, INV-D supported fixture
|
|
||||||
- Binding doctrine: `/src/jarvis-brain/infra/fleet/FLEET-DOCTRINE.md`
|
|
||||||
|
|
||||||
## Plan
|
|
||||||
|
|
||||||
1. Publish grant/validate v1 caller contract for MB-BRAIN-01.
|
|
||||||
2. Add repo PRD requirements and preregister acceptance tests.
|
|
||||||
3. Implement explicit estate registry, secure current file-store adapter, durable operation journal/audit, provider transport, and terminal result types.
|
|
||||||
4. Implement `grant` and side-effect-free `validate`; then provision/wire/get/whoami/list/rotate/revoke/audit.
|
|
||||||
5. Make git and API resolver refusals identical and fail closed under fleet context.
|
|
||||||
6. Reconcile live HOMELAB seats through each subject credential's own `/user`; #1044 hold is lifted, and its fail-closed change carries the pre-registered mechanism evidence (resolver refusal marker, same-run marker positive control, confirmed-lane negative arm).
|
|
||||||
7. Run baseline/situational tests, independent code review and mandatory independent security review, CI on the exact head, then open the PR directly against `main` without closing issues or claiming Jarvis validation.
|
|
||||||
8. C1 merges first. After any base/head move, re-derive merge-base, commit set, diff, CI, reviews, and provider measurements from the replacement SHA.
|
|
||||||
|
|
||||||
## Budget
|
|
||||||
|
|
||||||
No explicit token cap supplied. Working cap: keep implementation in one package plus shipped framework resolver changes and required docs/tests; avoid unrelated wrapper defect fixes and VaultWarden redesign. Escalate only if a charter requirement is technically unsatisfiable.
|
|
||||||
|
|
||||||
## Decisions
|
|
||||||
|
|
||||||
- VaultWarden is out for the agent tier per the charter verdict; phase 1 governs the existing per-identity file store.
|
|
||||||
- Estate is explicit input and must match a configured host mapping; target host is never inferred from machine location.
|
|
||||||
- Grant authority and basic-auth provisioning material are delegated control-plane credentials, never caller bearer material and never CLI argument/output.
|
|
||||||
- `ok`, `refused`, `error`, and `indeterminate` are distinct machine outcomes. Security callers fail closed on all but `ok`, while retaining the semantic distinction.
|
|
||||||
- Gitea write-differential resolves the subject once and binds provider identity, repository permission, and receive-pack to the same in-memory credential handle. It adds a distinct provider-confirmed read-only-principal control plus the unauthenticated control, with no ref update. The live HOMELAB negative-control subject is `tl-mosaic`, verified read-only on `mosaicstack/stack`; code and contract remain principal-agnostic.
|
|
||||||
|
|
||||||
## Progress
|
|
||||||
|
|
||||||
- [x] Mode/intake/core guides/skills/doctrine loaded.
|
|
||||||
- [x] Spec repository READ confirmed under be-coder-06 from provider object.
|
|
||||||
- [x] Target-branch conflict resolved by the trunk-only ruling; the lane was rebased from `next` onto `origin/main`.
|
|
||||||
- [x] Canonical remote PRD v3 addenda re-read at new head.
|
|
||||||
- [x] Required issues read via Mosaic wrapper.
|
|
||||||
- [x] Early grant/validate contract v1 published at `docs/credentials/GRANT-VALIDATE-CONTRACT.md`.
|
|
||||||
- [x] Contract v1.1 binds transport to the same resolved principal and adds a provider-confirmed read-only-principal control.
|
|
||||||
- [x] Contract v1.2 distinguishes provider outage, absent identity, and rejected credential.
|
|
||||||
- [x] Contract v1.3 positive-controlled anonymous visibility; subsequently withdrawn as unsound for private identities.
|
|
||||||
- [x] Contract v1.4 implements ruling (b): subject credential's own `/user`, no admin/inventory authority, no implemented `identity-not-found` path.
|
|
||||||
- [x] PRD update.
|
|
||||||
- [x] Red-first principal-bound validate, estate-registry, file-store, provider-transport, and journal tests.
|
|
||||||
- [x] Implementation: validate, direct/team grant, protected delegated authority, provision/wire/get/whoami/list/rotate/revoke/audit, reverse registry, and fleet fail-closed resolver paths.
|
|
||||||
- [x] Review hardening: rotation returns visible open journals; team evidence records absent objects accurately; team scope is checked before/after under a host-qualified OS advisory lock with verified compensation; `wire` authenticates the exact seat/path/roster binding and preserves post-rename mutation semantics.
|
|
||||||
- [x] Author advisory remediation: provisioning rollback verifies provider/token-store/Tea state and cannot suppress Tea cleanup failure; Tea put/remove always unlink secret-bearing temporary files; unrelated hosts exit before Mosaic identity grammar; `cred get` persists issuance start before disclosure, writes through a short-write-safe loop, and preserves partial/applied indeterminate semantics under write/append/seal faults; provision/rotate/revoke share a fixed cross-state-root lifecycle lock for cooperating processes only (provider authority is the authorization boundary; generation preconditions are optimistic for cooperating mutators; hostile same-UID filesystem mutation is explicitly deferred); Tea pre-state is snapshotted/restored independently; final journal seal faults revert to open classification.
|
|
||||||
- [ ] Legacy-token estate binding is explicitly deferred: the legacy format contains no estate and the installed shell path has no distributed strict registry. Enabling refusal before registry distribution plus token-envelope migration would strand active legacy-only seats; governed envelopes already bind estate exactly.
|
|
||||||
- [ ] Hostile same-UID direct filesystem mutation is explicitly deferred to #1065. The finding is copied verbatim there; PR #1059 links it. Phase 1 claims only optimistic generation preconditions and advisory locking for cooperating mutators, with provider authority as the authorization boundary.
|
|
||||||
- [ ] Independent code/security approvals on the final exact head (Codex advisory iterations are not independent approval).
|
|
||||||
- [ ] Final exact-head CI and provider evidence.
|
|
||||||
|
|
||||||
## Tests and evidence
|
|
||||||
|
|
||||||
Baseline after workspace build: package typecheck passed; Vitest 81/81 files and 1,514/1,514 tests passed. The package shell suite reached a pre-existing tracked #973 Bash 5.2 BASH_LINENO incompatibility and exited 97 before wake tests; this is baseline, not introduced by MC-CRED.
|
|
||||||
|
|
||||||
Red-first evidence:
|
|
||||||
- principal-bound validate module absent → focused suite red;
|
|
||||||
- incremental v1.1 run: write-capable, identity-mismatched, and receive-pack-admitted read-only controls each returned `ok`, causing 3/13 tests to fail for the exact control defect; after the control checks, 13/13 passed;
|
|
||||||
- read validation absent → 2 tests failed `evaluateGiteaReadValidation is not a function`; after implementation, 15/15 validate tests passed;
|
|
||||||
- estate registry, secure file resolver, Gitea transport, and audit journal each failed first because the module did not exist, then passed focused behavior suites.
|
|
||||||
|
|
||||||
Pre-remediation focused evidence: 80/80 across 11 credential/command suites; package lint, typecheck, formatting, and build were green. The advisory remediation adds thirty-five focused regression cases for rollback cleanup, Tea temporary-file cleanup, unsupported-host passthrough, and credential issuance partial-write/post-write-audit truthfulness; focused reruns are green (latest credential/command set: 109/109). Final uncommitted author advisories report code `approve` with no findings and security `none` with no findings; they remain advisory rather than independent approval. Full package Vitest reached 1,614 passing tests and three unrelated CLI-smoke failures caused solely by the installed-version update banner writing to stderr. Provider bodies are stream-bounded and requests deadline-bounded; delegated fd input is ownership/mode/size/time bounded; token and Tea stores are private and use atomic rename only for each explicitly scoped single-file replacement primitive; cross-system lifecycle completion uses verified compensation rather than an atomic-commit claim; grant mutation/read-back state is journaled.
|
|
||||||
|
|
||||||
Fail-closed resolver evidence: synthetic missing-token API and git paths each emitted stable `MOSAIC_CREDENTIAL_REFUSAL` with `reason=no-token-for-identity` and `shared_path_entered=false`; all 13 live token-bearing identities bypassed the shared path without over-fire in the same run. Evidence: `/home/hermes/agent-work/be-coder-06/review-evidence/failclosed-postcondition.jsonl`; independent verification remains tl-mosaic's obligation.
|
|
||||||
|
|
||||||
Live validation v1.4 (subject credential's own `/user`, no admin): population 13; CONFIRMED 8; CREDENTIAL-REJECTED 4 (`coder-mos1`, `coder-mos2`, `f10-coder`, `merge-gate`); MISMATCH 1 (`mos-admin` token authenticates as `Mos`); NOT-MEASURED 0. The four false v1.2 `identity-not-found` sealed journals remain immutable and are explicitly superseded by four sealed correction journals. Evidence: `/home/hermes/agent-work/be-coder-06/live-validation-v1.4/`.
|
|
||||||
|
|
||||||
Write differential for be-coder-06 passed with the configured read-only control and unauthenticated arm. Unit evidence proves the control arm invalidates validation when write-capable, identity-mismatched, or receive-pack-admitted.
|
|
||||||
|
|
||||||
## Successor review-remediation evidence
|
|
||||||
|
|
||||||
- Canonical-image CI portability: `/usr/bin/true` was changed only to `/bin/true`; the second-process `flock` acquisition assertion remains `status === 0` and passes in the focused lifecycle suite.
|
|
||||||
- Required red phase: five exact finding controls failed before implementation (journal one-byte/zero/oversized progress, recursively reordered Tea metadata, and lock-release failure). Review remediation added a sixth red control proving final-seal failure could compensate a later cooperating team mutation after lock release; a prototype-named Tea metadata control also failed before canonical object construction was hardened.
|
|
||||||
- Focused final: 120/120 passed across all 11 credential and credential-command files.
|
|
||||||
- Package lint and typecheck passed; dependency-aware workspace build passed 13/13 packages; repository format check and `git diff --check` passed; both git credential resolver shell regressions passed.
|
|
||||||
- Full local package Vitest: 1,624 passed / 3 failed. The failures are the same installed-version update banner emitted to stderr by three `cli-smoke.spec.ts` cases; prior canonical pipeline #2223 ran all 22 CLI-smoke cases green. Exact-head canonical CI remains required after push.
|
|
||||||
- First uncommitted advisories found a real post-release compensation race. Its red control observed one removal after lock release; the fix forbids compensation after successful release, and the control then passed without weakening an assertion.
|
|
||||||
- Final uncommitted advisories: code `approve` with no findings; security risk `none` with no findings. Codex could not execute tests in its read-only sandbox (EROFS), so these verdicts rely on review only; the writable author runs above are the test evidence and independent reviewers remain required.
|
|
||||||
|
|
||||||
## Risks/blockers
|
|
||||||
|
|
||||||
- Hostile same-UID direct filesystem mutation is outside phase-1 and requires a transactional service, broker/distinct identity, or equivalent non-bypassable primitive; lifecycle flock and generation preconditions cover cooperating `mosaic cred` mutators only. Track the explicit security deferral linked from PR #1059.
|
|
||||||
- The full CLI surface is broad; protect scope by sharing one provider/registry/journal core rather than per-command scripts.
|
|
||||||
- Gitea exact token-scope read-back may require delegated Basic Auth. If a bearer-only validation path cannot obtain an exact provider token object, return `indeterminate` rather than claim a scope.
|
|
||||||
- #1044 hold is LIFTED. The four least-privilege credentials are capability-confirmed and identity-not-measured, not dead. Fleet fail-closed paths now refuse with stable reason markers and never enter shared fallback under `MOSAIC_AGENT_NAME`; interactive callers retain explicit shared behavior. Runtime mismatch coverage remains limited to tokens holding `read:user`; future mints close identity binding at creation without widening seat scopes.
|
|
||||||
- C1 PR #1054 remains sequencing-prior and requires its own exact-head gates. MC-CRED PR #1059 must freeze only after a new advisory review, independent review, and exact-head CI.
|
|
||||||
@@ -1,58 +0,0 @@
|
|||||||
# RM-01 — Reproducible checkout
|
|
||||||
|
|
||||||
- Task/ref: RM-01 (`docs/remediation/TASKS.md`, internal mission tracking)
|
|
||||||
- Objective: make checkout/install/typecheck hooks fail on code rather than environmental residue, for root CI and non-root seats.
|
|
||||||
- Scope: pnpm store configuration, transactional Husky installation, dependency/generated-state preflight, checkout regression tests, developer documentation.
|
|
||||||
- Constraints: isolated worktree; no skip-switch fixes; no writes under `/root` or `/tmp`; workers do not edit `docs/remediation/TASKS.md`; author does not review or merge.
|
|
||||||
- Acceptance: AC1–AC8 from the orchestrator dispatch/addendum.
|
|
||||||
- Plan:
|
|
||||||
1. Add RED-first tests for missing dependencies, stale/foreign `.next`, and interrupted hook installation.
|
|
||||||
2. Implement environment-overridable HOME-based pnpm store defaults, deterministic preflight, and transactional hook installation.
|
|
||||||
3. Run focused tests, install/build/baseline gates, and explicit AC negative controls.
|
|
||||||
4. Obtain independent review, push after queue guard, open PR, and send evidence to `mos-remediation`.
|
|
||||||
- Budget: orchestrator estimate 6K/60K; no explicit hard token cap. Keep scope to RM-01 and avoid unrelated cleanup.
|
|
||||||
- Risks: 97%-full shared `/tmp`; native dependency install size; root-owned fixtures may require Docker for realistic verification.
|
|
||||||
|
|
||||||
## Progress / evidence
|
|
||||||
|
|
||||||
- Worktree created at `/home/hermes/agent-work/rm-01` from `origin/main` `06e0d403`.
|
|
||||||
- `/tmp` baseline: 28G used, 889M available (97%); worktree and planned store are on `/home`.
|
|
||||||
- Root causes confirmed from source: committed `.npmrc` pins `/root`; `prepare` invokes Husky directly; web typecheck includes generated `.next` types without validating ownership/freshness.
|
|
||||||
|
|
||||||
## Checkpoint evidence (c45e5e19)
|
|
||||||
|
|
||||||
- AC1 IN PROGRESS: non-root `pnpm install --frozen-lockfile --store-dir "$HOME/.local/share/pnpm/store"` exited 0; `pnpm exec turbo run typecheck --force` exited 0 (45/45 uncached). Clean CI-container run not performed.
|
|
||||||
- AC2 DONE: with `node_modules` absent, `pnpm preflight` exited 42 with `MOSAIC_PREFLIGHT_MISSING_DEPS` and `run pnpm install`; after install it exited 0.
|
|
||||||
- AC3 DONE: appending `export const x: number = "s"` to `packages/types/src/index.ts` made `pnpm -w typecheck` exit 2 with TS2322; reverting made it exit 0.
|
|
||||||
- AC4 IN PROGRESS: local `pnpm -w build` exited 0 and `git status --porcelain` showed no generated residue beyond the intended RM-01 source changes. Fresh-clone proof not performed.
|
|
||||||
- AC5 DONE: non-root install exited 0; `pnpm store path` resolved `/home/hermes/.local/share/pnpm/store/v10`; no `/root` write was attempted.
|
|
||||||
- AC6 IN PROGRESS: focused failure/rollback tests passed, but final review found a concurrent-install race. Two installers can both observe `.husky/_` absent; after one installs successfully, the losing install's catch path can quarantine the winner's active hooks and restore stale Git config (`scripts/install-hooks.mjs`, activation/catch transaction). A RED regression is committed after the checkpoint.
|
|
||||||
- AC7 DONE: install/store/worktree were on `/home`; full `pnpm -w build` exited 0; `/tmp` usage changed by 4096 bytes during the build (23,805,173,760 → 23,805,177,856 bytes), not materially.
|
|
||||||
- AC8 DONE for the implemented path: store resolves under `$HOME`; test/quarantine/build state resolves under the worktree; no implemented component requires a writable path outside `$HOME` or the worktree.
|
|
||||||
|
|
||||||
## Continuation evidence
|
|
||||||
|
|
||||||
- AC6 DONE: the committed race reproducer was observed RED (`node --test --test-name-pattern='a competing successful installer is not removed by the losing process' scripts/install-hooks.test.mjs`, exit 1/ENOENT), then passed after cleanup became ownership-safe. The losing installer never removes an active hook set or restores Git configuration it did not activate. `pnpm test:checkout` passes 21/21, exit 0, including the original race and a post-rename peer-replacement regression.
|
|
||||||
- Generated-state remediation: replaced mtime inference with a source/build-input fingerprint, written only after a serialized successful Next build with unchanged inputs. Failed/interrupted/overlapping builds leave no trusted marker. The fingerprint uses Next's own environment loader, covers resolved `NEXT_PUBLIC_*` values, inherited TypeScript configuration, lock/workspace inputs, and rejects symlink inputs.
|
|
||||||
- Baseline: `pnpm typecheck`, `pnpm lint`, and `pnpm format:check` each exit 0. Local `pnpm test` still exits 97 only at the pre-existing Bash `BASH_LINENO` convention guard (#973/#1003), after checkout tests and package tests pass; this is not reported as a green full-suite result.
|
|
||||||
- Automated review remediation: resolved findings for peer-hook ownership, stale/failed build markers, build-input changes, expanded environment inputs, inherited TypeScript config, symlink inputs, and overlapping build serialization. Independent PR review remains assigned to rev-974.
|
|
||||||
- AC1 DONE at `0f706119`: a clean clone created inside `git.mosaicstack.dev/mosaicstack/stack/ci-base:latest` ran the exact acceptance sequence `pnpm install --frozen-lockfile && pnpm -w typecheck`; exit 0 with 45/45 uncached typecheck tasks successful. An earlier bind-mounted clone attempt exited 1 because root in the container rejected the host-owned Git directory; that failed attempt is not counted as evidence.
|
|
||||||
- AC4 DONE at `0f706119`: in that same fresh clone and CI image, `pnpm -w build` completed 25/25 tasks and the immediately following `git status --porcelain` was empty; combined assertion exit 0.
|
|
||||||
- Push BLOCKED after the required queue guard: `git push origin fix/rm-01-reproducible-checkout` was rejected by Gitea with `User permission denied for writing` / `pre-receive hook declined`, despite `MOSAIC_GIT_IDENTITY=f10-coder` resolving username `f10-coder` from the provisioned `gitea-mosaicstack-f10-coder.token`.
|
|
||||||
|
|
||||||
## Review remediation — restated AC2
|
|
||||||
|
|
||||||
- Independent review correctly found that an added symlink under a successfully built `.next` tree passed preflight. The exact reviewer control, `ln -s /etc/hosts apps/web/.next/reviewer-symlink && pnpm preflight`, was observed passing before remediation.
|
|
||||||
- The original blanket symlink wording conflicts with AC4 because canonical Next `output: 'standalone'` emits legitimate pnpm dependency symlinks. The coordinator independently verified 42 such links and approved the operative restatement: `.next` itself must not be a symlink; descendant symlinks must exactly match the successful build's certified manifest.
|
|
||||||
- RED-first controls were observed failing together against the prior implementation (exit 1): `.next` root, added, removed, retargeted, tampered-manifest, and canonical-style certified-link cases. The build now publishes the manifest atomically before the existing source certification commit marker; that marker binds the manifest SHA-256. Missing/partial/modified manifests remain untrusted.
|
|
||||||
- GREEN evidence: the six-case symlink control passes; the exact reviewer-added link exits 43; removing it restores preflight exit 0. The added RED-first build-publication control also proves a symlinked `.next` cannot redirect certification writes outside the checkout. `pnpm test:checkout` passes 23 top-level tests / 29 including subtests. Canonical `pnpm --filter @mosaicstack/web build` and the following `pnpm preflight` both exit 0.
|
|
||||||
- Threat-model ruling: the manifest detects accidental, independent, stale, and foreign-residue mutation—the class exposed by the five-month-stale `.next` that produced 19 phantom TS2307 errors. It does not defend against a same-UID actor able to rewrite both manifest and marker consistently (CWE-345); no local worktree construction can without an external trust anchor. RM-59 tracks the residual: executor/spine-side attestation outside worktree authority, dependent on RM-12, RM-21, and RM-25.
|
|
||||||
- AC8 concrete proof at `df7530ae`: a clean clone ran in `ci-base:latest` with Docker `--read-only`; its only writable mounts were `/workspace` (the worktree) and `/home/ci` (`HOME`, with `NPM_CONFIG_STORE_DIR=/home/ci/store`). `pnpm install --frozen-lockfile && pnpm -w typecheck` exited 0 with 45/45 uncached tasks. This proves the implemented checkout path requires no writable location outside `$HOME` and the worktree. An initial fixture attempt failed only because Git required `/workspace` safe-directory setup; it is not counted as evidence.
|
|
||||||
|
|
||||||
## Handoff
|
|
||||||
|
|
||||||
1. Keep the newly committed RED tests red until implementing: (a) source-fingerprint marker support for valid incremental `.next` output, and (b) ownership-safe concurrent hook activation.
|
|
||||||
2. The latest automated review rejected oldest-generated-file mtime as a false positive for valid incremental Next output. Use a source-content fingerprint marker written only after successful `next build`; do not continue tuning mtimes.
|
|
||||||
3. For Husky, generation in an isolated temporary Git repo avoids mutating real `core.hooksPath` during staging. Preserve that design. Fix the losing concurrent process so it never removes a peer's completed hook set or restores stale config.
|
|
||||||
4. Codex review runs in a read-only sandbox, so its attempts to run the fixture-writing Node tests report opaque test-file failures. The same tests run normally in the worktree.
|
|
||||||
5. Full `pnpm test` is not green on this host: it exits 97 at the pre-existing Bash `BASH_LINENO` convention guard (#1003), after the changed checkout tests and package tests pass. Do not weaken that gate.
|
|
||||||
@@ -1,120 +0,0 @@
|
|||||||
# RM-03 — CI Queue Guard Repair
|
|
||||||
|
|
||||||
- **Task:** RM-03
|
|
||||||
- **Issue:** #1019
|
|
||||||
- **Branch:** `fix/rm-03-queue-guard`
|
|
||||||
- **Owner:** coder-mos1
|
|
||||||
- **Reviewer:** rev-974 (independent; author != reviewer)
|
|
||||||
- **Started:** 2026-08-01
|
|
||||||
|
|
||||||
## Objective
|
|
||||||
|
|
||||||
Repair the mandatory CI queue guard so it reads provider payloads, blocks asserted non-green CI, distinguishes provider unavailability from a real non-green result, and inspects the branch actually being pushed or merged.
|
|
||||||
|
|
||||||
## Constraints
|
|
||||||
|
|
||||||
- Worktree only: `/home/hermes/agent-work/rm-03`; never mutate `/src/mosaic-stack`.
|
|
||||||
- JSON payload travels through stdin; never argv. Large payload must remain below no ARG_MAX dependency.
|
|
||||||
- TDD is mandatory. Every behavior case must be observed red before implementation.
|
|
||||||
- No bypass flags or hook suppression.
|
|
||||||
- Do not cite the existing guard's green as evidence; D-23 establishes it is zero-information.
|
|
||||||
- Gate-ready is a frozen exact head. Any push after a merge-gate verdict voids that verdict.
|
|
||||||
- No merge: coordinator holds the merge hand pending Jason.
|
|
||||||
|
|
||||||
## Design
|
|
||||||
|
|
||||||
1. Feed JSON to `python3 -c` on stdin, including pending-context rendering.
|
|
||||||
2. Classify valid green as `READY`; pending/failure/no-status/malformed/mixed as `ASSERTED_NOT_READY`; provider/credential/transport inability as `CANNOT_ASSERT`.
|
|
||||||
3. `ASSERTED_NOT_READY` exits nonzero. `CANNOT_ASSERT` emits a loud diagnostic and appends a local JSONL audit record. Push degrades to exit 0; merge holds with distinct retryable exit 75 until provider recovery, then self-clears without manual reset. Inability to write the audit exits nonzero.
|
|
||||||
4. Derive the current branch when `-B` is omitted. The merge wrapper passes the exact PR head branch, repository, and full commit SHA—not its `main` base—so fork PRs cannot resolve against an adjacent base-repository branch.
|
|
||||||
|
|
||||||
## Test matrix
|
|
||||||
|
|
||||||
| Case | Required outcome |
|
|
||||||
| --- | --- |
|
|
||||||
| success | exit 0; terminal-success |
|
|
||||||
| pending | nonzero after bounded timeout |
|
|
||||||
| failure | nonzero |
|
|
||||||
| no-status | nonzero |
|
|
||||||
| malformed | nonzero |
|
|
||||||
| >=150 KiB payload | unchanged classification; never rc126 |
|
|
||||||
| provider unreachable on push | loud audited CANNOT_ASSERT; degraded exit 0 |
|
|
||||||
| provider unreachable on merge | loud audited CANNOT_ASSERT; retryable exit 75/HOLD |
|
|
||||||
| audit unavailable | nonzero |
|
|
||||||
| implicit push branch | provider URL uses checked-out feature branch |
|
|
||||||
| merge wrapper | queue guard receives exact PR head branch/repository/full SHA |
|
|
||||||
|
|
||||||
## RED-first evidence
|
|
||||||
|
|
||||||
Observed against the unmodified `origin/main` implementation before source edits:
|
|
||||||
|
|
||||||
- `bash packages/mosaic/framework/tools/git/test-ci-queue-wait-tristate.sh` → rc 1 with 15 failed assertions.
|
|
||||||
- Success payload was reported `state=unknown`.
|
|
||||||
- Pending, failure, no-status, and malformed payloads each exited 0 and omitted `ASSERTED_NOT_READY`.
|
|
||||||
- The 160 KiB payload produced rc 141 because Python never consumed the pipe; it did not classify success.
|
|
||||||
- Provider-unreachable exited 7 with no `CANNOT_ASSERT` audit record.
|
|
||||||
- Implicit push queried `/branches/main`, not `/branches/fix/rm-03-fixture`.
|
|
||||||
- Audit-unavailable emitted no audit diagnostic.
|
|
||||||
- A credential-resolution hard-block mutant was then run before trusting that added case: `credential-unresolvable` returned rc 1 and omitted `CANNOT_ASSERT`; the matrix returned rc 1 with two named assertion failures.
|
|
||||||
- Review-blocker controls were observed red: structurally invalid `statuses` string and null-entry payloads each exited 0 as `terminal-success`; unsupported-platform discovery exited 1 without diagnostic or audit (seven named assertion failures total).
|
|
||||||
- After the push/merge asymmetry ruling, merge-side provider unavailability was observed red at rc 0; its registered case required distinct retryable rc 75.
|
|
||||||
- Aggregate `state=success` with zero contexts was observed red: it exited 0 as `terminal-success`; the registered case requires `no-status`/nonzero.
|
|
||||||
- Fork/exact-head controls were observed red: `pr-merge.sh` omitted the fork repository and full SHA, and an ignored-arguments mutant re-resolved through `/branches/` instead of the exact fork commit (two named failures).
|
|
||||||
- GitHub check-run-only success/pending/failure were each misclassified as `no-status`; the RED run had five named failures and proved the Checks API was never queried.
|
|
||||||
- The first merge-pin control was unrunnable because one `local` declaration referenced a variable before assignment under `set -u`; this was disclosed and corrected rather than counted. The runnable RED then showed Gitea payload `{"Do":"squash"}` lacked `head_commit_id`; a separate GitHub run showed `gh pr merge 123 --squash` lacked `--match-head-commit`.
|
|
||||||
- A stale-verdict mutant removed the `--expect-head` comparison and was observed red because a moved head reached the provider merge call.
|
|
||||||
- `bash packages/mosaic/framework/tools/git/test-pr-merge-queue-branch.sh` initially returned rc 1; captured call was `--purpose merge -B main -t 900 -i 15`.
|
|
||||||
|
|
||||||
Logs remain untracked under the worktree as `.mosaic-test-work-red-*.log` and will not be committed.
|
|
||||||
|
|
||||||
## Progress
|
|
||||||
|
|
||||||
- [x] Mission, remediation charter, task evidence, board, issue #1019, and superseded PR #1023 read.
|
|
||||||
- [x] Isolated worktree created and identity configured coherently.
|
|
||||||
- [x] Mutant tests authored and observed red.
|
|
||||||
- [x] Implementation green.
|
|
||||||
- [x] Baseline and focused situational gates green; full package suite has an unrelated framework-shell environment abort recorded below.
|
|
||||||
- [ ] Independent review clean (rev-974 requested changes at `44ffa99a`; bypass remediation committed and awaiting re-review).
|
|
||||||
- [ ] PR CI terminal-green at exact head by full step scan.
|
|
||||||
- [ ] Merge-gate verdict issued against frozen head.
|
|
||||||
|
|
||||||
## Scope disposition
|
|
||||||
|
|
||||||
- The five framework guides are consequential documentation: they define the purpose-aware tri-state contract, including audited push degradation and merge HOLD.
|
|
||||||
- The agent templates are consequential because they ship the same queue-guard instructions into newly seeded agent contracts; leaving them binary/stale would contradict the repaired tool.
|
|
||||||
- `pr-merge.sh` is consequential: it must inspect the PR's exact head branch/repository/SHA and enforce the exact-head merge pin.
|
|
||||||
- `pr-metadata.sh` is consequential only as the normalized source of that head branch/repository/SHA. Its diff is limited to exposing those fields on GitHub and Gitea.
|
|
||||||
- `test-pr-merge-gitea-empty-uid.sh` changes because exact-head Gitea merges now always use the API path (the only path that can send `head_commit_id`), superseding the prior tea-empty-identity fallback behavior.
|
|
||||||
|
|
||||||
## Review remediation
|
|
||||||
|
|
||||||
- rev-974 independently proved that the documented `--skip-queue-guard` merge option bypassed an exit-99 guard stub, reached the provider merge payload, printed success, and exited 0 at head `44ffa99a`.
|
|
||||||
- RED-first reproduction was added to `test-pr-merge-head-pin.sh` before the production fix: `FAIL merge-bypass: --skip-queue-guard reached the provider merge path`, suite rc 1. The test-only commit is `241113e6`.
|
|
||||||
- Production remediation `37aae650` removes the option from parsing, usage, help, and examples. Every merge-capable path now invokes the queue guard; `--dry-run` alone omits it and has a regression proving that it exits before provider dispatch and creates no merge payload.
|
|
||||||
- Existing Gitea merge tests now exercise a successful guard response rather than bypassing the guard.
|
|
||||||
|
|
||||||
## Risks / boundaries
|
|
||||||
|
|
||||||
- The local JSONL audit is durable operational evidence but not tamper-resistant against the same UID. RM-03 does not claim otherwise.
|
|
||||||
- Push-side audited exit 0 is an explicit owner ruling (Option B), accepted to avoid bricking recovery work; merge-side CANNOT_ASSERT remains retryable exit 75/HOLD. The automated security reviewer continues to flag the deliberate push availability tradeoff.
|
|
||||||
- Source/deployed-copy equality is owned by RM-02/D-22; this branch changes repository source and its tests only.
|
|
||||||
|
|
||||||
## Test evidence
|
|
||||||
|
|
||||||
Fresh after rescue checkpoint `b7175012`:
|
|
||||||
|
|
||||||
- Focused situational matrix: tri-state, GitHub checks pagination, branch-absent, merge head branch/repository/SHA, exact-head pin, and Gitea exact-head API regressions all passed.
|
|
||||||
- `bash -n` on the three production shell scripts passed.
|
|
||||||
- `shellcheck -x -P packages/mosaic/framework/tools/git ...` on all changed shell scripts passed.
|
|
||||||
- `pnpm typecheck` passed (45/45 Turbo tasks).
|
|
||||||
- `pnpm lint` passed (25/25 Turbo tasks).
|
|
||||||
- `pnpm format:check` passed.
|
|
||||||
- `pnpm --filter @mosaicstack/mosaic test`: Vitest passed 1508/1508 on the confirmation run; framework-shell then aborted at the pre-existing wake coordinate assertion with exit 97: `BASH_LINENO ... probe reported [3 5], expected [3 4] ... (#973)`. This is outside the RM-03 diff and is disclosed rather than substituted or called green.
|
|
||||||
- The prior package-suite attempt had one transient, out-of-diff `install-ordering-guard.spec.ts` failure (1/1508); its isolated rerun passed 19/19 and the confirmation full Vitest run passed 1508/1508.
|
|
||||||
- After bypass remediation: all six focused RM-03 queue/merge regressions passed, including bypass refusal and dry-run non-dispatch; shell syntax and source-aware ShellCheck passed; `pnpm typecheck`, `pnpm lint`, and `pnpm format:check` passed.
|
|
||||||
- Fresh `test:framework-shell` reached and passed every RM-03 test, then again aborted at the unrelated wake coordinate assertion with exit 97; it remains explicitly non-green rather than substituted.
|
|
||||||
- An ad hoc raw Prettier invocation over `.template` and `.sh` files was unrunnable because no parser is registered for those extensions; it was not used as a substitute for canonical `pnpm format:check`.
|
|
||||||
|
|
||||||
## Final evidence
|
|
||||||
|
|
||||||
Pending.
|
|
||||||
+3
-6
@@ -6,14 +6,11 @@
|
|||||||
"build": "turbo run build",
|
"build": "turbo run build",
|
||||||
"dev": "turbo run dev",
|
"dev": "turbo run dev",
|
||||||
"lint": "turbo run lint",
|
"lint": "turbo run lint",
|
||||||
"preflight": "node scripts/preflight.mjs",
|
"typecheck": "turbo run typecheck",
|
||||||
"clean:generated": "node scripts/clean-generated.mjs",
|
"test": "turbo run test",
|
||||||
"typecheck": "pnpm preflight && turbo run typecheck",
|
|
||||||
"test:checkout": "node --test scripts/*.test.mjs",
|
|
||||||
"test": "pnpm test:checkout && turbo run test",
|
|
||||||
"format": "prettier --write \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
"format": "prettier --write \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
||||||
"format:check": "prettier --check \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
"format:check": "prettier --check \"**/*.{ts,tsx,js,jsx,json,md}\"",
|
||||||
"prepare": "node scripts/install-hooks.mjs"
|
"prepare": "husky"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@typescript-eslint/eslint-plugin": "^8.0.0",
|
"@typescript-eslint/eslint-plugin": "^8.0.0",
|
||||||
|
|||||||
@@ -13,14 +13,7 @@ It is a **gate** role: the one and only merge path.
|
|||||||
2. **Use the wrapped scripts as the ONLY merge path** — the merge-gate merges
|
2. **Use the wrapped scripts as the ONLY merge path** — the merge-gate merges
|
||||||
**exclusively** by calling **`pr-merge.sh`** (the merge action, which carries the
|
**exclusively** by calling **`pr-merge.sh`** (the merge action, which carries the
|
||||||
authoritative forbidden-path guard) and **`pr-ci-wait.sh`** (to wait for green
|
authoritative forbidden-path guard) and **`pr-ci-wait.sh`** (to wait for green
|
||||||
CI before merging). Before issuing a verdict, scan the full JSON/API child-step
|
CI before merging). These two scripts are the _only_ sanctioned merge path.
|
||||||
record (including `clone`) with **`verify-terminal-green.py --expect-commit
|
|
||||||
<current-provider-PR-head>`** and record the equal expected/observed full-40
|
|
||||||
commits, exact step count, anomalies, and named exemptions. Missing or mismatched
|
|
||||||
commit binding is a hard refusal. The verifier's sole interim
|
|
||||||
exemption is `WP-K8S-1000-CI-POSTGRES-TEARDOWN`; it is signature-scoped, tracked
|
|
||||||
by #1000, and retires when #1000 is fixed. These scripts are the _only_
|
|
||||||
sanctioned merge path.
|
|
||||||
3. **Never call the raw API** — the merge-gate **does NOT** call `tea`, the raw
|
3. **Never call the raw API** — the merge-gate **does NOT** call `tea`, the raw
|
||||||
Gitea/forge HTTP API, or any other merge mechanism directly. Only `pr-merge.sh`
|
Gitea/forge HTTP API, or any other merge mechanism directly. Only `pr-merge.sh`
|
||||||
and `pr-ci-wait.sh`.
|
and `pr-ci-wait.sh`.
|
||||||
|
|||||||
@@ -868,38 +868,6 @@ steps:
|
|||||||
7. **Test on a short-lived non-main branch first** — open a PR and verify quality gates before merging to `main`
|
7. **Test on a short-lived non-main branch first** — open a PR and verify quality gates before merging to `main`
|
||||||
8. **Verify images appear** in Gitea Packages tab after successful pipeline
|
8. **Verify images appear** in Gitea Packages tab after successful pipeline
|
||||||
|
|
||||||
## Terminal-Green Full-Step Contract
|
|
||||||
|
|
||||||
A successful pipeline summary is not sufficient: verification MUST consume the full JSON/API child-step record, including `clone`.
|
|
||||||
|
|
||||||
```bash
|
|
||||||
PR_HEAD=<full-40-hex-provider-head>
|
|
||||||
~/.config/mosaic/tools/woodpecker/pipeline-status.sh \
|
|
||||||
-r mosaicstack/stack -n <pipeline-number> -f json \
|
|
||||||
| ~/.config/mosaic/tools/woodpecker/verify-terminal-green.py \
|
|
||||||
--expect-commit "$PR_HEAD" -
|
|
||||||
```
|
|
||||||
|
|
||||||
`PR_HEAD` MUST come from the current provider PR metadata and MUST be the full 40-hex head, not a local branch guess. The verifier fails if the argument is missing, malformed, absent from the pipeline record, or differs from that record.
|
|
||||||
|
|
||||||
The verifier reports the expected and observed commits, total step count, state counts, anomalies, and any applied exemption. Exit `0` means the record satisfies the contract; exit `1` means the commit binding or at least one pipeline, workflow, or child-step state blocks terminal-green; exit `2` means the invocation or JSON input could not be verified.
|
|
||||||
|
|
||||||
### Named interim exemption: `WP-K8S-1000-CI-POSTGRES-TEARDOWN`
|
|
||||||
|
|
||||||
Only this exact conjunction is exempted:
|
|
||||||
|
|
||||||
- pipeline and workflow state are `success`;
|
|
||||||
- exactly one non-success child exists;
|
|
||||||
- its name is `ci-postgres` and type is `service`;
|
|
||||||
- its state is `failure`, exit code is the JSON integer `0` (not boolean, float, string, or null); and
|
|
||||||
- its error exactly matches `pods "wp-svc-<ULID>-ci-postgres" not found`.
|
|
||||||
|
|
||||||
Every near miss remains blocking, including non-zero service exits, startup failures, post-readiness crashes, connection errors, image-pull errors, skipped steps, another failed child, malformed pod names, duplicate matches, or a non-success pipeline/workflow.
|
|
||||||
|
|
||||||
**Boundary in both directions:** this exemption recognizes the observed Woodpecker Kubernetes reconciliation miss after an otherwise-successful run. It does not prove that every future PostgreSQL or Kubernetes failure is distinguishable. It does prove, through provider controls, that a deterministic startup failure (`exit_code=1`) and an armed post-readiness postmaster crash (`exit_code=137`, dependent probe `Connection refused`) do not match and remain red.
|
|
||||||
|
|
||||||
**Tracking and retirement:** [mosaicstack/stack#1000](https://git.mosaicstack.dev/mosaicstack/stack/issues/1000) owns the provider-seam fix. This exemption MUST be removed when #1000 is fixed. It is not authority to retry or re-trigger a pipeline, and no per-PR re-roll is part of the contract.
|
|
||||||
|
|
||||||
## Post-Merge CI Monitoring (Hard Rule)
|
## Post-Merge CI Monitoring (Hard Rule)
|
||||||
|
|
||||||
For source-code delivery, completion is not allowed at "PR opened" stage.
|
For source-code delivery, completion is not allowed at "PR opened" stage.
|
||||||
@@ -925,16 +893,14 @@ Woodpecker note:
|
|||||||
Before pushing a branch or merging a PR, guard against overlapping project pipelines:
|
Before pushing a branch or merging a PR, guard against overlapping project pipelines:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push
|
~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main
|
||||||
~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>
|
~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main
|
||||||
```
|
```
|
||||||
|
|
||||||
Behavior:
|
Behavior:
|
||||||
|
|
||||||
- If pipeline state is running/queued/pending, wait until queue clears; timeout is `ASSERTED_NOT_READY` and exits nonzero.
|
- If pipeline state is running/queued/pending, wait until queue clears.
|
||||||
- Failure, missing status, malformed status, or any other provider-asserted non-green state is `ASSERTED_NOT_READY` and exits nonzero.
|
- If timeout or API/auth failure occurs, treat as `blocked`, report exact failed wrapper command, and stop.
|
||||||
- Credential, transport, or provider unavailability is `CANNOT_ASSERT`: the guard emits a loud diagnostic and durable JSONL audit record. For push it exits 0 so recovery work is not bricked. For merge it returns distinct retryable exit 75 and holds until provider recovery; rerunning then self-clears without manual reset. This result is never evidence that CI was clear. If the audit cannot be written, the guard exits nonzero.
|
|
||||||
- `pr-merge.sh` resolves and guards the exact PR head repository and full SHA automatically, including fork PRs.
|
|
||||||
|
|
||||||
## Gitea as Unified Platform
|
## Gitea as Unified Platform
|
||||||
|
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ Merge strategy enforcement (HARD RULE):
|
|||||||
- PR target for delivery is `main`.
|
- PR target for delivery is `main`.
|
||||||
- Direct pushes to `main` are prohibited.
|
- Direct pushes to `main` are prohibited.
|
||||||
- Merge to `main` MUST be squash-only.
|
- Merge to `main` MUST be squash-only.
|
||||||
- Use `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}` (or PowerShell equivalent).
|
- Use `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash` (or PowerShell equivalent).
|
||||||
|
|
||||||
## Review Checklist
|
## Review Checklist
|
||||||
|
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ For implementation work, you MUST run this cycle in order:
|
|||||||
8. `pre-push queue guard` - before pushing, wait for running/queued project pipelines to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. `pre-push queue guard` - before pushing, wait for running/queued project pipelines to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
||||||
9. `push` - push immediately after queue guard passes.
|
9. `push` - push immediately after queue guard passes.
|
||||||
10. `PR integration` - if external git provider is available, create/update PR to `main` and merge with required strategy via Mosaic wrappers.
|
10. `PR integration` - if external git provider is available, create/update PR to `main` and merge with required strategy via Mosaic wrappers.
|
||||||
11. `pre-merge queue guard` - before merging PR, wait for running/queued project pipelines on the exact PR head to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
11. `pre-merge queue guard` - before merging PR, wait for running/queued project pipelines to clear: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge`.
|
||||||
12. `CI/pipeline verification` - wait for terminal CI status and require green before completion (`~/.config/mosaic/tools/git/pr-ci-wait.sh` for PR-based workflow).
|
12. `CI/pipeline verification` - wait for terminal CI status and require green before completion (`~/.config/mosaic/tools/git/pr-ci-wait.sh` for PR-based workflow).
|
||||||
13. `issue closure` - close linked external issue (or close internal `docs/TASKS.md` task ref when provider is unavailable).
|
13. `issue closure` - close linked external issue (or close internal `docs/TASKS.md` task ref when provider is unavailable).
|
||||||
14. `greenfield situational test` - validate required user flows in a clean environment/startup path (post-merge for trunk workflow changes).
|
14. `greenfield situational test` - validate required user flows in a clean environment/startup path (post-merge for trunk workflow changes).
|
||||||
@@ -93,8 +93,8 @@ For implementation work, you MUST run this cycle in order:
|
|||||||
> the gate (AGENTS.md hard gate "Merge authority"). Solo delivery proceeds
|
> the gate (AGENTS.md hard gate "Merge authority"). Solo delivery proceeds
|
||||||
> without asking.
|
> without asking.
|
||||||
|
|
||||||
1. `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`
|
1. `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`
|
||||||
2. `~/.config/mosaic/tools/git/pr-merge.sh -n <PR_NUMBER> -m squash --expect-head <APPROVED_FULL_SHA>`
|
2. `~/.config/mosaic/tools/git/pr-merge.sh -n <PR_NUMBER> -m squash`
|
||||||
3. `~/.config/mosaic/tools/git/pr-ci-wait.sh -n <PR_NUMBER>`
|
3. `~/.config/mosaic/tools/git/pr-ci-wait.sh -n <PR_NUMBER>`
|
||||||
4. `~/.config/mosaic/tools/git/issue-close.sh -i <ISSUE_NUMBER>` (or close internal `docs/TASKS.md` ref when no provider exists)
|
4. `~/.config/mosaic/tools/git/issue-close.sh -i <ISSUE_NUMBER>` (or close internal `docs/TASKS.md` ref when no provider exists)
|
||||||
5. If any step fails: set status `blocked`, report the exact failed wrapper command, and stop.
|
5. If any step fails: set status `blocked`, report the exact failed wrapper command, and stop.
|
||||||
|
|||||||
@@ -425,11 +425,11 @@ git push
|
|||||||
and checklist completed (`~/.config/mosaic/templates/docs/DOCUMENTATION-CHECKLIST.md`) when applicable.
|
and checklist completed (`~/.config/mosaic/templates/docs/DOCUMENTATION-CHECKLIST.md`) when applicable.
|
||||||
13. **PR + CI + Issue Closure Gate** (HARD RULE for source-code tasks):
|
13. **PR + CI + Issue Closure Gate** (HARD RULE for source-code tasks):
|
||||||
- Before merging, run queue guard:
|
- Before merging, run queue guard:
|
||||||
`~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`
|
`~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`
|
||||||
- Ensure PR exists for the task branch (create/update via wrappers if needed):
|
- Ensure PR exists for the task branch (create/update via wrappers if needed):
|
||||||
`~/.config/mosaic/tools/git/pr-create.sh ... -B main`
|
`~/.config/mosaic/tools/git/pr-create.sh ... -B main`
|
||||||
- Merge via wrapper:
|
- Merge via wrapper:
|
||||||
`~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}`
|
`~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash`
|
||||||
- Wait for terminal CI status:
|
- Wait for terminal CI status:
|
||||||
`~/.config/mosaic/tools/git/pr-ci-wait.sh -n {PR_NUMBER}`
|
`~/.config/mosaic/tools/git/pr-ci-wait.sh -n {PR_NUMBER}`
|
||||||
- Close linked issue after merge + green CI:
|
- Close linked issue after merge + green CI:
|
||||||
@@ -630,7 +630,7 @@ Construct this from the task row and pass to worker via Task tool:
|
|||||||
|
|
||||||
**MANDATORY:** This ALWAYS includes linting. If the project has a linter configured
|
**MANDATORY:** This ALWAYS includes linting. If the project has a linter configured
|
||||||
(ESLint, Biome, ruff, etc.), you MUST run it and fix ALL violations in files you touched.
|
(ESLint, Biome, ruff, etc.), you MUST run it and fix ALL violations in files you touched.
|
||||||
Do NOT leave lint warnings or errors for someone else to clean up. 6. Run REQUIRED situational tests based on changed surfaces (see `~/.config/mosaic/guides/E2E-DELIVERY.md` and `~/.config/mosaic/guides/QA-TESTING.md`). 7. If task is bug fix/security/auth/critical business logic, apply REQUIRED TDD discipline per `~/.config/mosaic/guides/QA-TESTING.md`. 8. If gates or required situational tests fail: Fix and retry. Do NOT report success with failures. 9. Commit: `git commit -m "fix({finding_id}): brief description"` 10. Before push, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B {branch}` 11. Push: `git push origin {branch}` 12. Report result as JSON (see format below)
|
Do NOT leave lint warnings or errors for someone else to clean up. 6. Run REQUIRED situational tests based on changed surfaces (see `~/.config/mosaic/guides/E2E-DELIVERY.md` and `~/.config/mosaic/guides/QA-TESTING.md`). 7. If task is bug fix/security/auth/critical business logic, apply REQUIRED TDD discipline per `~/.config/mosaic/guides/QA-TESTING.md`. 8. If gates or required situational tests fail: Fix and retry. Do NOT report success with failures. 9. Commit: `git commit -m "fix({finding_id}): brief description"` 10. Before push, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main` 11. Push: `git push origin {branch}` 12. Report result as JSON (see format below)
|
||||||
|
|
||||||
## Git Scripts
|
## Git Scripts
|
||||||
|
|
||||||
@@ -638,9 +638,8 @@ For issue/PR/milestone operations, use scripts (NOT raw tea/gh):
|
|||||||
|
|
||||||
- `~/.config/mosaic/tools/git/issue-view.sh -i {N}`
|
- `~/.config/mosaic/tools/git/issue-view.sh -i {N}`
|
||||||
- `~/.config/mosaic/tools/git/pr-create.sh -t "Title" -b "Desc" -B main`
|
- `~/.config/mosaic/tools/git/pr-create.sh -t "Title" -b "Desc" -B main`
|
||||||
- Push: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B {task_branch}`
|
- `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`
|
||||||
- Merge: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B {pr_head_branch} -R {pr_head_owner/repo} --sha {pr_head_full_sha}`
|
- `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash`
|
||||||
- `~/.config/mosaic/tools/git/pr-merge.sh -n {PR_NUMBER} -m squash --expect-head {approved_full_sha}`
|
|
||||||
- `~/.config/mosaic/tools/git/pr-ci-wait.sh -n {PR_NUMBER}`
|
- `~/.config/mosaic/tools/git/pr-ci-wait.sh -n {PR_NUMBER}`
|
||||||
- `~/.config/mosaic/tools/git/issue-close.sh -i {N}`
|
- `~/.config/mosaic/tools/git/issue-close.sh -i {N}`
|
||||||
|
|
||||||
|
|||||||
@@ -23,12 +23,10 @@ Mosaic wrappers at `~/.config/mosaic/tools/git/*.sh` handle platform detection a
|
|||||||
# Milestones
|
# Milestones
|
||||||
~/.config/mosaic/tools/git/milestone-create.sh
|
~/.config/mosaic/tools/git/milestone-create.sh
|
||||||
|
|
||||||
# CI queue guard (required before push/merge; defaults to the checked-out branch)
|
# CI queue guard (required before push/merge)
|
||||||
~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge
|
~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge
|
||||||
```
|
```
|
||||||
|
|
||||||
The guard exits nonzero for any provider-asserted non-green, missing, or malformed CI state. If credentials or the provider are unavailable, it emits `CANNOT_ASSERT` and writes a JSONL audit record. Push degrades to exit 0 so recovery work is not bricked; merge holds with retryable exit 75 until the provider recovers, then self-clears without manual reset. Neither outcome is evidence that CI was clear. `pr-merge.sh` automatically inspects the exact PR head repository and full commit SHA rather than its `main` base; this also handles fork PRs without branch-name ambiguity. Pass `--expect-head <approved-full-sha>` to bind a commit-specific review or merge-gate verdict; Gitea uses atomic `head_commit_id` and GitHub uses `--match-head-commit`.
|
|
||||||
|
|
||||||
### Code Review (Codex)
|
### Code Review (Codex)
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
||||||
3. Completion is forbidden at PR-open stage.
|
3. Completion is forbidden at PR-open stage.
|
||||||
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
||||||
5. Before push or merge, run the queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
5. Before push or merge, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
||||||
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
||||||
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
||||||
@@ -88,7 +88,7 @@ Reference:
|
|||||||
5. Do not mark implementation complete until PR is merged.
|
5. Do not mark implementation complete until PR is merged.
|
||||||
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
||||||
7. Close linked issues/tasks only after merge + green CI.
|
7. Close linked issues/tasks only after merge + green CI.
|
||||||
8. Before push or merge, run the CI queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
8. Before push or merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
|
|
||||||
## Container Release Strategy (When Applicable)
|
## Container Release Strategy (When Applicable)
|
||||||
|
|
||||||
|
|||||||
@@ -147,9 +147,9 @@ Do NOT stop at "PR created" and do NOT ask "should I merge?" or "should I close
|
|||||||
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
||||||
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
||||||
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
||||||
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main`.
|
||||||
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
||||||
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`.
|
||||||
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
||||||
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
||||||
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
||||||
3. Completion is forbidden at PR-open stage.
|
3. Completion is forbidden at PR-open stage.
|
||||||
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
||||||
5. Before push or merge, run the queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
5. Before push or merge, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
||||||
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
||||||
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
||||||
@@ -97,7 +97,7 @@ Reference:
|
|||||||
5. Do not mark implementation complete until PR is merged.
|
5. Do not mark implementation complete until PR is merged.
|
||||||
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
||||||
7. Close linked issues/tasks only after merge + green CI.
|
7. Close linked issues/tasks only after merge + green CI.
|
||||||
8. Before push or merge, run the CI queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
8. Before push or merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
|
|
||||||
|
|
||||||
## Container Release Strategy (When Applicable)
|
## Container Release Strategy (When Applicable)
|
||||||
|
|||||||
@@ -198,9 +198,9 @@ Do NOT stop at "PR created" and do NOT ask "should I merge?" or "should I close
|
|||||||
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
||||||
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
||||||
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
||||||
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main`.
|
||||||
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
||||||
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`.
|
||||||
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
||||||
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
||||||
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
||||||
3. Completion is forbidden at PR-open stage.
|
3. Completion is forbidden at PR-open stage.
|
||||||
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
||||||
5. Before push or merge, run the queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
5. Before push or merge, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
||||||
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
||||||
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
||||||
@@ -101,7 +101,7 @@ Reference:
|
|||||||
5. Do not mark implementation complete until PR is merged.
|
5. Do not mark implementation complete until PR is merged.
|
||||||
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
||||||
7. Close linked issues/tasks only after merge + green CI.
|
7. Close linked issues/tasks only after merge + green CI.
|
||||||
8. Before push or merge, run the CI queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
8. Before push or merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
|
|
||||||
|
|
||||||
## Container Release Strategy (When Applicable)
|
## Container Release Strategy (When Applicable)
|
||||||
|
|||||||
@@ -230,9 +230,9 @@ Do NOT stop at "PR created" and do NOT ask "should I merge?" or "should I close
|
|||||||
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
||||||
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
||||||
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
||||||
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main`.
|
||||||
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
||||||
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`.
|
||||||
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
||||||
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
||||||
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
||||||
|
|||||||
+2
-2
@@ -9,7 +9,7 @@
|
|||||||
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
||||||
3. Completion is forbidden at PR-open stage.
|
3. Completion is forbidden at PR-open stage.
|
||||||
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
||||||
5. Before push or merge, run the queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
5. Before push or merge, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
||||||
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
||||||
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
||||||
@@ -87,7 +87,7 @@ Reference:
|
|||||||
5. Do not mark implementation complete until PR is merged.
|
5. Do not mark implementation complete until PR is merged.
|
||||||
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
||||||
7. Close linked issues/tasks only after merge + green CI.
|
7. Close linked issues/tasks only after merge + green CI.
|
||||||
8. Before push or merge, run the CI queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
8. Before push or merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
|
|
||||||
## Container Release Strategy (When Applicable)
|
## Container Release Strategy (When Applicable)
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -146,9 +146,9 @@ Do NOT stop at "PR created" and do NOT ask "should I merge?" or "should I close
|
|||||||
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
||||||
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
||||||
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
||||||
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main`.
|
||||||
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
||||||
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`.
|
||||||
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
||||||
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
||||||
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
||||||
|
|||||||
+2
-2
@@ -9,7 +9,7 @@
|
|||||||
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
||||||
3. Completion is forbidden at PR-open stage.
|
3. Completion is forbidden at PR-open stage.
|
||||||
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
||||||
5. Before push or merge, run the queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
5. Before push or merge, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
||||||
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
||||||
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
||||||
@@ -84,7 +84,7 @@ Reference:
|
|||||||
5. Do not mark implementation complete until PR is merged.
|
5. Do not mark implementation complete until PR is merged.
|
||||||
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
||||||
7. Close linked issues/tasks only after merge + green CI.
|
7. Close linked issues/tasks only after merge + green CI.
|
||||||
8. Before push or merge, run the CI queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
8. Before push or merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
|
|
||||||
## Container Release Strategy (When Applicable)
|
## Container Release Strategy (When Applicable)
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -136,9 +136,9 @@ Do NOT stop at "PR created" and do NOT ask "should I merge?" or "should I close
|
|||||||
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
||||||
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
||||||
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
||||||
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main`.
|
||||||
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
||||||
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`.
|
||||||
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
||||||
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
||||||
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
||||||
|
|||||||
@@ -9,7 +9,7 @@
|
|||||||
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
2. Do NOT ask for routine confirmation before required push/merge/issue-close/release/tag actions.
|
||||||
3. Completion is forbidden at PR-open stage.
|
3. Completion is forbidden at PR-open stage.
|
||||||
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
4. Completion requires merged PR to `main` + terminal green CI + linked issue/internal task closed.
|
||||||
5. Before push or merge, run the queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
5. Before push or merge, run queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
6. For issue/PR/milestone operations, use Mosaic wrappers first (`~/.config/mosaic/tools/git/*.sh`).
|
||||||
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
7. If any required wrapper command fails: report `blocked` with the exact failed wrapper command and stop.
|
||||||
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
8. Do NOT stop at "PR created" and do NOT ask "should I merge?" for routine flow.
|
||||||
@@ -85,7 +85,7 @@ Reference:
|
|||||||
5. Do not mark implementation complete until PR is merged.
|
5. Do not mark implementation complete until PR is merged.
|
||||||
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
6. Do not mark implementation complete until CI/pipeline status is terminal green.
|
||||||
7. Close linked issues/tasks only after merge + green CI.
|
7. Close linked issues/tasks only after merge + green CI.
|
||||||
8. Before push or merge, run the CI queue guard against the push branch or the merge PR's exact head repository/SHA (`ci-queue-wait.sh --help`); `pr-merge.sh` supplies exact merge metadata automatically.
|
8. Before push or merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push|merge -B main`.
|
||||||
|
|
||||||
## Container Release Strategy (When Applicable)
|
## Container Release Strategy (When Applicable)
|
||||||
|
|
||||||
|
|||||||
@@ -133,9 +133,9 @@ Do NOT stop at "PR created" and do NOT ask "should I merge?" or "should I close
|
|||||||
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
5. Ensure `docs/PRD.md` or `docs/PRD.json` exists and is current before coding.
|
||||||
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
6. Create scratchpad: `docs/scratchpads/{task-id}-{short-name}.md` and include issue/internal ref.
|
||||||
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
7. Update `docs/TASKS.md` status + issue/internal ref before coding.
|
||||||
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push`.
|
8. Before push, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose push -B main`.
|
||||||
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
9. Open PR to `main` for delivery changes (no direct push to `main`).
|
||||||
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B <PR_HEAD_BRANCH> -R <PR_HEAD_OWNER/REPO> --sha <PR_HEAD_FULL_SHA>`.
|
10. Before merge, run CI queue guard: `~/.config/mosaic/tools/git/ci-queue-wait.sh --purpose merge -B main`.
|
||||||
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
11. Merge PRs that pass required checks and review gates with squash strategy only.
|
||||||
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
12. Reference issues/internal refs in commits (`Fixes #123`, `Refs #123`, or `Refs TASKS:T1`).
|
||||||
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
13. Close issue/internal task only after testing and documentation gates pass, PR merge is complete, and CI/pipeline status is terminal green.
|
||||||
|
|||||||
@@ -7,9 +7,7 @@ set -euo pipefail
|
|||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
source "$SCRIPT_DIR/detect-platform.sh"
|
source "$SCRIPT_DIR/detect-platform.sh"
|
||||||
|
|
||||||
BRANCH=""
|
BRANCH="main"
|
||||||
TARGET_REPO=""
|
|
||||||
HEAD_SHA=""
|
|
||||||
TIMEOUT_SEC=900
|
TIMEOUT_SEC=900
|
||||||
INTERVAL_SEC=15
|
INTERVAL_SEC=15
|
||||||
PURPOSE="merge"
|
PURPOSE="merge"
|
||||||
@@ -17,12 +15,10 @@ REQUIRE_STATUS=0
|
|||||||
|
|
||||||
usage() {
|
usage() {
|
||||||
cat <<EOF
|
cat <<EOF
|
||||||
Usage: $(basename "$0") [-B branch] [-R owner/repo] [--sha full-40] [-t timeout_sec] [-i interval_sec] [--purpose push|merge] [--require-status]
|
Usage: $(basename "$0") [-B branch] [-t timeout_sec] [-i interval_sec] [--purpose push|merge] [--require-status]
|
||||||
|
|
||||||
Options:
|
Options:
|
||||||
-B, --branch BRANCH Branch head to inspect (default: current branch)
|
-B, --branch BRANCH Branch head to inspect (default: main)
|
||||||
-R, --repo OWNER/REPO Repository containing the branch (default: origin repo)
|
|
||||||
--sha FULL_SHA Inspect this exact 40-character commit instead of resolving the branch
|
|
||||||
-t, --timeout SECONDS Max wait time in seconds (default: 900)
|
-t, --timeout SECONDS Max wait time in seconds (default: 900)
|
||||||
-i, --interval SECONDS Poll interval in seconds (default: 15)
|
-i, --interval SECONDS Poll interval in seconds (default: 15)
|
||||||
--purpose VALUE Log context: push|merge (default: merge)
|
--purpose VALUE Log context: push|merge (default: merge)
|
||||||
@@ -31,65 +27,63 @@ Options:
|
|||||||
|
|
||||||
Examples:
|
Examples:
|
||||||
$(basename "$0")
|
$(basename "$0")
|
||||||
$(basename "$0") --purpose push -t 600 -i 10
|
$(basename "$0") --purpose push -B main -t 600 -i 10
|
||||||
EOF
|
EOF
|
||||||
}
|
}
|
||||||
|
|
||||||
# get_remote_host and get_gitea_token are provided by detect-platform.sh
|
# get_remote_host and get_gitea_token are provided by detect-platform.sh
|
||||||
|
|
||||||
get_state_from_status_json() {
|
get_state_from_status_json() {
|
||||||
# Python source comes from -c so the provider payload remains on stdin.
|
python3 - <<'PY'
|
||||||
# Never move the payload to argv: commit-status responses can exceed ARG_MAX.
|
|
||||||
python3 -c '
|
|
||||||
import json
|
import json
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
try:
|
try:
|
||||||
payload = json.load(sys.stdin)
|
payload = json.load(sys.stdin)
|
||||||
if not isinstance(payload, dict):
|
|
||||||
raise ValueError("status payload is not an object")
|
|
||||||
except Exception:
|
except Exception:
|
||||||
print("malformed")
|
print("unknown")
|
||||||
raise SystemExit(0)
|
raise SystemExit(0)
|
||||||
|
|
||||||
raw_statuses = payload.get("statuses", [])
|
statuses = payload.get("statuses") or []
|
||||||
raw_state = payload.get("state", "")
|
state = (payload.get("state") or "").lower()
|
||||||
if not isinstance(raw_statuses, list) or not isinstance(raw_state, str):
|
|
||||||
print("malformed")
|
|
||||||
raise SystemExit(0)
|
|
||||||
statuses = raw_statuses
|
|
||||||
state = raw_state.lower()
|
|
||||||
|
|
||||||
pending_values = {"pending", "queued", "running", "waiting"}
|
pending_values = {"pending", "queued", "running", "waiting"}
|
||||||
failure_values = {"failure", "error", "failed"}
|
failure_values = {"failure", "error", "failed"}
|
||||||
success_values = {"success"}
|
success_values = {"success"}
|
||||||
|
|
||||||
|
if state in pending_values:
|
||||||
|
print("pending")
|
||||||
|
raise SystemExit(0)
|
||||||
|
if state in failure_values:
|
||||||
|
print("terminal-failure")
|
||||||
|
raise SystemExit(0)
|
||||||
|
if state in success_values:
|
||||||
|
print("terminal-success")
|
||||||
|
raise SystemExit(0)
|
||||||
|
|
||||||
values = []
|
values = []
|
||||||
for item in statuses:
|
for item in statuses:
|
||||||
if not isinstance(item, dict):
|
if not isinstance(item, dict):
|
||||||
print("malformed")
|
continue
|
||||||
raise SystemExit(0)
|
value = (item.get("status") or item.get("state") or "").lower()
|
||||||
raw_value = item.get("status") or item.get("state")
|
if value:
|
||||||
if not isinstance(raw_value, str) or not raw_value:
|
values.append(value)
|
||||||
print("malformed")
|
|
||||||
raise SystemExit(0)
|
|
||||||
values.append(raw_value.lower())
|
|
||||||
|
|
||||||
if any(value in pending_values for value in values) or state in pending_values:
|
if not values and not state:
|
||||||
print("pending")
|
|
||||||
elif any(value in failure_values for value in values) or state in failure_values:
|
|
||||||
print("terminal-failure")
|
|
||||||
elif values and all(value in success_values for value in values) and state in {"", "success"}:
|
|
||||||
print("terminal-success")
|
|
||||||
elif not values:
|
|
||||||
print("no-status")
|
print("no-status")
|
||||||
|
elif any(v in pending_values for v in values):
|
||||||
|
print("pending")
|
||||||
|
elif any(v in failure_values for v in values):
|
||||||
|
print("terminal-failure")
|
||||||
|
elif values and all(v in success_values for v in values):
|
||||||
|
print("terminal-success")
|
||||||
else:
|
else:
|
||||||
print("unknown")
|
print("unknown")
|
||||||
'
|
PY
|
||||||
}
|
}
|
||||||
|
|
||||||
print_pending_contexts() {
|
print_pending_contexts() {
|
||||||
python3 -c '
|
python3 - <<'PY'
|
||||||
import json
|
import json
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
@@ -110,61 +104,17 @@ for item in statuses:
|
|||||||
if not isinstance(item, dict):
|
if not isinstance(item, dict):
|
||||||
continue
|
continue
|
||||||
name = item.get("context") or item.get("name") or "unknown-context"
|
name = item.get("context") or item.get("name") or "unknown-context"
|
||||||
value = str(item.get("status") or item.get("state") or "unknown").lower()
|
value = (item.get("status") or item.get("state") or "unknown").lower()
|
||||||
target = item.get("target_url") or item.get("url") or ""
|
target = item.get("target_url") or item.get("url") or ""
|
||||||
if value in pending_values:
|
if value in pending_values:
|
||||||
found = True
|
found = True
|
||||||
suffix = f" ({target})" if target else ""
|
if target:
|
||||||
print(f"[ci-queue-wait] pending: {name}={value}{suffix}")
|
print(f"[ci-queue-wait] pending: {name}={value} ({target})")
|
||||||
|
else:
|
||||||
|
print(f"[ci-queue-wait] pending: {name}={value}")
|
||||||
if not found:
|
if not found:
|
||||||
print("[ci-queue-wait] no pending contexts")
|
print("[ci-queue-wait] no pending contexts")
|
||||||
'
|
|
||||||
}
|
|
||||||
|
|
||||||
record_cannot_assert() {
|
|
||||||
local reason="$1"
|
|
||||||
local audit_log="${MOSAIC_CI_QUEUE_AUDIT_LOG:-${XDG_STATE_HOME:-${HOME:-}/.local/state}/mosaic/audit/ci-queue-wait.jsonl}"
|
|
||||||
|
|
||||||
if [[ -z "$audit_log" ]] || ! mkdir -p "$(dirname "$audit_log")"; then
|
|
||||||
echo "Error: CANNOT_ASSERT and audit directory is unavailable; refusing degraded pass." >&2
|
|
||||||
return 70
|
|
||||||
fi
|
|
||||||
|
|
||||||
if ! python3 - "$audit_log" "$reason" "${PLATFORM:-unknown}" "$PURPOSE" "${BRANCH:-unknown}" "${OWNER:-unknown}/${REPO:-unknown}" <<'PY'
|
|
||||||
import datetime
|
|
||||||
import json
|
|
||||||
import os
|
|
||||||
import sys
|
|
||||||
|
|
||||||
path, reason, platform, purpose, branch, repo = sys.argv[1:]
|
|
||||||
record = {
|
|
||||||
"timestamp": datetime.datetime.now(datetime.timezone.utc).isoformat(),
|
|
||||||
"outcome": "CANNOT_ASSERT",
|
|
||||||
"reason": reason,
|
|
||||||
"platform": platform,
|
|
||||||
"purpose": purpose,
|
|
||||||
"disposition": "hold" if purpose == "merge" else "degraded-pass",
|
|
||||||
"branch": branch,
|
|
||||||
"repo": repo,
|
|
||||||
}
|
|
||||||
fd = os.open(path, os.O_WRONLY | os.O_CREAT | os.O_APPEND, 0o600)
|
|
||||||
try:
|
|
||||||
os.write(fd, (json.dumps(record, separators=(",", ":")) + "\n").encode())
|
|
||||||
finally:
|
|
||||||
os.close(fd)
|
|
||||||
PY
|
PY
|
||||||
then
|
|
||||||
echo "Error: CANNOT_ASSERT and audit write failed at ${audit_log}; refusing degraded pass." >&2
|
|
||||||
return 70
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ "$PURPOSE" == "merge" ]]; then
|
|
||||||
echo "[ci-queue-wait] CANNOT_ASSERT reason=${reason} purpose=merge branch=${BRANCH:-unknown}; audited=${audit_log}; HOLD (exit 75). Retry after provider recovery; no manual reset is required." >&2
|
|
||||||
return 75
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "[ci-queue-wait] CANNOT_ASSERT reason=${reason} purpose=push branch=${BRANCH:-unknown}; audited=${audit_log}; push may proceed in degraded mode." >&2
|
|
||||||
return 0
|
|
||||||
}
|
}
|
||||||
|
|
||||||
github_get_branch_head_sha() {
|
github_get_branch_head_sha() {
|
||||||
@@ -178,87 +128,7 @@ github_get_commit_status_json() {
|
|||||||
local owner="$1"
|
local owner="$1"
|
||||||
local repo="$2"
|
local repo="$2"
|
||||||
local sha="$3"
|
local sha="$3"
|
||||||
local work_root status_file checks_file
|
gh api "repos/${owner}/${repo}/commits/${sha}/status"
|
||||||
work_root="${AGENT_WORK_ROOT:-${HOME:-}/.cache/mosaic/ci-queue-wait}"
|
|
||||||
mkdir -p "$work_root" || return 1
|
|
||||||
status_file=$(mktemp "$work_root/github-status.XXXXXX") || return 1
|
|
||||||
checks_file=$(mktemp "$work_root/github-checks.XXXXXX") || {
|
|
||||||
rm -f "$status_file"
|
|
||||||
return 1
|
|
||||||
}
|
|
||||||
|
|
||||||
if ! gh api --paginate --slurp "repos/${owner}/${repo}/commits/${sha}/statuses?per_page=100" > "$status_file" ||
|
|
||||||
! gh api --paginate --slurp "repos/${owner}/${repo}/commits/${sha}/check-runs?per_page=100&filter=latest" > "$checks_file"; then
|
|
||||||
rm -f "$status_file" "$checks_file"
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
python3 - "$status_file" "$checks_file" <<'PY'
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
|
|
||||||
with open(sys.argv[1], encoding="utf-8") as handle:
|
|
||||||
status_pages = json.load(handle)
|
|
||||||
with open(sys.argv[2], encoding="utf-8") as handle:
|
|
||||||
check_pages = json.load(handle)
|
|
||||||
|
|
||||||
if not isinstance(status_pages, list) or not isinstance(check_pages, list):
|
|
||||||
raise SystemExit(1)
|
|
||||||
|
|
||||||
# The statuses endpoint is newest-first and can contain retries for one context.
|
|
||||||
# Keep only the newest entry per context after flattening every page.
|
|
||||||
combined = []
|
|
||||||
seen_contexts = set()
|
|
||||||
for page in status_pages:
|
|
||||||
if not isinstance(page, list):
|
|
||||||
raise SystemExit(1)
|
|
||||||
for status in page:
|
|
||||||
if not isinstance(status, dict):
|
|
||||||
raise SystemExit(1)
|
|
||||||
context = status.get("context")
|
|
||||||
if not isinstance(context, str) or not context or context in seen_contexts:
|
|
||||||
continue
|
|
||||||
seen_contexts.add(context)
|
|
||||||
combined.append(status)
|
|
||||||
|
|
||||||
check_runs = []
|
|
||||||
reported_total = 0
|
|
||||||
for page in check_pages:
|
|
||||||
if not isinstance(page, dict):
|
|
||||||
raise SystemExit(1)
|
|
||||||
page_runs = page.get("check_runs") or []
|
|
||||||
total_count = page.get("total_count")
|
|
||||||
if not isinstance(page_runs, list) or not isinstance(total_count, int):
|
|
||||||
raise SystemExit(1)
|
|
||||||
reported_total = max(reported_total, total_count)
|
|
||||||
check_runs.extend(page_runs)
|
|
||||||
if len(check_runs) < reported_total:
|
|
||||||
raise SystemExit(1)
|
|
||||||
|
|
||||||
for run in check_runs:
|
|
||||||
if not isinstance(run, dict):
|
|
||||||
raise SystemExit(1)
|
|
||||||
status = run.get("status")
|
|
||||||
conclusion = run.get("conclusion")
|
|
||||||
if status != "completed":
|
|
||||||
value = "pending"
|
|
||||||
elif conclusion == "success":
|
|
||||||
value = "success"
|
|
||||||
elif conclusion in {"failure", "cancelled", "timed_out", "action_required", "startup_failure", "stale"}:
|
|
||||||
value = "failure"
|
|
||||||
else:
|
|
||||||
value = "unknown"
|
|
||||||
combined.append({
|
|
||||||
"context": run.get("name") or "github-check",
|
|
||||||
"status": value,
|
|
||||||
"target_url": run.get("html_url") or run.get("details_url") or "",
|
|
||||||
})
|
|
||||||
|
|
||||||
json.dump({"state": "", "statuses": combined}, sys.stdout)
|
|
||||||
PY
|
|
||||||
local status=$?
|
|
||||||
rm -f "$status_file" "$checks_file"
|
|
||||||
return "$status"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
gitea_get_branch_head_sha() {
|
gitea_get_branch_head_sha() {
|
||||||
@@ -304,14 +174,6 @@ while [[ $# -gt 0 ]]; do
|
|||||||
BRANCH="$2"
|
BRANCH="$2"
|
||||||
shift 2
|
shift 2
|
||||||
;;
|
;;
|
||||||
-R|--repo)
|
|
||||||
TARGET_REPO="$2"
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
--sha)
|
|
||||||
HEAD_SHA="$2"
|
|
||||||
shift 2
|
|
||||||
;;
|
|
||||||
-t|--timeout)
|
-t|--timeout)
|
||||||
TIMEOUT_SEC="$2"
|
TIMEOUT_SEC="$2"
|
||||||
shift 2
|
shift 2
|
||||||
@@ -344,89 +206,45 @@ if ! [[ "$TIMEOUT_SEC" =~ ^[0-9]+$ ]] || ! [[ "$INTERVAL_SEC" =~ ^[0-9]+$ ]]; th
|
|||||||
echo "Error: timeout and interval must be integer seconds." >&2
|
echo "Error: timeout and interval must be integer seconds." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
if [[ -n "$HEAD_SHA" && ! "$HEAD_SHA" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
|
||||||
echo "Error: --sha must be a full 40-character hexadecimal commit SHA." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -n "$TARGET_REPO" && ! "$TARGET_REPO" =~ ^[^/[:space:]]+/[^/[:space:]]+$ ]]; then
|
|
||||||
echo "Error: --repo must be OWNER/REPO." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ "$PURPOSE" != "push" && "$PURPOSE" != "merge" ]]; then
|
OWNER=$(get_repo_owner)
|
||||||
echo "Error: --purpose must be push or merge." >&2
|
REPO=$(get_repo_name)
|
||||||
exit 1
|
detect_platform > /dev/null
|
||||||
fi
|
|
||||||
|
|
||||||
OWNER="unknown"
|
|
||||||
REPO="unknown"
|
|
||||||
PLATFORM="unknown"
|
|
||||||
if ! OWNER=$(get_repo_owner) || [[ -z "$OWNER" ]]; then
|
|
||||||
record_cannot_assert "repository-owner-unresolvable"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
if ! REPO=$(get_repo_name) || [[ -z "$REPO" ]]; then
|
|
||||||
record_cannot_assert "repository-name-unresolvable"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
if ! detect_platform > /dev/null; then
|
|
||||||
PLATFORM="${PLATFORM:-unknown}"
|
|
||||||
record_cannot_assert "unsupported-platform"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
PLATFORM="${PLATFORM:-unknown}"
|
PLATFORM="${PLATFORM:-unknown}"
|
||||||
|
|
||||||
if [[ -n "$TARGET_REPO" ]]; then
|
|
||||||
OWNER="${TARGET_REPO%%/*}"
|
|
||||||
REPO="${TARGET_REPO##*/}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ -z "$BRANCH" ]]; then
|
|
||||||
if ! BRANCH=$(git symbolic-ref --quiet --short HEAD) || [[ -z "$BRANCH" ]]; then
|
|
||||||
record_cannot_assert "current-branch-unresolvable"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ "$PLATFORM" == "github" ]]; then
|
if [[ "$PLATFORM" == "github" ]]; then
|
||||||
if ! command -v gh >/dev/null 2>&1; then
|
if ! command -v gh >/dev/null 2>&1; then
|
||||||
record_cannot_assert "github-cli-unavailable"
|
echo "Error: gh CLI is required for GitHub CI queue guard." >&2
|
||||||
exit $?
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
HEAD_SHA=$(github_get_branch_head_sha "$OWNER" "$REPO" "$BRANCH")
|
||||||
if [[ -z "$HEAD_SHA" ]]; then
|
if [[ -z "$HEAD_SHA" ]]; then
|
||||||
if ! HEAD_SHA=$(github_get_branch_head_sha "$OWNER" "$REPO" "$BRANCH") || [[ -z "$HEAD_SHA" ]]; then
|
echo "Error: Could not resolve ${BRANCH} head SHA." >&2
|
||||||
record_cannot_assert "branch-head-unavailable"
|
exit 1
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
echo "[ci-queue-wait] platform=github purpose=${PURPOSE} branch=${BRANCH} sha=${HEAD_SHA}"
|
echo "[ci-queue-wait] platform=github purpose=${PURPOSE} branch=${BRANCH} sha=${HEAD_SHA}"
|
||||||
elif [[ "$PLATFORM" == "gitea" ]]; then
|
elif [[ "$PLATFORM" == "gitea" ]]; then
|
||||||
if ! HOST=$(get_remote_host) || [[ -z "$HOST" ]]; then
|
HOST=$(get_remote_host) || {
|
||||||
record_cannot_assert "remote-host-unresolvable"
|
echo "Error: Could not determine remote host." >&2
|
||||||
exit $?
|
exit 1
|
||||||
fi
|
}
|
||||||
if ! TOKEN=$(get_gitea_token "$HOST") || [[ -z "$TOKEN" ]]; then
|
TOKEN=$(get_gitea_token "$HOST") || {
|
||||||
record_cannot_assert "credential-unresolvable"
|
echo "Error: Gitea token not found. Set GITEA_TOKEN or configure ~/.git-credentials." >&2
|
||||||
exit $?
|
exit 1
|
||||||
|
}
|
||||||
|
HEAD_SHA=$(gitea_get_branch_head_sha "$HOST" "$OWNER/$REPO" "$BRANCH" "$TOKEN")
|
||||||
|
if [[ "$HEAD_SHA" == "__BRANCH_ABSENT__" ]]; then
|
||||||
|
echo "[ci-queue-wait] branch ${BRANCH} not yet on remote — no in-flight pipeline; queue clear."
|
||||||
|
exit 0
|
||||||
fi
|
fi
|
||||||
if [[ -z "$HEAD_SHA" ]]; then
|
if [[ -z "$HEAD_SHA" ]]; then
|
||||||
if ! HEAD_SHA=$(gitea_get_branch_head_sha "$HOST" "$OWNER/$REPO" "$BRANCH" "$TOKEN"); then
|
echo "Error: Could not resolve ${BRANCH} head SHA." >&2
|
||||||
record_cannot_assert "branch-head-unavailable"
|
exit 1
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
if [[ "$HEAD_SHA" == "__BRANCH_ABSENT__" ]]; then
|
|
||||||
echo "[ci-queue-wait] branch ${BRANCH} not yet on remote — no in-flight pipeline; queue clear."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
if [[ -z "$HEAD_SHA" ]]; then
|
|
||||||
record_cannot_assert "branch-head-unavailable"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
echo "[ci-queue-wait] platform=gitea purpose=${PURPOSE} branch=${BRANCH} sha=${HEAD_SHA}"
|
echo "[ci-queue-wait] platform=gitea purpose=${PURPOSE} branch=${BRANCH} sha=${HEAD_SHA}"
|
||||||
else
|
else
|
||||||
record_cannot_assert "unsupported-platform"
|
echo "Error: Unsupported platform '${PLATFORM}'." >&2
|
||||||
exit $?
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
START_TS=$(date +%s)
|
START_TS=$(date +%s)
|
||||||
@@ -435,20 +253,14 @@ DEADLINE_TS=$((START_TS + TIMEOUT_SEC))
|
|||||||
while true; do
|
while true; do
|
||||||
NOW_TS=$(date +%s)
|
NOW_TS=$(date +%s)
|
||||||
if (( NOW_TS > DEADLINE_TS )); then
|
if (( NOW_TS > DEADLINE_TS )); then
|
||||||
echo "Error: ASSERTED_NOT_READY state=pending; timed out waiting for CI queue to clear on ${BRANCH} after ${TIMEOUT_SEC}s." >&2
|
echo "Error: Timed out waiting for CI queue to clear on ${BRANCH} after ${TIMEOUT_SEC}s." >&2
|
||||||
exit 124
|
exit 124
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$PLATFORM" == "github" ]]; then
|
if [[ "$PLATFORM" == "github" ]]; then
|
||||||
if ! STATUS_JSON=$(github_get_commit_status_json "$OWNER" "$REPO" "$HEAD_SHA"); then
|
STATUS_JSON=$(github_get_commit_status_json "$OWNER" "$REPO" "$HEAD_SHA")
|
||||||
record_cannot_assert "status-provider-unreachable"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
else
|
else
|
||||||
if ! STATUS_JSON=$(gitea_get_commit_status_json "$HOST" "$OWNER/$REPO" "$HEAD_SHA" "$TOKEN"); then
|
STATUS_JSON=$(gitea_get_commit_status_json "$HOST" "$OWNER/$REPO" "$HEAD_SHA" "$TOKEN")
|
||||||
record_cannot_assert "status-provider-unreachable"
|
|
||||||
exit $?
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
STATE=$(printf '%s' "$STATUS_JSON" | get_state_from_status_json)
|
STATE=$(printf '%s' "$STATUS_JSON" | get_state_from_status_json)
|
||||||
@@ -459,24 +271,21 @@ while true; do
|
|||||||
printf '%s' "$STATUS_JSON" | print_pending_contexts
|
printf '%s' "$STATUS_JSON" | print_pending_contexts
|
||||||
sleep "$INTERVAL_SEC"
|
sleep "$INTERVAL_SEC"
|
||||||
;;
|
;;
|
||||||
terminal-success)
|
|
||||||
exit 0
|
|
||||||
;;
|
|
||||||
no-status)
|
no-status)
|
||||||
if [[ "$REQUIRE_STATUS" -eq 1 ]]; then
|
if [[ "$REQUIRE_STATUS" -eq 1 ]]; then
|
||||||
echo "Error: ASSERTED_NOT_READY state=no-status; --require-status was set for ${BRANCH}." >&2
|
echo "Error: No CI status contexts found for ${BRANCH} while --require-status is set." >&2
|
||||||
else
|
exit 1
|
||||||
echo "Error: ASSERTED_NOT_READY state=no-status purpose=${PURPOSE} branch=${BRANCH}." >&2
|
|
||||||
fi
|
fi
|
||||||
exit 3
|
echo "[ci-queue-wait] no status contexts present; proceeding."
|
||||||
|
exit 0
|
||||||
;;
|
;;
|
||||||
terminal-failure|malformed|unknown)
|
terminal-success|terminal-failure|unknown)
|
||||||
echo "Error: ASSERTED_NOT_READY state=${STATE} purpose=${PURPOSE} branch=${BRANCH}." >&2
|
# Queue guard only blocks on pending/running/queued states.
|
||||||
exit 3
|
exit 0
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
echo "Error: ASSERTED_NOT_READY unrecognized-state=${STATE} purpose=${PURPOSE} branch=${BRANCH}." >&2
|
echo "[ci-queue-wait] unrecognized state '${STATE}', proceeding conservatively."
|
||||||
exit 3
|
exit 0
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
done
|
done
|
||||||
|
|||||||
@@ -499,17 +499,8 @@ get_gitea_url_for_host() {
|
|||||||
|
|
||||||
# Resolve a Gitea API token for the given host.
|
# Resolve a Gitea API token for the given host.
|
||||||
# Priority: Mosaic credential loader → GITEA_TOKEN env → ~/.git-credentials
|
# Priority: Mosaic credential loader → GITEA_TOKEN env → ~/.git-credentials
|
||||||
_trace_credential_resolution() {
|
|
||||||
[[ "${MOSAIC_CREDENTIAL_TRACE:-}" == 1 ]] || return 0
|
|
||||||
local reason="$1" identity="$2" host="$3" source="$4"
|
|
||||||
local shared_path_entered=false
|
|
||||||
[[ "$_resolution_path" == shared ]] && shared_path_entered=true
|
|
||||||
printf 'MOSAIC_CREDENTIAL_RESOLUTION outcome=ok reason=%s identity=%s host=%s resolution_path=%s shared_path_entered=%s source=%s\n' \
|
|
||||||
"$reason" "$identity" "$host" "$_resolution_path" "$shared_path_entered" "$source" >&2
|
|
||||||
}
|
|
||||||
|
|
||||||
get_gitea_token() {
|
get_gitea_token() {
|
||||||
local host="$1" _resolution_path=unresolved
|
local host="$1"
|
||||||
local script_dir
|
local script_dir
|
||||||
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
local cred_loader="$script_dir/../_lib/credentials.sh"
|
local cred_loader="$script_dir/../_lib/credentials.sh"
|
||||||
@@ -525,16 +516,6 @@ get_gitea_token() {
|
|||||||
_ident="$(git config --get mosaic.gitIdentity 2>/dev/null || true)"
|
_ident="$(git config --get mosaic.gitIdentity 2>/dev/null || true)"
|
||||||
_ident_src="git config mosaic.gitIdentity"
|
_ident_src="git config mosaic.gitIdentity"
|
||||||
fi
|
fi
|
||||||
if [[ -n "$_ident" && ! "$_ident" =~ ^[A-Za-z0-9][A-Za-z0-9_.-]*$ ]]; then
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=invalid-identity identity=<invalid> host=%s shared_path_entered=false source=%s\n' \
|
|
||||||
"$host" "$_ident_src" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
if [[ -n "${MOSAIC_AGENT_NAME:-}" && -n "$_ident" && "$_ident" != "$MOSAIC_AGENT_NAME" ]]; then
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=provider-identity-mismatch identity=%s fleet_identity=%s host=%s shared_path_entered=false source=%s\n' \
|
|
||||||
"$_ident" "$MOSAIC_AGENT_NAME" "$host" "$_ident_src" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
if [[ -n "$_ident" ]]; then
|
if [[ -n "$_ident" ]]; then
|
||||||
local _idpfx=""
|
local _idpfx=""
|
||||||
case "$host" in
|
case "$host" in
|
||||||
@@ -543,23 +524,8 @@ get_gitea_token() {
|
|||||||
esac
|
esac
|
||||||
if [[ -n "$_idpfx" ]]; then
|
if [[ -n "$_idpfx" ]]; then
|
||||||
local _idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${_idpfx}-${_ident}.token"
|
local _idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${_idpfx}-${_ident}.token"
|
||||||
local _idcred="$HOME/.config/mosaic/secrets/gitea-tokens/${_idpfx}-${_ident}.credential.json"
|
if [[ -r "$_idtok" ]]; then
|
||||||
if [[ -e "$_idcred" || -L "$_idcred" ]]; then
|
cat "$_idtok"
|
||||||
local _resolved_token
|
|
||||||
_resolved_token=$(python3 "$script_dir/resolve-credential-envelope.py" \
|
|
||||||
"$HOME/.config/mosaic/secrets/gitea-tokens" "$_idcred" "$_ident" "${MOSAIC_CREDENTIAL_ESTATE:-}" "$host") || return 1
|
|
||||||
_resolution_path=identity
|
|
||||||
_trace_credential_resolution credential-resolved "$_ident" "$host" "$_ident_src"
|
|
||||||
printf '%s\n' "$_resolved_token"
|
|
||||||
return 0
|
|
||||||
fi
|
|
||||||
if [[ -e "$_idtok" || -L "$_idtok" ]]; then
|
|
||||||
local _resolved_token
|
|
||||||
_resolved_token=$(python3 "$script_dir/resolve-legacy-token.py" \
|
|
||||||
"$HOME/.config/mosaic/secrets/gitea-tokens" "$_idtok") || return 1
|
|
||||||
_resolution_path=identity
|
|
||||||
_trace_credential_resolution credential-resolved "$_ident" "$host" "$_ident_src"
|
|
||||||
printf '%s\n' "$_resolved_token"
|
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
# FAIL LOUD: an explicit git identity was requested for a recognized Gitea host,
|
# FAIL LOUD: an explicit git identity was requested for a recognized Gitea host,
|
||||||
@@ -568,21 +534,12 @@ get_gitea_token() {
|
|||||||
# would post PRs/issues/reviews under the WRONG agent (e.g. rev2's review attributed
|
# would post PRs/issues/reviews under the WRONG agent (e.g. rev2's review attributed
|
||||||
# to coder3), corrupting Gate-16 author≠reviewer separation. Hard-stop instead so the
|
# to coder3), corrupting Gate-16 author≠reviewer separation. Hard-stop instead so the
|
||||||
# caller aborts loudly rather than acting as the wrong identity.
|
# caller aborts loudly rather than acting as the wrong identity.
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=no-token-for-identity identity=%s host=%s shared_path_entered=false source=%s path=%s\n' \
|
echo "Error: git identity '$_ident' requested (via $_ident_src) for host '$host', but no per-slot token at $_idtok." >&2
|
||||||
"$_ident" "$host" "$_ident_src" "$_idtok" >&2
|
echo " Refusing to borrow another slot's token. Provision the per-slot token, or unset the identity to use shared credentials." >&2
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Fleet automation never borrows a shared human/default credential. An
|
|
||||||
# explicit interactive caller may still reach the shared paths below, but
|
|
||||||
# a fleet process must name an identity and resolve that identity exactly.
|
|
||||||
if [[ -n "${MOSAIC_AGENT_NAME:-}" ]]; then
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=identity-required identity=<unset> host=%s shared_path_entered=false source=MOSAIC_AGENT_NAME\n' \
|
|
||||||
"$host" >&2
|
|
||||||
return 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# 1. Mosaic credential loader (host → service mapping, run in subshell to avoid polluting env)
|
# 1. Mosaic credential loader (host → service mapping, run in subshell to avoid polluting env)
|
||||||
if [[ -f "$cred_loader" ]]; then
|
if [[ -f "$cred_loader" ]]; then
|
||||||
local token
|
local token
|
||||||
@@ -614,8 +571,6 @@ get_gitea_token() {
|
|||||||
echo "${GITEA_TOKEN:-}"
|
echo "${GITEA_TOKEN:-}"
|
||||||
)
|
)
|
||||||
if [[ -n "$token" ]]; then
|
if [[ -n "$token" ]]; then
|
||||||
_resolution_path=shared
|
|
||||||
_trace_credential_resolution shared-credential-resolved '<interactive-shared>' "$host" credentials-loader
|
|
||||||
echo "$token"
|
echo "$token"
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
@@ -624,8 +579,6 @@ get_gitea_token() {
|
|||||||
# 2. GITEA_TOKEN env var (only when GITEA_URL, if present, matches the remote host)
|
# 2. GITEA_TOKEN env var (only when GITEA_URL, if present, matches the remote host)
|
||||||
if [[ -n "${GITEA_TOKEN:-}" ]]; then
|
if [[ -n "${GITEA_TOKEN:-}" ]]; then
|
||||||
if [[ -z "${GITEA_URL:-}" ]] || gitea_url_matches_host "$GITEA_URL" "$host"; then
|
if [[ -z "${GITEA_URL:-}" ]] || gitea_url_matches_host "$GITEA_URL" "$host"; then
|
||||||
_resolution_path=shared
|
|
||||||
_trace_credential_resolution shared-credential-resolved '<interactive-shared>' "$host" environment
|
|
||||||
echo "$GITEA_TOKEN"
|
echo "$GITEA_TOKEN"
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
@@ -637,8 +590,6 @@ get_gitea_token() {
|
|||||||
local token
|
local token
|
||||||
token=$(grep -F "$host" "$creds" 2>/dev/null | sed -n 's#https\?://[^@]*:\([^@/]*\)@.*#\1#p' | head -n 1)
|
token=$(grep -F "$host" "$creds" 2>/dev/null | sed -n 's#https\?://[^@]*:\([^@/]*\)@.*#\1#p' | head -n 1)
|
||||||
if [[ -n "$token" ]]; then
|
if [[ -n "$token" ]]; then
|
||||||
_resolution_path=shared
|
|
||||||
_trace_credential_resolution shared-credential-resolved '<interactive-shared>' "$host" git-credentials
|
|
||||||
echo "$token"
|
echo "$token"
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -24,79 +24,29 @@ while IFS= read -r line; do
|
|||||||
username=*) username_in=${line#username=};;
|
username=*) username_in=${line#username=};;
|
||||||
esac
|
esac
|
||||||
done
|
done
|
||||||
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
trace_resolution() {
|
|
||||||
[ "${MOSAIC_CREDENTIAL_TRACE:-}" = 1 ] || return 0
|
|
||||||
reason="$1" trace_identity="$2" trace_host="$3" source="$4"
|
|
||||||
shared_path_entered=false
|
|
||||||
[ "$resolution_path" = shared ] && shared_path_entered=true
|
|
||||||
printf 'MOSAIC_CREDENTIAL_RESOLUTION outcome=ok reason=%s identity=%s host=%s resolution_path=%s shared_path_entered=%s source=%s\n' \
|
|
||||||
"$reason" "$trace_identity" "$trace_host" "$resolution_path" "$shared_path_entered" "$source" >&2
|
|
||||||
}
|
|
||||||
resolution_path=unresolved
|
|
||||||
# Per-agent identity resolution (Gate-16 author≠reviewer separation).
|
# Per-agent identity resolution (Gate-16 author≠reviewer separation).
|
||||||
# Priority: MOSAIC_GIT_IDENTITY env > git config mosaic.gitIdentity (per-worktree,
|
# Priority: MOSAIC_GIT_IDENTITY env > git config mosaic.gitIdentity (per-worktree,
|
||||||
# survives across non-persistent shells) > git-supplied username (credential.username
|
# survives across non-persistent shells) > git-supplied username (credential.username
|
||||||
# / URL). When the resolved identity has a matching per-agent token, use it instead of
|
# / URL). When the resolved identity has a matching per-agent token, use it instead of
|
||||||
# the shared account. Backward-compatible: nothing resolvable → shared token.
|
# the shared account. Backward-compatible: nothing resolvable → shared token.
|
||||||
case "$host" in
|
|
||||||
git.uscllc.com) idpfx=gitea-usc;;
|
|
||||||
git.mosaicstack.dev) idpfx=gitea-mosaicstack;;
|
|
||||||
*) exit 0;;
|
|
||||||
esac
|
|
||||||
ident="$MOSAIC_GIT_IDENTITY"
|
ident="$MOSAIC_GIT_IDENTITY"
|
||||||
[ -z "$ident" ] && ident=$(git config --get mosaic.gitIdentity 2>/dev/null)
|
[ -z "$ident" ] && ident=$(git config --get mosaic.gitIdentity 2>/dev/null)
|
||||||
[ -z "$ident" ] && ident="$username_in"
|
[ -z "$ident" ] && ident="$username_in"
|
||||||
if [[ -n "$ident" && ! "$ident" =~ ^[A-Za-z0-9][A-Za-z0-9_.-]*$ ]]; then
|
|
||||||
echo "quit=true"
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=invalid-identity identity=<invalid> host=%s shared_path_entered=false source=git-credential-mosaic\n' "$host" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [ -n "$idpfx" ] && [ -n "${MOSAIC_AGENT_NAME:-}" ] && [ -n "$ident" ] && [ "$ident" != "$MOSAIC_AGENT_NAME" ]; then
|
|
||||||
echo "quit=true"
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=provider-identity-mismatch identity=%s fleet_identity=%s host=%s shared_path_entered=false source=git-credential-mosaic\n' \
|
|
||||||
"$ident" "$MOSAIC_AGENT_NAME" "$host" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [ -n "$ident" ]; then
|
if [ -n "$ident" ]; then
|
||||||
|
case "$host" in
|
||||||
|
git.uscllc.com) idpfx=gitea-usc;;
|
||||||
|
git.mosaicstack.dev) idpfx=gitea-mosaicstack;;
|
||||||
|
*) idpfx="";;
|
||||||
|
esac
|
||||||
if [ -n "$idpfx" ]; then
|
if [ -n "$idpfx" ]; then
|
||||||
idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${idpfx}-${ident}.token"
|
idtok="$HOME/.config/mosaic/secrets/gitea-tokens/${idpfx}-${ident}.token"
|
||||||
idcred="$HOME/.config/mosaic/secrets/gitea-tokens/${idpfx}-${ident}.credential.json"
|
if [ -r "$idtok" ]; then
|
||||||
if [ -e "$idcred" ] || [ -L "$idcred" ]; then
|
|
||||||
token=$(python3 "$script_dir/resolve-credential-envelope.py" \
|
|
||||||
"$HOME/.config/mosaic/secrets/gitea-tokens" "$idcred" "$ident" "${MOSAIC_CREDENTIAL_ESTATE:-}" "$host") || exit 1
|
|
||||||
resolution_path=identity
|
|
||||||
trace_resolution credential-resolved "$ident" "$host" git-credential-mosaic
|
|
||||||
echo "username=${ident}"
|
echo "username=${ident}"
|
||||||
echo "password=${token}"
|
echo "password=$(cat "$idtok")"
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
if [ -e "$idtok" ] || [ -L "$idtok" ]; then
|
|
||||||
token=$(python3 "$script_dir/resolve-legacy-token.py" \
|
|
||||||
"$HOME/.config/mosaic/secrets/gitea-tokens" "$idtok") || exit 1
|
|
||||||
resolution_path=identity
|
|
||||||
trace_resolution credential-resolved "$ident" "$host" git-credential-mosaic
|
|
||||||
echo "username=${ident}"
|
|
||||||
echo "password=${token}"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
if [ -n "${MOSAIC_AGENT_NAME:-}" ]; then
|
|
||||||
echo "quit=true"
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=no-token-for-identity identity=%s host=%s shared_path_entered=false source=git-credential-mosaic path=%s\n' \
|
|
||||||
"$ident" "$host" "$idtok" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
if [ -n "${MOSAIC_AGENT_NAME:-}" ] && [ -z "$ident" ]; then
|
|
||||||
case "$host" in
|
|
||||||
git.uscllc.com|git.mosaicstack.dev)
|
|
||||||
echo "quit=true"
|
|
||||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=identity-required identity=<unset> host=%s shared_path_entered=false source=git-credential-mosaic\n' "$host" >&2
|
|
||||||
exit 1
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
fi
|
|
||||||
case "$host" in
|
case "$host" in
|
||||||
git.uscllc.com) svc=gitea-usc;;
|
git.uscllc.com) svc=gitea-usc;;
|
||||||
git.mosaicstack.dev) svc=gitea-mosaicstack;;
|
git.mosaicstack.dev) svc=gitea-mosaicstack;;
|
||||||
@@ -105,11 +55,10 @@ esac
|
|||||||
# Script-relative (not $HOME-absolute) so this resolves correctly regardless
|
# Script-relative (not $HOME-absolute) so this resolves correctly regardless
|
||||||
# of where the framework installer places tools/ under $HOME — mirrors
|
# of where the framework installer places tools/ under $HOME — mirrors
|
||||||
# detect-platform.sh's own cred_loader resolution in this same directory.
|
# detect-platform.sh's own cred_loader resolution in this same directory.
|
||||||
|
script_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
# shellcheck source=../_lib/credentials.sh
|
# shellcheck source=../_lib/credentials.sh
|
||||||
source "$script_dir/../_lib/credentials.sh"
|
source "$script_dir/../_lib/credentials.sh"
|
||||||
load_credentials "$svc" >/dev/null 2>&1 || exit 0
|
load_credentials "$svc" >/dev/null 2>&1 || exit 0
|
||||||
resolution_path=shared
|
|
||||||
trace_resolution shared-credential-resolved '<interactive-shared>' "$host" credentials-loader
|
|
||||||
# GITEA_USER is not populated by load_credentials (it only exports
|
# GITEA_USER is not populated by load_credentials (it only exports
|
||||||
# GITEA_URL/GITEA_TOKEN for gitea-*), so this fallback is normally taken. Gitea's
|
# GITEA_URL/GITEA_TOKEN for gitea-*), so this fallback is normally taken. Gitea's
|
||||||
# git-over-HTTP auth authenticates from the token itself (the password field),
|
# git-over-HTTP auth authenticates from the token itself (the password field),
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# pr-merge.sh - Merge pull requests on Gitea or GitHub
|
# pr-merge.sh - Merge pull requests on Gitea or GitHub
|
||||||
# Usage: pr-merge.sh -n PR_NUMBER [-m squash] [-d]
|
# Usage: pr-merge.sh -n PR_NUMBER [-m squash] [-d] [--skip-queue-guard]
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
@@ -12,8 +12,8 @@ source "$SCRIPT_DIR/detect-platform.sh"
|
|||||||
PR_NUMBER=""
|
PR_NUMBER=""
|
||||||
MERGE_METHOD="squash"
|
MERGE_METHOD="squash"
|
||||||
DELETE_BRANCH=false
|
DELETE_BRANCH=false
|
||||||
|
SKIP_QUEUE_GUARD=false
|
||||||
DRY_RUN=false
|
DRY_RUN=false
|
||||||
EXPECT_HEAD=""
|
|
||||||
|
|
||||||
usage() {
|
usage() {
|
||||||
cat <<EOF
|
cat <<EOF
|
||||||
@@ -25,14 +25,15 @@ Options:
|
|||||||
-n, --number NUMBER PR number to merge (required)
|
-n, --number NUMBER PR number to merge (required)
|
||||||
-m, --method METHOD Merge method: squash only (default: squash)
|
-m, --method METHOD Merge method: squash only (default: squash)
|
||||||
-d, --delete-branch Delete the head branch after merge
|
-d, --delete-branch Delete the head branch after merge
|
||||||
|
--skip-queue-guard Skip CI queue guard wait before merge
|
||||||
--dry-run Run metadata/login preflight without merging
|
--dry-run Run metadata/login preflight without merging
|
||||||
--expect-head SHA Refuse unless the PR head matches this full commit SHA
|
|
||||||
-h, --help Show this help message
|
-h, --help Show this help message
|
||||||
|
|
||||||
Examples:
|
Examples:
|
||||||
$(basename "$0") -n 42 # Merge PR #42
|
$(basename "$0") -n 42 # Merge PR #42
|
||||||
$(basename "$0") -n 42 -m squash # Squash merge
|
$(basename "$0") -n 42 -m squash # Squash merge
|
||||||
$(basename "$0") -n 42 -d # Squash merge and delete branch
|
$(basename "$0") -n 42 -d # Squash merge and delete branch
|
||||||
|
$(basename "$0") -n 42 --skip-queue-guard # Skip queue guard wait
|
||||||
EOF
|
EOF
|
||||||
exit "${1:-1}"
|
exit "${1:-1}"
|
||||||
}
|
}
|
||||||
@@ -52,13 +53,14 @@ while [[ $# -gt 0 ]]; do
|
|||||||
DELETE_BRANCH=true
|
DELETE_BRANCH=true
|
||||||
shift
|
shift
|
||||||
;;
|
;;
|
||||||
--dry-run)
|
--skip-queue-guard)
|
||||||
DRY_RUN=true
|
SKIP_QUEUE_GUARD=true
|
||||||
shift
|
shift
|
||||||
;;
|
;;
|
||||||
--expect-head)
|
--dry-run)
|
||||||
EXPECT_HEAD="$2"
|
DRY_RUN=true
|
||||||
shift 2
|
SKIP_QUEUE_GUARD=true
|
||||||
|
shift
|
||||||
;;
|
;;
|
||||||
-h|--help)
|
-h|--help)
|
||||||
usage 0
|
usage 0
|
||||||
@@ -84,36 +86,18 @@ if [[ "$MERGE_METHOD" != "squash" ]]; then
|
|||||||
echo "Error: Mosaic policy enforces squash merge only. Received '$MERGE_METHOD'." >&2
|
echo "Error: Mosaic policy enforces squash merge only. Received '$MERGE_METHOD'." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
if [[ -n "$EXPECT_HEAD" && ! "$EXPECT_HEAD" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
|
||||||
echo "Error: --expect-head must be a full 40-character hexadecimal commit SHA." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
PR_METADATA="$("$SCRIPT_DIR/pr-metadata.sh" -n "$PR_NUMBER")"
|
PR_METADATA="$("$SCRIPT_DIR/pr-metadata.sh" -n "$PR_NUMBER")"
|
||||||
BASE_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("baseRefName") or "").strip())')"
|
BASE_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("baseRefName") or "").strip())')"
|
||||||
HEAD_BRANCH="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("headRefName") or "").strip())')"
|
|
||||||
HEAD_SHA="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; print((json.load(sys.stdin).get("headRefOid") or "").strip())')"
|
|
||||||
HEAD_REPO="$(printf '%s' "$PR_METADATA" | python3 -c 'import json, sys; value=json.load(sys.stdin).get("headRepository") or ""; print((value.get("nameWithOwner") or value.get("full_name") or "") if isinstance(value, dict) else str(value).strip())')"
|
|
||||||
if [[ "$BASE_BRANCH" != "main" ]]; then
|
if [[ "$BASE_BRANCH" != "main" ]]; then
|
||||||
echo "Error: Mosaic policy allows merges only for PRs targeting 'main' (found '$BASE_BRANCH')." >&2
|
echo "Error: Mosaic policy allows merges only for PRs targeting 'main' (found '$BASE_BRANCH')." >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ -z "$HEAD_BRANCH" || -z "$HEAD_REPO" || ! "$HEAD_SHA" =~ ^[0-9a-fA-F]{40}$ ]]; then
|
if [[ "$SKIP_QUEUE_GUARD" != true ]]; then
|
||||||
echo "Error: Could not resolve the PR head branch, repository, and full commit SHA for queue inspection." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ -n "$EXPECT_HEAD" && "$HEAD_SHA" != "$EXPECT_HEAD" ]]; then
|
|
||||||
echo "Error: PR head moved: expected $EXPECT_HEAD, found $HEAD_SHA." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ "$DRY_RUN" != true ]]; then
|
|
||||||
"$SCRIPT_DIR/ci-queue-wait.sh" \
|
"$SCRIPT_DIR/ci-queue-wait.sh" \
|
||||||
--purpose merge \
|
--purpose merge \
|
||||||
-B "$HEAD_BRANCH" \
|
-B "$BASE_BRANCH" \
|
||||||
-R "$HEAD_REPO" \
|
|
||||||
--sha "$HEAD_SHA" \
|
|
||||||
-t "${MOSAIC_CI_QUEUE_TIMEOUT_SEC:-900}" \
|
-t "${MOSAIC_CI_QUEUE_TIMEOUT_SEC:-900}" \
|
||||||
-i "${MOSAIC_CI_QUEUE_POLL_SEC:-15}"
|
-i "${MOSAIC_CI_QUEUE_POLL_SEC:-15}"
|
||||||
fi
|
fi
|
||||||
@@ -122,22 +106,31 @@ PLATFORM=$(detect_platform)
|
|||||||
OWNER=$(get_repo_owner)
|
OWNER=$(get_repo_owner)
|
||||||
REPO=$(get_repo_name)
|
REPO=$(get_repo_name)
|
||||||
|
|
||||||
|
is_known_tea_empty_identity_failure() {
|
||||||
|
local error_file="$1"
|
||||||
|
|
||||||
|
python3 - "$error_file" <<'PY'
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
|
||||||
|
with open(sys.argv[1], encoding="utf-8", errors="replace") as handle:
|
||||||
|
error = handle.read()
|
||||||
|
|
||||||
|
known_empty_identity = re.search(
|
||||||
|
r"user does not exist.*\[.*uid:\s*0,\s*name:\s*\]",
|
||||||
|
error,
|
||||||
|
flags=re.IGNORECASE | re.DOTALL,
|
||||||
|
)
|
||||||
|
raise SystemExit(0 if known_empty_identity else 1)
|
||||||
|
PY
|
||||||
|
}
|
||||||
|
|
||||||
merge_gitea_with_api() {
|
merge_gitea_with_api() {
|
||||||
local host="$1" api_url token basic_auth body_file raw_code payload
|
local host="$1" api_url token basic_auth body_file raw_code payload
|
||||||
api_url="https://${host}/api/v1/repos/${OWNER}/${REPO}/pulls/${PR_NUMBER}/merge"
|
api_url="https://${host}/api/v1/repos/${OWNER}/${REPO}/pulls/${PR_NUMBER}/merge"
|
||||||
mkdir -p "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}"
|
mkdir -p "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}"
|
||||||
body_file=$(mktemp "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}/pr-merge-api-response.XXXXXX")
|
body_file=$(mktemp "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}/pr-merge-api-response.XXXXXX")
|
||||||
payload=$(python3 - "$HEAD_SHA" "$DELETE_BRANCH" <<'PY'
|
payload='{"Do":"squash"}'
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
|
|
||||||
head_sha, delete_branch = sys.argv[1:]
|
|
||||||
payload = {"Do": "squash", "head_commit_id": head_sha}
|
|
||||||
if delete_branch == "true":
|
|
||||||
payload["delete_branch_after_merge"] = True
|
|
||||||
print(json.dumps(payload, separators=(",", ":")))
|
|
||||||
PY
|
|
||||||
)
|
|
||||||
|
|
||||||
token=$(get_gitea_token "$host" || true)
|
token=$(get_gitea_token "$host" || true)
|
||||||
if [[ -n "$token" ]]; then
|
if [[ -n "$token" ]]; then
|
||||||
@@ -209,7 +202,7 @@ fi
|
|||||||
|
|
||||||
case "$PLATFORM" in
|
case "$PLATFORM" in
|
||||||
github)
|
github)
|
||||||
cmd=(gh pr merge "$PR_NUMBER" --squash --match-head-commit "$HEAD_SHA")
|
cmd=(gh pr merge "$PR_NUMBER" --squash)
|
||||||
[[ "$DELETE_BRANCH" == true ]] && cmd+=(--delete-branch)
|
[[ "$DELETE_BRANCH" == true ]] && cmd+=(--delete-branch)
|
||||||
"${cmd[@]}"
|
"${cmd[@]}"
|
||||||
;;
|
;;
|
||||||
@@ -218,9 +211,32 @@ case "$PLATFORM" in
|
|||||||
echo "Error: Cannot determine host from origin remote URL" >&2
|
echo "Error: Cannot determine host from origin remote URL" >&2
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
# Gitea's API head_commit_id is an atomic compare-and-merge precondition.
|
TEA_LOGIN="$(get_gitea_login_for_host "$HOST" || true)"
|
||||||
# tea cannot express it, so exact-head merges use the authenticated API path.
|
|
||||||
merge_gitea_with_api "$HOST"
|
if [[ -n "$TEA_LOGIN" ]]; then
|
||||||
|
mkdir -p "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}"
|
||||||
|
TEA_ERROR_FILE=$(mktemp "${AGENT_WORK_ROOT:-${HOME:-/tmp}/mosaic/agent-work}/pr-merge-tea-error.XXXXXX")
|
||||||
|
if tea pr merge "$PR_NUMBER" --style squash --repo "$OWNER/$REPO" --login "$TEA_LOGIN" 2> "$TEA_ERROR_FILE"; then
|
||||||
|
rm -f "$TEA_ERROR_FILE"
|
||||||
|
elif is_known_tea_empty_identity_failure "$TEA_ERROR_FILE"; then
|
||||||
|
cat "$TEA_ERROR_FILE" >&2
|
||||||
|
echo "Known tea empty identity failure detected; using authenticated Gitea API merge fallback." >&2
|
||||||
|
rm -f "$TEA_ERROR_FILE"
|
||||||
|
merge_gitea_with_api "$HOST"
|
||||||
|
else
|
||||||
|
cat "$TEA_ERROR_FILE" >&2
|
||||||
|
rm -f "$TEA_ERROR_FILE"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "No tea login configured for $HOST; using authenticated Gitea API merge fallback." >&2
|
||||||
|
merge_gitea_with_api "$HOST"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Delete branch after merge if requested
|
||||||
|
if [[ "$DELETE_BRANCH" == true ]]; then
|
||||||
|
echo "Note: Branch deletion after merge may need to be done separately with tea" >&2
|
||||||
|
fi
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
echo "Error: Could not detect git platform" >&2
|
echo "Error: Could not detect git platform" >&2
|
||||||
|
|||||||
@@ -109,7 +109,7 @@ PY
|
|||||||
detect_platform > /dev/null
|
detect_platform > /dev/null
|
||||||
|
|
||||||
if [[ "$PLATFORM" == "github" ]]; then
|
if [[ "$PLATFORM" == "github" ]]; then
|
||||||
METADATA=$(gh pr view "$PR_NUMBER" --json number,title,body,state,author,headRefName,headRefOid,headRepository,baseRefName,files,labels,assignees,milestone,createdAt,updatedAt,url,isDraft)
|
METADATA=$(gh pr view "$PR_NUMBER" --json number,title,body,state,author,headRefName,baseRefName,files,labels,assignees,milestone,createdAt,updatedAt,url,isDraft)
|
||||||
write_metadata "$METADATA"
|
write_metadata "$METADATA"
|
||||||
elif [[ "$PLATFORM" == "gitea" ]]; then
|
elif [[ "$PLATFORM" == "gitea" ]]; then
|
||||||
OWNER=$(get_repo_owner)
|
OWNER=$(get_repo_owner)
|
||||||
@@ -182,25 +182,6 @@ if isinstance(head_ref, str) and head_ref.startswith('refs/pull/'):
|
|||||||
data.get('head_ref'),
|
data.get('head_ref'),
|
||||||
head_ref,
|
head_ref,
|
||||||
)
|
)
|
||||||
head_sha = first_non_empty(
|
|
||||||
nested(data, 'head', 'sha'),
|
|
||||||
nested(data, 'head', 'id'),
|
|
||||||
data.get('head_sha'),
|
|
||||||
)
|
|
||||||
head_repo = first_non_empty(
|
|
||||||
nested(data, 'head', 'repo', 'full_name'),
|
|
||||||
nested(data, 'head', 'repo', 'name_with_owner'),
|
|
||||||
)
|
|
||||||
if not head_repo:
|
|
||||||
head_repo_owner = first_non_empty(
|
|
||||||
nested(data, 'head', 'repo', 'owner', 'login'),
|
|
||||||
nested(data, 'head', 'repo', 'owner', 'username'),
|
|
||||||
nested(data, 'head', 'repo', 'owner_name'),
|
|
||||||
)
|
|
||||||
head_repo_name = first_non_empty(nested(data, 'head', 'repo', 'name'))
|
|
||||||
if head_repo_owner and head_repo_name:
|
|
||||||
head_repo = f'{head_repo_owner}/{head_repo_name}'
|
|
||||||
|
|
||||||
base_ref = first_non_empty(
|
base_ref = first_non_empty(
|
||||||
nested(data, 'base', 'ref'),
|
nested(data, 'base', 'ref'),
|
||||||
nested(data, 'base', 'name'),
|
nested(data, 'base', 'name'),
|
||||||
@@ -226,8 +207,6 @@ normalized = {
|
|||||||
'state': data.get('state'),
|
'state': data.get('state'),
|
||||||
'author': nested(data, 'user', 'login') or '',
|
'author': nested(data, 'user', 'login') or '',
|
||||||
'headRefName': head_ref,
|
'headRefName': head_ref,
|
||||||
'headRefOid': head_sha,
|
|
||||||
'headRepository': head_repo,
|
|
||||||
'baseRefName': base_ref,
|
'baseRefName': base_ref,
|
||||||
'labels': [l.get('name', '') for l in data.get('labels', []) if isinstance(l, dict)],
|
'labels': [l.get('name', '') for l in data.get('labels', []) if isinstance(l, dict)],
|
||||||
'assignees': [a.get('login', '') for a in data.get('assignees', []) if isinstance(a, dict)],
|
'assignees': [a.get('login', '') for a in data.get('assignees', []) if isinstance(a, dict)],
|
||||||
|
|||||||
@@ -1,80 +0,0 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
"""Fail-closed reader for one governed Mosaic credential envelope."""
|
|
||||||
|
|
||||||
import hashlib
|
|
||||||
import json
|
|
||||||
import os
|
|
||||||
import stat
|
|
||||||
import sys
|
|
||||||
|
|
||||||
MAX_BYTES = 64 * 1024
|
|
||||||
EXPECTED_KEYS = {
|
|
||||||
"schemaVersion",
|
|
||||||
"identity",
|
|
||||||
"estate",
|
|
||||||
"host",
|
|
||||||
"providerLogin",
|
|
||||||
"tokenName",
|
|
||||||
"scopes",
|
|
||||||
"createdAt",
|
|
||||||
"tokenDigest",
|
|
||||||
"token",
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
def refuse(message: str) -> None:
|
|
||||||
print(f"credential envelope refused: {message}", file=sys.stderr)
|
|
||||||
raise SystemExit(1)
|
|
||||||
|
|
||||||
|
|
||||||
if len(sys.argv) != 6:
|
|
||||||
refuse("expected governed root, path, identity, estate, and host")
|
|
||||||
root, path, identity, estate, host = sys.argv[1:]
|
|
||||||
if os.path.abspath(os.path.dirname(path)) != os.path.abspath(root):
|
|
||||||
refuse("credential is not a direct child of the governed root")
|
|
||||||
if not estate:
|
|
||||||
refuse("explicit estate is required")
|
|
||||||
parent = os.path.dirname(path)
|
|
||||||
try:
|
|
||||||
parent_stat = os.stat(parent, follow_symlinks=False)
|
|
||||||
except OSError:
|
|
||||||
refuse("credential directory unavailable")
|
|
||||||
if not stat.S_ISDIR(parent_stat.st_mode) or stat.S_ISLNK(parent_stat.st_mode):
|
|
||||||
refuse("credential directory is not a real directory")
|
|
||||||
if parent_stat.st_uid != os.getuid() or parent_stat.st_mode & 0o022:
|
|
||||||
refuse("credential directory owner or mode is unsafe")
|
|
||||||
try:
|
|
||||||
fd = os.open(path, os.O_RDONLY | os.O_NOFOLLOW | os.O_CLOEXEC)
|
|
||||||
except OSError:
|
|
||||||
refuse("credential file unavailable or symbolic")
|
|
||||||
try:
|
|
||||||
file_stat = os.fstat(fd)
|
|
||||||
if not stat.S_ISREG(file_stat.st_mode):
|
|
||||||
refuse("credential is not a regular file")
|
|
||||||
if file_stat.st_uid != os.getuid() or file_stat.st_mode & 0o077:
|
|
||||||
refuse("credential owner or mode is unsafe")
|
|
||||||
content = os.read(fd, MAX_BYTES + 1)
|
|
||||||
if len(content) > MAX_BYTES:
|
|
||||||
refuse("credential exceeds size limit")
|
|
||||||
finally:
|
|
||||||
os.close(fd)
|
|
||||||
try:
|
|
||||||
value = json.loads(content)
|
|
||||||
except (UnicodeDecodeError, json.JSONDecodeError):
|
|
||||||
refuse("credential is not valid JSON")
|
|
||||||
if not isinstance(value, dict) or set(value) != EXPECTED_KEYS:
|
|
||||||
refuse("credential schema is not exact")
|
|
||||||
if (
|
|
||||||
value.get("schemaVersion") != 1
|
|
||||||
or value.get("identity") != identity
|
|
||||||
or value.get("estate") != estate
|
|
||||||
or value.get("host") != host
|
|
||||||
or value.get("providerLogin") != identity
|
|
||||||
):
|
|
||||||
refuse("credential binding does not match requested identity, estate, host, and principal")
|
|
||||||
token = value.get("token")
|
|
||||||
if not isinstance(token, str) or not token or any(ch.isspace() for ch in token):
|
|
||||||
refuse("credential token is invalid")
|
|
||||||
if value.get("tokenDigest") != hashlib.sha256(token.encode()).hexdigest():
|
|
||||||
refuse("credential digest does not match token")
|
|
||||||
sys.stdout.write(token + "\n")
|
|
||||||
@@ -1,51 +0,0 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
"""Fail-closed reader for one legacy per-seat token file."""
|
|
||||||
|
|
||||||
import os
|
|
||||||
import stat
|
|
||||||
import sys
|
|
||||||
|
|
||||||
MAX_BYTES = 16 * 1024
|
|
||||||
|
|
||||||
|
|
||||||
def refuse(message: str) -> None:
|
|
||||||
print(f"legacy credential refused: {message}", file=sys.stderr)
|
|
||||||
raise SystemExit(1)
|
|
||||||
|
|
||||||
|
|
||||||
if len(sys.argv) != 3:
|
|
||||||
refuse("expected governed root and token path")
|
|
||||||
root, path = sys.argv[1:]
|
|
||||||
if os.path.abspath(os.path.dirname(path)) != os.path.abspath(root):
|
|
||||||
refuse("credential is not a direct child of the governed root")
|
|
||||||
parent = os.path.dirname(path)
|
|
||||||
try:
|
|
||||||
parent_stat = os.stat(parent, follow_symlinks=False)
|
|
||||||
except OSError:
|
|
||||||
refuse("credential directory unavailable")
|
|
||||||
if not stat.S_ISDIR(parent_stat.st_mode) or stat.S_ISLNK(parent_stat.st_mode):
|
|
||||||
refuse("credential directory is not a real directory")
|
|
||||||
if parent_stat.st_uid != os.getuid() or parent_stat.st_mode & 0o022:
|
|
||||||
refuse("credential directory owner or mode is unsafe")
|
|
||||||
try:
|
|
||||||
fd = os.open(path, os.O_RDONLY | os.O_NOFOLLOW | os.O_CLOEXEC)
|
|
||||||
except OSError:
|
|
||||||
refuse("credential file unavailable or symbolic")
|
|
||||||
try:
|
|
||||||
file_stat = os.fstat(fd)
|
|
||||||
if not stat.S_ISREG(file_stat.st_mode):
|
|
||||||
refuse("credential is not a regular file")
|
|
||||||
if file_stat.st_uid != os.getuid() or file_stat.st_mode & 0o077:
|
|
||||||
refuse("credential owner or mode is unsafe")
|
|
||||||
content = os.read(fd, MAX_BYTES + 1)
|
|
||||||
if len(content) > MAX_BYTES:
|
|
||||||
refuse("credential exceeds size limit")
|
|
||||||
finally:
|
|
||||||
os.close(fd)
|
|
||||||
try:
|
|
||||||
token = content.decode("utf-8").strip()
|
|
||||||
except UnicodeDecodeError:
|
|
||||||
refuse("credential is not UTF-8")
|
|
||||||
if not token or any(ch.isspace() for ch in token):
|
|
||||||
refuse("credential token is invalid")
|
|
||||||
sys.stdout.write(token + "\n")
|
|
||||||
@@ -13,7 +13,7 @@
|
|||||||
# Covers:
|
# Covers:
|
||||||
# (a) 404 branch-absent -> exit 0, "queue clear" message.
|
# (a) 404 branch-absent -> exit 0, "queue clear" message.
|
||||||
# (b) 200 existing branch + a terminal CI state -> unchanged behavior.
|
# (b) 200 existing branch + a terminal CI state -> unchanged behavior.
|
||||||
# (c) genuine API error (500) -> loud, audited CANNOT_ASSERT; degraded exit 0.
|
# (c) genuine API error (500) -> still fail-closed (nonzero exit).
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
@@ -62,7 +62,7 @@ case "$mode" in
|
|||||||
200) code=200; body='{"commit":{"id":"deadbeefcafef00d0123456789abcdef01234567"}}' ;;
|
200) code=200; body='{"commit":{"id":"deadbeefcafef00d0123456789abcdef01234567"}}' ;;
|
||||||
500) code=500; body='{"message":"internal server error"}' ;;
|
500) code=500; body='{"message":"internal server error"}' ;;
|
||||||
no-status) code=200; body='{}' ;;
|
no-status) code=200; body='{}' ;;
|
||||||
terminal-success) code=200; body='{"state":"success","statuses":[{"status":"success"}]}' ;;
|
terminal-success) code=200; body='{"state":"success"}' ;;
|
||||||
*)
|
*)
|
||||||
echo "curl stub: unknown mode=$mode" >&2
|
echo "curl stub: unknown mode=$mode" >&2
|
||||||
exit 2
|
exit 2
|
||||||
@@ -91,7 +91,6 @@ run_ci_queue_wait() {
|
|||||||
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
||||||
export GITEA_TOKEN="stub-token"
|
export GITEA_TOKEN="stub-token"
|
||||||
export GITEA_URL="https://git.example.test"
|
export GITEA_URL="https://git.example.test"
|
||||||
export MOSAIC_CI_QUEUE_AUDIT_LOG="$WORK_DIR/audit/ci-queue-wait.jsonl"
|
|
||||||
"$SCRIPT_DIR/ci-queue-wait.sh" -B "$branch" --purpose push -t 5 -i 1
|
"$SCRIPT_DIR/ci-queue-wait.sh" -B "$branch" --purpose push -t 5 -i 1
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
@@ -132,26 +131,19 @@ elif [[ "$out_b" == *"queue clear"* ]]; then
|
|||||||
fail=1
|
fail=1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# (c) genuine API error (500) -> CANNOT_ASSERT is loud and audited, but does not brick delivery.
|
# (c) genuine API error (500) -> still fail-closed, exit nonzero.
|
||||||
set +e
|
set +e
|
||||||
out_c=$(MOSAIC_STUB_BRANCH_MODE=500 run_ci_queue_wait "feat/some-branch" 2>&1)
|
out_c=$(MOSAIC_STUB_BRANCH_MODE=500 run_ci_queue_wait "feat/some-branch" 2>&1)
|
||||||
status_c=$?
|
status_c=$?
|
||||||
set -e
|
set -e
|
||||||
if [[ "$status_c" -ne 0 ]]; then
|
if [[ "$status_c" -eq 0 ]]; then
|
||||||
echo "FAIL(c): expected degraded exit 0 for provider unavailability, got $status_c" >&2
|
echo "FAIL(c): expected a nonzero exit for a genuine 500 API error, got 0" >&2
|
||||||
echo "$out_c" >&2
|
|
||||||
fail=1
|
|
||||||
elif [[ "$out_c" != *"CANNOT_ASSERT"* ]]; then
|
|
||||||
echo "FAIL(c): expected a loud CANNOT_ASSERT diagnostic" >&2
|
|
||||||
echo "$out_c" >&2
|
echo "$out_c" >&2
|
||||||
fail=1
|
fail=1
|
||||||
elif [[ "$out_c" == *"queue clear"* ]]; then
|
elif [[ "$out_c" == *"queue clear"* ]]; then
|
||||||
echo "FAIL(c): a genuine API error must not be reported as queue-clear" >&2
|
echo "FAIL(c): a genuine API error must not be reported as queue-clear" >&2
|
||||||
echo "$out_c" >&2
|
echo "$out_c" >&2
|
||||||
fail=1
|
fail=1
|
||||||
elif [[ ! -s "$WORK_DIR/audit/ci-queue-wait.jsonl" ]]; then
|
|
||||||
echo "FAIL(c): expected a durable CANNOT_ASSERT audit record" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$fail" -eq 0 ]]; then
|
if [[ "$fail" -eq 0 ]]; then
|
||||||
|
|||||||
@@ -1,95 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# GitHub Actions uses Checks API check-runs, not only legacy commit statuses.
|
|
||||||
|
|
||||||
set -u
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/ci-queue-wait-github-checks}"
|
|
||||||
REPO_DIR="$WORK_DIR/repo"
|
|
||||||
STUB_DIR="$WORK_DIR/stubs"
|
|
||||||
rm -rf "$WORK_DIR"
|
|
||||||
mkdir -p "$REPO_DIR" "$STUB_DIR"
|
|
||||||
git -C "$REPO_DIR" init -q
|
|
||||||
git -C "$REPO_DIR" checkout -q -b fix/github-checks
|
|
||||||
git -C "$REPO_DIR" remote add origin https://github.com/acme/widgets.git
|
|
||||||
|
|
||||||
cat > "$STUB_DIR/gh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
endpoint=""
|
|
||||||
for arg in "$@"; do
|
|
||||||
[[ "$arg" == repos/* ]] && endpoint="$arg"
|
|
||||||
done
|
|
||||||
printf '%s\n' "$*" >> "${MOSAIC_GH_CALL_LOG:?}"
|
|
||||||
case "$endpoint" in
|
|
||||||
repos/acme/widgets/branches/fix/github-checks)
|
|
||||||
printf '%s\n' '0123456789abcdef0123456789abcdef01234567'
|
|
||||||
;;
|
|
||||||
repos/acme/widgets/commits/*/statuses?per_page=100)
|
|
||||||
printf '%s\n' '[[]]'
|
|
||||||
;;
|
|
||||||
repos/acme/widgets/commits/*/check-runs?per_page=100\&filter=latest)
|
|
||||||
case "${MOSAIC_GH_CHECK_MODE:?}" in
|
|
||||||
success) printf '%s\n' '[{"total_count":1,"check_runs":[{"name":"ci","status":"completed","conclusion":"success"}]}]' ;;
|
|
||||||
pending) printf '%s\n' '[{"total_count":1,"check_runs":[{"name":"ci","status":"in_progress","conclusion":null}]}]' ;;
|
|
||||||
failure) printf '%s\n' '[{"total_count":1,"check_runs":[{"name":"ci","status":"completed","conclusion":"failure"}]}]' ;;
|
|
||||||
late-failure) printf '%s\n' '[{"total_count":2,"check_runs":[{"name":"first-page","status":"completed","conclusion":"success"}]},{"total_count":2,"check_runs":[{"name":"later-page","status":"completed","conclusion":"failure"}]}]' ;;
|
|
||||||
*) exit 2 ;;
|
|
||||||
esac
|
|
||||||
;;
|
|
||||||
*) echo "unexpected gh endpoint: $endpoint" >&2; exit 2 ;;
|
|
||||||
esac
|
|
||||||
SH
|
|
||||||
chmod +x "$STUB_DIR/gh"
|
|
||||||
|
|
||||||
run_guard() {
|
|
||||||
local mode="$1"
|
|
||||||
(
|
|
||||||
cd "$REPO_DIR" || exit
|
|
||||||
export PATH="$STUB_DIR:$PATH"
|
|
||||||
export MOSAIC_GH_CHECK_MODE="$mode"
|
|
||||||
export MOSAIC_GH_CALL_LOG="$WORK_DIR/gh-calls.log"
|
|
||||||
export MOSAIC_CI_QUEUE_AUDIT_LOG="$WORK_DIR/audit.jsonl"
|
|
||||||
"$SCRIPT_DIR/ci-queue-wait.sh" --purpose push -t 0 -i 0
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
failures=0
|
|
||||||
assert_case() {
|
|
||||||
local mode="$1" expected_rc="$2" expected_state="$3" output rc
|
|
||||||
set +e
|
|
||||||
output=$(run_guard "$mode" 2>&1)
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$expected_rc" == zero && "$rc" -ne 0 ]]; then
|
|
||||||
echo "FAIL github-$mode: expected rc=0, got $rc" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
elif [[ "$expected_rc" == nonzero && "$rc" -eq 0 ]]; then
|
|
||||||
echo "FAIL github-$mode: expected rc!=0, got 0" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$output" != *"state=$expected_state"* ]]; then
|
|
||||||
echo "FAIL github-$mode: expected state=$expected_state, got:" >&2
|
|
||||||
printf '%s\n' "$output" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
set -e
|
|
||||||
: > "$WORK_DIR/gh-calls.log"
|
|
||||||
assert_case success zero terminal-success
|
|
||||||
assert_case pending nonzero pending
|
|
||||||
assert_case failure nonzero terminal-failure
|
|
||||||
assert_case late-failure nonzero terminal-failure
|
|
||||||
|
|
||||||
if [[ $(grep -c 'check-runs?per_page=100&filter=latest' "$WORK_DIR/gh-calls.log") -lt 4 ]]; then
|
|
||||||
echo "FAIL: expected every case to query all Checks API pages" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ "$failures" -ne 0 ]]; then
|
|
||||||
echo "GitHub check-runs regression failed ($failures assertions)" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "GitHub check-runs regression passed (4/4 cases, including later-page failure)"
|
|
||||||
@@ -1,364 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Exit-asserting RM-03 regression harness for ci-queue-wait.sh.
|
|
||||||
# Every case is a process-level assertion: a classifier-only green cannot satisfy it.
|
|
||||||
|
|
||||||
set -u
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/ci-queue-wait-tristate}"
|
|
||||||
REPO_DIR="$WORK_DIR/repo"
|
|
||||||
STUB_DIR="$WORK_DIR/stubs"
|
|
||||||
AUDIT_LOG="$WORK_DIR/audit/ci-queue-wait.jsonl"
|
|
||||||
STATUS_OBSERVED="$WORK_DIR/status-observed"
|
|
||||||
CLOCK_LOG="$WORK_DIR/clock.log"
|
|
||||||
WATCHDOG_PYTHON="/usr/bin/python3"
|
|
||||||
WATCHDOG_SCRIPT="$WORK_DIR/real-clock-watchdog.py"
|
|
||||||
WATCHDOG_TIMEOUT_SEC=5
|
|
||||||
WATCHDOG_EXIT=90
|
|
||||||
FEATURE_BRANCH="fix/rm-03-fixture"
|
|
||||||
|
|
||||||
if [[ ! -x "$WATCHDOG_PYTHON" ]]; then
|
|
||||||
echo "FAIL setup: required real-clock watchdog runtime is unavailable at $WATCHDOG_PYTHON" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
rm -rf "$WORK_DIR"
|
|
||||||
mkdir -p "$REPO_DIR" "$STUB_DIR"
|
|
||||||
cat > "$WATCHDOG_SCRIPT" <<'PY'
|
|
||||||
import os
|
|
||||||
import signal
|
|
||||||
import subprocess
|
|
||||||
import sys
|
|
||||||
|
|
||||||
if len(sys.argv) < 3:
|
|
||||||
raise SystemExit(2)
|
|
||||||
|
|
||||||
timeout_seconds = float(sys.argv[1])
|
|
||||||
process = subprocess.Popen(sys.argv[2:], start_new_session=True)
|
|
||||||
try:
|
|
||||||
return_code = process.wait(timeout=timeout_seconds)
|
|
||||||
except subprocess.TimeoutExpired:
|
|
||||||
try:
|
|
||||||
os.killpg(process.pid, signal.SIGKILL)
|
|
||||||
except ProcessLookupError:
|
|
||||||
pass
|
|
||||||
process.wait()
|
|
||||||
print(
|
|
||||||
f"FAIL HANG watchdog: subject exceeded {timeout_seconds:g}s "
|
|
||||||
"before completing its intended path",
|
|
||||||
file=sys.stderr,
|
|
||||||
)
|
|
||||||
raise SystemExit(90)
|
|
||||||
|
|
||||||
if return_code < 0:
|
|
||||||
raise SystemExit(128 - return_code)
|
|
||||||
raise SystemExit(return_code)
|
|
||||||
PY
|
|
||||||
git -C "$REPO_DIR" init -q
|
|
||||||
git -C "$REPO_DIR" checkout -q -b "$FEATURE_BRANCH"
|
|
||||||
git -C "$REPO_DIR" remote add origin https://git.example.test/acme/widgets.git
|
|
||||||
|
|
||||||
cat > "$STUB_DIR/curl" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
url=""
|
|
||||||
has_write_out=0
|
|
||||||
for arg in "$@"; do
|
|
||||||
case "$arg" in
|
|
||||||
-w) has_write_out=1 ;;
|
|
||||||
http://*|https://*) url="$arg" ;;
|
|
||||||
esac
|
|
||||||
done
|
|
||||||
printf '%s\n' "$url" >> "${MOSAIC_STUB_URL_LOG:?}"
|
|
||||||
|
|
||||||
case "$url" in
|
|
||||||
*/branches/*)
|
|
||||||
if [[ "${MOSAIC_STUB_BRANCH_MODE:-ok}" == "hang-before-provider" ]]; then
|
|
||||||
while :; do :; done
|
|
||||||
fi
|
|
||||||
if [[ "${MOSAIC_STUB_BRANCH_MODE:-ok}" == "unreachable" ]]; then
|
|
||||||
exit 7
|
|
||||||
fi
|
|
||||||
body='{"commit":{"id":"deadbeefcafef00d0123456789abcdef01234567"}}'
|
|
||||||
if [[ "$has_write_out" -eq 1 ]]; then
|
|
||||||
printf '%s\n200' "$body"
|
|
||||||
else
|
|
||||||
printf '%s' "$body"
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
*/status)
|
|
||||||
: > "${MOSAIC_STUB_STATUS_OBSERVED:?}"
|
|
||||||
case "${MOSAIC_STUB_STATUS_MODE:?}" in
|
|
||||||
success) printf '%s' '{"state":"success","statuses":[{"status":"success"}]}' ;;
|
|
||||||
pending) printf '%s' '{"state":"pending","statuses":[{"status":"pending","context":"ci/test"}]}' ;;
|
|
||||||
failure) printf '%s' '{"state":"failure","statuses":[{"status":"failure"}]}' ;;
|
|
||||||
no-status) printf '%s' '{"state":"","statuses":[]}' ;;
|
|
||||||
aggregate-success-no-status) printf '%s' '{"state":"success","statuses":[]}' ;;
|
|
||||||
malformed) printf '%s' 'not-json' ;;
|
|
||||||
malformed-statuses-type) printf '%s' '{"state":"success","statuses":"corrupt"}' ;;
|
|
||||||
malformed-status-entry) printf '%s' '{"state":"success","statuses":[null]}' ;;
|
|
||||||
large-success)
|
|
||||||
python3 -c 'import json; print(json.dumps({"state":"success", "statuses":[{"status":"success"}], "padding":"x" * (160 * 1024)}), end="")'
|
|
||||||
;;
|
|
||||||
unreachable) exit 7 ;;
|
|
||||||
*) echo "unknown status mode" >&2; exit 2 ;;
|
|
||||||
esac
|
|
||||||
;;
|
|
||||||
*) echo "unexpected curl URL: $url" >&2; exit 2 ;;
|
|
||||||
esac
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$STUB_DIR/date" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
if [[ "$#" -ne 1 || "$1" != "+%s" ]]; then
|
|
||||||
echo "unexpected date invocation: $*" >&2
|
|
||||||
exit 2
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ -e "${MOSAIC_STUB_STATUS_OBSERVED:?}" ]]; then
|
|
||||||
printf 'date-phase=after-status\n' >> "${MOSAIC_STUB_CLOCK_LOG:?}"
|
|
||||||
printf '1002\n'
|
|
||||||
else
|
|
||||||
printf 'date-phase=before-status\n' >> "${MOSAIC_STUB_CLOCK_LOG:?}"
|
|
||||||
printf '1000\n'
|
|
||||||
fi
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$STUB_DIR/sleep" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
printf 'sleep-after-status=%s\n' "$*" >> "${MOSAIC_STUB_CLOCK_LOG:?}"
|
|
||||||
SH
|
|
||||||
chmod +x "$STUB_DIR/curl" "$STUB_DIR/date" "$STUB_DIR/sleep"
|
|
||||||
|
|
||||||
run_guard() {
|
|
||||||
local status_mode="$1"
|
|
||||||
local audit_log="${2:-$AUDIT_LOG}"
|
|
||||||
shift 2 || true
|
|
||||||
(
|
|
||||||
cd "$REPO_DIR" || exit
|
|
||||||
export PATH="$STUB_DIR:$PATH"
|
|
||||||
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
|
||||||
if [[ "$status_mode" == "credential-unresolvable" ]]; then
|
|
||||||
export HOME="$WORK_DIR/empty-home"
|
|
||||||
mkdir -p "$HOME"
|
|
||||||
unset GITEA_TOKEN GITEA_URL MOSAIC_GIT_IDENTITY
|
|
||||||
export MOSAIC_STUB_STATUS_MODE=success
|
|
||||||
else
|
|
||||||
export GITEA_TOKEN=stub-token
|
|
||||||
export GITEA_URL=https://git.example.test
|
|
||||||
export MOSAIC_STUB_STATUS_MODE="$status_mode"
|
|
||||||
fi
|
|
||||||
rm -f "$STATUS_OBSERVED" "$CLOCK_LOG"
|
|
||||||
export MOSAIC_STUB_URL_LOG="$WORK_DIR/urls.log"
|
|
||||||
export MOSAIC_STUB_STATUS_OBSERVED="$STATUS_OBSERVED"
|
|
||||||
export MOSAIC_STUB_CLOCK_LOG="$CLOCK_LOG"
|
|
||||||
export MOSAIC_CI_QUEUE_AUDIT_LOG="$audit_log"
|
|
||||||
# Provider observation is the synchronization event. The one-second
|
|
||||||
# timeout is subject semantics under virtual time, never a wall wait.
|
|
||||||
# The absolute Python runtime uses an internal monotonic wait and kills
|
|
||||||
# the subject's isolated process group. Neither operation can resolve
|
|
||||||
# to the virtual date/sleep stubs at the front of PATH.
|
|
||||||
local subject_rc
|
|
||||||
if "$WATCHDOG_PYTHON" "$WATCHDOG_SCRIPT" "$WATCHDOG_TIMEOUT_SEC" \
|
|
||||||
"$SCRIPT_DIR/ci-queue-wait.sh" --purpose "${MOSAIC_TEST_PURPOSE:-push}" -t 1 -i 1 "$@"; then
|
|
||||||
subject_rc=0
|
|
||||||
else
|
|
||||||
subject_rc=$?
|
|
||||||
fi
|
|
||||||
return "$subject_rc"
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
failures=0
|
|
||||||
assert_provider_observed() {
|
|
||||||
local name="$1" require_expiration="${2:-0}"
|
|
||||||
if [[ ! -e "$STATUS_OBSERVED" ]]; then
|
|
||||||
echo "FAIL $name: status provider was not observed" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ ! -s "$CLOCK_LOG" ]] || ! grep -q '^date-phase=before-status$' "$CLOCK_LOG"; then
|
|
||||||
echo "FAIL $name: virtual clock interception did not run before provider observation" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$require_expiration" -eq 1 ]]; then
|
|
||||||
if ! grep -q '^sleep-after-status=' "$CLOCK_LOG" || ! grep -q '^date-phase=after-status$' "$CLOCK_LOG"; then
|
|
||||||
echo "FAIL $name: pending path did not expire after provider observation" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
run_assertion() {
|
|
||||||
local name="$1" expected_rc="$2" status_mode="$3" required_text="$4"
|
|
||||||
local output rc
|
|
||||||
shift 4
|
|
||||||
set +e
|
|
||||||
output=$(run_guard "$status_mode" "$AUDIT_LOG" "$@" 2>&1)
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
|
|
||||||
case "$expected_rc" in
|
|
||||||
zero)
|
|
||||||
if [[ "$rc" -ne 0 ]]; then
|
|
||||||
echo "FAIL $name: expected rc=0, got rc=$rc" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
nonzero)
|
|
||||||
if [[ "$rc" -eq 0 ]]; then
|
|
||||||
echo "FAIL $name: expected rc!=0, got rc=0" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
not126)
|
|
||||||
if [[ "$rc" -eq 126 ]]; then
|
|
||||||
echo "FAIL $name: payload transport hit ARG_MAX (rc=126)" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
;;
|
|
||||||
esac
|
|
||||||
if [[ "$output" != *"$required_text"* ]]; then
|
|
||||||
echo "FAIL $name: output missing '$required_text' (rc=$rc)" >&2
|
|
||||||
printf '%s\n' "$output" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$status_mode" != "credential-unresolvable" ]]; then
|
|
||||||
if [[ "$status_mode" == "pending" ]]; then
|
|
||||||
assert_provider_observed "$name" 1
|
|
||||||
else
|
|
||||||
assert_provider_observed "$name"
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
set -e
|
|
||||||
: > "$WORK_DIR/urls.log"
|
|
||||||
run_assertion success zero success 'state=terminal-success'
|
|
||||||
run_assertion pending nonzero pending 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion failure nonzero failure 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion no-status nonzero no-status 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion aggregate-success-no-status nonzero aggregate-success-no-status 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion malformed nonzero malformed 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion malformed-statuses-type nonzero malformed-statuses-type 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion malformed-status-entry nonzero malformed-status-entry 'ASSERTED_NOT_READY'
|
|
||||||
run_assertion large-payload not126 large-success 'state=terminal-success'
|
|
||||||
run_assertion credential-unresolvable zero credential-unresolvable 'CANNOT_ASSERT'
|
|
||||||
run_assertion provider-unreachable zero unreachable 'CANNOT_ASSERT'
|
|
||||||
|
|
||||||
# Positive liveness control: a subject mutant hangs before the branch lookup
|
|
||||||
# can reach the status provider. Only the independent real-clock watchdog may
|
|
||||||
# terminate it, and its failure must be distinct from subject timeout rc=124.
|
|
||||||
set +e
|
|
||||||
watchdog_output=$(MOSAIC_STUB_BRANCH_MODE=hang-before-provider run_guard success "$AUDIT_LOG" 2>&1)
|
|
||||||
watchdog_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$watchdog_rc" -ne "$WATCHDOG_EXIT" ]]; then
|
|
||||||
echo "FAIL watchdog-control: expected hang-specific rc=$WATCHDOG_EXIT, got rc=$watchdog_rc" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$watchdog_output" != *"FAIL HANG watchdog:"* ]]; then
|
|
||||||
echo "FAIL watchdog-control: expected distinct hang-specific diagnostic" >&2
|
|
||||||
printf '%s\n' "$watchdog_output" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ -e "$STATUS_OBSERVED" ]]; then
|
|
||||||
echo "FAIL watchdog-control: hanging mutant unexpectedly reached the status provider" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ ! -s "$AUDIT_LOG" ]] || ! grep -q '"outcome":"CANNOT_ASSERT"' "$AUDIT_LOG"; then
|
|
||||||
echo "FAIL provider-unreachable-audit: expected durable CANNOT_ASSERT JSONL record" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Merge cannot proceed without exact-head evidence. CANNOT_ASSERT is retryable exit 75,
|
|
||||||
# distinct from ASSERTED_NOT_READY (3/124), and still writes its audit record.
|
|
||||||
merge_audit_lines_before=$(wc -l < "$AUDIT_LOG")
|
|
||||||
set +e
|
|
||||||
merge_unreachable_output=$(MOSAIC_TEST_PURPOSE=merge run_guard unreachable "$AUDIT_LOG" 2>&1)
|
|
||||||
merge_unreachable_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$merge_unreachable_rc" -ne 75 ]]; then
|
|
||||||
echo "FAIL merge-provider-unreachable: expected rc=75, got rc=$merge_unreachable_rc" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$merge_unreachable_output" != *"CANNOT_ASSERT"* ]]; then
|
|
||||||
echo "FAIL merge-provider-unreachable: expected loud CANNOT_ASSERT diagnostic" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
assert_provider_observed merge-provider-unreachable
|
|
||||||
merge_audit_lines_after=$(wc -l < "$AUDIT_LOG")
|
|
||||||
if [[ "$merge_audit_lines_after" -le "$merge_audit_lines_before" ]]; then
|
|
||||||
echo "FAIL merge-provider-unreachable: expected an additional audit record" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
# A feature-branch push with no -B must inspect the checked-out feature branch.
|
|
||||||
if ! grep -q "/branches/$FEATURE_BRANCH" "$WORK_DIR/urls.log"; then
|
|
||||||
echo "FAIL implicit-branch: provider was not queried for $FEATURE_BRANCH" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Merge callers can pin both a fork repository and the exact reviewed head SHA.
|
|
||||||
exact_sha=0123456789abcdef0123456789abcdef01234567
|
|
||||||
: > "$WORK_DIR/urls.log"
|
|
||||||
run_assertion exact-fork-head zero success 'state=terminal-success' \
|
|
||||||
-B fix/rm-03-fixture -R contributor/widgets-fork --sha "$exact_sha"
|
|
||||||
if ! grep -q "/repos/contributor/widgets-fork/commits/$exact_sha/status" "$WORK_DIR/urls.log"; then
|
|
||||||
echo "FAIL exact-fork-head: status URL did not bind fork repository and exact SHA" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if grep -q '/branches/' "$WORK_DIR/urls.log"; then
|
|
||||||
echo "FAIL exact-fork-head: explicit SHA must not be re-resolved through a branch" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Platform/repository discovery failures use the same audited CANNOT_ASSERT path.
|
|
||||||
audit_lines_before=$(wc -l < "$AUDIT_LOG")
|
|
||||||
git -C "$REPO_DIR" remote set-url origin https://gitlab.com/acme/widgets.git
|
|
||||||
set +e
|
|
||||||
unsupported_output=$(run_guard success "$AUDIT_LOG" 2>&1)
|
|
||||||
unsupported_rc=$?
|
|
||||||
set -e
|
|
||||||
git -C "$REPO_DIR" remote set-url origin https://git.example.test/acme/widgets.git
|
|
||||||
if [[ "$unsupported_rc" -ne 0 ]]; then
|
|
||||||
echo "FAIL unsupported-platform: expected degraded rc=0, got rc=$unsupported_rc" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$unsupported_output" != *"CANNOT_ASSERT"* ]]; then
|
|
||||||
echo "FAIL unsupported-platform: expected loud CANNOT_ASSERT diagnostic" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
audit_lines_after=$(wc -l < "$AUDIT_LOG")
|
|
||||||
if [[ "$audit_lines_after" -le "$audit_lines_before" ]]; then
|
|
||||||
echo "FAIL unsupported-platform: expected an additional audit record" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
|
|
||||||
# A degraded pass is forbidden if the audit receipt cannot be written.
|
|
||||||
mkdir -p "$WORK_DIR/not-a-directory"
|
|
||||||
printf 'file' > "$WORK_DIR/not-a-directory/parent"
|
|
||||||
set +e
|
|
||||||
audit_failure_output=$(run_guard unreachable "$WORK_DIR/not-a-directory/parent/audit.jsonl" 2>&1)
|
|
||||||
audit_failure_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$audit_failure_rc" -eq 0 ]]; then
|
|
||||||
echo "FAIL audit-unavailable: expected rc!=0, got rc=0" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
if [[ "$audit_failure_output" != *"audit"* ]]; then
|
|
||||||
echo "FAIL audit-unavailable: expected loud audit failure diagnostic" >&2
|
|
||||||
failures=$((failures + 1))
|
|
||||||
fi
|
|
||||||
assert_provider_observed audit-unavailable
|
|
||||||
|
|
||||||
if [[ "$failures" -ne 0 ]]; then
|
|
||||||
echo "ci-queue-wait tri-state regression failed ($failures assertions)" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "ci-queue-wait tri-state regression passed (all outcome classes)"
|
|
||||||
@@ -16,7 +16,6 @@
|
|||||||
# NEVER reads real secrets or touches the real ~/.config/mosaic/secrets.
|
# NEVER reads real secrets or touches the real ~/.config/mosaic/secrets.
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
umask 077
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/git-credential-mosaic}"
|
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/git-credential-mosaic}"
|
||||||
@@ -35,8 +34,6 @@ mkdir -p "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens" \
|
|||||||
"$REPO_DIR"
|
"$REPO_DIR"
|
||||||
|
|
||||||
cp "$SCRIPT_DIR/git-credential-mosaic" "$HELPER"
|
cp "$SCRIPT_DIR/git-credential-mosaic" "$HELPER"
|
||||||
cp "$SCRIPT_DIR/resolve-credential-envelope.py" "$FAKE_HOME/.config/mosaic/tools/git/resolve-credential-envelope.py"
|
|
||||||
cp "$SCRIPT_DIR/resolve-legacy-token.py" "$FAKE_HOME/.config/mosaic/tools/git/resolve-legacy-token.py"
|
|
||||||
chmod +x "$HELPER"
|
chmod +x "$HELPER"
|
||||||
|
|
||||||
git -C "$REPO_DIR" init -q
|
git -C "$REPO_DIR" init -q
|
||||||
@@ -87,22 +84,6 @@ git -C "$REPO_DIR" config --unset mosaic.gitIdentity 2>/dev/null || true
|
|||||||
out=$(run_helper "git.mosaicstack.dev" "")
|
out=$(run_helper "git.mosaicstack.dev" "")
|
||||||
assert_eq "shared fallback: username" "username=git" "$(echo "$out" | grep '^username=')"
|
assert_eq "shared fallback: username" "username=git" "$(echo "$out" | grep '^username=')"
|
||||||
assert_eq "shared fallback: password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
assert_eq "shared fallback: password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
||||||
out=$(run_helper "git.mosaicstack.dev" "" MOSAIC_CREDENTIAL_TRACE=1 2>"$WORK_DIR/shared-trace.stderr")
|
|
||||||
err=$(cat "$WORK_DIR/shared-trace.stderr")
|
|
||||||
if [[ "$err" != *"resolution_path=shared"* || "$err" != *"shared_path_entered=true"* ]]; then
|
|
||||||
echo "FAIL: shared credential materialization did not emit its computed path" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
set +e
|
|
||||||
out=$(run_helper "git.mosaicstack.dev" "" MOSAIC_AGENT_NAME=synthetic-seat 2>"$WORK_DIR/fleet-unset.stderr")
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
err=$(cat "$WORK_DIR/fleet-unset.stderr")
|
|
||||||
if [[ "$rc" -eq 0 || "$out" != *"quit=true"* || "$err" != *"reason=identity-required"* || "$err" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: fleet unset identity did not stop at the resolver marker" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 2. git-supplied username resolves to an identity WITH a per-slot token ->
|
# 2. git-supplied username resolves to an identity WITH a per-slot token ->
|
||||||
@@ -112,21 +93,6 @@ echo -n "agentA-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-to
|
|||||||
out=$(run_helper "git.mosaicstack.dev" "agentA")
|
out=$(run_helper "git.mosaicstack.dev" "agentA")
|
||||||
assert_eq "username-resolved identity: username" "username=agentA" "$(echo "$out" | grep '^username=')"
|
assert_eq "username-resolved identity: username" "username=agentA" "$(echo "$out" | grep '^username=')"
|
||||||
assert_eq "username-resolved identity: password" "password=agentA-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
assert_eq "username-resolved identity: password" "password=agentA-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
||||||
out=$(run_helper "git.mosaicstack.dev" "agentA" MOSAIC_AGENT_NAME=agentA MOSAIC_CREDENTIAL_TRACE=1 2>"$WORK_DIR/identity-trace.stderr")
|
|
||||||
err=$(cat "$WORK_DIR/identity-trace.stderr")
|
|
||||||
if [[ "$err" != *"resolution_path=identity"* || "$err" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: identity credential did not emit its computed path" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
set +e
|
|
||||||
out=$(run_helper "git.mosaicstack.dev" "agentA" MOSAIC_AGENT_NAME=agentB 2>"$WORK_DIR/fleet-mismatch.stderr")
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
err=$(cat "$WORK_DIR/fleet-mismatch.stderr")
|
|
||||||
if [[ "$rc" -eq 0 || "$out" != *"quit=true"* || "$err" != *"reason=provider-identity-mismatch"* || "$err" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: fleet identity override was not refused before token resolution" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 3. git config mosaic.gitIdentity (per-worktree) beats git-supplied username.
|
# 3. git config mosaic.gitIdentity (per-worktree) beats git-supplied username.
|
||||||
@@ -154,16 +120,6 @@ out=$(run_helper "git.mosaicstack.dev" "no-such-agent")
|
|||||||
assert_eq "no per-slot token: username" "username=git" "$(echo "$out" | grep '^username=')"
|
assert_eq "no per-slot token: username" "username=git" "$(echo "$out" | grep '^username=')"
|
||||||
assert_eq "no per-slot token: password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
assert_eq "no per-slot token: password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
||||||
|
|
||||||
set +e
|
|
||||||
out=$(run_helper "git.mosaicstack.dev" "no-such-agent" MOSAIC_AGENT_NAME=no-such-agent 2>"$WORK_DIR/fleet-missing.stderr")
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
err=$(cat "$WORK_DIR/fleet-missing.stderr")
|
|
||||||
if [[ "$rc" -eq 0 || "$out" != *"quit=true"* || "$err" != *"reason=no-token-for-identity"* || "$err" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: fleet missing token did not stop at the resolver marker" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 6. Correct per-slot token PATH is chosen per host: same agent id, different
|
# 6. Correct per-slot token PATH is chosen per host: same agent id, different
|
||||||
# host prefix (gitea-usc- vs gitea-mosaicstack-).
|
# host prefix (gitea-usc- vs gitea-mosaicstack-).
|
||||||
@@ -179,47 +135,14 @@ assert_eq "host-scoped token path (cross-host must not leak): username" "usernam
|
|||||||
assert_eq "host-scoped token path (cross-host must not leak): password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
assert_eq "host-scoped token path (cross-host must not leak): password" "password=shared-mosaicstack-token" "$(echo "$out" | grep '^password=')"
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 7. Governed envelopes use the same binding, owner, mode, and digest checks.
|
# 7. Unrelated/unknown host -> exit 0, no output (passthrough for non-Gitea
|
||||||
# ---------------------------------------------------------------------------
|
|
||||||
envelope="$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentE.credential.json"
|
|
||||||
python3 - "$envelope" <<'PY'
|
|
||||||
import hashlib, json, sys
|
|
||||||
secret = "agentE-envelope-token"
|
|
||||||
json.dump({
|
|
||||||
"schemaVersion": 1, "identity": "agentE", "estate": "homelab",
|
|
||||||
"host": "git.mosaicstack.dev", "providerLogin": "agentE",
|
|
||||||
"tokenName": "mosaic-agentE-1", "scopes": ["write:repository"],
|
|
||||||
"createdAt": "2026-08-05T00:00:00.000Z",
|
|
||||||
"tokenDigest": hashlib.sha256(secret.encode()).hexdigest(), "token": secret,
|
|
||||||
}, open(sys.argv[1], "w", encoding="utf-8"))
|
|
||||||
PY
|
|
||||||
chmod 600 "$envelope"
|
|
||||||
out=$(run_helper "git.mosaicstack.dev" "agentE" MOSAIC_AGENT_NAME=agentE MOSAIC_CREDENTIAL_ESTATE=homelab)
|
|
||||||
assert_eq "governed envelope: password" "password=agentE-envelope-token" "$(echo "$out" | grep '^password=')"
|
|
||||||
echo -n "must-not-fallback-legacy" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentE.token"
|
|
||||||
chmod 640 "$envelope"
|
|
||||||
set +e
|
|
||||||
out=$(run_helper "git.mosaicstack.dev" "agentE" MOSAIC_AGENT_NAME=agentE MOSAIC_CREDENTIAL_ESTATE=homelab 2>"$WORK_DIR/envelope-mode.stderr")
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$rc" -eq 0 || "$out" == *"password="* ]]; then
|
|
||||||
echo "FAIL: permissive envelope was consumed" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
|
||||||
# 8. Unrelated/unknown host -> exit 0, no output (passthrough for non-Gitea
|
|
||||||
# remotes, e.g. github.com via a different credential helper).
|
# remotes, e.g. github.com via a different credential helper).
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
out=$(run_helper "github.com" "agentA")
|
out=$(run_helper "github.com" "agentA")
|
||||||
assert_eq "unknown host: no output" "" "$out"
|
assert_eq "unknown host: no output" "" "$out"
|
||||||
out=$(run_helper "github.com" "[email protected]")
|
|
||||||
assert_eq "unknown host with non-Mosaic username: no output" "" "$out"
|
|
||||||
out=$(run_helper "github.com" "github-user" MOSAIC_AGENT_NAME=agentA)
|
|
||||||
assert_eq "unknown host in fleet context: no output" "" "$out"
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 9. Non-"get" verb (store/erase) -> exit 0, no output (git-credential
|
# 8. Non-"get" verb (store/erase) -> exit 0, no output (git-credential
|
||||||
# protocol: this helper only implements get).
|
# protocol: this helper only implements get).
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
store_out=$(cd "$REPO_DIR" && env -i HOME="$FAKE_HOME" PATH="$PATH" bash "$HELPER" store <<EOF
|
store_out=$(cd "$REPO_DIR" && env -i HOME="$FAKE_HOME" PATH="$PATH" bash "$HELPER" store <<EOF
|
||||||
|
|||||||
@@ -28,7 +28,6 @@
|
|||||||
# HOME. NEVER reads real secrets or touches the real ~/.config/mosaic/secrets.
|
# HOME. NEVER reads real secrets or touches the real ~/.config/mosaic/secrets.
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
umask 077
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/gitea-token-identity}"
|
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/gitea-token-identity}"
|
||||||
@@ -86,23 +85,7 @@ call_get_gitea_token() {
|
|||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
git -C "$REPO_DIR" config --unset mosaic.gitIdentity 2>/dev/null || true
|
git -C "$REPO_DIR" config --unset mosaic.gitIdentity 2>/dev/null || true
|
||||||
out=$(call_get_gitea_token "git.mosaicstack.dev")
|
out=$(call_get_gitea_token "git.mosaicstack.dev")
|
||||||
assert_eq "interactive shared fallback (no identity)" "shared-mosaicstack-token" "$out"
|
assert_eq "shared fallback (no identity)" "shared-mosaicstack-token" "$out"
|
||||||
|
|
||||||
# Fleet context with no explicit identity refuses before the shared path. This
|
|
||||||
# is the marker-emission positive control for the fail-closed mechanism.
|
|
||||||
set +e
|
|
||||||
out=$(call_get_gitea_token "git.mosaicstack.dev" MOSAIC_AGENT_NAME=synthetic-seat 2>"$WORK_DIR/stderr-fleet-unset.tmp")
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
err=$(cat "$WORK_DIR/stderr-fleet-unset.tmp")
|
|
||||||
if [[ "$rc" -eq 0 || -n "$out" ]]; then
|
|
||||||
echo "FAIL: fleet unset identity must refuse with empty stdout" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
if [[ "$err" != *"MOSAIC_CREDENTIAL_REFUSAL"* || "$err" != *"reason=identity-required"* || "$err" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: fleet unset identity did not emit the stable resolver refusal marker: $err" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 2. git config mosaic.gitIdentity resolves to an agent WITH a per-slot
|
# 2. git config mosaic.gitIdentity resolves to an agent WITH a per-slot
|
||||||
@@ -110,17 +93,8 @@ fi
|
|||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
echo -n "agentA-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentA.token"
|
echo -n "agentA-mosaicstack-token" > "$FAKE_HOME/.config/mosaic/secrets/gitea-tokens/gitea-mosaicstack-agentA.token"
|
||||||
git -C "$REPO_DIR" config mosaic.gitIdentity agentA
|
git -C "$REPO_DIR" config mosaic.gitIdentity agentA
|
||||||
out=$(call_get_gitea_token "git.mosaicstack.dev" MOSAIC_AGENT_NAME=agentA)
|
out=$(call_get_gitea_token "git.mosaicstack.dev")
|
||||||
assert_eq "confirmed fleet identity bypasses shared path" "agentA-mosaicstack-token" "$out"
|
assert_eq "git-config identity token" "agentA-mosaicstack-token" "$out"
|
||||||
set +e
|
|
||||||
out=$(call_get_gitea_token "git.mosaicstack.dev" MOSAIC_AGENT_NAME=agentA MOSAIC_GIT_IDENTITY=agentB 2>"$WORK_DIR/fleet-mismatch.stderr")
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
err=$(cat "$WORK_DIR/fleet-mismatch.stderr")
|
|
||||||
if [[ "$rc" -eq 0 || -n "$out" || "$err" != *"reason=provider-identity-mismatch"* || "$err" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: fleet identity override was not refused before token resolution" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
# 3. MOSAIC_GIT_IDENTITY env beats git config mosaic.gitIdentity.
|
# 3. MOSAIC_GIT_IDENTITY env beats git config mosaic.gitIdentity.
|
||||||
@@ -169,17 +143,13 @@ assert_failloud() {
|
|||||||
echo "$stderr" >&2
|
echo "$stderr" >&2
|
||||||
fail=1
|
fail=1
|
||||||
fi
|
fi
|
||||||
if [[ "$stderr" != *"MOSAIC_CREDENTIAL_REFUSAL"* || "$stderr" != *"reason=no-token-for-identity"* || "$stderr" != *"shared_path_entered=false"* ]]; then
|
|
||||||
echo "FAIL: $desc — stable resolver refusal marker missing: $stderr" >&2
|
|
||||||
fail=1
|
|
||||||
fi
|
|
||||||
if [[ "$stderr" != *"$expected_tok_path"* ]]; then
|
if [[ "$stderr" != *"$expected_tok_path"* ]]; then
|
||||||
echo "FAIL: $desc — stderr does not name the expected per-slot token path '$expected_tok_path':" >&2
|
echo "FAIL: $desc — stderr does not name the expected per-slot token path '$expected_tok_path':" >&2
|
||||||
echo "$stderr" >&2
|
echo "$stderr" >&2
|
||||||
fail=1
|
fail=1
|
||||||
fi
|
fi
|
||||||
if [[ "$stderr" == *"shared-mosaicstack-token"* || "$stderr" == *"shared-usc-token"* ]]; then
|
if [[ "$stderr" == *"shared"*"token"* ]]; then
|
||||||
echo "FAIL: $desc — stderr unexpectedly contains a shared credential value:" >&2
|
echo "FAIL: $desc — stderr unexpectedly mentions a shared token value:" >&2
|
||||||
echo "$stderr" >&2
|
echo "$stderr" >&2
|
||||||
fail=1
|
fail=1
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# Regression harness for pr-merge.sh Gitea exact-head API path and input safety.
|
# Regression harness for pr-merge.sh Gitea non-interactive tea empty identity fallback.
|
||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
@@ -79,24 +79,15 @@ emit_response() {
|
|||||||
printf '200'
|
printf '200'
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
if [[ "$args" == *"/api/v1/repos/mosaicstack/stack/commits/0123456789abcdef0123456789abcdef01234567/status"* ]]; then
|
|
||||||
emit_response '{"state":"success","statuses":[{"context":"ci/test","status":"success"}]}'
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
if [[ "$args" == *"/api/v1/repos/mosaicstack/stack/pulls/123"* && "$args" != *"/api/v1/repos/mosaicstack/stack/pulls/123/merge"* ]]; then
|
if [[ "$args" == *"/api/v1/repos/mosaicstack/stack/pulls/123"* && "$args" != *"/api/v1/repos/mosaicstack/stack/pulls/123/merge"* ]]; then
|
||||||
emit_response '{"number":123,"title":"mock","state":"open","user":{"login":"tester"},"head":{"ref":"feature/mock","sha":"0123456789abcdef0123456789abcdef01234567","repo":{"full_name":"mosaicstack/stack"}},"base":{"ref":"main"},"labels":[],"assignees":[],"html_url":"https://git.mosaicstack.dev/mosaicstack/stack/pulls/123","mergeable":true}'
|
emit_response '{"number":123,"title":"mock","state":"open","user":{"login":"tester"},"head":{"ref":"feature/mock"},"base":{"ref":"main"},"labels":[],"assignees":[],"html_url":"https://git.mosaicstack.dev/mosaicstack/stack/pulls/123","mergeable":true}'
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
if [[ "$args" == *"-X POST"* && "$args" == *"/api/v1/repos/mosaicstack/stack/pulls/123/merge"* ]]; then
|
if [[ "$args" == *"-X POST"* && "$args" == *"/api/v1/repos/mosaicstack/stack/pulls/123/merge"* ]]; then
|
||||||
POST_DATA="$post_data" python3 - <<'PY'
|
if [[ "$post_data" != '{"Do":"squash"}' ]]; then
|
||||||
import json
|
echo "unexpected merge payload: $post_data" >&2
|
||||||
import os
|
exit 96
|
||||||
payload = json.loads(os.environ["POST_DATA"])
|
fi
|
||||||
assert payload == {
|
|
||||||
"Do": "squash",
|
|
||||||
"head_commit_id": "0123456789abcdef0123456789abcdef01234567",
|
|
||||||
}, payload
|
|
||||||
PY
|
|
||||||
emit_response '{"merged":true,"message":"mock merge complete"}'
|
emit_response '{"merged":true,"message":"mock merge complete"}'
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
@@ -116,8 +107,8 @@ export GITEA_URL="https://git.mosaicstack.dev"
|
|||||||
export GITEA_TOKEN="redacted-test-token"
|
export GITEA_TOKEN="redacted-test-token"
|
||||||
|
|
||||||
OUTPUT="$SANDBOX/output.log"
|
OUTPUT="$SANDBOX/output.log"
|
||||||
if ! "$SCRIPT_DIR/pr-merge.sh" -n 123 -m squash > "$OUTPUT" 2>&1; then
|
if ! "$SCRIPT_DIR/pr-merge.sh" -n 123 -m squash --skip-queue-guard > "$OUTPUT" 2>&1; then
|
||||||
echo "Expected pr-merge.sh to use the exact-head Gitea API path." >&2
|
echo "Expected pr-merge.sh to recover via Gitea API fallback." >&2
|
||||||
echo "--- output ---" >&2
|
echo "--- output ---" >&2
|
||||||
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
||||||
echo "--- mock log ---" >&2
|
echo "--- mock log ---" >&2
|
||||||
@@ -136,6 +127,38 @@ if grep -q 'redacted-test-token' "$OUTPUT"; then
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
cat > "$MOCK_BIN/tea" <<'EOF'
|
||||||
|
#!/bin/bash
|
||||||
|
set -euo pipefail
|
||||||
|
printf 'tea %q ' "$@" >> "$PR_MERGE_TEST_LOG"
|
||||||
|
printf '\n' >> "$PR_MERGE_TEST_LOG"
|
||||||
|
if [[ "$*" == *"login list"* ]]; then
|
||||||
|
echo '[{"name":"git.mosaicstack.dev","url":"https://git.mosaicstack.dev"}]'
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
if [[ "$*" == *"pr merge"* ]]; then
|
||||||
|
echo 'tea network timeout' >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
exit 0
|
||||||
|
EOF
|
||||||
|
chmod +x "$MOCK_BIN/tea"
|
||||||
|
: > "$LOG_FILE"
|
||||||
|
if "$SCRIPT_DIR/pr-merge.sh" -n 123 -m squash --skip-queue-guard > "$OUTPUT" 2>&1; then
|
||||||
|
echo "Expected arbitrary tea failure to remain blocking." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if grep -q '/api/v1/repos/mosaicstack/stack/pulls/123/merge' "$LOG_FILE"; then
|
||||||
|
echo "Arbitrary tea failure unexpectedly used Gitea API merge fallback." >&2
|
||||||
|
sed 's/redacted-test-token/***REDACTED***/g' "$LOG_FILE" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
if ! grep -q 'tea network timeout' "$OUTPUT"; then
|
||||||
|
echo "Expected arbitrary tea error to be preserved in output." >&2
|
||||||
|
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
cat > "$MOCK_BIN/tea" <<'EOF'
|
cat > "$MOCK_BIN/tea" <<'EOF'
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
@@ -154,8 +177,8 @@ EOF
|
|||||||
chmod +x "$MOCK_BIN/tea"
|
chmod +x "$MOCK_BIN/tea"
|
||||||
unset GITEA_LOGIN
|
unset GITEA_LOGIN
|
||||||
: > "$LOG_FILE"
|
: > "$LOG_FILE"
|
||||||
if ! "$SCRIPT_DIR/pr-merge.sh" -n 123 -m squash > "$OUTPUT" 2>&1; then
|
if ! "$SCRIPT_DIR/pr-merge.sh" -n 123 -m squash --skip-queue-guard > "$OUTPUT" 2>&1; then
|
||||||
echo "Expected the exact-head API path not to depend on a tea login." >&2
|
echo "Expected missing tea login to use authenticated Gitea API fallback." >&2
|
||||||
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
||||||
sed 's/redacted-test-token/***REDACTED***/g' "$LOG_FILE" >&2
|
sed 's/redacted-test-token/***REDACTED***/g' "$LOG_FILE" >&2
|
||||||
exit 1
|
exit 1
|
||||||
@@ -192,7 +215,7 @@ cd "$REPO_DIR"
|
|||||||
git remote set-url origin https://github.com/mosaicstack/stack.git
|
git remote set-url origin https://github.com/mosaicstack/stack.git
|
||||||
: > "$LOG_FILE"
|
: > "$LOG_FILE"
|
||||||
rm -f "$SENTINEL"
|
rm -f "$SENTINEL"
|
||||||
if "$SCRIPT_DIR/pr-merge.sh" -n "$INJECTION" -m squash > "$OUTPUT" 2>&1; then
|
if "$SCRIPT_DIR/pr-merge.sh" -n "$INJECTION" -m squash --skip-queue-guard > "$OUTPUT" 2>&1; then
|
||||||
echo "Expected GitHub metacharacter PR number to be rejected." >&2
|
echo "Expected GitHub metacharacter PR number to be rejected." >&2
|
||||||
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
||||||
exit 1
|
exit 1
|
||||||
@@ -217,7 +240,7 @@ git remote set-url origin https://git.mosaicstack.dev/mosaicstack/stack.git
|
|||||||
export GITEA_LOGIN="git.mosaicstack.dev"
|
export GITEA_LOGIN="git.mosaicstack.dev"
|
||||||
: > "$LOG_FILE"
|
: > "$LOG_FILE"
|
||||||
rm -f "$SENTINEL"
|
rm -f "$SENTINEL"
|
||||||
if "$SCRIPT_DIR/pr-merge.sh" -n "$INJECTION" -m squash > "$OUTPUT" 2>&1; then
|
if "$SCRIPT_DIR/pr-merge.sh" -n "$INJECTION" -m squash --skip-queue-guard > "$OUTPUT" 2>&1; then
|
||||||
echo "Expected Gitea metacharacter PR number to be rejected." >&2
|
echo "Expected Gitea metacharacter PR number to be rejected." >&2
|
||||||
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
sed 's/redacted-test-token/***REDACTED***/g' "$OUTPUT" >&2
|
||||||
exit 1
|
exit 1
|
||||||
@@ -237,4 +260,4 @@ if ! grep -q 'Invalid PR number' "$OUTPUT"; then
|
|||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "pr-merge.sh Gitea exact-head API regression passed"
|
echo "pr-merge.sh Gitea fallback regression passed"
|
||||||
|
|||||||
@@ -1,156 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# shellcheck disable=SC2030,SC2031 # Provider arms isolate PATH/credentials in subshells.
|
|
||||||
# The commit whose CI was guarded must be the commit the provider atomically merges.
|
|
||||||
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-merge-head-pin}"
|
|
||||||
SHA=0123456789abcdef0123456789abcdef01234567
|
|
||||||
|
|
||||||
make_fixture() {
|
|
||||||
local name="$1" remote="$2"
|
|
||||||
local root="$WORK_DIR/$name"
|
|
||||||
local tools="$root/tools/git"
|
|
||||||
mkdir -p "$tools" "$root/repo"
|
|
||||||
cp "$SCRIPT_DIR/pr-merge.sh" "$tools/pr-merge.sh"
|
|
||||||
cp "$SCRIPT_DIR/detect-platform.sh" "$tools/detect-platform.sh"
|
|
||||||
git -C "$root/repo" init -q
|
|
||||||
git -C "$root/repo" remote add origin "$remote"
|
|
||||||
cat > "$tools/pr-metadata.sh" <<SH
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
printf '%s\n' '{"baseRefName":"main","headRefName":"fix/pinned","headRefOid":"$SHA","headRepository":"contributor/widgets-fork"}'
|
|
||||||
SH
|
|
||||||
cat > "$tools/ci-queue-wait.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
exit 0
|
|
||||||
SH
|
|
||||||
chmod +x "$tools"/*.sh
|
|
||||||
}
|
|
||||||
|
|
||||||
rm -rf "$WORK_DIR"
|
|
||||||
make_fixture gitea https://git.example.test/acme/widgets.git
|
|
||||||
make_fixture github https://github.com/acme/widgets.git
|
|
||||||
|
|
||||||
cat > "$WORK_DIR/gitea/curl" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
payload=""
|
|
||||||
for ((i=1; i<=$#; i++)); do
|
|
||||||
if [[ "${!i}" == "-d" ]]; then
|
|
||||||
j=$((i + 1))
|
|
||||||
payload="${!j}"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
printf '%s' "$payload" > "${MOSAIC_MERGE_PAYLOAD_LOG:?}"
|
|
||||||
printf '200'
|
|
||||||
SH
|
|
||||||
chmod +x "$WORK_DIR/gitea/curl"
|
|
||||||
|
|
||||||
set +e
|
|
||||||
(
|
|
||||||
cd "$WORK_DIR/gitea/repo"
|
|
||||||
export PATH="$WORK_DIR/gitea:$PATH"
|
|
||||||
export GITEA_TOKEN=stub-token
|
|
||||||
export GITEA_URL=https://git.example.test
|
|
||||||
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
|
||||||
export MOSAIC_MERGE_PAYLOAD_LOG="$WORK_DIR/gitea-payload.json"
|
|
||||||
env -u MOSAIC_GIT_IDENTITY "$WORK_DIR/gitea/tools/git/pr-merge.sh" -n 123
|
|
||||||
) >"$WORK_DIR/gitea.out" 2>&1
|
|
||||||
gitea_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$gitea_rc" -ne 0 ]]; then
|
|
||||||
echo "FAIL gitea-pin: merge fixture returned $gitea_rc" >&2
|
|
||||||
cat "$WORK_DIR/gitea.out" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
python3 - "$WORK_DIR/gitea-payload.json" "$SHA" <<'PY'
|
|
||||||
import json
|
|
||||||
import sys
|
|
||||||
payload = json.load(open(sys.argv[1], encoding="utf-8"))
|
|
||||||
assert set(payload) <= {"Do", "head_commit_id", "delete_branch_after_merge"}, payload
|
|
||||||
assert payload.get("Do") == "squash", payload
|
|
||||||
assert payload.get("head_commit_id") == sys.argv[2], payload
|
|
||||||
PY
|
|
||||||
|
|
||||||
# A merge-gate verdict is commit-bound. A stale expected head must fail before merge.
|
|
||||||
wrong_sha=ffffffffffffffffffffffffffffffffffffffff
|
|
||||||
rm -f "$WORK_DIR/gitea-payload-stale.json"
|
|
||||||
set +e
|
|
||||||
(
|
|
||||||
cd "$WORK_DIR/gitea/repo"
|
|
||||||
export PATH="$WORK_DIR/gitea:$PATH"
|
|
||||||
export GITEA_TOKEN=stub-token
|
|
||||||
export GITEA_URL=https://git.example.test
|
|
||||||
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
|
||||||
export MOSAIC_MERGE_PAYLOAD_LOG="$WORK_DIR/gitea-payload-stale.json"
|
|
||||||
env -u MOSAIC_GIT_IDENTITY "$WORK_DIR/gitea/tools/git/pr-merge.sh" -n 123 --expect-head "$wrong_sha"
|
|
||||||
) >"$WORK_DIR/gitea-stale.out" 2>&1
|
|
||||||
stale_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$stale_rc" -eq 0 ]] || [[ -e "$WORK_DIR/gitea-payload-stale.json" ]]; then
|
|
||||||
echo "FAIL stale-verdict: moved head was not refused before provider merge" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# A merge-capable path cannot bypass the mandatory queue guard. The legacy
|
|
||||||
# --skip-queue-guard option must be rejected before any provider merge call.
|
|
||||||
cat > "$WORK_DIR/gitea/tools/git/ci-queue-wait.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
exit 99
|
|
||||||
SH
|
|
||||||
chmod +x "$WORK_DIR/gitea/tools/git/ci-queue-wait.sh"
|
|
||||||
rm -f "$WORK_DIR/gitea-payload-bypass.json"
|
|
||||||
set +e
|
|
||||||
(
|
|
||||||
cd "$WORK_DIR/gitea/repo"
|
|
||||||
export PATH="$WORK_DIR/gitea:$PATH"
|
|
||||||
export GITEA_TOKEN=stub-token
|
|
||||||
export GITEA_URL=https://git.example.test
|
|
||||||
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
|
||||||
export MOSAIC_MERGE_PAYLOAD_LOG="$WORK_DIR/gitea-payload-bypass.json"
|
|
||||||
env -u MOSAIC_GIT_IDENTITY "$WORK_DIR/gitea/tools/git/pr-merge.sh" -n 123 --skip-queue-guard
|
|
||||||
) >"$WORK_DIR/gitea-bypass.out" 2>&1
|
|
||||||
bypass_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$bypass_rc" -eq 0 ]] || [[ -e "$WORK_DIR/gitea-payload-bypass.json" ]]; then
|
|
||||||
echo "FAIL merge-bypass: --skip-queue-guard reached the provider merge path" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Dry-run is the only path that may omit the guard because it exits before the
|
|
||||||
# provider merge dispatch. Prove the exit and absence of a merge payload.
|
|
||||||
rm -f "$WORK_DIR/gitea-payload-dry-run.json"
|
|
||||||
(
|
|
||||||
cd "$WORK_DIR/gitea/repo"
|
|
||||||
export PATH="$WORK_DIR/gitea:$PATH"
|
|
||||||
export GITEA_TOKEN=stub-token
|
|
||||||
export GITEA_URL=https://git.example.test
|
|
||||||
export MOSAIC_CREDENTIALS_FILE="$WORK_DIR/no-credentials.json"
|
|
||||||
export MOSAIC_MERGE_PAYLOAD_LOG="$WORK_DIR/gitea-payload-dry-run.json"
|
|
||||||
env -u MOSAIC_GIT_IDENTITY "$WORK_DIR/gitea/tools/git/pr-merge.sh" -n 123 --dry-run
|
|
||||||
) >"$WORK_DIR/gitea-dry-run.out" 2>&1
|
|
||||||
if [[ -e "$WORK_DIR/gitea-payload-dry-run.json" ]]; then
|
|
||||||
echo "FAIL dry-run: non-merging preflight reached the provider merge path" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
cat > "$WORK_DIR/github/gh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -euo pipefail
|
|
||||||
printf '%s\n' "$*" > "${MOSAIC_GH_MERGE_LOG:?}"
|
|
||||||
SH
|
|
||||||
chmod +x "$WORK_DIR/github/gh"
|
|
||||||
(
|
|
||||||
cd "$WORK_DIR/github/repo"
|
|
||||||
export PATH="$WORK_DIR/github:$PATH"
|
|
||||||
export MOSAIC_GH_MERGE_LOG="$WORK_DIR/github-call.log"
|
|
||||||
"$WORK_DIR/github/tools/git/pr-merge.sh" -n 123
|
|
||||||
) >"$WORK_DIR/github.out" 2>&1
|
|
||||||
if ! grep -q -- "--match-head-commit $SHA" "$WORK_DIR/github-call.log"; then
|
|
||||||
echo "FAIL github-pin: merge command omitted --match-head-commit $SHA" >&2
|
|
||||||
cat "$WORK_DIR/github-call.log" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "PR merge exact-head pin regression passed (Gitea + GitHub)"
|
|
||||||
@@ -1,66 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# RM-03: pr-merge must guard the PR head branch, not its main base branch.
|
|
||||||
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
WORK_DIR="${MOSAIC_TEST_WORK_DIR:-$PWD/.mosaic-test-work/pr-merge-queue-branch}"
|
|
||||||
FIXTURE_DIR="$WORK_DIR/tools/git"
|
|
||||||
CALL_LOG="$WORK_DIR/queue-call.log"
|
|
||||||
|
|
||||||
rm -rf "$WORK_DIR"
|
|
||||||
mkdir -p "$FIXTURE_DIR"
|
|
||||||
cp "$SCRIPT_DIR/pr-merge.sh" "$FIXTURE_DIR/pr-merge.sh"
|
|
||||||
cp "$SCRIPT_DIR/detect-platform.sh" "$FIXTURE_DIR/detect-platform.sh"
|
|
||||||
|
|
||||||
cat > "$FIXTURE_DIR/pr-metadata.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
printf '%s\n' '{"baseRefName":"main","headRefName":"fix/rm-03-fixture","headRefOid":"0123456789abcdef0123456789abcdef01234567","headRepository":"contributor/widgets-fork"}'
|
|
||||||
SH
|
|
||||||
|
|
||||||
cat > "$FIXTURE_DIR/ci-queue-wait.sh" <<'SH'
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
printf '%s\n' "$*" > "${MOSAIC_QUEUE_CALL_LOG:?}"
|
|
||||||
exit 42
|
|
||||||
SH
|
|
||||||
chmod +x "$FIXTURE_DIR"/*.sh
|
|
||||||
|
|
||||||
set +e
|
|
||||||
(
|
|
||||||
cd "$WORK_DIR"
|
|
||||||
export MOSAIC_QUEUE_CALL_LOG="$CALL_LOG"
|
|
||||||
"$FIXTURE_DIR/pr-merge.sh" -n 123
|
|
||||||
) >/dev/null 2>&1
|
|
||||||
rc=$?
|
|
||||||
set -e
|
|
||||||
|
|
||||||
if [[ "$rc" -ne 42 ]]; then
|
|
||||||
echo "FAIL: expected queue stub rc=42 to propagate, got $rc" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if [[ ! -s "$CALL_LOG" ]]; then
|
|
||||||
echo "FAIL: merge wrapper did not invoke the queue guard" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if ! grep -q -- '-B fix/rm-03-fixture' "$CALL_LOG"; then
|
|
||||||
echo "FAIL: merge queue guard did not receive PR head branch" >&2
|
|
||||||
cat "$CALL_LOG" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if grep -q -- '-B main' "$CALL_LOG"; then
|
|
||||||
echo "FAIL: merge queue guard still received the main base branch" >&2
|
|
||||||
cat "$CALL_LOG" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if ! grep -q -- '-R contributor/widgets-fork' "$CALL_LOG"; then
|
|
||||||
echo "FAIL: merge queue guard did not receive the fork head repository" >&2
|
|
||||||
cat "$CALL_LOG" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
if ! grep -q -- '--sha 0123456789abcdef0123456789abcdef01234567' "$CALL_LOG"; then
|
|
||||||
echo "FAIL: merge queue guard did not receive the exact PR head SHA" >&2
|
|
||||||
cat "$CALL_LOG" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "pr-merge queue branch/repository/SHA regression passed"
|
|
||||||
@@ -39,12 +39,11 @@ ORIG_PATH="$PATH"
|
|||||||
# loop — which would make the control a false negative. A root dotfile is
|
# loop — which would make the control a false negative. A root dotfile is
|
||||||
# operator-owned (unknown→operator), so the sync loop skips it. Clean up on exit.
|
# operator-owned (unknown→operator), so the sync loop skips it. Clean up on exit.
|
||||||
STRIPPED="$FW/.install-rollback-control.tmp.sh"
|
STRIPPED="$FW/.install-rollback-control.tmp.sh"
|
||||||
SIGNALED="$FW/.install-signal-control.tmp.sh"
|
|
||||||
NOEXIT="$FW/.install-noexit-control.tmp.sh"
|
NOEXIT="$FW/.install-noexit-control.tmp.sh"
|
||||||
D1CTRL="$FW/.install-d1guard-control.tmp.sh"
|
D1CTRL="$FW/.install-d1guard-control.tmp.sh"
|
||||||
D2CTRL="$FW/.install-d2guard-control.tmp.sh"
|
D2CTRL="$FW/.install-d2guard-control.tmp.sh"
|
||||||
rm -f "$STRIPPED" "$SIGNALED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
rm -f "$STRIPPED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
||||||
trap 'rm -f "$STRIPPED" "$SIGNALED" "$NOEXIT" "$D1CTRL" "$D2CTRL"' EXIT
|
trap 'rm -f "$STRIPPED" "$NOEXIT" "$D1CTRL" "$D2CTRL"' EXIT
|
||||||
|
|
||||||
pass=0; fail=0
|
pass=0; fail=0
|
||||||
chk() { if eval "$2"; then echo " ✓ $1"; pass=$((pass + 1)); else echo " ✗ $1"; fail=$((fail + 1)); fi; }
|
chk() { if eval "$2"; then echo " ✓ $1"; pass=$((pass + 1)); else echo " ✗ $1"; fail=$((fail + 1)); fi; }
|
||||||
@@ -181,86 +180,41 @@ chk "[control] without -E the mid-sync corruption survives (no rollback)" \
|
|||||||
# ── Part C: an INT/TERM interrupt must terminate, not resume (blocker-A) ──────
|
# ── Part C: an INT/TERM interrupt must terminate, not resume (blocker-A) ──────
|
||||||
# A bash signal trap that merely returns lets the script continue past the
|
# A bash signal trap that merely returns lets the script continue past the
|
||||||
# interrupt — restoring the snapshot, then resuming the sync and reporting
|
# interrupt — restoring the snapshot, then resuming the sync and reporting
|
||||||
# success. The earlier test used a child cp shim to signal its parent, making
|
# success. We inject a SIGTERM mid-sync with a cp that SUCCEEDS (so set -e never
|
||||||
# child completion race Bash's interrupted wait. Concurrency is not part of the
|
# fires and ONLY the signal path governs), and assert the shipped installer
|
||||||
# guarded property: sync_framework_keep() runs in the installer's own Bash
|
# restores AND exits without reporting success. The control strips `exit 1` from
|
||||||
# process, and `kill` is a builtin. Generate two installer fixtures that signal
|
# the trap and shows the buggy resume-to-success.
|
||||||
# themselves at the same known mid-sync point. Their TERM handlers emit the same
|
make_term_shim() {
|
||||||
# observable before diverging, so missing signal delivery fails BOTH arms rather
|
local dir="$1"
|
||||||
# than manufacturing a pass. The only semantic difference between fixtures is
|
cat > "$dir/cp" <<SHIM
|
||||||
# the explicit `exit 1` whose load-bearing behavior this control proves.
|
#!/usr/bin/env bash
|
||||||
TERM_MARKER='[test-control] TERM handler entered'
|
dest="\${@: -1}"
|
||||||
HANDLER_WITH_EXIT="trap 'echo \"$TERM_MARKER\" >&2; restore_snapshot; exit 1' TERM # TEST-TERM-HANDLER"
|
case "\$dest" in
|
||||||
HANDLER_WITHOUT_EXIT="trap 'echo \"$TERM_MARKER\" >&2; restore_snapshot' TERM # TEST-TERM-HANDLER"
|
*/$POISON_REL)
|
||||||
|
kill -TERM "\$PPID" 2>/dev/null # signal install.sh; the copy still succeeds
|
||||||
make_signal_installer() {
|
exec env PATH="$ORIG_PATH" cp "\$@" ;;
|
||||||
local output="$1" handler="$2"
|
esac
|
||||||
local target_trap="trap 'restore_snapshot; exit 1' ERR INT TERM"
|
exec env PATH="$ORIG_PATH" cp "\$@"
|
||||||
local target_cp=' cp "$abs" "$dst/$rel"'
|
SHIM
|
||||||
local inject_open=" if [[ \"\$rel\" == \"$POISON_REL\" ]]; then"
|
chmod +x "$dir/cp"
|
||||||
local inject_kill=' kill -TERM "$$" # TEST-TERM-INJECTION'
|
|
||||||
local inject_close=' fi'
|
|
||||||
|
|
||||||
if ! awk \
|
|
||||||
-v target_trap="$target_trap" -v target_cp="$target_cp" \
|
|
||||||
-v handler="$handler" -v inject_open="$inject_open" \
|
|
||||||
-v inject_kill="$inject_kill" -v inject_close="$inject_close" '
|
|
||||||
$0 == target_cp {
|
|
||||||
print inject_open
|
|
||||||
print inject_kill
|
|
||||||
print inject_close
|
|
||||||
injection_sites++
|
|
||||||
}
|
|
||||||
{ print }
|
|
||||||
$0 == target_trap {
|
|
||||||
print handler
|
|
||||||
handler_sites++
|
|
||||||
}
|
|
||||||
END {
|
|
||||||
if (handler_sites != 1 || injection_sites != 1) exit 42
|
|
||||||
}
|
|
||||||
' "$INSTALL" > "$output"; then
|
|
||||||
rm -f "$output"
|
|
||||||
fail "Could not construct the self-TERM control installer at the exact trap/copy sites"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
chmod +x "$output"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
make_signal_installer "$SIGNALED" "$HANDLER_WITH_EXIT"
|
# Run one keep-mode upgrade with the SIGTERM shim. Echoes "<exit>\t<out>\t<home>".
|
||||||
make_signal_installer "$NOEXIT" "$HANDLER_WITHOUT_EXIT"
|
|
||||||
signal_fixture_ready() {
|
|
||||||
local fixture="$1" expected_handler="$2"
|
|
||||||
[[ "$(grep -cF '# TEST-TERM-INJECTION' "$fixture")" -eq 1 ]] \
|
|
||||||
&& [[ "$(grep -cF '# TEST-TERM-HANDLER' "$fixture")" -eq 1 ]] \
|
|
||||||
&& grep -Fqx "$expected_handler" "$fixture"
|
|
||||||
}
|
|
||||||
signaled_fixture_ready() { signal_fixture_ready "$SIGNALED" "$HANDLER_WITH_EXIT"; }
|
|
||||||
noexit_fixture_ready() { signal_fixture_ready "$NOEXIT" "$HANDLER_WITHOUT_EXIT"; }
|
|
||||||
chk "[signal] shipped fixture has exactly one self-TERM injection and marked handler" \
|
|
||||||
"signaled_fixture_ready"
|
|
||||||
chk "[control] no-exit fixture has exactly one self-TERM injection and marked handler" \
|
|
||||||
"noexit_fixture_ready"
|
|
||||||
chk "[control] removing the explicit TERM exit changes the fixture" \
|
|
||||||
"! cmp -s '$SIGNALED' '$NOEXIT'"
|
|
||||||
|
|
||||||
# Run one keep-mode upgrade whose own shell delivers SIGTERM synchronously at
|
|
||||||
# the selected copy. Echoes "<exit>\t<out>\t<home>".
|
|
||||||
run_signal_upgrade() {
|
run_signal_upgrade() {
|
||||||
local installer="$1" H OUT rc
|
local installer="$1" H OUT SHIM rc
|
||||||
H=$(mktemp -d); OUT=$(mktemp)
|
H=$(mktemp -d); OUT=$(mktemp); SHIM=$(mktemp -d)
|
||||||
seed_home "$H"
|
seed_home "$H"
|
||||||
|
make_term_shim "$SHIM"
|
||||||
set +e
|
set +e
|
||||||
PATH="$ORIG_PATH" \
|
PATH="$SHIM:$ORIG_PATH" \
|
||||||
MOSAIC_HOME="$H" MOSAIC_INSTALL_MODE=keep MOSAIC_SYNC_ONLY=1 bash "$installer" >"$OUT" 2>&1
|
MOSAIC_HOME="$H" MOSAIC_INSTALL_MODE=keep MOSAIC_SYNC_ONLY=1 bash "$installer" >"$OUT" 2>&1
|
||||||
rc=$?
|
rc=$?
|
||||||
set -e 2>/dev/null || true
|
set -e 2>/dev/null || true
|
||||||
|
rm -rf "$SHIM"
|
||||||
printf '%s\t%s\t%s\n' "$rc" "$OUT" "$H"
|
printf '%s\t%s\t%s\n' "$rc" "$OUT" "$H"
|
||||||
}
|
}
|
||||||
|
|
||||||
IFS=$'\t' read -r rcC OUTC HC < <(run_signal_upgrade "$SIGNALED")
|
IFS=$'\t' read -r rcC OUTC HC < <(run_signal_upgrade "$INSTALL")
|
||||||
chk "[signal] TERM handler observable fires exactly once" \
|
|
||||||
"[ \"\$(grep -cF '$TERM_MARKER' '$OUTC')\" -eq 1 ]"
|
|
||||||
chk "[signal] SIGTERM mid-sync aborts non-zero (trap exits, does not resume)" \
|
chk "[signal] SIGTERM mid-sync aborts non-zero (trap exits, does not resume)" \
|
||||||
"[ '$rcC' -ne 0 ]"
|
"[ '$rcC' -ne 0 ]"
|
||||||
chk "[signal] restore_snapshot fires on the interrupt" \
|
chk "[signal] restore_snapshot fires on the interrupt" \
|
||||||
@@ -268,13 +222,13 @@ chk "[signal] restore_snapshot fires on the interrupt" \
|
|||||||
chk "[signal] does NOT resume to report sync success after the interrupt" \
|
chk "[signal] does NOT resume to report sync success after the interrupt" \
|
||||||
"! grep -q 'file phase complete' '$OUTC'"
|
"! grep -q 'file phase complete' '$OUTC'"
|
||||||
|
|
||||||
IFS=$'\t' read -r rcD OUTD HD < <(run_signal_upgrade "$NOEXIT")
|
# Control: strip `exit 1` from the signal trap → the handler returns, the script
|
||||||
chk "[control] TERM handler observable fires exactly once" \
|
# resumes past the interrupt and wrongly reports success. In $FW so SOURCE_DIR resolves.
|
||||||
"[ \"\$(grep -cF '$TERM_MARKER' '$OUTD')\" -eq 1 ]"
|
sed "s/trap 'restore_snapshot; exit 1' ERR INT TERM/trap 'restore_snapshot' ERR INT TERM/" \
|
||||||
chk "[control] without 'exit 1' the handler restores before returning" \
|
"$INSTALL" > "$NOEXIT"
|
||||||
"grep -q 'restoring previous state from snapshot' '$OUTD'"
|
chk "[control] the exit-strip actually changed the installer" \
|
||||||
chk "[control] without 'exit 1' the installer exits zero after resuming" \
|
"! cmp -s '$INSTALL' '$NOEXIT'"
|
||||||
"[ '$rcD' -eq 0 ]"
|
IFS=$'\t' read -r _rcD OUTD HD < <(run_signal_upgrade "$NOEXIT")
|
||||||
chk "[control] without 'exit 1' the trap resumes and reports sync success (the bug)" \
|
chk "[control] without 'exit 1' the trap resumes and reports sync success (the bug)" \
|
||||||
"grep -q 'file phase complete' '$OUTD'"
|
"grep -q 'file phase complete' '$OUTD'"
|
||||||
|
|
||||||
@@ -355,10 +309,10 @@ chk "[control] without the D2 recovery line the operator gets no snapshot pointe
|
|||||||
# Reap any snapshot the reset-fail runs left in /tmp (reset failed → never cleaned).
|
# Reap any snapshot the reset-fail runs left in /tmp (reset failed → never cleaned).
|
||||||
grep -o '/[^ ]*mosaic-snapshot[^ ]*' "$OUTH" 2>/dev/null | head -1 | while read -r s; do rm -rf "$s"; done
|
grep -o '/[^ ]*mosaic-snapshot[^ ]*' "$OUTH" 2>/dev/null | head -1 | while read -r s; do rm -rf "$s"; done
|
||||||
|
|
||||||
# Cleanup (generated installer controls are also removed by the EXIT trap).
|
# Cleanup ($STRIPPED / $NOEXIT / $D1CTRL / $D2CTRL are also removed by the EXIT trap).
|
||||||
for d in "$HA" "$REFA" "$HB" "$REFB" "$HC" "$HD" "$HE" "$REFE" "$HF" "$REFF" "$HG" "$HH"; do rm -rf "$d"; done
|
for d in "$HA" "$REFA" "$HB" "$REFB" "$HC" "$HD" "$HE" "$REFE" "$HF" "$REFF" "$HG" "$HH"; do rm -rf "$d"; done
|
||||||
rm -f "$OUTA" "$OUTB" "$OUTC" "$OUTD" "$OUTE" "$OUTF" "$OUTG" "$OUTH" \
|
rm -f "$OUTA" "$OUTB" "$OUTC" "$OUTD" "$OUTE" "$OUTF" "$OUTG" "$OUTH" \
|
||||||
"$STRIPPED" "$SIGNALED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
"$STRIPPED" "$NOEXIT" "$D1CTRL" "$D2CTRL"
|
||||||
|
|
||||||
echo
|
echo
|
||||||
echo "RESULT: $pass passed, $fail failed"
|
echo "RESULT: $pass passed, $fail failed"
|
||||||
|
|||||||
@@ -26,13 +26,12 @@ A Woodpecker API token is required. To configure:
|
|||||||
|
|
||||||
## Scripts
|
## Scripts
|
||||||
|
|
||||||
| Script | Purpose |
|
| Script | Purpose |
|
||||||
| -------------------------- | -------------------------------------------------------------- |
|
| --------------------- | -------------------------------------------- |
|
||||||
| `pipeline-list.sh` | List recent pipelines for a repo |
|
| `pipeline-list.sh` | List recent pipelines for a repo |
|
||||||
| `pipeline-status.sh` | Get status of a specific or latest pipeline |
|
| `pipeline-status.sh` | Get status of a specific or latest pipeline |
|
||||||
| `pipeline-trigger.sh` | Trigger a new pipeline build |
|
| `pipeline-trigger.sh` | Trigger a new pipeline build |
|
||||||
| `ci-wait.sh` | Block until pipeline(s) reach terminal state |
|
| `ci-wait.sh` | Block until pipeline(s) reach terminal state |
|
||||||
| `verify-terminal-green.py` | Verify every JSON/API child step under the bounded CI contract |
|
|
||||||
|
|
||||||
## Common Options
|
## Common Options
|
||||||
|
|
||||||
@@ -60,9 +59,4 @@ A Woodpecker API token is required. To configure:
|
|||||||
|
|
||||||
# Block until one or more pipelines finish (event-driven CI wait)
|
# Block until one or more pipelines finish (event-driven CI wait)
|
||||||
~/.config/mosaic/tools/woodpecker/ci-wait.sh -r usc/uconnect -n 3917 -n 3918
|
~/.config/mosaic/tools/woodpecker/ci-wait.sh -r usc/uconnect -n 3917 -n 3918
|
||||||
|
|
||||||
# Verify the full JSON child-step record; do not use the text summary for this gate
|
|
||||||
PR_HEAD=<full-40-hex-provider-head>
|
|
||||||
~/.config/mosaic/tools/woodpecker/pipeline-status.sh -r mosaicstack/stack -n 2188 -f json \
|
|
||||||
| ~/.config/mosaic/tools/woodpecker/verify-terminal-green.py --expect-commit "$PR_HEAD" -
|
|
||||||
```
|
```
|
||||||
|
|||||||
@@ -1,109 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
# Red-first contract harness for RM-61 / #1000.
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
||||||
VERIFIER="$SCRIPT_DIR/verify-terminal-green.py"
|
|
||||||
EXPECTED_COMMIT=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
|
|
||||||
TMP=$(mktemp -d)
|
|
||||||
trap 'rm -rf "$TMP"' EXIT
|
|
||||||
|
|
||||||
write_fixture() {
|
|
||||||
local file="$1" pipeline_status="$2" postgres_state="$3" postgres_exit="$4" postgres_error="$5" test_state="$6"
|
|
||||||
python3 - "$file" "$pipeline_status" "$postgres_state" "$postgres_exit" "$postgres_error" "$test_state" <<'PY'
|
|
||||||
import json, sys
|
|
||||||
path, pipeline_status, pg_state, pg_exit, pg_error, test_state = sys.argv[1:]
|
|
||||||
steps = [
|
|
||||||
{"name": "clone", "type": "clone", "state": "success", "exit_code": 0, "error": None},
|
|
||||||
{"name": "ci-postgres", "type": "service", "state": pg_state, "exit_code": int(pg_exit), "error": pg_error or None},
|
|
||||||
{"name": "test", "type": "commands", "state": test_state, "exit_code": 0 if test_state == "success" else 1, "error": None},
|
|
||||||
]
|
|
||||||
json.dump({
|
|
||||||
"number": 9999,
|
|
||||||
"status": pipeline_status,
|
|
||||||
"commit": "a" * 40,
|
|
||||||
"workflows": [{"name": "ci", "state": pipeline_status, "children": steps}],
|
|
||||||
}, open(path, "w"))
|
|
||||||
PY
|
|
||||||
}
|
|
||||||
|
|
||||||
expect_exit() {
|
|
||||||
local expected_exit="$1" label="$2" file="$3" expected_commit="${4:-$EXPECTED_COMMIT}"
|
|
||||||
set +e
|
|
||||||
output=$(python3 "$VERIFIER" --expect-commit "$expected_commit" "$file" 2>&1)
|
|
||||||
actual=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$actual" -ne "$expected_exit" ]]; then
|
|
||||||
printf 'FAIL %s: expected exit %s, got %s\n%s\n' "$label" "$expected_exit" "$actual" "$output" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
printf 'PASS %s\n' "$label"
|
|
||||||
printf '%s' "$output"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Ordinary terminal green.
|
|
||||||
write_fixture "$TMP/green.json" success success 0 '' success
|
|
||||||
out=$(expect_exit 0 green "$TMP/green.json")
|
|
||||||
grep -q '"total_steps": 3' <<<"$out"
|
|
||||||
grep -q '"exempted_steps": 0' <<<"$out"
|
|
||||||
|
|
||||||
# Exact, named #1000 teardown artifact: the only permitted non-success child.
|
|
||||||
artifact='pods "wp-svc-01kyxzjhdf6w81swsnbfzh85z9-ci-postgres" not found'
|
|
||||||
write_fixture "$TMP/artifact.json" success failure 0 "$artifact" success
|
|
||||||
out=$(expect_exit 0 exact-artifact "$TMP/artifact.json")
|
|
||||||
grep -q '"exemption_id": "WP-K8S-1000-CI-POSTGRES-TEARDOWN"' <<<"$out"
|
|
||||||
grep -q '"exempted_steps": 1' <<<"$out"
|
|
||||||
|
|
||||||
# Negative controls: both real PostgreSQL failures must remain red.
|
|
||||||
write_fixture "$TMP/startup.json" failure failure 1 '' failure
|
|
||||||
expect_exit 1 startup-failure "$TMP/startup.json" >/dev/null
|
|
||||||
write_fixture "$TMP/crash.json" failure failure 137 '' failure
|
|
||||||
expect_exit 1 post-readiness-crash "$TMP/crash.json" >/dev/null
|
|
||||||
|
|
||||||
# The exemption is signature-scoped, not step-scoped.
|
|
||||||
write_fixture "$TMP/wrong-error.json" success failure 0 'connection refused' success
|
|
||||||
expect_exit 1 other-postgres-error "$TMP/wrong-error.json" >/dev/null
|
|
||||||
write_fixture "$TMP/wrong-pod.json" success failure 0 'pods "other-ci-postgres" not found' success
|
|
||||||
expect_exit 1 wrong-pod-signature "$TMP/wrong-pod.json" >/dev/null
|
|
||||||
write_fixture "$TMP/nonzero-artifact.json" success failure 137 "$artifact" success
|
|
||||||
expect_exit 1 nonzero-with-artifact-text "$TMP/nonzero-artifact.json" >/dev/null
|
|
||||||
|
|
||||||
# JSON booleans and non-integer zero look equal to 0 in Python but are not exit codes.
|
|
||||||
python3 - "$TMP/artifact.json" "$TMP" <<'PY'
|
|
||||||
import json, os, sys
|
|
||||||
record = json.load(open(sys.argv[1]))
|
|
||||||
for label, value in (("false", False), ("true", True), ("float", 0.0), ("string", "0"), ("null", None)):
|
|
||||||
changed = json.loads(json.dumps(record))
|
|
||||||
changed["workflows"][0]["children"][1]["exit_code"] = value
|
|
||||||
json.dump(changed, open(os.path.join(sys.argv[2], f"exit-{label}.json"), "w"))
|
|
||||||
PY
|
|
||||||
for label in false true float string null; do
|
|
||||||
expect_exit 1 "non-integer-exit-$label" "$TMP/exit-$label.json" >/dev/null
|
|
||||||
done
|
|
||||||
|
|
||||||
# Exact artifact cannot mask any independent failure or non-success pipeline.
|
|
||||||
write_fixture "$TMP/artifact-plus-failure.json" failure failure 0 "$artifact" failure
|
|
||||||
expect_exit 1 artifact-plus-real-failure "$TMP/artifact-plus-failure.json" >/dev/null
|
|
||||||
write_fixture "$TMP/skipped.json" success success 0 '' skipped
|
|
||||||
expect_exit 1 skipped-step "$TMP/skipped.json" >/dev/null
|
|
||||||
|
|
||||||
# The scanned pipeline must be bound to an explicit, full PR-head commit.
|
|
||||||
set +e
|
|
||||||
missing_output=$(python3 "$VERIFIER" "$TMP/artifact.json" 2>&1)
|
|
||||||
missing_rc=$?
|
|
||||||
set -e
|
|
||||||
if [[ "$missing_rc" -ne 2 ]] || ! grep -q -- '--expect-commit' <<<"$missing_output"; then
|
|
||||||
printf 'FAIL missing-expected-commit: expected usage exit 2\n%s\n' "$missing_output" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
expect_exit 1 mismatched-expected-commit "$TMP/artifact.json" bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb >/dev/null
|
|
||||||
|
|
||||||
python3 - "$TMP/artifact.json" "$TMP/missing-record-commit.json" <<'PY'
|
|
||||||
import json, sys
|
|
||||||
record = json.load(open(sys.argv[1]))
|
|
||||||
record.pop("commit")
|
|
||||||
json.dump(record, open(sys.argv[2], "w"))
|
|
||||||
PY
|
|
||||||
expect_exit 1 missing-record-commit "$TMP/missing-record-commit.json" >/dev/null
|
|
||||||
|
|
||||||
printf 'terminal-green contract harness: PASS (17 cases)\n'
|
|
||||||
@@ -1,230 +0,0 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
"""Verify Mosaic's full-step Woodpecker terminal-green contract.
|
|
||||||
|
|
||||||
RM-61 permits one named, signature-scoped exception for issue #1000. The
|
|
||||||
exception retires when #1000 is fixed; all other non-success states block.
|
|
||||||
This program consumes the JSON/API record emitted by pipeline-status.sh -f json.
|
|
||||||
It does not fetch, retry, or re-trigger pipelines.
|
|
||||||
"""
|
|
||||||
|
|
||||||
from __future__ import annotations
|
|
||||||
|
|
||||||
import argparse
|
|
||||||
import json
|
|
||||||
import re
|
|
||||||
import sys
|
|
||||||
from collections import Counter
|
|
||||||
from pathlib import Path
|
|
||||||
from typing import Any
|
|
||||||
|
|
||||||
EXEMPTION_ID = "WP-K8S-1000-CI-POSTGRES-TEARDOWN"
|
|
||||||
EXEMPTION_ISSUE = "https://git.mosaicstack.dev/mosaicstack/stack/issues/1000"
|
|
||||||
POD_NOT_FOUND = re.compile(
|
|
||||||
r'^pods "wp-svc-[0-9a-hjkmnp-tv-z]{26}-ci-postgres" not found$'
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
def fail_usage(message: str) -> int:
|
|
||||||
print(f"terminal-green contract input error: {message}", file=sys.stderr)
|
|
||||||
return 2
|
|
||||||
|
|
||||||
|
|
||||||
def load_record(argument: str | None) -> dict[str, Any]:
|
|
||||||
if argument in (None, "-"):
|
|
||||||
value = json.load(sys.stdin)
|
|
||||||
else:
|
|
||||||
with Path(argument).open(encoding="utf-8") as handle:
|
|
||||||
value = json.load(handle)
|
|
||||||
if not isinstance(value, dict):
|
|
||||||
raise ValueError("pipeline record must be a JSON object")
|
|
||||||
return value
|
|
||||||
|
|
||||||
|
|
||||||
def is_issue_1000_artifact(step: dict[str, Any]) -> bool:
|
|
||||||
error = step.get("error")
|
|
||||||
exit_code = step.get("exit_code")
|
|
||||||
return (
|
|
||||||
step.get("name") == "ci-postgres"
|
|
||||||
and step.get("type") == "service"
|
|
||||||
and step.get("state") == "failure"
|
|
||||||
and type(exit_code) is int
|
|
||||||
and not isinstance(exit_code, bool)
|
|
||||||
and exit_code == 0
|
|
||||||
and isinstance(error, str)
|
|
||||||
and POD_NOT_FOUND.fullmatch(error) is not None
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
def verify(record: dict[str, Any], expected_commit: str) -> tuple[int, dict[str, Any]]:
|
|
||||||
anomalies: list[dict[str, Any]] = []
|
|
||||||
candidates: list[dict[str, Any]] = []
|
|
||||||
steps: list[dict[str, Any]] = []
|
|
||||||
|
|
||||||
pipeline_status = record.get("status")
|
|
||||||
actual_commit = record.get("commit")
|
|
||||||
if actual_commit != expected_commit:
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "pipeline",
|
|
||||||
"name": str(record.get("number", "unknown")),
|
|
||||||
"state": pipeline_status,
|
|
||||||
"reason": "pipeline commit does not equal the expected PR head",
|
|
||||||
"expected_commit": expected_commit,
|
|
||||||
"actual_commit": actual_commit,
|
|
||||||
}
|
|
||||||
)
|
|
||||||
if pipeline_status != "success":
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "pipeline",
|
|
||||||
"name": str(record.get("number", "unknown")),
|
|
||||||
"state": pipeline_status,
|
|
||||||
"reason": "pipeline status is not success",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
|
|
||||||
workflows = record.get("workflows")
|
|
||||||
if not isinstance(workflows, list) or not workflows:
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "pipeline",
|
|
||||||
"name": str(record.get("number", "unknown")),
|
|
||||||
"state": pipeline_status,
|
|
||||||
"reason": "workflows are missing or empty",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
workflows = []
|
|
||||||
|
|
||||||
for workflow_index, workflow in enumerate(workflows):
|
|
||||||
if not isinstance(workflow, dict):
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "workflow",
|
|
||||||
"name": str(workflow_index),
|
|
||||||
"state": None,
|
|
||||||
"reason": "workflow is not an object",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
continue
|
|
||||||
workflow_name = str(workflow.get("name", workflow_index))
|
|
||||||
if workflow.get("state") != "success":
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "workflow",
|
|
||||||
"name": workflow_name,
|
|
||||||
"state": workflow.get("state"),
|
|
||||||
"reason": "workflow state is not success",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
children = workflow.get("children")
|
|
||||||
if not isinstance(children, list) or not children:
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "workflow",
|
|
||||||
"name": workflow_name,
|
|
||||||
"state": workflow.get("state"),
|
|
||||||
"reason": "child-step list is missing or empty",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
continue
|
|
||||||
for child_index, child in enumerate(children):
|
|
||||||
if not isinstance(child, dict):
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "step",
|
|
||||||
"name": f"{workflow_name}[{child_index}]",
|
|
||||||
"state": None,
|
|
||||||
"reason": "step is not an object",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
continue
|
|
||||||
steps.append(child)
|
|
||||||
if child.get("state") == "success":
|
|
||||||
continue
|
|
||||||
if is_issue_1000_artifact(child):
|
|
||||||
candidates.append(child)
|
|
||||||
continue
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "step",
|
|
||||||
"name": child.get("name"),
|
|
||||||
"type": child.get("type"),
|
|
||||||
"state": child.get("state"),
|
|
||||||
"exit_code": child.get("exit_code"),
|
|
||||||
"error": child.get("error"),
|
|
||||||
"reason": "non-success step does not match the #1000 teardown signature",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
|
|
||||||
if len(candidates) > 1:
|
|
||||||
anomalies.append(
|
|
||||||
{
|
|
||||||
"scope": "exemption",
|
|
||||||
"name": EXEMPTION_ID,
|
|
||||||
"state": "invalid",
|
|
||||||
"reason": "the #1000 exemption may apply to exactly one step",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
|
|
||||||
exemption_applies = len(candidates) == 1 and not anomalies
|
|
||||||
state_counts = Counter(str(step.get("state", "missing")) for step in steps)
|
|
||||||
result: dict[str, Any] = {
|
|
||||||
"schema_version": "mosaic-terminal-green/v1",
|
|
||||||
"verdict": "terminal-green" if not anomalies else "not-terminal-green",
|
|
||||||
"pipeline_number": record.get("number"),
|
|
||||||
"commit": actual_commit,
|
|
||||||
"expected_commit": expected_commit,
|
|
||||||
"pipeline_status": pipeline_status,
|
|
||||||
"total_steps": len(steps),
|
|
||||||
"state_counts": dict(sorted(state_counts.items())),
|
|
||||||
"exempted_steps": 1 if exemption_applies else 0,
|
|
||||||
"anomalies": anomalies,
|
|
||||||
}
|
|
||||||
if exemption_applies:
|
|
||||||
candidate = candidates[0]
|
|
||||||
result["exemptions"] = [
|
|
||||||
{
|
|
||||||
"exemption_id": EXEMPTION_ID,
|
|
||||||
"step": candidate.get("name"),
|
|
||||||
"signature": candidate.get("error"),
|
|
||||||
"tracking_issue": EXEMPTION_ISSUE,
|
|
||||||
"retires_when": "issue #1000 is fixed",
|
|
||||||
}
|
|
||||||
]
|
|
||||||
else:
|
|
||||||
result["exemptions"] = []
|
|
||||||
|
|
||||||
return (0 if not anomalies else 1), result
|
|
||||||
|
|
||||||
|
|
||||||
def parse_arguments() -> argparse.Namespace:
|
|
||||||
parser = argparse.ArgumentParser(
|
|
||||||
description="verify the full Woodpecker terminal-green child-step contract"
|
|
||||||
)
|
|
||||||
parser.add_argument(
|
|
||||||
"--expect-commit",
|
|
||||||
required=True,
|
|
||||||
metavar="FULL_SHA",
|
|
||||||
help="full 40-hex PR-head commit that the pipeline record must match",
|
|
||||||
)
|
|
||||||
parser.add_argument("record", nargs="?", default="-", help="pipeline JSON file or -")
|
|
||||||
arguments = parser.parse_args()
|
|
||||||
if re.fullmatch(r"[0-9a-fA-F]{40}", arguments.expect_commit) is None:
|
|
||||||
parser.error("--expect-commit must be a full 40-hex commit")
|
|
||||||
arguments.expect_commit = arguments.expect_commit.lower()
|
|
||||||
return arguments
|
|
||||||
|
|
||||||
|
|
||||||
def main() -> int:
|
|
||||||
arguments = parse_arguments()
|
|
||||||
try:
|
|
||||||
record = load_record(arguments.record)
|
|
||||||
except (OSError, ValueError, json.JSONDecodeError) as error:
|
|
||||||
return fail_usage(str(error))
|
|
||||||
code, result = verify(record, arguments.expect_commit)
|
|
||||||
print(json.dumps(result, indent=2, sort_keys=True))
|
|
||||||
return code
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
raise SystemExit(main())
|
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "@mosaicstack/mosaic",
|
"name": "@mosaicstack/mosaic",
|
||||||
"version": "0.0.49",
|
"version": "0.0.48",
|
||||||
"repository": {
|
"repository": {
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://git.mosaicstack.dev/mosaicstack/stack.git",
|
"url": "https://git.mosaicstack.dev/mosaicstack/stack.git",
|
||||||
@@ -25,7 +25,7 @@
|
|||||||
"lint": "eslint src",
|
"lint": "eslint src",
|
||||||
"typecheck": "tsc --noEmit",
|
"typecheck": "tsc --noEmit",
|
||||||
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
|
"test": "vitest run --passWithNoTests && pnpm run test:framework-shell",
|
||||||
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-ci-queue-wait-tristate.sh && bash framework/tools/git/test-ci-queue-wait-github-checks.sh && bash framework/tools/git/test-pr-merge-queue-branch.sh && bash framework/tools/git/test-pr-merge-head-pin.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/woodpecker/test-terminal-green-contract.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh"
|
"test:framework-shell": "bash framework/tools/quality/scripts/check-test-enumeration.sh && bash framework/tools/quality/scripts/test-check-test-enumeration.sh && python3 src/lease-broker/daemon_deadline_unittest.py && python3 src/lease-broker/normative_fragments_unittest.py && python3 src/lease-broker/receipt_challenge_unittest.py && python3 src/lease-broker/context_recovery_unittest.py && python3 src/lease-broker/recovery_runtime_unittest.py && python3 src/lease-broker/recovery_b1_adversarial_unittest.py && python3 src/lease-broker/framework_skill_portability_unittest.py && python3 src/mutator-gate/runtime_tools_unittest.py && python3 src/mutator-gate/runtime_launch_guard_unittest.py && python3 src/mutator-gate/version_coupling_unittest.py && python3 framework/tools/lease-broker/check-runtime-launches.py --root ../.. && bash framework/tools/codex/test-pr-diff-context.sh && bash framework/tools/qa/test-deps-preflight.sh && bash framework/tools/git/test-pr-review-gitea-comment.sh && bash framework/tools/git/test-pr-review-repo-host-override.sh && bash framework/tools/git/test-ci-queue-wait-branch-absent.sh && bash framework/tools/git/test-git-credential-mosaic.sh && bash framework/tools/git/test-gitea-token-identity.sh && bash framework/tools/_scripts/test-install-ordering-guard.sh && bash framework/tools/tmux/agent-send.test.sh && bash framework/tools/wake/test-wake-store-ack.sh && bash framework/tools/wake/test-wake-store-enqueue-race.sh && bash framework/tools/wake/test-wake-digest-hmac.sh && bash framework/tools/wake/test-wake-digest-quarantine.sh && bash framework/tools/wake/test-wake-detector.sh && bash framework/tools/wake/test-wake-fn-oracle.sh && bash framework/tools/wake/test-wake-reconcile.sh && bash framework/tools/wake/test-wake-beacon.sh && bash framework/tools/wake/test-wake-preimage.sh && bash framework/tools/wake/test-wake-install.sh"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@mosaicstack/brain": "workspace:*",
|
"@mosaicstack/brain": "workspace:*",
|
||||||
|
|||||||
@@ -14,7 +14,6 @@ import { registerTelemetryCommand } from './commands/telemetry.js';
|
|||||||
import { registerAgentCommand } from './commands/agent.js';
|
import { registerAgentCommand } from './commands/agent.js';
|
||||||
import { registerInteractionCommand } from './commands/interaction.js';
|
import { registerInteractionCommand } from './commands/interaction.js';
|
||||||
import { registerConfigCommand } from './commands/config.js';
|
import { registerConfigCommand } from './commands/config.js';
|
||||||
import { registerCredentialCommand } from './commands/cred.js';
|
|
||||||
import { registerFleetCommand } from './commands/fleet.js';
|
import { registerFleetCommand } from './commands/fleet.js';
|
||||||
import { registerMissionCommand } from './commands/mission.js';
|
import { registerMissionCommand } from './commands/mission.js';
|
||||||
import { registerUninstallCommand } from './commands/uninstall.js';
|
import { registerUninstallCommand } from './commands/uninstall.js';
|
||||||
@@ -372,10 +371,6 @@ registerInteractionCommand(program);
|
|||||||
|
|
||||||
registerFleetCommand(program);
|
registerFleetCommand(program);
|
||||||
|
|
||||||
// ─── credential governance ─────────────────────────────────────────────
|
|
||||||
|
|
||||||
registerCredentialCommand(program);
|
|
||||||
|
|
||||||
// ─── config ────────────────────────────────────────────────────────────
|
// ─── config ────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
registerConfigCommand(program);
|
registerConfigCommand(program);
|
||||||
|
|||||||
@@ -1,795 +0,0 @@
|
|||||||
import {
|
|
||||||
chmod,
|
|
||||||
mkdtemp,
|
|
||||||
mkdir,
|
|
||||||
open,
|
|
||||||
readFile,
|
|
||||||
readdir,
|
|
||||||
rename,
|
|
||||||
rm,
|
|
||||||
symlink,
|
|
||||||
unlink,
|
|
||||||
writeFile,
|
|
||||||
} from 'node:fs/promises';
|
|
||||||
import { writeSync } from 'node:fs';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
|
||||||
import {
|
|
||||||
CredentialAuditJournal,
|
|
||||||
CredentialJournalError,
|
|
||||||
listCredentialJournals,
|
|
||||||
} from '../credentials/audit-journal.js';
|
|
||||||
import { parseCredentialEstateRegistry } from '../credentials/estate-registry.js';
|
|
||||||
import { FileCredentialStore } from '../credentials/file-credential-store.js';
|
|
||||||
import { credentialLifecycleLocksDirectory } from '../credentials/lifecycle.js';
|
|
||||||
import { TeaLoginStore } from '../credentials/tea-login-store.js';
|
|
||||||
import { executeCredentialGet, executeCredentialRotate, executeCredentialWire } from './cred.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
vi.restoreAllMocks();
|
|
||||||
vi.unstubAllGlobals();
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
async function fixture(): Promise<{
|
|
||||||
readonly mosaicHome: string;
|
|
||||||
readonly registryPath: string;
|
|
||||||
readonly tokenDirectory: string;
|
|
||||||
readonly stateRoot: string;
|
|
||||||
}> {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-cred-command-'));
|
|
||||||
await chmod(cleanup, 0o700);
|
|
||||||
const mosaicHome = join(cleanup, 'mosaic');
|
|
||||||
const credentialDirectory = join(mosaicHome, 'cred');
|
|
||||||
await mkdir(credentialDirectory, { recursive: true, mode: 0o700 });
|
|
||||||
const registryPath = join(credentialDirectory, 'estates.json');
|
|
||||||
await writeFile(
|
|
||||||
registryPath,
|
|
||||||
JSON.stringify({
|
|
||||||
version: 1,
|
|
||||||
estates: [
|
|
||||||
{
|
|
||||||
name: 'homelab',
|
|
||||||
hosts: [
|
|
||||||
{
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
provider: 'gitea',
|
|
||||||
apiBaseUrl: 'https://git.example.invalid',
|
|
||||||
tokenPrefix: 'gitea-example',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
],
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
return {
|
|
||||||
mosaicHome,
|
|
||||||
registryPath,
|
|
||||||
tokenDirectory: join(mosaicHome, 'secrets', 'gitea-tokens'),
|
|
||||||
stateRoot: join(cleanup, 'state'),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
describe('credential lifecycle command controls', (): void => {
|
|
||||||
it('returns the visible open rotation journal when protected authority resolution fails', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const registry = parseCredentialEstateRegistry(await readFile(paths.registryPath, 'utf8'));
|
|
||||||
await mkdir(join(paths.mosaicHome, 'secrets'), { mode: 0o700 });
|
|
||||||
const store = new FileCredentialStore(paths.tokenDirectory, registry);
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat-name',
|
|
||||||
tokenName: 'old-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('old-token-canary'),
|
|
||||||
);
|
|
||||||
|
|
||||||
const result = await executeCredentialRotate('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: '999',
|
|
||||||
tokenName: 'new-generation',
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('error');
|
|
||||||
expect(result.mutation).toBe('none');
|
|
||||||
expect(result.audit.state).toBe('open');
|
|
||||||
expect(result.audit.journalId).not.toBeNull();
|
|
||||||
await expect(listCredentialJournals(paths.stateRoot)).resolves.toContainEqual(
|
|
||||||
expect.objectContaining({ id: result.audit.journalId, state: 'open' }),
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['partialWrite', 'shortWrite', 'recordMutation', 'seal'] as const)(
|
|
||||||
'handles %s without overstating credential disclosure',
|
|
||||||
async (method): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const registry = parseCredentialEstateRegistry(await readFile(paths.registryPath, 'utf8'));
|
|
||||||
await mkdir(join(paths.mosaicHome, 'secrets'), { mode: 0o700 });
|
|
||||||
const store = new FileCredentialStore(paths.tokenDirectory, registry);
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat-name',
|
|
||||||
tokenName: 'active-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('seat-token-canary'),
|
|
||||||
);
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
const outputPath = join(cleanup!, 'credential.out');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'seat-token-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
vi.stubGlobal(
|
|
||||||
'fetch',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
if (method === 'recordMutation') {
|
|
||||||
const original = CredentialAuditJournal.prototype.recordMutation;
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'recordMutation').mockImplementation(
|
|
||||||
async function (this: CredentialAuditJournal, decision): Promise<void> {
|
|
||||||
if (decision === 'credential-issued') {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected append failure');
|
|
||||||
}
|
|
||||||
await original.call(this, decision);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
} else if (method === 'seal') {
|
|
||||||
const original = CredentialAuditJournal.prototype.seal;
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'seal').mockImplementation(async function (
|
|
||||||
this: CredentialAuditJournal,
|
|
||||||
outcome,
|
|
||||||
reason,
|
|
||||||
): Promise<string> {
|
|
||||||
if (outcome === 'ok') {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected seal failure');
|
|
||||||
}
|
|
||||||
return original.call(this, outcome, reason);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
let writes = 0;
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
const output = await open(outputPath, 'w+', 0o600);
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialGet('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
outputFd: output.fd.toString(),
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
credentialWrite:
|
|
||||||
method === 'partialWrite'
|
|
||||||
? (fd, data): number => {
|
|
||||||
writes += 1;
|
|
||||||
if (writes === 2) throw new Error('injected partial write failure');
|
|
||||||
return writeSync(fd, data);
|
|
||||||
}
|
|
||||||
: method === 'shortWrite'
|
|
||||||
? (fd, data): number =>
|
|
||||||
writeSync(fd, data.subarray(0, Math.max(1, Math.floor(data.byteLength / 2))))
|
|
||||||
: undefined,
|
|
||||||
});
|
|
||||||
if (method === 'shortWrite') {
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'ok',
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: 'get-verified' },
|
|
||||||
});
|
|
||||||
} else {
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation: method === 'partialWrite' ? 'unknown' : 'applied',
|
|
||||||
reason: { code: 'credential-issuance-indeterminate' },
|
|
||||||
});
|
|
||||||
}
|
|
||||||
const emitted = await readFile(outputPath, 'utf8');
|
|
||||||
if (method === 'partialWrite') {
|
|
||||||
expect(emitted).toContain('username=seat-name');
|
|
||||||
expect(emitted).not.toContain('seat-token-canary');
|
|
||||||
} else {
|
|
||||||
expect(emitted).toContain('password=seat-token-canary');
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
await output.close();
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it.each(['absent', 'divergent'] as const)(
|
|
||||||
'restores an independently %s Tea pre-state after rotation journal failure',
|
|
||||||
async (teaState): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const registry = parseCredentialEstateRegistry(await readFile(paths.registryPath, 'utf8'));
|
|
||||||
await mkdir(join(paths.mosaicHome, 'secrets'), { mode: 0o700 });
|
|
||||||
const store = new FileCredentialStore(paths.tokenDirectory, registry);
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat-name',
|
|
||||||
tokenName: 'old-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('old-token'),
|
|
||||||
);
|
|
||||||
const teaConfig = join(cleanup!, 'tea', 'config.yml');
|
|
||||||
const teaStore = new TeaLoginStore(teaConfig);
|
|
||||||
if (teaState === 'divergent') {
|
|
||||||
await teaStore.put(
|
|
||||||
'seat-name',
|
|
||||||
'git.example.invalid',
|
|
||||||
new TextEncoder().encode('divergent-tea-token'),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
let replacementRevoked = false;
|
|
||||||
vi.stubGlobal('fetch', async (input: string | URL | Request, init?: RequestInit) => {
|
|
||||||
const url = new URL(typeof input === 'string' || input instanceof URL ? input : input.url);
|
|
||||||
const method = init?.method ?? 'GET';
|
|
||||||
if (url.pathname === '/api/v1/user') {
|
|
||||||
return new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (url.pathname.endsWith('/tokens') && method === 'POST') {
|
|
||||||
return new Response(
|
|
||||||
JSON.stringify({
|
|
||||||
name: 'new-generation',
|
|
||||||
sha1: 'replacement-token',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
}),
|
|
||||||
{ status: 201, headers: { 'content-type': 'application/json' } },
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (url.pathname.endsWith('/tokens') && method === 'GET') {
|
|
||||||
return new Response(
|
|
||||||
JSON.stringify(
|
|
||||||
replacementRevoked ? [] : [{ name: 'new-generation', scopes: ['write:repository'] }],
|
|
||||||
),
|
|
||||||
{ status: 200, headers: { 'content-type': 'application/json' } },
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (url.pathname.endsWith('/tokens/new-generation') && method === 'DELETE') {
|
|
||||||
replacementRevoked = true;
|
|
||||||
return new Response(null, { status: 204 });
|
|
||||||
}
|
|
||||||
throw new Error(`unexpected provider request: ${method} ${url.pathname}`);
|
|
||||||
});
|
|
||||||
let mintRecords = 0;
|
|
||||||
const recordMutation = CredentialAuditJournal.prototype.recordMutation;
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'recordMutation').mockImplementation(
|
|
||||||
async function (this: CredentialAuditJournal, decision): Promise<void> {
|
|
||||||
if (decision === 'token-mint-applied') {
|
|
||||||
mintRecords += 1;
|
|
||||||
if (mintRecords === 2) {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected rotation failure');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
await recordMutation.call(this, decision);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialRotate('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
tokenName: 'new-generation',
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
teaConfig,
|
|
||||||
});
|
|
||||||
expect(result).toMatchObject({ outcome: 'error', mutation: 'none' });
|
|
||||||
if (teaState === 'absent') {
|
|
||||||
expect(teaStore.snapshot('seat-name', 'git.example.invalid')).toBeUndefined();
|
|
||||||
} else {
|
|
||||||
expect(
|
|
||||||
teaStore.matchesSecret(
|
|
||||||
'seat-name',
|
|
||||||
'git.example.invalid',
|
|
||||||
new TextEncoder().encode('divergent-tea-token'),
|
|
||||||
),
|
|
||||||
).toBe(true);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('preserves an open nested provision journal in the rotate result', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const registry = parseCredentialEstateRegistry(await readFile(paths.registryPath, 'utf8'));
|
|
||||||
await mkdir(paths.tokenDirectory, { recursive: true, mode: 0o700 });
|
|
||||||
const store = new FileCredentialStore(paths.tokenDirectory, registry);
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat-name',
|
|
||||||
tokenName: 'old-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('old-token'),
|
|
||||||
);
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const snapshot = TeaLoginStore.prototype.snapshot;
|
|
||||||
let snapshotCalls = 0;
|
|
||||||
vi.spyOn(TeaLoginStore.prototype, 'snapshot').mockImplementation(function (
|
|
||||||
this: TeaLoginStore,
|
|
||||||
identity,
|
|
||||||
host,
|
|
||||||
) {
|
|
||||||
snapshotCalls += 1;
|
|
||||||
if (snapshotCalls === 2) throw new Error('injected nested snapshot failure');
|
|
||||||
return snapshot.call(this, identity, host);
|
|
||||||
});
|
|
||||||
const seal = CredentialAuditJournal.prototype.seal;
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'seal').mockImplementation(async function (
|
|
||||||
this: CredentialAuditJournal,
|
|
||||||
outcome,
|
|
||||||
reasonCode,
|
|
||||||
): Promise<string> {
|
|
||||||
if (reasonCode === 'credential-snapshot-unavailable') {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected nested seal failure');
|
|
||||||
}
|
|
||||||
return seal.call(this, outcome, reasonCode);
|
|
||||||
});
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialRotate('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
tokenName: 'new-generation',
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
teaConfig: join(cleanup!, 'tea', 'config.yml'),
|
|
||||||
});
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
operation: 'rotate',
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
audit: { state: 'open' },
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('preserves the journal failure diagnosis when rotate lock failure cannot be sealed', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const registry = parseCredentialEstateRegistry(await readFile(paths.registryPath, 'utf8'));
|
|
||||||
await mkdir(paths.tokenDirectory, { recursive: true, mode: 0o700 });
|
|
||||||
const store = new FileCredentialStore(paths.tokenDirectory, registry);
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat-name',
|
|
||||||
tokenName: 'old-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('old-token'),
|
|
||||||
);
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const locksDirectory = credentialLifecycleLocksDirectory();
|
|
||||||
await mkdir(locksDirectory, { recursive: true, mode: 0o700 });
|
|
||||||
const lockPath = join(locksDirectory, 'homelab--git.example.invalid--seat-name.lock');
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
await symlink('/dev/null', lockPath);
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'seal').mockRejectedValue(
|
|
||||||
new CredentialJournalError('journal-recovery-required', 'injected final seal failure'),
|
|
||||||
);
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialRotate('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
tokenName: 'new-generation',
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
teaConfig: join(cleanup!, 'tea', 'config.yml'),
|
|
||||||
});
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
operation: 'rotate',
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: 'journal-recovery-required' },
|
|
||||||
audit: { state: 'open' },
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses an unauthenticated actor before rewriting another seat environment', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'seat-name.env.generated');
|
|
||||||
const before = 'MOSAIC_AGENT_NAME=seat-name\nMOSAIC_AGENT_CLASS=coder\n';
|
|
||||||
await writeFile(seatEnvironment, before, { mode: 0o600 });
|
|
||||||
|
|
||||||
const result = await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'intruder-seat',
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.mutation).toBe('none');
|
|
||||||
await expect(readFile(seatEnvironment, 'utf8')).resolves.toBe(before);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('authenticates the exact seat and rewrites its roster-derived projection idempotently', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'seat-name.env.generated');
|
|
||||||
await writeFile(seatEnvironment, 'MOSAIC_AGENT_NAME=seat-name\nMOSAIC_AGENT_CLASS=coder\n', {
|
|
||||||
mode: 0o600,
|
|
||||||
});
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
vi.stubGlobal(
|
|
||||||
'fetch',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
|
|
||||||
const invoke = async () => {
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
return await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
const first = await invoke();
|
|
||||||
const afterFirst = await readFile(seatEnvironment, 'utf8');
|
|
||||||
const second = await invoke();
|
|
||||||
const afterSecond = await readFile(seatEnvironment, 'utf8');
|
|
||||||
|
|
||||||
expect(first.outcome).toBe('ok');
|
|
||||||
expect(second.outcome).toBe('ok');
|
|
||||||
expect(afterSecond).toBe(afterFirst);
|
|
||||||
expect(afterSecond).toContain('MOSAIC_GIT_IDENTITY=seat-name\n');
|
|
||||||
expect(afterSecond).toContain('MOSAIC_CREDENTIAL_ESTATE=homelab\n');
|
|
||||||
expect(afterSecond).toContain('GITEA_LOGIN=seat-name--git.example.invalid\n');
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['recordMutation', 'seal'] as const)(
|
|
||||||
'reports an applied wire as indeterminate when audit %s fails after rename',
|
|
||||||
async (method): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'seat-name.env.generated');
|
|
||||||
await writeFile(seatEnvironment, 'MOSAIC_AGENT_NAME=seat-name\n', { mode: 0o600 });
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
vi.stubGlobal(
|
|
||||||
'fetch',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, method).mockRejectedValueOnce(
|
|
||||||
new CredentialJournalError('journal-unavailable', 'injected audit failure'),
|
|
||||||
);
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
});
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.mutation).toBe('applied');
|
|
||||||
expect(await readFile(seatEnvironment, 'utf8')).toContain('MOSAIC_GIT_IDENTITY=seat-name');
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('refuses to overwrite a roster projection replaced after validation', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'seat-name.env.generated');
|
|
||||||
await writeFile(seatEnvironment, 'MOSAIC_AGENT_NAME=seat-name\n', { mode: 0o600 });
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
vi.stubGlobal(
|
|
||||||
'fetch',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
wireBeforeRename: async (): Promise<void> => {
|
|
||||||
const replacement = join(agents, 'replacement');
|
|
||||||
await writeFile(replacement, 'MOSAIC_AGENT_NAME=seat-name\nNEW=value\n', { mode: 0o600 });
|
|
||||||
await rename(replacement, seatEnvironment);
|
|
||||||
},
|
|
||||||
});
|
|
||||||
expect(result.outcome).toBe('error');
|
|
||||||
expect(result.mutation).toBe('none');
|
|
||||||
expect(await readFile(seatEnvironment, 'utf8')).toBe(
|
|
||||||
'MOSAIC_AGENT_NAME=seat-name\nNEW=value\n',
|
|
||||||
);
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('reports directory-sync failure after rename as applied and indeterminate', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'seat-name.env.generated');
|
|
||||||
await writeFile(seatEnvironment, 'MOSAIC_AGENT_NAME=seat-name\n', { mode: 0o600 });
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
vi.stubGlobal(
|
|
||||||
'fetch',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
wireDirectorySync: async (): Promise<void> => {
|
|
||||||
throw new Error('injected directory sync failure');
|
|
||||||
},
|
|
||||||
});
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.mutation).toBe('applied');
|
|
||||||
expect(await readFile(seatEnvironment, 'utf8')).toContain('MOSAIC_GIT_IDENTITY=seat-name');
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('removes a temporary projection when directory revalidation fails before rename', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'seat-name.env.generated');
|
|
||||||
await writeFile(seatEnvironment, 'MOSAIC_AGENT_NAME=seat-name\n', { mode: 0o600 });
|
|
||||||
const authorityPath = join(cleanup!, 'authority.json');
|
|
||||||
await writeFile(
|
|
||||||
authorityPath,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
vi.stubGlobal('fetch', async (): Promise<Response> => {
|
|
||||||
await chmod(agents, 0o777);
|
|
||||||
return new Response(JSON.stringify({ id: 7, login: 'seat-name' }), {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'application/json' },
|
|
||||||
});
|
|
||||||
});
|
|
||||||
const authority = await open(authorityPath, 'r');
|
|
||||||
try {
|
|
||||||
const result = await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: authority.fd.toString(),
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
});
|
|
||||||
expect(result.outcome).toBe('error');
|
|
||||||
expect(await readdir(agents)).toEqual(['seat-name.env.generated']);
|
|
||||||
} finally {
|
|
||||||
await authority.close();
|
|
||||||
await chmod(agents, 0o700);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a caller-selected seat filename that is not bound to the requested identity', async (): Promise<void> => {
|
|
||||||
const paths = await fixture();
|
|
||||||
const agents = join(paths.mosaicHome, 'fleet', 'agents');
|
|
||||||
await mkdir(agents, { recursive: true, mode: 0o700 });
|
|
||||||
const seatEnvironment = join(agents, 'other-seat.env.generated');
|
|
||||||
const before = 'MOSAIC_AGENT_NAME=other-seat\nMOSAIC_AGENT_CLASS=coder\n';
|
|
||||||
await writeFile(seatEnvironment, before, { mode: 0o600 });
|
|
||||||
|
|
||||||
const result = await executeCredentialWire('seat-name', {
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
actor: 'seat-name',
|
|
||||||
authorityFd: '999',
|
|
||||||
seatEnv: seatEnvironment,
|
|
||||||
mosaicHome: paths.mosaicHome,
|
|
||||||
registry: paths.registryPath,
|
|
||||||
tokenDir: paths.tokenDirectory,
|
|
||||||
stateDir: paths.stateRoot,
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('credential-binding-mismatch');
|
|
||||||
await expect(readFile(seatEnvironment, 'utf8')).resolves.toBe(before);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,67 +0,0 @@
|
|||||||
import type { FileHandle } from 'node:fs/promises';
|
|
||||||
|
|
||||||
export type CredentialJournalOperation =
|
|
||||||
| 'provision'
|
|
||||||
| 'wire'
|
|
||||||
| 'grant'
|
|
||||||
| 'get'
|
|
||||||
| 'validate'
|
|
||||||
| 'rotate'
|
|
||||||
| 'revoke'
|
|
||||||
| 'whoami'
|
|
||||||
| 'list'
|
|
||||||
| 'audit';
|
|
||||||
|
|
||||||
export interface CredentialJournalContextDto {
|
|
||||||
readonly operation: CredentialJournalOperation;
|
|
||||||
readonly actor: string;
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly repo: string | null;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialProviderJournalEvidenceDto {
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
readonly decision: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialJournalCorrectionDto {
|
|
||||||
readonly supersedesJournalId: string;
|
|
||||||
readonly correctedByJournalId: string;
|
|
||||||
readonly previousReason: string;
|
|
||||||
readonly correctedReason: string;
|
|
||||||
readonly previousOutcome?: 'ok' | 'refused' | 'error' | 'indeterminate';
|
|
||||||
readonly correctedOutcome?: 'ok' | 'refused' | 'error' | 'indeterminate';
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialPopulationCorrectionDto {
|
|
||||||
readonly entries: readonly {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly supersedesJournalIds: readonly string[];
|
|
||||||
readonly settledByJournalId: string;
|
|
||||||
readonly capability: 'confirmed';
|
|
||||||
readonly identityBinding: 'not-measured';
|
|
||||||
readonly mechanism: 'identity-scope-forbidden-in-scope-capability-confirmed';
|
|
||||||
}[];
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialJournalRuntimeOptionsDto {
|
|
||||||
readonly id?: string;
|
|
||||||
readonly now?: () => string;
|
|
||||||
readonly syncDirectory?: (path: string) => Promise<void>;
|
|
||||||
readonly rename?: (source: string, destination: string) => Promise<void>;
|
|
||||||
readonly write?: (
|
|
||||||
handle: FileHandle,
|
|
||||||
data: Uint8Array,
|
|
||||||
offset: number,
|
|
||||||
length: number,
|
|
||||||
) => Promise<number>;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialJournalSummaryDto {
|
|
||||||
readonly id: string;
|
|
||||||
readonly state: 'open' | 'sealed';
|
|
||||||
readonly path: string;
|
|
||||||
}
|
|
||||||
@@ -1,415 +0,0 @@
|
|||||||
import {
|
|
||||||
chmod,
|
|
||||||
mkdir,
|
|
||||||
mkdtemp,
|
|
||||||
open,
|
|
||||||
readFile,
|
|
||||||
rename,
|
|
||||||
rm,
|
|
||||||
symlink,
|
|
||||||
truncate,
|
|
||||||
writeFile,
|
|
||||||
} from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it } from 'vitest';
|
|
||||||
import { CredentialAuditJournal, listCredentialJournals } from './audit-journal.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
|
|
||||||
async function stateRoot(): Promise<string> {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-cred-journal-'));
|
|
||||||
return join(cleanup, 'state');
|
|
||||||
}
|
|
||||||
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('credential durable audit journal', (): void => {
|
|
||||||
it('opens before mutation, appends provider evidence, and seals durably', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const journal = await CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'grant',
|
|
||||||
actor: 'provisioner',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
},
|
|
||||||
{ id: 'journal-id', now: (): string => '2026-08-05T00:00:00.000Z' },
|
|
||||||
);
|
|
||||||
|
|
||||||
await journal.recordIntent('provider-grant');
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: 'GET /api/v1/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
decision: 'permission-write',
|
|
||||||
});
|
|
||||||
const sealedPath = await journal.seal('ok', 'grant-verified');
|
|
||||||
|
|
||||||
expect(sealedPath).toMatch(/journal-id\.sealed\.jsonl$/);
|
|
||||||
const records = (await readFile(sealedPath, 'utf8')).trim().split('\n');
|
|
||||||
expect(records).toHaveLength(4);
|
|
||||||
expect(records[0]).toContain('"phase":"opened"');
|
|
||||||
expect(records[1]).toContain('"phase":"intent"');
|
|
||||||
expect(records[2]).toContain('"phase":"provider-evidence"');
|
|
||||||
expect(records[3]).toContain('"phase":"sealed"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('writes every journal record completely when each write makes one-byte progress', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
let writeCalls = 0;
|
|
||||||
const journal = await CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'grant',
|
|
||||||
actor: 'provisioner',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
},
|
|
||||||
{
|
|
||||||
id: 'short-write',
|
|
||||||
now: (): string => '2026-08-05T00:00:00.000Z',
|
|
||||||
write: async (handle, data, offset, length): Promise<number> => {
|
|
||||||
writeCalls += 1;
|
|
||||||
const result = await handle.write(data, offset, Math.min(1, length), null);
|
|
||||||
return result.bytesWritten;
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
await journal.recordIntent('provider-grant');
|
|
||||||
const sealedPath = await journal.seal('ok', 'grant-verified');
|
|
||||||
const records = (await readFile(sealedPath, 'utf8')).trim().split('\n');
|
|
||||||
|
|
||||||
expect(writeCalls).toBeGreaterThan(3);
|
|
||||||
expect(records).toHaveLength(3);
|
|
||||||
expect(records[0]).toContain('"phase":"opened"');
|
|
||||||
expect(records[1]).toContain('"phase":"intent"');
|
|
||||||
expect(records[2]).toContain('"phase":"sealed"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each([
|
|
||||||
['zero', (_remaining: number): number => 0],
|
|
||||||
['oversized', (remaining: number): number => remaining + 1],
|
|
||||||
] as const)(
|
|
||||||
'rejects %s journal write progress before reporting an opened journal',
|
|
||||||
async (_label, progress): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
await expect(
|
|
||||||
CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'grant',
|
|
||||||
actor: 'provisioner',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
},
|
|
||||||
{
|
|
||||||
id: `invalid-progress-${_label}`,
|
|
||||||
write: async (_handle, _data, _offset, length): Promise<number> => progress(length),
|
|
||||||
},
|
|
||||||
),
|
|
||||||
).rejects.toThrow(/journal-unavailable/);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('keeps a final seal non-accepting while directory durability is pending', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
let directorySyncs = 0;
|
|
||||||
let signalFinalSync: (() => void) | undefined;
|
|
||||||
let releaseFinalSync: (() => void) | undefined;
|
|
||||||
const finalSyncEntered = new Promise<void>((resolve): void => {
|
|
||||||
signalFinalSync = resolve;
|
|
||||||
});
|
|
||||||
const finalSyncRelease = new Promise<void>((resolve): void => {
|
|
||||||
releaseFinalSync = resolve;
|
|
||||||
});
|
|
||||||
const journal = await CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'get',
|
|
||||||
actor: 'seat-name',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
id: 'seal-pending',
|
|
||||||
syncDirectory: async (path): Promise<void> => {
|
|
||||||
directorySyncs += 1;
|
|
||||||
if (directorySyncs === 3) {
|
|
||||||
signalFinalSync?.();
|
|
||||||
await finalSyncRelease;
|
|
||||||
}
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
const sealing = journal.seal('ok', 'get-verified');
|
|
||||||
await finalSyncEntered;
|
|
||||||
await expect(listCredentialJournals(root)).resolves.toContainEqual(
|
|
||||||
expect.objectContaining({ id: 'seal-pending', state: 'open' }),
|
|
||||||
);
|
|
||||||
releaseFinalSync?.();
|
|
||||||
await sealing;
|
|
||||||
await expect(listCredentialJournals(root)).resolves.toContainEqual(
|
|
||||||
expect.objectContaining({ id: 'seal-pending', state: 'sealed' }),
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('reverts a failed final seal commit to visible open state', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
let directorySyncs = 0;
|
|
||||||
const journal = await CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'get',
|
|
||||||
actor: 'seat-name',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
id: 'seal-fault',
|
|
||||||
syncDirectory: async (path): Promise<void> => {
|
|
||||||
directorySyncs += 1;
|
|
||||||
if (directorySyncs === 3) throw new Error('injected final directory sync failure');
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(journal.seal('ok', 'get-verified')).rejects.toThrow(/journal-unavailable/);
|
|
||||||
const [entry] = await listCredentialJournals(root);
|
|
||||||
expect(entry).toMatchObject({ id: 'seal-fault', state: 'open' });
|
|
||||||
expect(await readFile(entry?.path ?? '', 'utf8')).not.toContain('"phase":"sealed"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('uses a non-accepting recovery path when the compensating rename fails', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
let directorySyncs = 0;
|
|
||||||
let renames = 0;
|
|
||||||
const journal = await CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'get',
|
|
||||||
actor: 'seat-name',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
id: 'seal-recovery-fault',
|
|
||||||
syncDirectory: async (path): Promise<void> => {
|
|
||||||
directorySyncs += 1;
|
|
||||||
if (directorySyncs === 3) throw new Error('injected final directory sync failure');
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
},
|
|
||||||
rename: async (source, destination): Promise<void> => {
|
|
||||||
renames += 1;
|
|
||||||
if (renames === 3) throw new Error('injected compensating rename failure');
|
|
||||||
await rename(source, destination);
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(journal.seal('ok', 'get-verified')).rejects.toThrow(/journal-recovery-required/);
|
|
||||||
const [entry] = await listCredentialJournals(root);
|
|
||||||
expect(entry).toMatchObject({ id: 'seal-recovery-fault', state: 'open' });
|
|
||||||
expect(entry?.path).toMatch(/\.recovery\.jsonl$/);
|
|
||||||
expect(await readFile(entry?.path ?? '', 'utf8')).not.toContain('"phase":"sealed"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['symlink', 'oversized'] as const)(
|
|
||||||
'classifies an unsafe %s sealed-looking journal as open without consuming it',
|
|
||||||
async (kind): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const journal = await CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'audit',
|
|
||||||
actor: 'seat-name',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
});
|
|
||||||
await journal.closeIncomplete();
|
|
||||||
const journalsDirectory = join(root, 'journals');
|
|
||||||
const candidate = join(journalsDirectory, `unsafe-${kind}.sealed.jsonl`);
|
|
||||||
if (kind === 'symlink') {
|
|
||||||
if (cleanup === undefined) throw new Error('test fixture root is unavailable');
|
|
||||||
const outside = join(cleanup, 'outside-journal');
|
|
||||||
await writeFile(outside, '{"phase":"sealed","outcome":"ok"}\n', { mode: 0o600 });
|
|
||||||
await symlink(outside, candidate);
|
|
||||||
} else {
|
|
||||||
await writeFile(candidate, '', { mode: 0o600 });
|
|
||||||
await truncate(candidate, 4 * 1024 * 1024 + 1);
|
|
||||||
}
|
|
||||||
|
|
||||||
const entry = (await listCredentialJournals(root)).find(
|
|
||||||
(value): boolean => value.id === `unsafe-${kind}`,
|
|
||||||
);
|
|
||||||
expect(entry).toMatchObject({ state: 'open' });
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('leaves an unsealed journal visible for recovery', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const journal = await CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'rotate',
|
|
||||||
actor: 'provisioner',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
});
|
|
||||||
|
|
||||||
const journals = await listCredentialJournals(root);
|
|
||||||
|
|
||||||
expect(journals).toHaveLength(1);
|
|
||||||
expect(journals[0]?.state).toBe('open');
|
|
||||||
await journal.closeIncomplete();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('fails fatally when the durable journal root cannot be created', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
await writeFile(root, 'not-a-directory', { mode: 0o600 });
|
|
||||||
|
|
||||||
await expect(
|
|
||||||
CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'grant',
|
|
||||||
actor: 'provisioner',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
}),
|
|
||||||
).rejects.toThrow(/journal-unavailable/);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects secret-shaped evidence instead of writing it', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const journal = await CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'validate',
|
|
||||||
actor: 'seat-name',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
});
|
|
||||||
|
|
||||||
await expect(
|
|
||||||
journal.recordProviderEvidence({
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
decision: 'seeded-secret-canary',
|
|
||||||
}),
|
|
||||||
).rejects.toThrow(/unsafe-audit-value/);
|
|
||||||
const journals = await listCredentialJournals(root);
|
|
||||||
const source = await readFile(journals[0]?.path ?? '', 'utf8');
|
|
||||||
expect(source).not.toContain('seeded-secret-canary');
|
|
||||||
await journal.closeIncomplete();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a group-writable journal root before opening evidence', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
await mkdir(root, { mode: 0o700 });
|
|
||||||
await chmod(root, 0o770);
|
|
||||||
await expect(
|
|
||||||
CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'grant',
|
|
||||||
actor: 'provisioner',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
}),
|
|
||||||
).rejects.toThrow(/journal-unavailable/);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('supersedes a false sealed classification without editing the original journal', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const journal = await CredentialAuditJournal.open(
|
|
||||||
root,
|
|
||||||
{
|
|
||||||
operation: 'validate',
|
|
||||||
actor: 'be-coder-06',
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
},
|
|
||||||
{ id: 'correction-1' },
|
|
||||||
);
|
|
||||||
await journal.recordIntent('classification-correction');
|
|
||||||
await journal.recordCorrection({
|
|
||||||
supersedesJournalId: 'old-sealed-id',
|
|
||||||
correctedByJournalId: 'new-validation-id',
|
|
||||||
previousReason: 'identity-not-found',
|
|
||||||
correctedReason: 'credential-rejected',
|
|
||||||
previousOutcome: 'indeterminate',
|
|
||||||
correctedOutcome: 'refused',
|
|
||||||
});
|
|
||||||
const path = await journal.seal('indeterminate', 'credential-rejected');
|
|
||||||
const source = await readFile(path, 'utf8');
|
|
||||||
expect(source).toContain('"phase":"classification-correction"');
|
|
||||||
expect(source).toContain('"supersedesJournalId":"old-sealed-id"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('records one settled population correction across a classification chain', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const journal = await CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'validate',
|
|
||||||
actor: 'be-coder-06',
|
|
||||||
identity: 'fleet-reconciliation',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
});
|
|
||||||
await journal.recordIntent('classification-correction');
|
|
||||||
await journal.recordPopulationCorrection({
|
|
||||||
entries: [
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
supersedesJournalIds: ['v1-2-id', 'v1-4-id', 'v1-4-1-id'],
|
|
||||||
settledByJournalId: 'v1-5-id',
|
|
||||||
capability: 'confirmed',
|
|
||||||
identityBinding: 'not-measured',
|
|
||||||
mechanism: 'identity-scope-forbidden-in-scope-capability-confirmed',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
});
|
|
||||||
const path = await journal.seal('ok', 'classification-corrected');
|
|
||||||
const source = await readFile(path, 'utf8');
|
|
||||||
expect(source).toContain('"phase":"population-classification-correction"');
|
|
||||||
expect(source).toContain('"capability":"confirmed"');
|
|
||||||
expect(source).toContain('"identityBinding":"not-measured"');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,467 +0,0 @@
|
|||||||
import { spawnSync } from 'node:child_process';
|
|
||||||
import { randomUUID } from 'node:crypto';
|
|
||||||
import { constants, lstatSync } from 'node:fs';
|
|
||||||
import { open, readdir, rename } from 'node:fs/promises';
|
|
||||||
import type { FileHandle } from 'node:fs/promises';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { ensureManagedDirectory, readRegularFileSecure } from '../fleet/secure-file.js';
|
|
||||||
import type {
|
|
||||||
CredentialJournalContextDto,
|
|
||||||
CredentialJournalCorrectionDto,
|
|
||||||
CredentialJournalRuntimeOptionsDto,
|
|
||||||
CredentialPopulationCorrectionDto,
|
|
||||||
CredentialJournalSummaryDto,
|
|
||||||
CredentialProviderJournalEvidenceDto,
|
|
||||||
} from './audit-journal.dto.js';
|
|
||||||
|
|
||||||
const SAFE_NAME = /^[A-Za-z0-9][A-Za-z0-9_.-]*$/;
|
|
||||||
const SAFE_ESTATE = /^[a-z0-9][a-z0-9-]*$/;
|
|
||||||
const SAFE_HOST = /^[a-z0-9][a-z0-9.-]*$/;
|
|
||||||
const SAFE_REPO = /^[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+$/;
|
|
||||||
const SAFE_ENDPOINT = /^(?:GET|PUT|POST|DELETE) \/[A-Za-z0-9_./{}:-]+$/;
|
|
||||||
const SAFE_CONTENT_TYPE = /^[A-Za-z0-9!#$&^_.+/-]+(?:;[A-Za-z0-9=._+-]+)*$/;
|
|
||||||
const MAX_JOURNAL_BYTES = 4 * 1024 * 1024;
|
|
||||||
const SAFE_DECISIONS = new Set<string>([
|
|
||||||
'provider-grant',
|
|
||||||
'permission-none',
|
|
||||||
'permission-read',
|
|
||||||
'permission-write',
|
|
||||||
'permission-admin',
|
|
||||||
'identity-verified',
|
|
||||||
'inventory-authority-verified',
|
|
||||||
'scope-verified',
|
|
||||||
'grant-verified',
|
|
||||||
'revoke-verified',
|
|
||||||
'rotate-verified',
|
|
||||||
'validation-requested',
|
|
||||||
'whoami-requested',
|
|
||||||
'provision-requested',
|
|
||||||
'rotate-requested',
|
|
||||||
'revoke-requested',
|
|
||||||
'wire-requested',
|
|
||||||
'get-requested',
|
|
||||||
'validation-verified',
|
|
||||||
'team-member-present',
|
|
||||||
'team-member-absent',
|
|
||||||
'team-repository-present',
|
|
||||||
'team-repository-absent',
|
|
||||||
'team-repository-set-verified',
|
|
||||||
'organization-member-present',
|
|
||||||
'organization-member-absent',
|
|
||||||
'collaborator-grant-applied',
|
|
||||||
'team-member-applied',
|
|
||||||
'team-member-rollback-applied',
|
|
||||||
'team-repository-applied',
|
|
||||||
'team-repository-rollback-applied',
|
|
||||||
'transport-write-verified',
|
|
||||||
'token-mint-applied',
|
|
||||||
'token-binding-stored',
|
|
||||||
'tea-login-stored',
|
|
||||||
'tea-login-removed',
|
|
||||||
'provision-rollback-verified',
|
|
||||||
'rotate-rollback-verified',
|
|
||||||
'token-revoke-applied',
|
|
||||||
'wire-applied',
|
|
||||||
'credential-issuance-authorized',
|
|
||||||
'credential-issuance-started',
|
|
||||||
'credential-issuance-possibly-issued',
|
|
||||||
'credential-issued',
|
|
||||||
'classification-correction',
|
|
||||||
]);
|
|
||||||
|
|
||||||
export class CredentialJournalError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
message: string,
|
|
||||||
) {
|
|
||||||
super(`Credential audit journal failed: code=${code} ${message}`);
|
|
||||||
this.name = 'CredentialJournalError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertPrivateDirectory(path: string): void {
|
|
||||||
const stat = lstatSync(path);
|
|
||||||
if (
|
|
||||||
!stat.isDirectory() ||
|
|
||||||
stat.isSymbolicLink() ||
|
|
||||||
stat.uid !== process.getuid?.() ||
|
|
||||||
(stat.mode & 0o022) !== 0
|
|
||||||
) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'journal-unavailable',
|
|
||||||
'journal directory owner or write permissions are unsafe',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertContext(context: CredentialJournalContextDto): void {
|
|
||||||
if (
|
|
||||||
!SAFE_NAME.test(context.actor) ||
|
|
||||||
!SAFE_NAME.test(context.identity) ||
|
|
||||||
!SAFE_ESTATE.test(context.estate) ||
|
|
||||||
!SAFE_HOST.test(context.host) ||
|
|
||||||
(context.repo !== null && !SAFE_REPO.test(context.repo))
|
|
||||||
) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'journal context is outside the non-secret allowlist grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertEvidence(evidence: CredentialProviderJournalEvidenceDto): void {
|
|
||||||
if (
|
|
||||||
!SAFE_ENDPOINT.test(evidence.endpoint) ||
|
|
||||||
!SAFE_CONTENT_TYPE.test(evidence.contentType) ||
|
|
||||||
!SAFE_DECISIONS.has(evidence.decision)
|
|
||||||
) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'provider evidence is outside the non-secret allowlist',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function writeJournalBytes(
|
|
||||||
handle: FileHandle,
|
|
||||||
data: Uint8Array,
|
|
||||||
offset: number,
|
|
||||||
length: number,
|
|
||||||
): Promise<number> {
|
|
||||||
const result = await handle.write(data, offset, length, null);
|
|
||||||
return result.bytesWritten;
|
|
||||||
}
|
|
||||||
|
|
||||||
async function syncDirectory(path: string): Promise<void> {
|
|
||||||
const directory = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await directory.sync();
|
|
||||||
} finally {
|
|
||||||
await directory.close();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function acquireJournalLock(
|
|
||||||
path: string,
|
|
||||||
mode: 'exclusive' | 'shared',
|
|
||||||
): Promise<FileHandle | undefined> {
|
|
||||||
let handle: FileHandle | undefined;
|
|
||||||
try {
|
|
||||||
handle = await open(path, constants.O_CREAT | constants.O_RDWR | constants.O_NOFOLLOW, 0o600);
|
|
||||||
const stat = await handle.stat();
|
|
||||||
if (!stat.isFile() || stat.uid !== process.getuid?.() || (stat.mode & 0o077) !== 0) {
|
|
||||||
throw new Error('journal lock file is unsafe');
|
|
||||||
}
|
|
||||||
const acquired = spawnSync('/usr/bin/flock', ['-n', mode === 'exclusive' ? '-x' : '-s', '3'], {
|
|
||||||
stdio: ['ignore', 'ignore', 'ignore', handle.fd],
|
|
||||||
});
|
|
||||||
if (acquired.error !== undefined || acquired.status !== 0) {
|
|
||||||
await handle.close();
|
|
||||||
return undefined;
|
|
||||||
}
|
|
||||||
return handle;
|
|
||||||
} catch {
|
|
||||||
await handle?.close().catch((): void => undefined);
|
|
||||||
return undefined;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export class CredentialAuditJournal {
|
|
||||||
private closed = false;
|
|
||||||
|
|
||||||
private constructor(
|
|
||||||
private readonly handle: FileHandle,
|
|
||||||
private readonly lockHandle: FileHandle,
|
|
||||||
private readonly openPath: string,
|
|
||||||
private readonly journalsDirectory: string,
|
|
||||||
private readonly id: string,
|
|
||||||
private readonly now: () => string,
|
|
||||||
private readonly syncJournalDirectory: (path: string) => Promise<void>,
|
|
||||||
private readonly renameJournal: (source: string, destination: string) => Promise<void>,
|
|
||||||
private readonly writeJournal: (
|
|
||||||
handle: FileHandle,
|
|
||||||
data: Uint8Array,
|
|
||||||
offset: number,
|
|
||||||
length: number,
|
|
||||||
) => Promise<number>,
|
|
||||||
) {}
|
|
||||||
|
|
||||||
static async open(
|
|
||||||
stateRoot: string,
|
|
||||||
context: CredentialJournalContextDto,
|
|
||||||
runtime: CredentialJournalRuntimeOptionsDto = {},
|
|
||||||
): Promise<CredentialAuditJournal> {
|
|
||||||
assertContext(context);
|
|
||||||
const id = runtime.id ?? randomUUID();
|
|
||||||
if (!SAFE_NAME.test(id)) {
|
|
||||||
throw new CredentialJournalError('unsafe-audit-value', 'journal id is outside the grammar');
|
|
||||||
}
|
|
||||||
const now = runtime.now ?? ((): string => new Date().toISOString());
|
|
||||||
const journalsDirectory = join(stateRoot, 'journals');
|
|
||||||
const locksDirectory = join(stateRoot, 'journal-locks');
|
|
||||||
let handle: FileHandle | undefined;
|
|
||||||
let lockHandle: FileHandle | undefined;
|
|
||||||
try {
|
|
||||||
ensureManagedDirectory(stateRoot, journalsDirectory);
|
|
||||||
ensureManagedDirectory(stateRoot, locksDirectory);
|
|
||||||
assertPrivateDirectory(stateRoot);
|
|
||||||
assertPrivateDirectory(journalsDirectory);
|
|
||||||
assertPrivateDirectory(locksDirectory);
|
|
||||||
const openPath = join(journalsDirectory, `${id}.open.jsonl`);
|
|
||||||
const lockPath = join(locksDirectory, `${id}.lock`);
|
|
||||||
handle = await open(openPath, 'wx', 0o600);
|
|
||||||
lockHandle = await acquireJournalLock(lockPath, 'exclusive');
|
|
||||||
if (lockHandle === undefined) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'journal-unavailable',
|
|
||||||
'journal lock could not be acquired',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const syncJournalDirectory = runtime.syncDirectory ?? syncDirectory;
|
|
||||||
const renameJournal = runtime.rename ?? rename;
|
|
||||||
const journal = new CredentialAuditJournal(
|
|
||||||
handle,
|
|
||||||
lockHandle,
|
|
||||||
openPath,
|
|
||||||
journalsDirectory,
|
|
||||||
id,
|
|
||||||
now,
|
|
||||||
syncJournalDirectory,
|
|
||||||
renameJournal,
|
|
||||||
runtime.write ?? writeJournalBytes,
|
|
||||||
);
|
|
||||||
await journal.append({ phase: 'opened', at: now(), context });
|
|
||||||
await syncJournalDirectory(journalsDirectory);
|
|
||||||
return journal;
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (handle !== undefined) await handle.close().catch((): void => undefined);
|
|
||||||
if (lockHandle !== undefined) await lockHandle.close().catch((): void => undefined);
|
|
||||||
if (error instanceof CredentialJournalError) throw error;
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'journal-unavailable',
|
|
||||||
'durable journal could not be opened and fsynced',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
private async append(record: object): Promise<void> {
|
|
||||||
if (this.closed) {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'journal is already closed');
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
const data = Buffer.from(`${JSON.stringify(record)}\n`, 'utf8');
|
|
||||||
let offset = 0;
|
|
||||||
while (offset < data.byteLength) {
|
|
||||||
const remaining = data.byteLength - offset;
|
|
||||||
const written = await this.writeJournal(this.handle, data, offset, remaining);
|
|
||||||
if (!Number.isSafeInteger(written) || written <= 0 || written > remaining) {
|
|
||||||
throw new Error('journal write made invalid progress');
|
|
||||||
}
|
|
||||||
offset += written;
|
|
||||||
}
|
|
||||||
await this.handle.sync();
|
|
||||||
} catch {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'journal-unavailable',
|
|
||||||
'durable journal append or fsync failed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
journalId(): string {
|
|
||||||
return this.id;
|
|
||||||
}
|
|
||||||
|
|
||||||
async recordIntent(decision: string): Promise<void> {
|
|
||||||
if (!SAFE_DECISIONS.has(decision)) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'intent decision is outside the non-secret allowlist',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await this.append({ phase: 'intent', at: this.now(), decision });
|
|
||||||
}
|
|
||||||
|
|
||||||
async recordProviderEvidence(evidence: CredentialProviderJournalEvidenceDto): Promise<void> {
|
|
||||||
assertEvidence(evidence);
|
|
||||||
await this.append({ phase: 'provider-evidence', at: this.now(), evidence });
|
|
||||||
}
|
|
||||||
|
|
||||||
async recordMutation(decision: string): Promise<void> {
|
|
||||||
if (!SAFE_DECISIONS.has(decision)) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'mutation decision is outside the non-secret allowlist',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await this.append({ phase: 'mutation', at: this.now(), decision });
|
|
||||||
}
|
|
||||||
|
|
||||||
async recordCorrection(correction: CredentialJournalCorrectionDto): Promise<void> {
|
|
||||||
if (
|
|
||||||
!SAFE_NAME.test(correction.supersedesJournalId) ||
|
|
||||||
!SAFE_NAME.test(correction.correctedByJournalId) ||
|
|
||||||
!SAFE_NAME.test(correction.previousReason) ||
|
|
||||||
!SAFE_NAME.test(correction.correctedReason) ||
|
|
||||||
(correction.previousOutcome === undefined) !== (correction.correctedOutcome === undefined)
|
|
||||||
) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'classification correction is outside the non-secret grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await this.append({ phase: 'classification-correction', at: this.now(), correction });
|
|
||||||
}
|
|
||||||
|
|
||||||
async recordPopulationCorrection(correction: CredentialPopulationCorrectionDto): Promise<void> {
|
|
||||||
if (
|
|
||||||
correction.entries.length === 0 ||
|
|
||||||
correction.entries.some(
|
|
||||||
(entry): boolean =>
|
|
||||||
!SAFE_NAME.test(entry.identity) ||
|
|
||||||
!SAFE_NAME.test(entry.settledByJournalId) ||
|
|
||||||
entry.supersedesJournalIds.length === 0 ||
|
|
||||||
entry.supersedesJournalIds.some((id): boolean => !SAFE_NAME.test(id)),
|
|
||||||
)
|
|
||||||
) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'population correction is outside the non-secret grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await this.append({
|
|
||||||
phase: 'population-classification-correction',
|
|
||||||
at: this.now(),
|
|
||||||
correction,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
async seal(
|
|
||||||
outcome: 'ok' | 'refused' | 'error' | 'indeterminate',
|
|
||||||
reasonCode: string,
|
|
||||||
): Promise<string> {
|
|
||||||
if (!SAFE_NAME.test(reasonCode)) {
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
'unsafe-audit-value',
|
|
||||||
'reason code is outside the non-secret grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const preSealSize = (await this.handle.stat()).size;
|
|
||||||
const sealingPath = join(this.journalsDirectory, `${this.id}.sealing.jsonl`);
|
|
||||||
const sealedPath = join(this.journalsDirectory, `${this.id}.sealed.jsonl`);
|
|
||||||
const recoveryPath = join(this.journalsDirectory, `${this.id}.recovery.jsonl`);
|
|
||||||
let currentPath = this.openPath;
|
|
||||||
try {
|
|
||||||
await this.renameJournal(currentPath, sealingPath);
|
|
||||||
currentPath = sealingPath;
|
|
||||||
await this.syncJournalDirectory(this.journalsDirectory);
|
|
||||||
await this.append({ phase: 'sealed', at: this.now(), outcome, reasonCode });
|
|
||||||
await this.renameJournal(currentPath, sealedPath);
|
|
||||||
currentPath = sealedPath;
|
|
||||||
await this.syncJournalDirectory(this.journalsDirectory);
|
|
||||||
await this.handle.close();
|
|
||||||
await this.lockHandle.close();
|
|
||||||
this.closed = true;
|
|
||||||
return sealedPath;
|
|
||||||
} catch {
|
|
||||||
let recovered = true;
|
|
||||||
try {
|
|
||||||
await this.handle.truncate(preSealSize);
|
|
||||||
await this.handle.sync();
|
|
||||||
} catch {
|
|
||||||
recovered = false;
|
|
||||||
}
|
|
||||||
if (currentPath !== this.openPath) {
|
|
||||||
try {
|
|
||||||
await this.renameJournal(currentPath, this.openPath);
|
|
||||||
currentPath = this.openPath;
|
|
||||||
} catch {
|
|
||||||
recovered = false;
|
|
||||||
try {
|
|
||||||
await this.renameJournal(currentPath, recoveryPath);
|
|
||||||
currentPath = recoveryPath;
|
|
||||||
} catch {
|
|
||||||
// The non-success return below remains authoritative; the path is reported by audit scan.
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
await this.syncJournalDirectory(this.journalsDirectory);
|
|
||||||
} catch {
|
|
||||||
recovered = false;
|
|
||||||
}
|
|
||||||
await this.handle.close().catch((): void => undefined);
|
|
||||||
await this.lockHandle.close().catch((): void => undefined);
|
|
||||||
this.closed = true;
|
|
||||||
throw new CredentialJournalError(
|
|
||||||
recovered ? 'journal-unavailable' : 'journal-recovery-required',
|
|
||||||
'sealed journal could not be committed durably',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async closeIncomplete(): Promise<void> {
|
|
||||||
if (this.closed) return;
|
|
||||||
await this.handle.close();
|
|
||||||
await this.lockHandle.close();
|
|
||||||
this.closed = true;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function listCredentialJournals(
|
|
||||||
stateRoot: string,
|
|
||||||
): Promise<readonly CredentialJournalSummaryDto[]> {
|
|
||||||
const journalsDirectory = join(stateRoot, 'journals');
|
|
||||||
const locksDirectory = join(stateRoot, 'journal-locks');
|
|
||||||
let names: string[];
|
|
||||||
try {
|
|
||||||
assertPrivateDirectory(stateRoot);
|
|
||||||
assertPrivateDirectory(journalsDirectory);
|
|
||||||
ensureManagedDirectory(stateRoot, locksDirectory);
|
|
||||||
assertPrivateDirectory(locksDirectory);
|
|
||||||
names = await readdir(journalsDirectory);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof Error && 'code' in error && error.code === 'ENOENT') return [];
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'journal directory could not be read');
|
|
||||||
}
|
|
||||||
return Promise.all(
|
|
||||||
names
|
|
||||||
.filter((name: string): boolean => /\.(?:open|sealing|recovery|sealed)\.jsonl$/.test(name))
|
|
||||||
.sort()
|
|
||||||
.map(async (name: string): Promise<CredentialJournalSummaryDto> => {
|
|
||||||
const path = join(journalsDirectory, name);
|
|
||||||
const id = name.replace(/\.(?:open|sealing|recovery|sealed)\.jsonl$/, '');
|
|
||||||
let committedSeal = false;
|
|
||||||
let scanLock: FileHandle | undefined;
|
|
||||||
if (name.endsWith('.sealed.jsonl') && SAFE_NAME.test(id)) {
|
|
||||||
try {
|
|
||||||
scanLock = await acquireJournalLock(join(locksDirectory, `${id}.lock`), 'shared');
|
|
||||||
if (scanLock === undefined) throw new Error('journal seal is still in progress');
|
|
||||||
const snapshot = readRegularFileSecure(path, {
|
|
||||||
root: journalsDirectory,
|
|
||||||
maxBytes: MAX_JOURNAL_BYTES,
|
|
||||||
});
|
|
||||||
if (snapshot.uid !== process.getuid?.() || (snapshot.mode & 0o077) !== 0) {
|
|
||||||
throw new Error('journal owner or mode is unsafe');
|
|
||||||
}
|
|
||||||
const records = snapshot.content.toString('utf8').trim().split('\n');
|
|
||||||
const finalRecord: unknown = JSON.parse(records.at(-1) ?? 'null');
|
|
||||||
committedSeal =
|
|
||||||
typeof finalRecord === 'object' &&
|
|
||||||
finalRecord !== null &&
|
|
||||||
'phase' in finalRecord &&
|
|
||||||
finalRecord.phase === 'sealed';
|
|
||||||
} catch {
|
|
||||||
committedSeal = false;
|
|
||||||
} finally {
|
|
||||||
await scanLock?.close().catch((): void => undefined);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
id,
|
|
||||||
state: committedSeal ? 'sealed' : 'open',
|
|
||||||
path,
|
|
||||||
};
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
export interface CredentialBindingMetadataDto {
|
|
||||||
readonly schemaVersion?: 1;
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly providerLogin: string;
|
|
||||||
readonly tokenName: string;
|
|
||||||
readonly scopes: readonly string[];
|
|
||||||
readonly createdAt: string;
|
|
||||||
readonly tokenDigest?: string;
|
|
||||||
}
|
|
||||||
@@ -1,52 +0,0 @@
|
|||||||
import type {
|
|
||||||
ProviderIdentityEvidenceDto,
|
|
||||||
ReceivePackEvidenceDto,
|
|
||||||
RepositoryPermission,
|
|
||||||
RepositoryPermissionEvidenceDto,
|
|
||||||
} from './credential-result.dto.js';
|
|
||||||
|
|
||||||
export interface ResolvedCredential {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly resolutionId: string;
|
|
||||||
readonly secret: Uint8Array;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialResolver {
|
|
||||||
resolve(identity: string, estate: string, host: string): Promise<ResolvedCredential | undefined>;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface GiteaCredentialProvider {
|
|
||||||
readIdentity(resolved: ResolvedCredential): Promise<ProviderIdentityEvidenceDto>;
|
|
||||||
readRepositoryPermission(
|
|
||||||
resolved: ResolvedCredential,
|
|
||||||
repo: string,
|
|
||||||
): Promise<RepositoryPermissionEvidenceDto>;
|
|
||||||
probeReceivePack(
|
|
||||||
resolved: ResolvedCredential | undefined,
|
|
||||||
repo: string,
|
|
||||||
): Promise<ReceivePackEvidenceDto>;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialEstateRegistry {
|
|
||||||
matches(estate: string, host: string): boolean;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialValidationDependencies {
|
|
||||||
readonly resolver: CredentialResolver;
|
|
||||||
readonly provider: GiteaCredentialProvider;
|
|
||||||
readonly estateRegistry: CredentialEstateRegistry;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface GiteaReadValidationRequestDto {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly repo: string;
|
|
||||||
readonly requiredPermission?: RepositoryPermission;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface GiteaWriteValidationRequestDto extends GiteaReadValidationRequestDto {
|
|
||||||
readonly readOnlyControlIdentity: string;
|
|
||||||
}
|
|
||||||
@@ -1,84 +0,0 @@
|
|||||||
export type CredentialOutcome = 'ok' | 'refused' | 'error' | 'indeterminate';
|
|
||||||
export type CredentialMutationState = 'none' | 'not-started' | 'applied' | 'unknown';
|
|
||||||
export type RepositoryPermission = 'none' | 'read' | 'write' | 'admin';
|
|
||||||
export type ReceivePackState = 'advertised' | 'refused';
|
|
||||||
|
|
||||||
export interface CredentialReasonDto {
|
|
||||||
readonly code: string;
|
|
||||||
readonly message: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialSubjectDto {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly repo: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface ProviderIdentityEvidenceDto {
|
|
||||||
readonly login: string;
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface RepositoryPermissionEvidenceDto {
|
|
||||||
readonly effective: RepositoryPermission;
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface ReceivePackEvidenceDto {
|
|
||||||
readonly state: ReceivePackState;
|
|
||||||
readonly principal: string | null;
|
|
||||||
readonly resolutionId: string | null;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface ReadOnlyControlEvidenceDto {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly providerPermission: RepositoryPermission;
|
|
||||||
readonly receivePack: ReceivePackState;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface WriteDifferentialEvidenceDto {
|
|
||||||
readonly state: 'can-write';
|
|
||||||
readonly credentialBinding: 'same-resolution';
|
|
||||||
readonly transportPrincipal: string;
|
|
||||||
readonly authenticatedReceivePack: 'advertised';
|
|
||||||
readonly readOnlyControl: ReadOnlyControlEvidenceDto;
|
|
||||||
readonly unauthenticatedReceivePack: 'refused';
|
|
||||||
readonly artifactCreated: false;
|
|
||||||
readonly proves: string;
|
|
||||||
readonly doesNotProve: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface TokenCapabilitiesEvidenceDto {
|
|
||||||
readonly state: 'measured' | 'not-measured';
|
|
||||||
readonly scopes: readonly string[];
|
|
||||||
readonly source: 'provider-token-object' | 'runtime-not-authorized';
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialValidationEvidenceDto {
|
|
||||||
readonly providerIdentity: ProviderIdentityEvidenceDto | null;
|
|
||||||
readonly tokenCapabilities: TokenCapabilitiesEvidenceDto;
|
|
||||||
readonly repositoryPermission: RepositoryPermissionEvidenceDto | null;
|
|
||||||
readonly writeDifferential: WriteDifferentialEvidenceDto | null;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialAuditResultDto {
|
|
||||||
readonly journalId: string | null;
|
|
||||||
readonly state: 'not-started' | 'open' | 'sealed';
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialValidationResultDto {
|
|
||||||
readonly schemaVersion: 1;
|
|
||||||
readonly operation: 'validate' | 'whoami';
|
|
||||||
readonly outcome: CredentialOutcome;
|
|
||||||
readonly exitCode: 0 | 10 | 20 | 30;
|
|
||||||
readonly retryable: boolean;
|
|
||||||
readonly subject: CredentialSubjectDto;
|
|
||||||
readonly mutation: CredentialMutationState;
|
|
||||||
readonly reason: CredentialReasonDto;
|
|
||||||
readonly evidence: CredentialValidationEvidenceDto;
|
|
||||||
readonly audit: CredentialAuditResultDto;
|
|
||||||
}
|
|
||||||
@@ -1,141 +0,0 @@
|
|||||||
import { CredentialAuditJournal, CredentialJournalError } from './audit-journal.js';
|
|
||||||
import type {
|
|
||||||
CredentialValidationDependencies,
|
|
||||||
GiteaReadValidationRequestDto,
|
|
||||||
GiteaWriteValidationRequestDto,
|
|
||||||
} from './credential-provider.dto.js';
|
|
||||||
import type {
|
|
||||||
CredentialValidationResultDto,
|
|
||||||
RepositoryPermission,
|
|
||||||
} from './credential-result.dto.js';
|
|
||||||
import { evaluateGiteaReadValidation, evaluateGiteaWriteValidation } from './validate.js';
|
|
||||||
|
|
||||||
export interface CredentialValidationServiceOptions {
|
|
||||||
readonly stateRoot: string;
|
|
||||||
readonly actor: string;
|
|
||||||
readonly operation?: 'validate' | 'whoami';
|
|
||||||
}
|
|
||||||
|
|
||||||
function permissionDecision(permission: RepositoryPermission): string {
|
|
||||||
if (permission === 'none') return 'permission-none';
|
|
||||||
if (permission === 'admin') return 'permission-admin';
|
|
||||||
if (permission === 'write') return 'permission-write';
|
|
||||||
return 'permission-read';
|
|
||||||
}
|
|
||||||
|
|
||||||
async function openValidationJournal(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
options: CredentialValidationServiceOptions,
|
|
||||||
): Promise<CredentialAuditJournal> {
|
|
||||||
const journal = await CredentialAuditJournal.open(options.stateRoot, {
|
|
||||||
operation: options.operation ?? 'validate',
|
|
||||||
actor: options.actor,
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
});
|
|
||||||
await journal.recordIntent(
|
|
||||||
options.operation === 'whoami' ? 'whoami-requested' : 'validation-requested',
|
|
||||||
);
|
|
||||||
return journal;
|
|
||||||
}
|
|
||||||
|
|
||||||
async function recordAndSealValidation(
|
|
||||||
journal: CredentialAuditJournal,
|
|
||||||
validation: CredentialValidationResultDto,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
if (validation.evidence.providerIdentity !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: validation.evidence.providerIdentity.endpoint,
|
|
||||||
contentType: validation.evidence.providerIdentity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.repositoryPermission !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: validation.evidence.repositoryPermission.endpoint,
|
|
||||||
contentType: validation.evidence.repositoryPermission.contentType,
|
|
||||||
decision: permissionDecision(validation.evidence.repositoryPermission.effective),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
await journal.seal(validation.outcome, validation.reason.code);
|
|
||||||
return {
|
|
||||||
...validation,
|
|
||||||
audit: { journalId: journal.journalId(), state: 'sealed' },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
function journalFailureResult(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
journal: CredentialAuditJournal,
|
|
||||||
error: CredentialJournalError,
|
|
||||||
operation: 'validate' | 'whoami',
|
|
||||||
): CredentialValidationResultDto {
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation,
|
|
||||||
outcome: 'error',
|
|
||||||
exitCode: 20,
|
|
||||||
retryable: false,
|
|
||||||
subject: {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
},
|
|
||||||
mutation: 'none',
|
|
||||||
reason: {
|
|
||||||
code: error.code,
|
|
||||||
message: 'Validation audit persistence failed; inspect the durable open journal.',
|
|
||||||
},
|
|
||||||
evidence: {
|
|
||||||
providerIdentity: null,
|
|
||||||
tokenCapabilities: {
|
|
||||||
state: 'not-measured',
|
|
||||||
scopes: [],
|
|
||||||
source: 'runtime-not-authorized',
|
|
||||||
},
|
|
||||||
repositoryPermission: null,
|
|
||||||
writeDifferential: null,
|
|
||||||
},
|
|
||||||
audit: { journalId: journal.journalId(), state: 'open' },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function runCredentialReadValidation(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
options: CredentialValidationServiceOptions,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
const journal = await openValidationJournal(request, options);
|
|
||||||
try {
|
|
||||||
const validation = await evaluateGiteaReadValidation(request, dependencies);
|
|
||||||
return await recordAndSealValidation(journal, {
|
|
||||||
...validation,
|
|
||||||
operation: options.operation ?? 'validate',
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof CredentialJournalError) {
|
|
||||||
return journalFailureResult(request, journal, error, options.operation ?? 'validate');
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function runCredentialValidation(
|
|
||||||
request: GiteaWriteValidationRequestDto,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
options: CredentialValidationServiceOptions,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
const journal = await openValidationJournal(request, options);
|
|
||||||
try {
|
|
||||||
const validation = await evaluateGiteaWriteValidation(request, dependencies);
|
|
||||||
return await recordAndSealValidation(journal, validation);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof CredentialJournalError) {
|
|
||||||
return journalFailureResult(request, journal, error, 'validate');
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,97 +0,0 @@
|
|||||||
import { mkdtemp, open, rm, writeFile } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it } from 'vitest';
|
|
||||||
import { readDelegatedCredentialFromFd } from './delegated-credential.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('protected delegated credential channel', (): void => {
|
|
||||||
it('reads authority from an inherited fd number without putting the secret in argv or env', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-authority-fd-'));
|
|
||||||
const path = join(cleanup, 'authority');
|
|
||||||
await writeFile(
|
|
||||||
path,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'provisioner',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'seeded-authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
const resolved = await readDelegatedCredentialFromFd(
|
|
||||||
handle.fd,
|
|
||||||
'provisioner',
|
|
||||||
'homelab',
|
|
||||||
'git.example.invalid',
|
|
||||||
);
|
|
||||||
expect(resolved.identity).toBe('provisioner');
|
|
||||||
expect(Buffer.from(resolved.secret).toString('utf8')).toBe('seeded-authority-canary');
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a regular-file authority fd with group or other access', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-authority-fd-'));
|
|
||||||
const path = join(cleanup, 'authority');
|
|
||||||
await writeFile(
|
|
||||||
path,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'provisioner',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'seeded-authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o644 },
|
|
||||||
);
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await expect(
|
|
||||||
readDelegatedCredentialFromFd(handle.fd, 'provisioner', 'homelab', 'git.example.invalid'),
|
|
||||||
).rejects.toMatchObject({ code: 'delegated-authority-unavailable' });
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects an authority identity or estate mismatch without echoing the secret', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-authority-fd-'));
|
|
||||||
const path = join(cleanup, 'authority');
|
|
||||||
await writeFile(
|
|
||||||
path,
|
|
||||||
JSON.stringify({
|
|
||||||
identity: 'other',
|
|
||||||
estate: 'usc',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
secret: 'seeded-authority-canary',
|
|
||||||
}),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
let message = '';
|
|
||||||
try {
|
|
||||||
await readDelegatedCredentialFromFd(
|
|
||||||
handle.fd,
|
|
||||||
'provisioner',
|
|
||||||
'homelab',
|
|
||||||
'git.example.invalid',
|
|
||||||
);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
message = error instanceof Error ? error.message : String(error);
|
|
||||||
}
|
|
||||||
expect(message).toContain('delegated-authority-mismatch');
|
|
||||||
expect(message).not.toContain('seeded-authority-canary');
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,122 +0,0 @@
|
|||||||
import { randomUUID } from 'node:crypto';
|
|
||||||
import { createReadStream, fstatSync } from 'node:fs';
|
|
||||||
import { z } from 'zod';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
|
|
||||||
const authoritySchema = z
|
|
||||||
.object({
|
|
||||||
identity: z.string().regex(/^[A-Za-z0-9][A-Za-z0-9_.-]*$/),
|
|
||||||
estate: z.string().regex(/^[a-z0-9][a-z0-9-]*$/),
|
|
||||||
host: z.string().regex(/^[a-z0-9][a-z0-9.-]*$/),
|
|
||||||
secret: z
|
|
||||||
.string()
|
|
||||||
.min(1)
|
|
||||||
.max(16 * 1024)
|
|
||||||
.regex(/^\S+$/),
|
|
||||||
})
|
|
||||||
.strict();
|
|
||||||
|
|
||||||
export class DelegatedCredentialError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
message: string,
|
|
||||||
) {
|
|
||||||
super(`Delegated credential rejected: code=${code} ${message}`);
|
|
||||||
this.name = 'DelegatedCredentialError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function readProtectedFd(fd: number): Promise<Buffer> {
|
|
||||||
const controller = new AbortController();
|
|
||||||
const timeout = setTimeout((): void => controller.abort(), 5_000);
|
|
||||||
const chunks: Buffer[] = [];
|
|
||||||
let total = 0;
|
|
||||||
try {
|
|
||||||
const stream = createReadStream(`/proc/self/fd/${fd}`, {
|
|
||||||
highWaterMark: 4 * 1024,
|
|
||||||
signal: controller.signal,
|
|
||||||
});
|
|
||||||
for await (const chunk of stream) {
|
|
||||||
const bytes = Buffer.isBuffer(chunk) ? chunk : Buffer.from(chunk);
|
|
||||||
total += bytes.byteLength;
|
|
||||||
if (total > 32 * 1024) {
|
|
||||||
stream.destroy();
|
|
||||||
throw new Error('protected credential payload exceeded the bound');
|
|
||||||
}
|
|
||||||
chunks.push(bytes);
|
|
||||||
}
|
|
||||||
return Buffer.concat(chunks, total);
|
|
||||||
} finally {
|
|
||||||
clearTimeout(timeout);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function readDelegatedCredentialFromFd(
|
|
||||||
fd: number,
|
|
||||||
expectedIdentity: string,
|
|
||||||
expectedEstate: string,
|
|
||||||
expectedHost: string,
|
|
||||||
): Promise<ResolvedCredential> {
|
|
||||||
if (!Number.isSafeInteger(fd) || fd < 3 || fd > 1024) {
|
|
||||||
throw new DelegatedCredentialError('delegated-authority-unavailable', 'invalid inherited fd');
|
|
||||||
}
|
|
||||||
let bytes: Buffer;
|
|
||||||
try {
|
|
||||||
const stat = fstatSync(fd);
|
|
||||||
if (!stat.isFile() && !stat.isFIFO()) {
|
|
||||||
throw new Error('fd is not a regular file or pipe');
|
|
||||||
}
|
|
||||||
const currentUid = process.getuid?.();
|
|
||||||
if (currentUid === undefined || stat.uid !== currentUid || (stat.mode & 0o077) !== 0) {
|
|
||||||
throw new Error('fd owner or permissions are unsafe');
|
|
||||||
}
|
|
||||||
bytes = await readProtectedFd(fd);
|
|
||||||
} catch {
|
|
||||||
throw new DelegatedCredentialError(
|
|
||||||
'delegated-authority-unavailable',
|
|
||||||
'protected inherited credential fd could not be read',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (bytes.byteLength > 32 * 1024) {
|
|
||||||
bytes.fill(0);
|
|
||||||
throw new DelegatedCredentialError(
|
|
||||||
'delegated-authority-unavailable',
|
|
||||||
'protected credential payload exceeded the bound',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
let raw: unknown;
|
|
||||||
try {
|
|
||||||
raw = JSON.parse(new TextDecoder('utf-8', { fatal: true }).decode(bytes));
|
|
||||||
} catch {
|
|
||||||
bytes.fill(0);
|
|
||||||
throw new DelegatedCredentialError(
|
|
||||||
'delegated-authority-unavailable',
|
|
||||||
'protected credential payload was invalid',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
bytes.fill(0);
|
|
||||||
const parsed = authoritySchema.safeParse(raw);
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new DelegatedCredentialError(
|
|
||||||
'delegated-authority-unavailable',
|
|
||||||
'protected credential payload did not match the schema',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
parsed.data.identity !== expectedIdentity ||
|
|
||||||
parsed.data.estate !== expectedEstate ||
|
|
||||||
parsed.data.host !== expectedHost
|
|
||||||
) {
|
|
||||||
throw new DelegatedCredentialError(
|
|
||||||
'delegated-authority-mismatch',
|
|
||||||
'protected credential does not match the explicit actor, estate, and host',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return Object.freeze({
|
|
||||||
identity: parsed.data.identity,
|
|
||||||
estate: parsed.data.estate,
|
|
||||||
host: parsed.data.host,
|
|
||||||
resolutionId: randomUUID(),
|
|
||||||
secret: new TextEncoder().encode(parsed.data.secret),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
export type CredentialProviderKind = 'gitea';
|
|
||||||
|
|
||||||
export interface CredentialHostConfigDto {
|
|
||||||
readonly host: string;
|
|
||||||
readonly provider: CredentialProviderKind;
|
|
||||||
readonly apiBaseUrl: string;
|
|
||||||
readonly tokenPrefix: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialEstateConfigDto {
|
|
||||||
readonly name: string;
|
|
||||||
readonly readOnlyControlIdentity?: string;
|
|
||||||
readonly inventoryAuthorityIdentity?: string;
|
|
||||||
readonly hosts: readonly CredentialHostConfigDto[];
|
|
||||||
}
|
|
||||||
@@ -1,99 +0,0 @@
|
|||||||
import { describe, expect, it } from 'vitest';
|
|
||||||
import { parseCredentialEstateRegistry } from './estate-registry.js';
|
|
||||||
|
|
||||||
const validRegistry = JSON.stringify({
|
|
||||||
version: 1,
|
|
||||||
estates: [
|
|
||||||
{
|
|
||||||
name: 'homelab',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
hosts: [
|
|
||||||
{
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
provider: 'gitea',
|
|
||||||
apiBaseUrl: 'https://git.example.invalid',
|
|
||||||
tokenPrefix: 'gitea-example',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
],
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('credential estate registry', (): void => {
|
|
||||||
it('requires an exact declared estate-host pair', (): void => {
|
|
||||||
const registry = parseCredentialEstateRegistry(validRegistry);
|
|
||||||
|
|
||||||
expect(registry.matches('homelab', 'git.example.invalid')).toBe(true);
|
|
||||||
expect(registry.matches('usc', 'git.example.invalid')).toBe(false);
|
|
||||||
expect(registry.matches('homelab', 'other.example.invalid')).toBe(false);
|
|
||||||
expect(registry.resolveByHost('git.example.invalid')).toMatchObject({
|
|
||||||
estate: 'homelab',
|
|
||||||
host: { host: 'git.example.invalid', provider: 'gitea' },
|
|
||||||
});
|
|
||||||
expect(registry.resolveByHost('other.example.invalid')).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a provider URL whose host differs from the declared host', (): void => {
|
|
||||||
const source = validRegistry.replace(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
'https://other.example.invalid',
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(() => parseCredentialEstateRegistry(source)).toThrow(/api-host-mismatch/);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects one host assigned to multiple estates', (): void => {
|
|
||||||
const source = JSON.stringify({
|
|
||||||
version: 1,
|
|
||||||
estates: [
|
|
||||||
{
|
|
||||||
name: 'homelab',
|
|
||||||
hosts: [
|
|
||||||
{
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
provider: 'gitea',
|
|
||||||
apiBaseUrl: 'https://git.example.invalid',
|
|
||||||
tokenPrefix: 'gitea-example',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: 'other',
|
|
||||||
hosts: [
|
|
||||||
{
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
provider: 'gitea',
|
|
||||||
apiBaseUrl: 'https://git.example.invalid',
|
|
||||||
tokenPrefix: 'gitea-other',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
],
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(() => parseCredentialEstateRegistry(source)).toThrow(/duplicate-host/);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects URLs with userinfo, path, query, fragment, or non-HTTPS scheme', (): void => {
|
|
||||||
for (const apiBaseUrl of [
|
|
||||||
'http://git.example.invalid',
|
|
||||||
'https://[email protected]',
|
|
||||||
'https://git.example.invalid/api',
|
|
||||||
'https://git.example.invalid?x=1',
|
|
||||||
'https://git.example.invalid#x',
|
|
||||||
]) {
|
|
||||||
const source = validRegistry.replace('https://git.example.invalid', apiBaseUrl);
|
|
||||||
expect(() => parseCredentialEstateRegistry(source), apiBaseUrl).toThrow(/invalid-api-url/);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('requires a configured read-only control for write validation', (): void => {
|
|
||||||
const registry = parseCredentialEstateRegistry(validRegistry);
|
|
||||||
const withoutControl = parseCredentialEstateRegistry(
|
|
||||||
validRegistry.replace('"readOnlyControlIdentity":"read-control",', ''),
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(registry.readOnlyControl('homelab')).toBe('read-control');
|
|
||||||
expect(() => withoutControl.readOnlyControl('homelab')).toThrow(/read-only-control-missing/);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,166 +0,0 @@
|
|||||||
import { z } from 'zod';
|
|
||||||
import type { CredentialEstateRegistry } from './credential-provider.dto.js';
|
|
||||||
import type { CredentialEstateConfigDto, CredentialHostConfigDto } from './estate-registry.dto.js';
|
|
||||||
|
|
||||||
const NAME = /^[a-z0-9][a-z0-9-]*$/;
|
|
||||||
const IDENTITY = /^[A-Za-z0-9][A-Za-z0-9_.-]*$/;
|
|
||||||
const HOST = /^[a-z0-9](?:[a-z0-9.-]*[a-z0-9])?$/;
|
|
||||||
|
|
||||||
const hostSchema = z
|
|
||||||
.object({
|
|
||||||
host: z.string().regex(HOST),
|
|
||||||
provider: z.literal('gitea'),
|
|
||||||
apiBaseUrl: z.string(),
|
|
||||||
tokenPrefix: z.string().regex(NAME),
|
|
||||||
})
|
|
||||||
.strict();
|
|
||||||
|
|
||||||
const estateSchema = z
|
|
||||||
.object({
|
|
||||||
name: z.string().regex(NAME),
|
|
||||||
readOnlyControlIdentity: z.string().regex(IDENTITY).optional(),
|
|
||||||
inventoryAuthorityIdentity: z.string().regex(IDENTITY).optional(),
|
|
||||||
hosts: z.array(hostSchema).min(1),
|
|
||||||
})
|
|
||||||
.strict();
|
|
||||||
|
|
||||||
const registrySchema = z
|
|
||||||
.object({
|
|
||||||
version: z.literal(1),
|
|
||||||
estates: z.array(estateSchema).min(1),
|
|
||||||
})
|
|
||||||
.strict();
|
|
||||||
|
|
||||||
export class CredentialEstateRegistryError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
message: string,
|
|
||||||
) {
|
|
||||||
super(`Credential estate registry rejected: code=${code} ${message}`);
|
|
||||||
this.name = 'CredentialEstateRegistryError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function validateApiUrl(host: CredentialHostConfigDto): void {
|
|
||||||
let url: URL;
|
|
||||||
try {
|
|
||||||
url = new URL(host.apiBaseUrl);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
const detail = error instanceof Error ? error.message : String(error);
|
|
||||||
throw new CredentialEstateRegistryError('invalid-api-url', detail);
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
url.protocol !== 'https:' ||
|
|
||||||
url.username !== '' ||
|
|
||||||
url.password !== '' ||
|
|
||||||
url.pathname !== '/' ||
|
|
||||||
url.search !== '' ||
|
|
||||||
url.hash !== ''
|
|
||||||
) {
|
|
||||||
throw new CredentialEstateRegistryError(
|
|
||||||
'invalid-api-url',
|
|
||||||
'provider API URL must be an HTTPS origin without userinfo, path, query, or fragment',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (url.hostname !== host.host) {
|
|
||||||
throw new CredentialEstateRegistryError(
|
|
||||||
'api-host-mismatch',
|
|
||||||
'provider API URL hostname does not equal the declared host',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export class ParsedCredentialEstateRegistry implements CredentialEstateRegistry {
|
|
||||||
private readonly estates: ReadonlyMap<string, CredentialEstateConfigDto>;
|
|
||||||
|
|
||||||
constructor(estates: readonly CredentialEstateConfigDto[]) {
|
|
||||||
this.estates = new Map(
|
|
||||||
estates.map(
|
|
||||||
(estate: CredentialEstateConfigDto): readonly [string, CredentialEstateConfigDto] => [
|
|
||||||
estate.name,
|
|
||||||
estate,
|
|
||||||
],
|
|
||||||
),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
matches(estate: string, host: string): boolean {
|
|
||||||
return this.resolve(estate, host) !== undefined;
|
|
||||||
}
|
|
||||||
|
|
||||||
resolve(estate: string, host: string): CredentialHostConfigDto | undefined {
|
|
||||||
return this.estates
|
|
||||||
.get(estate)
|
|
||||||
?.hosts.find((candidate: CredentialHostConfigDto): boolean => candidate.host === host);
|
|
||||||
}
|
|
||||||
|
|
||||||
resolveByHost(
|
|
||||||
host: string,
|
|
||||||
): { readonly estate: string; readonly host: CredentialHostConfigDto } | undefined {
|
|
||||||
for (const [estate, config] of this.estates) {
|
|
||||||
const match = config.hosts.find(
|
|
||||||
(candidate: CredentialHostConfigDto): boolean => candidate.host === host,
|
|
||||||
);
|
|
||||||
if (match !== undefined) return { estate, host: match };
|
|
||||||
}
|
|
||||||
return undefined;
|
|
||||||
}
|
|
||||||
|
|
||||||
inventoryAuthority(estate: string): string {
|
|
||||||
const identity = this.estates.get(estate)?.inventoryAuthorityIdentity;
|
|
||||||
if (identity === undefined) {
|
|
||||||
throw new CredentialEstateRegistryError(
|
|
||||||
'inventory-authority-missing',
|
|
||||||
`estate ${estate} has no delegated inventory authority identity`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return identity;
|
|
||||||
}
|
|
||||||
|
|
||||||
readOnlyControl(estate: string): string {
|
|
||||||
const identity = this.estates.get(estate)?.readOnlyControlIdentity;
|
|
||||||
if (identity === undefined) {
|
|
||||||
throw new CredentialEstateRegistryError(
|
|
||||||
'read-only-control-missing',
|
|
||||||
`estate ${estate} has no provider-confirmed read-only control identity`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return identity;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export function parseCredentialEstateRegistry(source: string): ParsedCredentialEstateRegistry {
|
|
||||||
let raw: unknown;
|
|
||||||
try {
|
|
||||||
raw = JSON.parse(source);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
const detail = error instanceof Error ? error.message : String(error);
|
|
||||||
throw new CredentialEstateRegistryError('invalid-json', detail);
|
|
||||||
}
|
|
||||||
|
|
||||||
const parsed = registrySchema.safeParse(raw);
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialEstateRegistryError(
|
|
||||||
'invalid-schema',
|
|
||||||
parsed.error.issues[0]?.message ?? 'invalid',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const estateNames = new Set<string>();
|
|
||||||
const hostNames = new Set<string>();
|
|
||||||
for (const estate of parsed.data.estates) {
|
|
||||||
if (estateNames.has(estate.name)) {
|
|
||||||
throw new CredentialEstateRegistryError('duplicate-estate', estate.name);
|
|
||||||
}
|
|
||||||
estateNames.add(estate.name);
|
|
||||||
for (const host of estate.hosts) {
|
|
||||||
validateApiUrl(host);
|
|
||||||
if (hostNames.has(host.host)) {
|
|
||||||
throw new CredentialEstateRegistryError('duplicate-host', host.host);
|
|
||||||
}
|
|
||||||
hostNames.add(host.host);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return new ParsedCredentialEstateRegistry(parsed.data.estates);
|
|
||||||
}
|
|
||||||
@@ -1,211 +0,0 @@
|
|||||||
import { chmod, copyFile, mkdir, symlink, unlink, writeFile } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { mkdtemp } from 'node:fs/promises';
|
|
||||||
import { afterEach, describe, expect, it } from 'vitest';
|
|
||||||
import { rm } from 'node:fs/promises';
|
|
||||||
import { parseCredentialEstateRegistry } from './estate-registry.js';
|
|
||||||
import { FileCredentialResolver, FileCredentialStore } from './file-credential-store.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
|
|
||||||
async function fixtureRoot(): Promise<string> {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-cred-store-'));
|
|
||||||
const root = join(cleanup, 'tokens');
|
|
||||||
await mkdir(root, { mode: 0o700 });
|
|
||||||
return root;
|
|
||||||
}
|
|
||||||
|
|
||||||
function registry(): ReturnType<typeof parseCredentialEstateRegistry> {
|
|
||||||
return parseCredentialEstateRegistry(
|
|
||||||
JSON.stringify({
|
|
||||||
version: 1,
|
|
||||||
estates: [
|
|
||||||
{
|
|
||||||
name: 'homelab',
|
|
||||||
hosts: [
|
|
||||||
{
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
provider: 'gitea',
|
|
||||||
apiBaseUrl: 'https://git.example.invalid',
|
|
||||||
tokenPrefix: 'gitea-example',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
],
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('phase-1 governed file credential resolver', (): void => {
|
|
||||||
it('resolves only the exact estate/host/identity token at a test-overridable root', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
await writeFile(join(root, 'gitea-example-seat.token'), 'canary-token', { mode: 0o600 });
|
|
||||||
const resolver = new FileCredentialResolver(root, registry());
|
|
||||||
|
|
||||||
const resolved = await resolver.resolve('seat', 'homelab', 'git.example.invalid');
|
|
||||||
const wrongEstate = await resolver.resolve('seat', 'usc', 'git.example.invalid');
|
|
||||||
|
|
||||||
expect(resolved?.identity).toBe('seat');
|
|
||||||
expect(Buffer.from(resolved?.secret ?? []).toString('utf8')).toBe('canary-token');
|
|
||||||
expect(wrongEstate).toBeUndefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a group-writable token directory even when the token file is private', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
await writeFile(join(root, 'gitea-example-seat-name.token'), 'private-token', {
|
|
||||||
mode: 0o600,
|
|
||||||
});
|
|
||||||
await chmod(root, 0o770);
|
|
||||||
const resolver = new FileCredentialResolver(root, registry());
|
|
||||||
|
|
||||||
await expect(resolver.resolve('seat-name', 'homelab', 'git.example.invalid')).rejects.toThrow(
|
|
||||||
/insecure-token-owner/,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a token file with group or other permissions', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
const path = join(root, 'gitea-example-seat.token');
|
|
||||||
await writeFile(path, 'canary-token', { mode: 0o600 });
|
|
||||||
await chmod(path, 0o640);
|
|
||||||
const resolver = new FileCredentialResolver(root, registry());
|
|
||||||
|
|
||||||
await expect(resolver.resolve('seat', 'homelab', 'git.example.invalid')).rejects.toThrow(
|
|
||||||
/insecure-token-mode/,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a symlinked token instead of following it', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
const target = join(cleanup ?? root, 'outside-token');
|
|
||||||
await writeFile(target, 'canary-token', { mode: 0o600 });
|
|
||||||
await symlink(target, join(root, 'gitea-example-seat.token'));
|
|
||||||
const resolver = new FileCredentialResolver(root, registry());
|
|
||||||
|
|
||||||
await expect(resolver.resolve('seat', 'homelab', 'git.example.invalid')).rejects.toThrow(
|
|
||||||
/symbolic link|unavailable/,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects traversal-shaped identities before touching storage', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
const resolver = new FileCredentialResolver(root, registry());
|
|
||||||
|
|
||||||
await expect(resolver.resolve('../other', 'homelab', 'git.example.invalid')).rejects.toThrow(
|
|
||||||
/invalid-identity/,
|
|
||||||
);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('stores one governed envelope, lists and reads it, then removes all credential artifacts', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
const store = new FileCredentialStore(root, registry());
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat',
|
|
||||||
tokenName: 'mosaic-seat-1',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('new-private-token'),
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(store.list('homelab', 'git.example.invalid')).resolves.toEqual(['seat']);
|
|
||||||
await expect(
|
|
||||||
store.readBinding('seat', 'homelab', 'git.example.invalid'),
|
|
||||||
).resolves.toMatchObject({
|
|
||||||
providerLogin: 'seat',
|
|
||||||
tokenName: 'mosaic-seat-1',
|
|
||||||
});
|
|
||||||
await expect(
|
|
||||||
new FileCredentialResolver(root, registry()).resolve(
|
|
||||||
'seat',
|
|
||||||
'homelab',
|
|
||||||
'git.example.invalid',
|
|
||||||
),
|
|
||||||
).resolves.toMatchObject({ identity: 'seat' });
|
|
||||||
await copyFile(
|
|
||||||
join(root, 'gitea-example-seat.credential.json'),
|
|
||||||
join(root, 'gitea-example-other.credential.json'),
|
|
||||||
);
|
|
||||||
await expect(
|
|
||||||
new FileCredentialResolver(root, registry()).resolve(
|
|
||||||
'other',
|
|
||||||
'homelab',
|
|
||||||
'git.example.invalid',
|
|
||||||
),
|
|
||||||
).rejects.toThrow(/credential-binding-mismatch/);
|
|
||||||
await unlink(join(root, 'gitea-example-other.credential.json'));
|
|
||||||
await store.remove('seat', 'homelab', 'git.example.invalid');
|
|
||||||
await expect(store.list('homelab', 'git.example.invalid')).resolves.toEqual([]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('changes generation for metadata-only rebinding and rejects stale replacement or removal', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
const store = new FileCredentialStore(root, registry());
|
|
||||||
const secret = new TextEncoder().encode('same-private-token');
|
|
||||||
const originalBinding = {
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat',
|
|
||||||
tokenName: 'mosaic-seat-original',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
};
|
|
||||||
await store.put(originalBinding, secret);
|
|
||||||
const original = await store.snapshot('seat', 'homelab', 'git.example.invalid');
|
|
||||||
if (original === undefined) throw new Error('original generation was not stored');
|
|
||||||
try {
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
...originalBinding,
|
|
||||||
tokenName: 'mosaic-seat-rebound',
|
|
||||||
createdAt: '2026-08-05T00:00:01.000Z',
|
|
||||||
},
|
|
||||||
secret,
|
|
||||||
original.generation,
|
|
||||||
);
|
|
||||||
const rebound = await store.snapshot('seat', 'homelab', 'git.example.invalid');
|
|
||||||
try {
|
|
||||||
expect(rebound?.generation).not.toBe(original.generation);
|
|
||||||
await expect(
|
|
||||||
store.put(
|
|
||||||
{ ...originalBinding, tokenName: 'mosaic-seat-stale' },
|
|
||||||
secret,
|
|
||||||
original.generation,
|
|
||||||
),
|
|
||||||
).rejects.toThrow(/credential-generation-mismatch/);
|
|
||||||
await expect(
|
|
||||||
store.remove('seat', 'homelab', 'git.example.invalid', original.generation),
|
|
||||||
).rejects.toThrow(/credential-generation-mismatch/);
|
|
||||||
await expect(
|
|
||||||
store.readBinding('seat', 'homelab', 'git.example.invalid'),
|
|
||||||
).resolves.toMatchObject({ tokenName: 'mosaic-seat-rebound' });
|
|
||||||
} finally {
|
|
||||||
rebound?.secret.fill(0);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
original.secret.fill(0);
|
|
||||||
secret.fill(0);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('returns undefined for an absent token without borrowing another identity', async (): Promise<void> => {
|
|
||||||
const root = await fixtureRoot();
|
|
||||||
await writeFile(join(root, 'gitea-example-shared.token'), 'shared-canary', { mode: 0o600 });
|
|
||||||
const resolver = new FileCredentialResolver(root, registry());
|
|
||||||
|
|
||||||
const resolved = await resolver.resolve('missing-seat', 'homelab', 'git.example.invalid');
|
|
||||||
|
|
||||||
expect(resolved).toBeUndefined();
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,549 +0,0 @@
|
|||||||
import { createHash, randomUUID } from 'node:crypto';
|
|
||||||
import { lstatSync } from 'node:fs';
|
|
||||||
import { open, readdir, rename, unlink } from 'node:fs/promises';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { z } from 'zod';
|
|
||||||
import {
|
|
||||||
ensureManagedDirectory,
|
|
||||||
readRegularFileSecure,
|
|
||||||
type SecureFileSnapshot,
|
|
||||||
} from '../fleet/secure-file.js';
|
|
||||||
import type { CredentialBindingMetadataDto } from './credential-binding.dto.js';
|
|
||||||
import type { CredentialResolver, ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
import type { ParsedCredentialEstateRegistry } from './estate-registry.js';
|
|
||||||
|
|
||||||
const IDENTITY = /^[A-Za-z0-9][A-Za-z0-9_.-]*$/;
|
|
||||||
const MAX_TOKEN_BYTES = 16 * 1024;
|
|
||||||
const bindingSchema = z
|
|
||||||
.object({
|
|
||||||
schemaVersion: z.literal(1),
|
|
||||||
identity: z.string().regex(IDENTITY),
|
|
||||||
estate: z.string().min(1),
|
|
||||||
host: z.string().min(1),
|
|
||||||
providerLogin: z.string().regex(IDENTITY),
|
|
||||||
tokenName: z.string().regex(IDENTITY),
|
|
||||||
scopes: z.array(z.string().regex(/^[a-z]+(?::[a-z]+)?$/)).max(32),
|
|
||||||
createdAt: z.string().datetime(),
|
|
||||||
tokenDigest: z
|
|
||||||
.string()
|
|
||||||
.regex(/^[a-f0-9]{64}$/)
|
|
||||||
.optional(),
|
|
||||||
})
|
|
||||||
.strict();
|
|
||||||
const credentialEnvelopeSchema = bindingSchema.extend({
|
|
||||||
token: z.string().min(1).max(MAX_TOKEN_BYTES).regex(/^\S+$/),
|
|
||||||
});
|
|
||||||
|
|
||||||
export class CredentialStoreError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
message: string,
|
|
||||||
) {
|
|
||||||
super(`Credential store rejected: code=${code} ${message}`);
|
|
||||||
this.name = 'CredentialStoreError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function isMissingFile(error: unknown): boolean {
|
|
||||||
return (
|
|
||||||
error instanceof Error &&
|
|
||||||
'code' in error &&
|
|
||||||
typeof error.code === 'string' &&
|
|
||||||
error.code === 'ENOENT'
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
export function credentialBindingGeneration(
|
|
||||||
metadata: CredentialBindingMetadataDto,
|
|
||||||
secret: Uint8Array,
|
|
||||||
): string {
|
|
||||||
const tokenDigest = createHash('sha256').update(secret).digest('hex');
|
|
||||||
const canonicalState = JSON.stringify({
|
|
||||||
schemaVersion: 1,
|
|
||||||
identity: metadata.identity,
|
|
||||||
estate: metadata.estate,
|
|
||||||
host: metadata.host,
|
|
||||||
providerLogin: metadata.providerLogin,
|
|
||||||
tokenName: metadata.tokenName,
|
|
||||||
scopes: [...metadata.scopes].sort(),
|
|
||||||
createdAt: metadata.createdAt,
|
|
||||||
tokenDigest,
|
|
||||||
});
|
|
||||||
return createHash('sha256').update(canonicalState).digest('hex');
|
|
||||||
}
|
|
||||||
|
|
||||||
function validateSecret(content: Buffer): Uint8Array {
|
|
||||||
if (content.byteLength === 0 || content.byteLength > MAX_TOKEN_BYTES) {
|
|
||||||
throw new CredentialStoreError('invalid-token-size', 'token file size is outside bounds');
|
|
||||||
}
|
|
||||||
for (const byte of content) {
|
|
||||||
if (byte <= 0x20 || byte === 0x7f) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'invalid-token-bytes',
|
|
||||||
'token file contains whitespace or control bytes',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
return new Uint8Array(content);
|
|
||||||
}
|
|
||||||
|
|
||||||
export class FileCredentialResolver implements CredentialResolver {
|
|
||||||
constructor(
|
|
||||||
private readonly tokenDirectory: string,
|
|
||||||
private readonly estateRegistry: ParsedCredentialEstateRegistry,
|
|
||||||
) {}
|
|
||||||
|
|
||||||
async resolve(
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
): Promise<ResolvedCredential | undefined> {
|
|
||||||
if (!IDENTITY.test(identity)) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'invalid-identity',
|
|
||||||
'identity is outside the allowlist grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const hostConfig = this.estateRegistry.resolve(estate, host);
|
|
||||||
if (hostConfig === undefined) return undefined;
|
|
||||||
|
|
||||||
const currentUid = process.getuid?.();
|
|
||||||
if (currentUid === undefined) {
|
|
||||||
throw new CredentialStoreError('insecure-token-owner', 'runtime uid is unavailable');
|
|
||||||
}
|
|
||||||
const directory = lstatSync(this.tokenDirectory);
|
|
||||||
if (
|
|
||||||
!directory.isDirectory() ||
|
|
||||||
directory.isSymbolicLink() ||
|
|
||||||
directory.uid !== currentUid ||
|
|
||||||
(directory.mode & 0o022) !== 0
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'insecure-token-owner',
|
|
||||||
'token directory ownership or write permissions are unsafe',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const envelopePath = join(
|
|
||||||
this.tokenDirectory,
|
|
||||||
`${hostConfig.tokenPrefix}-${identity}.credential.json`,
|
|
||||||
);
|
|
||||||
try {
|
|
||||||
const envelopeSnapshot = readRegularFileSecure(envelopePath, {
|
|
||||||
root: this.tokenDirectory,
|
|
||||||
maxBytes: 64 * 1024,
|
|
||||||
});
|
|
||||||
const envelope = credentialEnvelopeSchema.safeParse(
|
|
||||||
JSON.parse(envelopeSnapshot.content.toString('utf8')),
|
|
||||||
);
|
|
||||||
if (
|
|
||||||
!envelope.success ||
|
|
||||||
envelopeSnapshot.uid !== process.getuid?.() ||
|
|
||||||
(envelopeSnapshot.mode & 0o077) !== 0
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'invalid-binding',
|
|
||||||
'credential envelope failed schema, owner, or mode validation',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
envelope.data.identity !== identity ||
|
|
||||||
envelope.data.estate !== estate ||
|
|
||||||
envelope.data.host !== host ||
|
|
||||||
envelope.data.providerLogin !== identity
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'credential-binding-mismatch',
|
|
||||||
'credential envelope does not match the requested identity, estate, host, and principal',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const secret = validateSecret(Buffer.from(envelope.data.token, 'utf8'));
|
|
||||||
const digest = createHash('sha256').update(secret).digest('hex');
|
|
||||||
if (envelope.data.tokenDigest !== digest) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'credential-generation-mismatch',
|
|
||||||
'credential envelope digest does not match its token',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return Object.freeze({
|
|
||||||
identity,
|
|
||||||
estate,
|
|
||||||
host,
|
|
||||||
resolutionId: randomUUID(),
|
|
||||||
secret,
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!isMissingFile(error)) throw error;
|
|
||||||
}
|
|
||||||
|
|
||||||
const path = join(this.tokenDirectory, `${hostConfig.tokenPrefix}-${identity}.token`);
|
|
||||||
let snapshot: SecureFileSnapshot;
|
|
||||||
try {
|
|
||||||
snapshot = readRegularFileSecure(path, {
|
|
||||||
root: this.tokenDirectory,
|
|
||||||
maxBytes: MAX_TOKEN_BYTES,
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (isMissingFile(error)) return undefined;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
|
|
||||||
const bindingPath = join(
|
|
||||||
this.tokenDirectory,
|
|
||||||
`${hostConfig.tokenPrefix}-${identity}.binding.json`,
|
|
||||||
);
|
|
||||||
try {
|
|
||||||
const bindingSnapshot = readRegularFileSecure(bindingPath, {
|
|
||||||
root: this.tokenDirectory,
|
|
||||||
maxBytes: 64 * 1024,
|
|
||||||
});
|
|
||||||
const binding = bindingSchema.safeParse(JSON.parse(bindingSnapshot.content.toString('utf8')));
|
|
||||||
const digest = createHash('sha256').update(snapshot.content).digest('hex');
|
|
||||||
if (
|
|
||||||
!binding.success ||
|
|
||||||
binding.data.tokenDigest !== digest ||
|
|
||||||
binding.data.identity !== identity ||
|
|
||||||
binding.data.estate !== estate ||
|
|
||||||
binding.data.host !== host ||
|
|
||||||
binding.data.providerLogin !== identity
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'credential-generation-mismatch',
|
|
||||||
'token and binding metadata are not one committed identity-bound generation',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!isMissingFile(error)) throw error;
|
|
||||||
// Legacy token files predate binding metadata and remain readable until rotated.
|
|
||||||
}
|
|
||||||
|
|
||||||
const permissions = snapshot.mode & 0o777;
|
|
||||||
if (snapshot.uid !== currentUid) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'insecure-token-owner',
|
|
||||||
'token file is not owned by the runtime uid',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if ((permissions & 0o077) !== 0) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'insecure-token-mode',
|
|
||||||
'token file grants group or other access',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
return Object.freeze({
|
|
||||||
identity,
|
|
||||||
estate,
|
|
||||||
host,
|
|
||||||
resolutionId: randomUUID(),
|
|
||||||
secret: validateSecret(snapshot.content),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertPrivateTokenDirectory(path: string): {
|
|
||||||
readonly dev: number | bigint;
|
|
||||||
readonly ino: number | bigint;
|
|
||||||
} {
|
|
||||||
const stat = lstatSync(path);
|
|
||||||
if (
|
|
||||||
!stat.isDirectory() ||
|
|
||||||
stat.isSymbolicLink() ||
|
|
||||||
stat.uid !== process.getuid?.() ||
|
|
||||||
(stat.mode & 0o022) !== 0
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'insecure-token-owner',
|
|
||||||
'token directory ownership or write permissions are unsafe',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return { dev: stat.dev, ino: stat.ino };
|
|
||||||
}
|
|
||||||
|
|
||||||
async function syncDirectory(path: string): Promise<void> {
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export class FileCredentialStore {
|
|
||||||
constructor(
|
|
||||||
private readonly tokenDirectory: string,
|
|
||||||
private readonly estateRegistry: ParsedCredentialEstateRegistry,
|
|
||||||
) {}
|
|
||||||
|
|
||||||
private paths(
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
): {
|
|
||||||
readonly token: string;
|
|
||||||
readonly binding: string;
|
|
||||||
readonly envelope: string;
|
|
||||||
readonly prefix: string;
|
|
||||||
} {
|
|
||||||
if (!IDENTITY.test(identity)) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'invalid-identity',
|
|
||||||
'identity is outside the allowlist grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const config = this.estateRegistry.resolve(estate, host);
|
|
||||||
if (config === undefined) {
|
|
||||||
throw new CredentialStoreError('estate-host-mismatch', 'estate and host do not match');
|
|
||||||
}
|
|
||||||
const prefix = `${config.tokenPrefix}-${identity}`;
|
|
||||||
return {
|
|
||||||
token: join(this.tokenDirectory, `${prefix}.token`),
|
|
||||||
binding: join(this.tokenDirectory, `${prefix}.binding.json`),
|
|
||||||
envelope: join(this.tokenDirectory, `${prefix}.credential.json`),
|
|
||||||
prefix,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async put(
|
|
||||||
metadata: CredentialBindingMetadataDto,
|
|
||||||
secret: Uint8Array,
|
|
||||||
expectedGeneration?: string | null,
|
|
||||||
): Promise<void> {
|
|
||||||
const paths = this.paths(metadata.identity, metadata.estate, metadata.host);
|
|
||||||
ensureManagedDirectory(this.tokenDirectory, this.tokenDirectory);
|
|
||||||
const directoryIdentity = assertPrivateTokenDirectory(this.tokenDirectory);
|
|
||||||
const token = validateSecret(Buffer.from(secret));
|
|
||||||
const envelope = credentialEnvelopeSchema.parse({
|
|
||||||
...metadata,
|
|
||||||
schemaVersion: 1,
|
|
||||||
tokenDigest: createHash('sha256').update(token).digest('hex'),
|
|
||||||
token: Buffer.from(token).toString('utf8'),
|
|
||||||
});
|
|
||||||
const suffix = randomUUID();
|
|
||||||
const envelopeTemp = `${paths.envelope}.${suffix}.tmp`;
|
|
||||||
const lockPath = join(this.tokenDirectory, `${paths.prefix}.lock`);
|
|
||||||
let lock;
|
|
||||||
try {
|
|
||||||
lock = await open(lockPath, 'wx', 0o600);
|
|
||||||
} catch {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'conflicting-credential-mutation',
|
|
||||||
'another mutation owns the identity lock',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
if (expectedGeneration !== undefined) {
|
|
||||||
const current = await this.snapshot(metadata.identity, metadata.estate, metadata.host);
|
|
||||||
try {
|
|
||||||
const actualGeneration = current?.generation ?? null;
|
|
||||||
if (actualGeneration !== expectedGeneration) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'credential-generation-mismatch',
|
|
||||||
'credential generation changed before replacement',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
current?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
const handle = await open(envelopeTemp, 'wx', 0o600);
|
|
||||||
try {
|
|
||||||
await handle.writeFile(`${JSON.stringify(envelope)}\n`, 'utf8');
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
const beforeCommit = assertPrivateTokenDirectory(this.tokenDirectory);
|
|
||||||
if (
|
|
||||||
beforeCommit.dev !== directoryIdentity.dev ||
|
|
||||||
beforeCommit.ino !== directoryIdentity.ino
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'insecure-token-owner',
|
|
||||||
'token directory changed during credential commit',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await rename(envelopeTemp, paths.envelope);
|
|
||||||
await syncDirectory(this.tokenDirectory);
|
|
||||||
} finally {
|
|
||||||
await lock.close();
|
|
||||||
await unlink(envelopeTemp).catch((): void => undefined);
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
await syncDirectory(this.tokenDirectory);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async snapshot(
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
): Promise<
|
|
||||||
| {
|
|
||||||
readonly binding: CredentialBindingMetadataDto;
|
|
||||||
readonly secret: Uint8Array;
|
|
||||||
readonly generation: string;
|
|
||||||
}
|
|
||||||
| undefined
|
|
||||||
> {
|
|
||||||
const binding = await this.readBinding(identity, estate, host);
|
|
||||||
if (binding === undefined) return undefined;
|
|
||||||
const resolved = await new FileCredentialResolver(
|
|
||||||
this.tokenDirectory,
|
|
||||||
this.estateRegistry,
|
|
||||||
).resolve(identity, estate, host);
|
|
||||||
if (resolved === undefined) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'invalid-binding',
|
|
||||||
'binding metadata exists without its token generation',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const secret = new Uint8Array(resolved.secret);
|
|
||||||
const generation = credentialBindingGeneration(binding, resolved.secret);
|
|
||||||
resolved.secret.fill(0);
|
|
||||||
return { binding, secret, generation };
|
|
||||||
}
|
|
||||||
|
|
||||||
async readBinding(
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
): Promise<CredentialBindingMetadataDto | undefined> {
|
|
||||||
const paths = this.paths(identity, estate, host);
|
|
||||||
let snapshot: SecureFileSnapshot;
|
|
||||||
try {
|
|
||||||
const envelope = readRegularFileSecure(paths.envelope, {
|
|
||||||
root: this.tokenDirectory,
|
|
||||||
maxBytes: 64 * 1024,
|
|
||||||
});
|
|
||||||
const parsed = credentialEnvelopeSchema.safeParse(
|
|
||||||
JSON.parse(envelope.content.toString('utf8')),
|
|
||||||
);
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialStoreError('invalid-binding', 'credential envelope is malformed');
|
|
||||||
}
|
|
||||||
const verified = await new FileCredentialResolver(
|
|
||||||
this.tokenDirectory,
|
|
||||||
this.estateRegistry,
|
|
||||||
).resolve(identity, estate, host);
|
|
||||||
if (verified === undefined) {
|
|
||||||
throw new CredentialStoreError('invalid-binding', 'credential envelope was not resolvable');
|
|
||||||
}
|
|
||||||
verified.secret.fill(0);
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
identity: parsed.data.identity,
|
|
||||||
estate: parsed.data.estate,
|
|
||||||
host: parsed.data.host,
|
|
||||||
providerLogin: parsed.data.providerLogin,
|
|
||||||
tokenName: parsed.data.tokenName,
|
|
||||||
scopes: parsed.data.scopes,
|
|
||||||
createdAt: parsed.data.createdAt,
|
|
||||||
tokenDigest: parsed.data.tokenDigest,
|
|
||||||
};
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!isMissingFile(error)) throw error;
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
snapshot = readRegularFileSecure(paths.binding, {
|
|
||||||
root: this.tokenDirectory,
|
|
||||||
maxBytes: 64 * 1024,
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (isMissingFile(error)) return undefined;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
if ((snapshot.mode & 0o077) !== 0 || snapshot.uid !== process.getuid?.()) {
|
|
||||||
throw new CredentialStoreError('insecure-token-owner', 'binding metadata is not private');
|
|
||||||
}
|
|
||||||
const parsed = bindingSchema.safeParse(JSON.parse(snapshot.content.toString('utf8')));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'invalid-binding',
|
|
||||||
'binding metadata failed schema validation',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return parsed.data;
|
|
||||||
}
|
|
||||||
|
|
||||||
async list(estate: string, host: string): Promise<readonly string[]> {
|
|
||||||
const config = this.estateRegistry.resolve(estate, host);
|
|
||||||
if (config === undefined) return [];
|
|
||||||
const names = await readdir(this.tokenDirectory);
|
|
||||||
const prefix = `${config.tokenPrefix}-`;
|
|
||||||
return [
|
|
||||||
...new Set(
|
|
||||||
names.flatMap((name): string[] => {
|
|
||||||
if (!name.startsWith(prefix)) return [];
|
|
||||||
if (name.endsWith('.token')) {
|
|
||||||
return [name.slice(prefix.length, -'.token'.length)];
|
|
||||||
}
|
|
||||||
if (name.endsWith('.credential.json')) {
|
|
||||||
return [name.slice(prefix.length, -'.credential.json'.length)];
|
|
||||||
}
|
|
||||||
return [];
|
|
||||||
}),
|
|
||||||
),
|
|
||||||
]
|
|
||||||
.filter((identity): boolean => IDENTITY.test(identity))
|
|
||||||
.sort();
|
|
||||||
}
|
|
||||||
|
|
||||||
async remove(
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
expectedTokenDigest?: string,
|
|
||||||
): Promise<void> {
|
|
||||||
const paths = this.paths(identity, estate, host);
|
|
||||||
const directoryIdentity = assertPrivateTokenDirectory(this.tokenDirectory);
|
|
||||||
const lockPath = join(this.tokenDirectory, `${paths.prefix}.lock`);
|
|
||||||
let lock;
|
|
||||||
try {
|
|
||||||
lock = await open(lockPath, 'wx', 0o600);
|
|
||||||
} catch {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'conflicting-credential-mutation',
|
|
||||||
'another mutation owns the identity lock',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
if (expectedTokenDigest !== undefined) {
|
|
||||||
const current = await this.snapshot(identity, estate, host);
|
|
||||||
try {
|
|
||||||
if (current === undefined || current.generation !== expectedTokenDigest) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'credential-generation-mismatch',
|
|
||||||
'credential generation changed before removal',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
current?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
const beforeRemoval = assertPrivateTokenDirectory(this.tokenDirectory);
|
|
||||||
if (
|
|
||||||
beforeRemoval.dev !== directoryIdentity.dev ||
|
|
||||||
beforeRemoval.ino !== directoryIdentity.ino
|
|
||||||
) {
|
|
||||||
throw new CredentialStoreError(
|
|
||||||
'insecure-token-owner',
|
|
||||||
'token directory changed during credential removal',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await unlink(paths.token).catch((error: unknown): void => {
|
|
||||||
if (!isMissingFile(error)) throw error;
|
|
||||||
});
|
|
||||||
await unlink(paths.binding).catch((error: unknown): void => {
|
|
||||||
if (!isMissingFile(error)) throw error;
|
|
||||||
});
|
|
||||||
await unlink(paths.envelope).catch((error: unknown): void => {
|
|
||||||
if (!isMissingFile(error)) throw error;
|
|
||||||
});
|
|
||||||
await syncDirectory(this.tokenDirectory);
|
|
||||||
} finally {
|
|
||||||
await lock.close();
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
await syncDirectory(this.tokenDirectory);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,276 +0,0 @@
|
|||||||
import { describe, expect, it } from 'vitest';
|
|
||||||
import { GiteaCredentialProviderAdapter, GiteaTeamGrantProviderAdapter } from './gitea-provider.js';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
|
|
||||||
const credential: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'resolution-1',
|
|
||||||
secret: new TextEncoder().encode('seeded-secret-canary'),
|
|
||||||
});
|
|
||||||
|
|
||||||
function jsonResponse(body: object, status = 200): Response {
|
|
||||||
return new Response(JSON.stringify(body), {
|
|
||||||
status,
|
|
||||||
headers: { 'content-type': 'application/json;charset=utf-8' },
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
describe('Gitea credential provider transport', (): void => {
|
|
||||||
it('reads the provider identity with the fixed transport and no secret in the URL', async (): Promise<void> => {
|
|
||||||
const calls: Array<{ readonly input: string; readonly init?: RequestInit }> = [];
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (input: string | URL | Request, init?: RequestInit): Promise<Response> => {
|
|
||||||
calls.push({ input: String(input), ...(init === undefined ? {} : { init }) });
|
|
||||||
return jsonResponse({ id: 21, login: 'seat-name' });
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
const evidence = await adapter.readIdentity(credential);
|
|
||||||
|
|
||||||
expect(evidence).toEqual({
|
|
||||||
login: 'seat-name',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json;charset=utf-8',
|
|
||||||
});
|
|
||||||
expect(calls[0]?.input).toBe('https://git.example.invalid/api/v1/user');
|
|
||||||
expect(calls[0]?.input).not.toContain('seeded-secret-canary');
|
|
||||||
expect(new Headers(calls[0]?.init?.headers).get('user-agent')).toBe('mosaic-cred/1');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('maps the authenticated provider repository object to effective permission', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
jsonResponse({
|
|
||||||
id: 99,
|
|
||||||
full_name: 'owner/repo',
|
|
||||||
permissions: { admin: false, push: true, pull: true },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
|
|
||||||
const evidence = await adapter.readRepositoryPermission(credential, 'owner/repo');
|
|
||||||
|
|
||||||
expect(evidence.effective).toBe('write');
|
|
||||||
expect(evidence.endpoint).toBe('GET /api/v1/repos/owner/repo');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('binds an authenticated receive-pack advertisement to the supplied credential handle', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response('001f# service=git-receive-pack\n0000', {
|
|
||||||
status: 200,
|
|
||||||
headers: {
|
|
||||||
'content-type': 'application/x-git-receive-pack-advertisement',
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
|
|
||||||
const evidence = await adapter.probeReceivePack(credential, 'owner/repo');
|
|
||||||
|
|
||||||
expect(evidence).toEqual({
|
|
||||||
state: 'advertised',
|
|
||||||
principal: 'seat-name',
|
|
||||||
resolutionId: 'resolution-1',
|
|
||||||
contentType: 'application/x-git-receive-pack-advertisement',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('reports authenticated and unauthenticated receive-pack refusals without inventing success', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response('denied', { status: 403, headers: { 'content-type': 'text/plain' } }),
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.probeReceivePack(credential, 'owner/repo')).resolves.toMatchObject({
|
|
||||||
state: 'refused',
|
|
||||||
principal: 'seat-name',
|
|
||||||
resolutionId: 'resolution-1',
|
|
||||||
});
|
|
||||||
await expect(adapter.probeReceivePack(undefined, 'owner/repo')).resolves.toMatchObject({
|
|
||||||
state: 'refused',
|
|
||||||
principal: null,
|
|
||||||
resolutionId: null,
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('does not call a scope-forbidden identity read a dead credential', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> => jsonResponse({ message: 'forbidden' }, 403),
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readIdentity(credential)).rejects.toMatchObject({
|
|
||||||
code: 'identity-read-forbidden',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('classifies only the supplied credential as rejected without inferring identity absence', async (): Promise<void> => {
|
|
||||||
let calls = 0;
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> => {
|
|
||||||
calls += 1;
|
|
||||||
return jsonResponse({ message: 'unauthorized' }, 401);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readIdentity(credential)).rejects.toMatchObject({
|
|
||||||
code: 'credential-rejected',
|
|
||||||
});
|
|
||||||
expect(calls).toBe(1);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('classifies a rejected credential separately when the declared identity exists', async (): Promise<void> => {
|
|
||||||
let call = 0;
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> => {
|
|
||||||
call += 1;
|
|
||||||
if (call === 1) return jsonResponse({ message: 'unauthorized' }, 401);
|
|
||||||
return jsonResponse({ id: 21, login: 'seat-name' });
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readIdentity(credential)).rejects.toMatchObject({
|
|
||||||
code: 'credential-rejected',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('cancels an undeclared oversized streaming provider response before buffering it all', async (): Promise<void> => {
|
|
||||||
let pulls = 0;
|
|
||||||
let cancelled = false;
|
|
||||||
const stream = new ReadableStream<Uint8Array>({
|
|
||||||
pull(controller): void {
|
|
||||||
pulls += 1;
|
|
||||||
controller.enqueue(new Uint8Array(64 * 1024));
|
|
||||||
if (pulls === 100) controller.close();
|
|
||||||
},
|
|
||||||
cancel(): void {
|
|
||||||
cancelled = true;
|
|
||||||
},
|
|
||||||
});
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response(stream, { status: 200, headers: { 'content-type': 'application/json' } }),
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readIdentity(credential)).rejects.toMatchObject({
|
|
||||||
code: 'unexpected-provider-shape',
|
|
||||||
});
|
|
||||||
expect(pulls).toBeLessThan(100);
|
|
||||||
expect(cancelled).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a 200 HTML identity response as unexpected content type', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> =>
|
|
||||||
new Response('<html>not an API object</html>', {
|
|
||||||
status: 200,
|
|
||||||
headers: { 'content-type': 'text/html' },
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readIdentity(credential)).rejects.toMatchObject({
|
|
||||||
code: 'unexpected-content-type',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('reads team permission, member attachment, and repository attachment separately', async (): Promise<void> => {
|
|
||||||
let memberRemoved = false;
|
|
||||||
let repositoryDetached = false;
|
|
||||||
const adapter = new GiteaTeamGrantProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (input: string | URL | Request, init?: RequestInit): Promise<Response> => {
|
|
||||||
const url = String(input);
|
|
||||||
if (url.endsWith('/api/v1/orgs/owner/teams')) {
|
|
||||||
return jsonResponse([{ id: 7, name: 'writers', permission: 'write' }]);
|
|
||||||
}
|
|
||||||
if (init?.method === 'PUT') return new Response(null, { status: 204 });
|
|
||||||
if (init?.method === 'DELETE') {
|
|
||||||
if (url.includes('/members/')) memberRemoved = true;
|
|
||||||
if (url.includes('/repos/')) repositoryDetached = true;
|
|
||||||
return new Response(null, { status: 204 });
|
|
||||||
}
|
|
||||||
if (url.includes('/members/seat-name')) {
|
|
||||||
return jsonResponse({ id: 21, login: 'seat-name' });
|
|
||||||
}
|
|
||||||
if (url.includes('/repos/owner/repo')) {
|
|
||||||
return jsonResponse({
|
|
||||||
id: 4,
|
|
||||||
full_name: 'owner/repo',
|
|
||||||
permissions: { admin: false, push: true, pull: true },
|
|
||||||
});
|
|
||||||
}
|
|
||||||
return jsonResponse({ message: 'unexpected' }, 500);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
const team = await adapter.resolveTeam(credential, 'owner', 'writers');
|
|
||||||
await adapter.addTeamMember(credential, team.id, 'seat-name');
|
|
||||||
await adapter.attachTeamRepository(credential, team.id, 'owner/repo');
|
|
||||||
await expect(adapter.readTeamMember(credential, team.id, 'seat-name')).resolves.toMatchObject({
|
|
||||||
state: 'present',
|
|
||||||
});
|
|
||||||
await expect(
|
|
||||||
adapter.readTeamRepository(credential, team.id, 'owner/repo'),
|
|
||||||
).resolves.toMatchObject({ state: 'present' });
|
|
||||||
await adapter.removeTeamMember(credential, team.id, 'seat-name');
|
|
||||||
await adapter.detachTeamRepository(credential, team.id, 'owner/repo');
|
|
||||||
expect(memberRemoved).toBe(true);
|
|
||||||
expect(repositoryDetached).toBe(true);
|
|
||||||
expect(team).toMatchObject({ id: 7, name: 'writers', permission: 'write' });
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rejects a successful team read-back that names the wrong object', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaTeamGrantProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> => jsonResponse({ id: 99, login: 'other-seat' }),
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readTeamMember(credential, 7, 'seat-name')).rejects.toMatchObject({
|
|
||||||
code: 'unexpected-provider-shape',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('bounds a provider that never returns response headers', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (_input: string | URL | Request, init?: RequestInit): Promise<Response> =>
|
|
||||||
new Promise<Response>((_resolve, reject): void => {
|
|
||||||
init?.signal?.addEventListener('abort', (): void => {
|
|
||||||
reject(new Error('aborted'));
|
|
||||||
});
|
|
||||||
}),
|
|
||||||
10,
|
|
||||||
);
|
|
||||||
|
|
||||||
await expect(adapter.readIdentity(credential)).rejects.toMatchObject({
|
|
||||||
code: 'provider-unavailable',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('never includes seeded secret material in provider error messages', async (): Promise<void> => {
|
|
||||||
const adapter = new GiteaCredentialProviderAdapter(
|
|
||||||
'https://git.example.invalid',
|
|
||||||
async (): Promise<Response> => {
|
|
||||||
throw new Error('connection reset');
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
let message = '';
|
|
||||||
try {
|
|
||||||
await adapter.readIdentity(credential);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
message = error instanceof Error ? error.message : String(error);
|
|
||||||
}
|
|
||||||
expect(message).not.toContain('seeded-secret-canary');
|
|
||||||
expect(message).toContain('provider-unavailable');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,943 +0,0 @@
|
|||||||
import { z } from 'zod';
|
|
||||||
import type { GiteaCredentialProvider, ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
import type { GiteaGrantProvider } from './grant.js';
|
|
||||||
import type { GiteaLifecycleProvider, MintedToken } from './lifecycle.js';
|
|
||||||
import type { TokenObjectEvidenceDto } from './lifecycle.dto.js';
|
|
||||||
import type {
|
|
||||||
GiteaTeamGrantProvider,
|
|
||||||
PresenceEvidence,
|
|
||||||
TeamRepositorySetEvidence,
|
|
||||||
TeamResolutionEvidence,
|
|
||||||
} from './team-grant.js';
|
|
||||||
import type {
|
|
||||||
CollaboratorPermissionEvidenceDto,
|
|
||||||
OrganizationMembershipEvidenceDto,
|
|
||||||
} from './grant.dto.js';
|
|
||||||
import type {
|
|
||||||
ProviderIdentityEvidenceDto,
|
|
||||||
ReceivePackEvidenceDto,
|
|
||||||
RepositoryPermission,
|
|
||||||
RepositoryPermissionEvidenceDto,
|
|
||||||
} from './credential-result.dto.js';
|
|
||||||
|
|
||||||
const MAX_PROVIDER_BYTES = 1024 * 1024;
|
|
||||||
const USER_AGENT = 'mosaic-cred/1';
|
|
||||||
const JSON_CONTENT_TYPE = 'application/json';
|
|
||||||
const RECEIVE_PACK_CONTENT_TYPE = 'application/x-git-receive-pack-advertisement';
|
|
||||||
const REPO_COMPONENT = /^[A-Za-z0-9_.-]+$/;
|
|
||||||
|
|
||||||
type FetchLike = (input: string | URL | Request, init?: RequestInit) => Promise<Response>;
|
|
||||||
|
|
||||||
const userSchema = z
|
|
||||||
.object({
|
|
||||||
id: z.number().int(),
|
|
||||||
login: z.string().min(1),
|
|
||||||
is_admin: z.boolean().optional(),
|
|
||||||
visibility: z.enum(['public', 'limited', 'private']).optional(),
|
|
||||||
})
|
|
||||||
.passthrough();
|
|
||||||
|
|
||||||
const collaboratorPermissionSchema = z
|
|
||||||
.object({
|
|
||||||
permission: z.enum(['read', 'write', 'admin']),
|
|
||||||
user: z.object({ login: z.string().min(1) }).passthrough(),
|
|
||||||
})
|
|
||||||
.passthrough();
|
|
||||||
|
|
||||||
const organizationSchema = z.object({ username: z.string().min(1) }).passthrough();
|
|
||||||
const tokenObjectSchema = z
|
|
||||||
.object({
|
|
||||||
name: z.string().min(1),
|
|
||||||
sha1: z.string().min(1).optional(),
|
|
||||||
token: z.string().min(1).optional(),
|
|
||||||
scopes: z.array(z.string()).default([]),
|
|
||||||
})
|
|
||||||
.passthrough();
|
|
||||||
const teamSchema = z
|
|
||||||
.object({
|
|
||||||
id: z.number().int().positive(),
|
|
||||||
name: z.string().min(1),
|
|
||||||
permission: z.enum(['read', 'write', 'admin']),
|
|
||||||
})
|
|
||||||
.passthrough();
|
|
||||||
|
|
||||||
const repoSchema = z
|
|
||||||
.object({
|
|
||||||
id: z.number().int(),
|
|
||||||
full_name: z.string().min(3),
|
|
||||||
permissions: z
|
|
||||||
.object({
|
|
||||||
admin: z.boolean(),
|
|
||||||
push: z.boolean(),
|
|
||||||
pull: z.boolean(),
|
|
||||||
})
|
|
||||||
.strict(),
|
|
||||||
})
|
|
||||||
.passthrough();
|
|
||||||
|
|
||||||
export class CredentialProviderEvidenceError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
message: string,
|
|
||||||
) {
|
|
||||||
super(`Gitea credential evidence unavailable: code=${code} ${message}`);
|
|
||||||
this.name = 'CredentialProviderEvidenceError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function contentType(response: Response): string {
|
|
||||||
return response.headers.get('content-type') ?? '';
|
|
||||||
}
|
|
||||||
|
|
||||||
function isJson(response: Response): boolean {
|
|
||||||
return contentType(response).toLowerCase().startsWith(JSON_CONTENT_TYPE);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function boundedBody(response: Response): Promise<Uint8Array> {
|
|
||||||
const declared = response.headers.get('content-length');
|
|
||||||
if (declared !== null) {
|
|
||||||
if (!/^\d+$/.test(declared)) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider response declared an invalid content length',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const bytes = Number(declared);
|
|
||||||
if (!Number.isSafeInteger(bytes) || bytes > MAX_PROVIDER_BYTES) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider response exceeded the bounded size',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if (response.body === null) return new Uint8Array();
|
|
||||||
const reader = response.body.getReader();
|
|
||||||
const chunks: Uint8Array[] = [];
|
|
||||||
let total = 0;
|
|
||||||
try {
|
|
||||||
for (;;) {
|
|
||||||
const next = await reader.read();
|
|
||||||
if (next.done) break;
|
|
||||||
total += next.value.byteLength;
|
|
||||||
if (total > MAX_PROVIDER_BYTES) {
|
|
||||||
await reader.cancel();
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider response exceeded the bounded size',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
chunks.push(next.value);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
reader.releaseLock();
|
|
||||||
}
|
|
||||||
if (declared !== null && total !== Number(declared)) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider response length contradicted its declaration',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const body = new Uint8Array(total);
|
|
||||||
let offset = 0;
|
|
||||||
for (const chunk of chunks) {
|
|
||||||
body.set(chunk, offset);
|
|
||||||
offset += chunk.byteLength;
|
|
||||||
}
|
|
||||||
return body;
|
|
||||||
}
|
|
||||||
|
|
||||||
async function jsonObject(response: Response): Promise<unknown> {
|
|
||||||
if (!isJson(response)) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-content-type',
|
|
||||||
'provider response was not JSON',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const bytes = await boundedBody(response);
|
|
||||||
try {
|
|
||||||
return JSON.parse(new TextDecoder('utf-8', { fatal: true }).decode(bytes));
|
|
||||||
} catch {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider JSON could not be parsed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function tokenText(resolved: ResolvedCredential): string {
|
|
||||||
try {
|
|
||||||
return new TextDecoder('utf-8', { fatal: true }).decode(resolved.secret);
|
|
||||||
} catch {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'credential bytes were not valid text',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function apiAuthorization(resolved: ResolvedCredential): string {
|
|
||||||
return `token ${tokenText(resolved)}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function gitAuthorization(resolved: ResolvedCredential): string {
|
|
||||||
const basic = Buffer.from(`${resolved.identity}:${tokenText(resolved)}`, 'utf8').toString(
|
|
||||||
'base64',
|
|
||||||
);
|
|
||||||
return `Basic ${basic}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function repoPath(repo: string): { readonly owner: string; readonly name: string } {
|
|
||||||
const pieces = repo.split('/');
|
|
||||||
const owner = pieces[0];
|
|
||||||
const name = pieces[1];
|
|
||||||
if (
|
|
||||||
pieces.length !== 2 ||
|
|
||||||
owner === undefined ||
|
|
||||||
name === undefined ||
|
|
||||||
!REPO_COMPONENT.test(owner) ||
|
|
||||||
!REPO_COMPONENT.test(name)
|
|
||||||
) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'repository must be exactly owner/name in the allowlist grammar',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return { owner, name };
|
|
||||||
}
|
|
||||||
|
|
||||||
function effectivePermission(permissions: {
|
|
||||||
readonly admin: boolean;
|
|
||||||
readonly push: boolean;
|
|
||||||
readonly pull: boolean;
|
|
||||||
}): RepositoryPermission {
|
|
||||||
if (permissions.admin) return 'admin';
|
|
||||||
if (permissions.push) return 'write';
|
|
||||||
if (permissions.pull) return 'read';
|
|
||||||
return 'none';
|
|
||||||
}
|
|
||||||
|
|
||||||
export class GiteaCredentialProviderAdapter implements GiteaCredentialProvider {
|
|
||||||
protected readonly origin: string;
|
|
||||||
|
|
||||||
constructor(
|
|
||||||
apiBaseUrl: string,
|
|
||||||
private readonly fetchImpl: FetchLike = fetch,
|
|
||||||
private readonly requestTimeoutMs = 10_000,
|
|
||||||
) {
|
|
||||||
const parsed = new URL(apiBaseUrl);
|
|
||||||
this.origin = parsed.origin;
|
|
||||||
if (
|
|
||||||
!Number.isSafeInteger(requestTimeoutMs) ||
|
|
||||||
requestTimeoutMs < 1 ||
|
|
||||||
requestTimeoutMs > 30_000
|
|
||||||
) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'invalid-input',
|
|
||||||
'provider request timeout is outside the bounded range',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
protected async request(url: string, init: RequestInit): Promise<Response> {
|
|
||||||
const deadline = AbortSignal.timeout(this.requestTimeoutMs);
|
|
||||||
const signal = init.signal == null ? deadline : AbortSignal.any([init.signal, deadline]);
|
|
||||||
try {
|
|
||||||
return await this.fetchImpl(url, { ...init, signal });
|
|
||||||
} catch {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
'provider request failed before evidence was available',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
private async classifyRejectedIdentity(rejected: Response): Promise<never> {
|
|
||||||
if (!isJson(rejected)) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-content-type',
|
|
||||||
'provider credential rejection was not JSON',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const status = rejected.status;
|
|
||||||
await boundedBody(rejected);
|
|
||||||
if (status === 403 || status === 404) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'identity-read-forbidden',
|
|
||||||
'provider denied the identity endpoint; credential capability must be tested in scope',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'credential-rejected',
|
|
||||||
'provider rejected the supplied credential; account existence was not inferred',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
async readIdentity(resolved: ResolvedCredential): Promise<ProviderIdentityEvidenceDto> {
|
|
||||||
const endpoint = 'GET /api/v1/user';
|
|
||||||
const response = await this.request(`${this.origin}/api/v1/user`, {
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: apiAuthorization(resolved),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
});
|
|
||||||
if (response.status === 401 || response.status === 403 || response.status === 404) {
|
|
||||||
return this.classifyRejectedIdentity(response);
|
|
||||||
}
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
`provider identity request returned HTTP ${response.status.toString()}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = userSchema.safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider identity object lacked required fields',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
login: parsed.data.login,
|
|
||||||
endpoint,
|
|
||||||
contentType: contentType(response),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async readRepositoryPermission(
|
|
||||||
resolved: ResolvedCredential,
|
|
||||||
repo: string,
|
|
||||||
): Promise<RepositoryPermissionEvidenceDto> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
const endpoint = `GET /api/v1/repos/${owner}/${name}`;
|
|
||||||
const response = await this.request(`${this.origin}/api/v1/repos/${owner}/${name}`, {
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: apiAuthorization(resolved),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
});
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
`provider repository request returned HTTP ${response.status.toString()}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = repoSchema.safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success || parsed.data.full_name !== repo) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'provider repository object did not identify the requested repository',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
effective: effectivePermission(parsed.data.permissions),
|
|
||||||
endpoint,
|
|
||||||
contentType: contentType(response),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async probeReceivePack(
|
|
||||||
resolved: ResolvedCredential | undefined,
|
|
||||||
repo: string,
|
|
||||||
): Promise<ReceivePackEvidenceDto> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
const headers = new Headers({
|
|
||||||
Accept: RECEIVE_PACK_CONTENT_TYPE,
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
});
|
|
||||||
if (resolved !== undefined) headers.set('Authorization', gitAuthorization(resolved));
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/${owner}/${name}.git/info/refs?service=git-receive-pack`,
|
|
||||||
{ method: 'GET', headers },
|
|
||||||
);
|
|
||||||
const responseType = contentType(response);
|
|
||||||
if (response.status === 401 || response.status === 403) {
|
|
||||||
await boundedBody(response);
|
|
||||||
return {
|
|
||||||
state: 'refused',
|
|
||||||
principal: resolved?.identity ?? null,
|
|
||||||
resolutionId: resolved?.resolutionId ?? null,
|
|
||||||
contentType: responseType,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
if (!response.ok || !responseType.toLowerCase().startsWith(RECEIVE_PACK_CONTENT_TYPE)) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
response.ok ? 'unexpected-content-type' : 'provider-unavailable',
|
|
||||||
`receive-pack response was not an advertisement (HTTP ${response.status.toString()})`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const body = new TextDecoder('utf-8', { fatal: true }).decode(await boundedBody(response));
|
|
||||||
if (!body.includes('# service=git-receive-pack')) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'receive-pack advertisement lacked the protocol service preamble',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
state: 'advertised',
|
|
||||||
principal: resolved?.identity ?? null,
|
|
||||||
resolutionId: resolved?.resolutionId ?? null,
|
|
||||||
contentType: responseType,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export class GiteaGrantProviderAdapter
|
|
||||||
extends GiteaCredentialProviderAdapter
|
|
||||||
implements GiteaGrantProvider
|
|
||||||
{
|
|
||||||
async readBasicIdentity(authority: ResolvedCredential): Promise<ProviderIdentityEvidenceDto> {
|
|
||||||
const endpoint = 'GET /api/v1/user';
|
|
||||||
const response = await this.request(`${this.origin}/api/v1/user`, {
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
});
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'credential-rejected',
|
|
||||||
'delegated Basic authority was rejected',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = userSchema.safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'delegated Basic identity response was malformed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return { login: parsed.data.login, endpoint, contentType: contentType(response) };
|
|
||||||
}
|
|
||||||
|
|
||||||
async grantCollaborator(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
repo: string,
|
|
||||||
permission: RepositoryPermission,
|
|
||||||
): Promise<void> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/repos/${owner}/${name}/collaborators/${encodeURIComponent(identity)}`,
|
|
||||||
{
|
|
||||||
method: 'PUT',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'Content-Type': JSON_CONTENT_TYPE,
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
body: JSON.stringify({ permission }),
|
|
||||||
},
|
|
||||||
);
|
|
||||||
await boundedBody(response);
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
response.status === 401 || response.status === 403
|
|
||||||
? 'credential-rejected'
|
|
||||||
: 'provider-unavailable',
|
|
||||||
`provider grant request returned HTTP ${response.status.toString()}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async readCollaboratorPermission(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
repo: string,
|
|
||||||
): Promise<CollaboratorPermissionEvidenceDto> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
const endpoint = `GET /api/v1/repos/${owner}/${name}/collaborators/${identity}/permission`;
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/repos/${owner}/${name}/collaborators/${encodeURIComponent(identity)}/permission`,
|
|
||||||
{
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'readback-missing',
|
|
||||||
`collaborator permission read-back returned HTTP ${response.status.toString()}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = collaboratorPermissionSchema.safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success || parsed.data.user.login !== identity) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'collaborator permission object did not identify the declared subject',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
identity: parsed.data.user.login,
|
|
||||||
permission: parsed.data.permission,
|
|
||||||
endpoint,
|
|
||||||
contentType: contentType(response),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async readOrganizationMembership(
|
|
||||||
subject: ResolvedCredential,
|
|
||||||
organization: string,
|
|
||||||
): Promise<OrganizationMembershipEvidenceDto> {
|
|
||||||
const endpoint = `GET /api/v1/users/${subject.identity}/orgs`;
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/users/${encodeURIComponent(subject.identity)}/orgs`,
|
|
||||||
{
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: apiAuthorization(subject),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
response.status === 401 || response.status === 403
|
|
||||||
? 'scope-not-evaluable'
|
|
||||||
: 'provider-unavailable',
|
|
||||||
`organization membership read-back returned HTTP ${response.status.toString()}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = z.array(organizationSchema).safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'organization membership response was not an organization array',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
state: parsed.data.some((entry): boolean => entry.username === organization)
|
|
||||||
? 'present'
|
|
||||||
: 'absent',
|
|
||||||
endpoint,
|
|
||||||
contentType: contentType(response),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export class GiteaTeamGrantProviderAdapter
|
|
||||||
extends GiteaGrantProviderAdapter
|
|
||||||
implements GiteaTeamGrantProvider
|
|
||||||
{
|
|
||||||
async resolveTeam(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
organization: string,
|
|
||||||
team: string,
|
|
||||||
): Promise<TeamResolutionEvidence> {
|
|
||||||
const endpoint = `GET /api/v1/orgs/${organization}/teams`;
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/orgs/${encodeURIComponent(organization)}/teams`,
|
|
||||||
{
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
'team list was unavailable',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = z.array(teamSchema).safeParse(await jsonObject(response));
|
|
||||||
const matches = parsed.success
|
|
||||||
? parsed.data.filter((entry): boolean => entry.name === team)
|
|
||||||
: [];
|
|
||||||
if (matches.length !== 1 || matches[0] === undefined) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'readback-missing',
|
|
||||||
'team did not resolve uniquely',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return { ...matches[0], endpoint, contentType: contentType(response) };
|
|
||||||
}
|
|
||||||
|
|
||||||
async listTeamRepositories(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
): Promise<TeamRepositorySetEvidence> {
|
|
||||||
const endpoint = `GET /api/v1/teams/${teamId.toString()}/repos`;
|
|
||||||
const repositories: string[] = [];
|
|
||||||
let observedType = '';
|
|
||||||
for (let page = 1; page <= 100; page += 1) {
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/teams/${teamId.toString()}/repos?limit=50&page=${page.toString()}`,
|
|
||||||
{
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'readback-missing',
|
|
||||||
'team repository set was unavailable',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
observedType = contentType(response);
|
|
||||||
const parsed = z.array(repoSchema).safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'team repository set was not a repository array',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
repositories.push(...parsed.data.map((repo): string => repo.full_name));
|
|
||||||
if (parsed.data.length < 50) {
|
|
||||||
return { repositories, endpoint, contentType: observedType };
|
|
||||||
}
|
|
||||||
}
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'readback-missing',
|
|
||||||
'team repository set exceeded the pagination bound',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
async addTeamMember(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
identity: string,
|
|
||||||
): Promise<void> {
|
|
||||||
await this.putTeamPath(
|
|
||||||
authority,
|
|
||||||
`/api/v1/teams/${teamId.toString()}/members/${encodeURIComponent(identity)}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
async removeTeamMember(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
identity: string,
|
|
||||||
): Promise<void> {
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/teams/${teamId.toString()}/members/${encodeURIComponent(identity)}`,
|
|
||||||
{
|
|
||||||
method: 'DELETE',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
await boundedBody(response);
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
'team member rollback failed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async attachTeamRepository(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
repo: string,
|
|
||||||
): Promise<void> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
await this.putTeamPath(authority, `/api/v1/teams/${teamId.toString()}/repos/${owner}/${name}`);
|
|
||||||
}
|
|
||||||
|
|
||||||
async detachTeamRepository(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
repo: string,
|
|
||||||
): Promise<void> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/teams/${teamId.toString()}/repos/${owner}/${name}`,
|
|
||||||
{
|
|
||||||
method: 'DELETE',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
await boundedBody(response);
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
'team repository rollback failed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
private async putTeamPath(authority: ResolvedCredential, path: string): Promise<void> {
|
|
||||||
const response = await this.request(`${this.origin}${path}`, {
|
|
||||||
method: 'PUT',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
});
|
|
||||||
await boundedBody(response);
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'provider-unavailable',
|
|
||||||
'team grant mutation failed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async readTeamMember(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
identity: string,
|
|
||||||
): Promise<PresenceEvidence> {
|
|
||||||
return this.readPresence(
|
|
||||||
authority,
|
|
||||||
`GET /api/v1/teams/${teamId.toString()}/members/${encodeURIComponent(identity)}`,
|
|
||||||
(value: unknown): boolean => {
|
|
||||||
const parsed = userSchema.safeParse(value);
|
|
||||||
return parsed.success && parsed.data.login === identity;
|
|
||||||
},
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
async readTeamRepository(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
repo: string,
|
|
||||||
): Promise<PresenceEvidence> {
|
|
||||||
const { owner, name } = repoPath(repo);
|
|
||||||
return this.readPresence(
|
|
||||||
authority,
|
|
||||||
`GET /api/v1/teams/${teamId.toString()}/repos/${owner}/${name}`,
|
|
||||||
(value: unknown): boolean => {
|
|
||||||
const parsed = repoSchema.safeParse(value);
|
|
||||||
return parsed.success && parsed.data.full_name === repo;
|
|
||||||
},
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
private async readPresence(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
endpoint: string,
|
|
||||||
matchesExpectedObject: (value: unknown) => boolean,
|
|
||||||
): Promise<PresenceEvidence> {
|
|
||||||
const response = await this.request(`${this.origin}${endpoint.slice(4)}`, {
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
});
|
|
||||||
if (response.status === 404) {
|
|
||||||
await boundedBody(response);
|
|
||||||
return { state: 'absent', endpoint, contentType: contentType(response) };
|
|
||||||
}
|
|
||||||
if (!response.ok || !isJson(response)) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError('readback-missing', 'team read-back failed');
|
|
||||||
}
|
|
||||||
if (!matchesExpectedObject(await jsonObject(response))) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'team read-back did not identify the requested object',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return { state: 'present', endpoint, contentType: contentType(response) };
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function basicAuthorization(authority: ResolvedCredential): string {
|
|
||||||
const prefix = Buffer.from(`${authority.identity}:`, 'utf8');
|
|
||||||
const material = Buffer.concat([prefix, Buffer.from(authority.secret)]);
|
|
||||||
try {
|
|
||||||
return `Basic ${material.toString('base64')}`;
|
|
||||||
} finally {
|
|
||||||
prefix.fill(0);
|
|
||||||
material.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export class GiteaLifecycleProviderAdapter
|
|
||||||
extends GiteaCredentialProviderAdapter
|
|
||||||
implements GiteaLifecycleProvider
|
|
||||||
{
|
|
||||||
async readBasicIdentity(authority: ResolvedCredential): Promise<ProviderIdentityEvidenceDto> {
|
|
||||||
const endpoint = 'GET /api/v1/user';
|
|
||||||
const response = await this.request(`${this.origin}/api/v1/user`, {
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
});
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'credential-rejected',
|
|
||||||
'delegated Basic authority was rejected',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = userSchema.safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'delegated Basic identity response was malformed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return { login: parsed.data.login, endpoint, contentType: contentType(response) };
|
|
||||||
}
|
|
||||||
|
|
||||||
async mintToken(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
name: string,
|
|
||||||
scopes: readonly string[],
|
|
||||||
): Promise<MintedToken> {
|
|
||||||
const endpoint = `POST /api/v1/users/${identity}/tokens`;
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/users/${encodeURIComponent(identity)}/tokens`,
|
|
||||||
{
|
|
||||||
method: 'POST',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
'Content-Type': JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
body: JSON.stringify({ name, scopes }),
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError('provider-unavailable', 'token mint failed');
|
|
||||||
}
|
|
||||||
const parsed = tokenObjectSchema.safeParse(await jsonObject(response));
|
|
||||||
const secret = parsed.success ? (parsed.data.sha1 ?? parsed.data.token) : undefined;
|
|
||||||
if (!parsed.success || secret === undefined || parsed.data.name !== name) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'minted token object lacked the requested name or secret',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
secret: new TextEncoder().encode(secret),
|
|
||||||
evidence: {
|
|
||||||
name: parsed.data.name,
|
|
||||||
scopes: parsed.data.scopes,
|
|
||||||
endpoint,
|
|
||||||
contentType: contentType(response),
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async readToken(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
name: string,
|
|
||||||
): Promise<TokenObjectEvidenceDto> {
|
|
||||||
const endpoint = `GET /api/v1/users/${identity}/tokens`;
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/users/${encodeURIComponent(identity)}/tokens`,
|
|
||||||
{
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError('readback-missing', 'token list read-back failed');
|
|
||||||
}
|
|
||||||
const parsed = z.array(tokenObjectSchema).safeParse(await jsonObject(response));
|
|
||||||
const matches = parsed.success
|
|
||||||
? parsed.data.filter((token): boolean => token.name === name)
|
|
||||||
: [];
|
|
||||||
if (matches.length !== 1 || matches[0] === undefined) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'readback-missing',
|
|
||||||
'minted token did not resolve uniquely by name',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
name: matches[0].name,
|
|
||||||
scopes: matches[0].scopes,
|
|
||||||
endpoint,
|
|
||||||
contentType: contentType(response),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async tokenExists(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
name: string,
|
|
||||||
): Promise<boolean> {
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/users/${encodeURIComponent(identity)}/tokens`,
|
|
||||||
{
|
|
||||||
method: 'GET',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
if (!response.ok) {
|
|
||||||
await boundedBody(response);
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'readback-missing',
|
|
||||||
'token absence read-back failed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const parsed = z.array(tokenObjectSchema).safeParse(await jsonObject(response));
|
|
||||||
if (!parsed.success) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'unexpected-provider-shape',
|
|
||||||
'token absence read-back was malformed',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return parsed.data.some((token): boolean => token.name === name);
|
|
||||||
}
|
|
||||||
|
|
||||||
async revokeToken(authority: ResolvedCredential, identity: string, name: string): Promise<void> {
|
|
||||||
const response = await this.request(
|
|
||||||
`${this.origin}/api/v1/users/${encodeURIComponent(identity)}/tokens/${encodeURIComponent(name)}`,
|
|
||||||
{
|
|
||||||
method: 'DELETE',
|
|
||||||
headers: {
|
|
||||||
Accept: JSON_CONTENT_TYPE,
|
|
||||||
Authorization: basicAuthorization(authority),
|
|
||||||
'User-Agent': USER_AGENT,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
await boundedBody(response);
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new CredentialProviderEvidenceError('mutation-state-unknown', 'token revoke failed');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
import type {
|
|
||||||
CredentialAuditResultDto,
|
|
||||||
CredentialMutationState,
|
|
||||||
CredentialOutcome,
|
|
||||||
CredentialReasonDto,
|
|
||||||
CredentialSubjectDto,
|
|
||||||
CredentialValidationEvidenceDto,
|
|
||||||
RepositoryPermission,
|
|
||||||
} from './credential-result.dto.js';
|
|
||||||
|
|
||||||
export interface CollaboratorPermissionEvidenceDto {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly permission: RepositoryPermission;
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface OrganizationMembershipEvidenceDto {
|
|
||||||
readonly state: 'present' | 'absent';
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialGrantEvidenceDto extends CredentialValidationEvidenceDto {
|
|
||||||
readonly collaboratorPermission: CollaboratorPermissionEvidenceDto | null;
|
|
||||||
readonly organizationMembership: OrganizationMembershipEvidenceDto | null;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialGrantResultDto {
|
|
||||||
readonly schemaVersion: 1;
|
|
||||||
readonly operation: 'grant';
|
|
||||||
readonly outcome: CredentialOutcome;
|
|
||||||
readonly exitCode: 0 | 10 | 20 | 30;
|
|
||||||
readonly retryable: boolean;
|
|
||||||
readonly subject: CredentialSubjectDto;
|
|
||||||
readonly mutation: CredentialMutationState;
|
|
||||||
readonly reason: CredentialReasonDto;
|
|
||||||
readonly evidence: CredentialGrantEvidenceDto;
|
|
||||||
readonly audit: CredentialAuditResultDto;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface DirectGrantRequestDto extends CredentialSubjectDto {
|
|
||||||
readonly permission: RepositoryPermission;
|
|
||||||
readonly readOnlyControlIdentity: string;
|
|
||||||
}
|
|
||||||
@@ -1,230 +0,0 @@
|
|||||||
import { mkdtemp, readFile, rm } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it } from 'vitest';
|
|
||||||
import { listCredentialJournals } from './audit-journal.js';
|
|
||||||
import { grantDirectRepositoryPermission } from './grant.js';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
import type { GiteaGrantProvider } from './grant.js';
|
|
||||||
import type { CredentialValidationDependencies } from './validate.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
const authority: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'provisioner',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'authority',
|
|
||||||
secret: new TextEncoder().encode('authority-canary'),
|
|
||||||
});
|
|
||||||
|
|
||||||
async function stateRoot(): Promise<string> {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-grant-'));
|
|
||||||
return join(cleanup, 'state');
|
|
||||||
}
|
|
||||||
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
function validationDependencies(permission: 'read' | 'write'): CredentialValidationDependencies {
|
|
||||||
const subject: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'subject',
|
|
||||||
secret: new TextEncoder().encode('subject-canary'),
|
|
||||||
});
|
|
||||||
const control: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'read-control',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'control',
|
|
||||||
secret: new TextEncoder().encode('control-canary'),
|
|
||||||
});
|
|
||||||
return {
|
|
||||||
estateRegistry: { matches: (): boolean => true },
|
|
||||||
resolver: {
|
|
||||||
async resolve(identity: string): Promise<ResolvedCredential | undefined> {
|
|
||||||
if (identity === 'seat-name') return subject;
|
|
||||||
if (identity === 'read-control') return control;
|
|
||||||
return undefined;
|
|
||||||
},
|
|
||||||
},
|
|
||||||
provider: {
|
|
||||||
async readIdentity(resolved: ResolvedCredential) {
|
|
||||||
return {
|
|
||||||
login: resolved.identity,
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readRepositoryPermission(resolved: ResolvedCredential) {
|
|
||||||
return {
|
|
||||||
effective: resolved.identity === 'seat-name' ? permission : 'read',
|
|
||||||
endpoint: 'GET /api/v1/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async probeReceivePack(resolved: ResolvedCredential | undefined) {
|
|
||||||
const subjectWrite = resolved?.identity === 'seat-name' && permission === 'write';
|
|
||||||
return {
|
|
||||||
state: subjectWrite ? 'advertised' : 'refused',
|
|
||||||
principal: resolved?.identity ?? null,
|
|
||||||
resolutionId: resolved?.resolutionId ?? null,
|
|
||||||
contentType: subjectWrite ? 'application/x-git-receive-pack-advertisement' : 'text/plain',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
describe('direct repository grant', (): void => {
|
|
||||||
it('opens the journal before mutation and accepts only matching provider read-back', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const provider: GiteaGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async grantCollaborator(): Promise<void> {
|
|
||||||
expect((await listCredentialJournals(root))[0]?.state).toBe('open');
|
|
||||||
},
|
|
||||||
async readCollaboratorPermission() {
|
|
||||||
return {
|
|
||||||
identity: 'seat-name',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/repos/owner/repo/collaborators/seat-name/permission',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await grantDirectRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validationDependencies('write'),
|
|
||||||
{ stateRoot: root, actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
expect(result.mutation).toBe('applied');
|
|
||||||
expect(result.evidence.repositoryPermission?.effective).toBe('write');
|
|
||||||
expect(result.evidence.organizationMembership?.state).toBe('absent');
|
|
||||||
expect(result.audit.state).toBe('sealed');
|
|
||||||
const [sealed] = await listCredentialJournals(root);
|
|
||||||
const source = await readFile(sealed?.path ?? '', 'utf8');
|
|
||||||
expect(source).toContain('"phase":"mutation"');
|
|
||||||
expect(source).toContain('"decision":"collaborator-grant-applied"');
|
|
||||||
expect(source).toContain('"decision":"identity-verified"');
|
|
||||||
expect(source).toContain('"decision":"organization-member-absent"');
|
|
||||||
expect(source).toContain('"decision":"transport-write-verified"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('preserves applied mutation and journal context when post-grant read-back fails', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const provider: GiteaGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async grantCollaborator(): Promise<void> {},
|
|
||||||
async readCollaboratorPermission() {
|
|
||||||
throw new Error('read-back unavailable');
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
throw new Error('must not be reached');
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await grantDirectRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validationDependencies('write'),
|
|
||||||
{ stateRoot: root, actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.mutation).toBe('applied');
|
|
||||||
expect(result.reason.code).toBe('readback-missing');
|
|
||||||
expect(result.audit.journalId).not.toBeNull();
|
|
||||||
expect(result.audit.state).toBe('sealed');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('is indeterminate when grant read-back disagrees with the requested permission', async (): Promise<void> => {
|
|
||||||
const root = await stateRoot();
|
|
||||||
const provider: GiteaGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async grantCollaborator(): Promise<void> {},
|
|
||||||
async readCollaboratorPermission() {
|
|
||||||
return {
|
|
||||||
identity: 'seat-name',
|
|
||||||
permission: 'read',
|
|
||||||
endpoint: 'GET /api/v1/repos/owner/repo/collaborators/seat-name/permission',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await grantDirectRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validationDependencies('read'),
|
|
||||||
{ stateRoot: root, actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('permission-evidence-disagrees');
|
|
||||||
expect(result.mutation).toBe('applied');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,262 +0,0 @@
|
|||||||
import { CredentialAuditJournal, CredentialJournalError } from './audit-journal.js';
|
|
||||||
import type {
|
|
||||||
CredentialValidationDependencies,
|
|
||||||
ResolvedCredential,
|
|
||||||
} from './credential-provider.dto.js';
|
|
||||||
import type { RepositoryPermission } from './credential-result.dto.js';
|
|
||||||
import type {
|
|
||||||
CollaboratorPermissionEvidenceDto,
|
|
||||||
CredentialGrantResultDto,
|
|
||||||
DirectGrantRequestDto,
|
|
||||||
OrganizationMembershipEvidenceDto,
|
|
||||||
} from './grant.dto.js';
|
|
||||||
import { evaluateGiteaReadValidation, evaluateGiteaWriteValidation } from './validate.js';
|
|
||||||
|
|
||||||
export interface GiteaGrantProvider {
|
|
||||||
readBasicIdentity(authority: ResolvedCredential): Promise<{
|
|
||||||
readonly login: string;
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}>;
|
|
||||||
grantCollaborator(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
repo: string,
|
|
||||||
permission: RepositoryPermission,
|
|
||||||
): Promise<void>;
|
|
||||||
readCollaboratorPermission(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
repo: string,
|
|
||||||
): Promise<CollaboratorPermissionEvidenceDto>;
|
|
||||||
readOrganizationMembership(
|
|
||||||
subject: ResolvedCredential,
|
|
||||||
organization: string,
|
|
||||||
): Promise<OrganizationMembershipEvidenceDto>;
|
|
||||||
}
|
|
||||||
|
|
||||||
export class CredentialGrantExecutionError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
public readonly mutation: 'none' | 'unknown' | 'applied',
|
|
||||||
public readonly journalId: string,
|
|
||||||
) {
|
|
||||||
super(`Credential grant control failed: code=${code}`);
|
|
||||||
this.name = 'CredentialGrantExecutionError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialGrantServiceOptions {
|
|
||||||
readonly stateRoot: string;
|
|
||||||
readonly actor: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
function exitFor(outcome: CredentialGrantResultDto['outcome']): 0 | 10 | 20 | 30 {
|
|
||||||
if (outcome === 'ok') return 0;
|
|
||||||
if (outcome === 'refused') return 10;
|
|
||||||
if (outcome === 'error') return 20;
|
|
||||||
return 30;
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function grantDirectRepositoryPermission(
|
|
||||||
request: DirectGrantRequestDto,
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
grantProvider: GiteaGrantProvider,
|
|
||||||
validationDependencies: CredentialValidationDependencies,
|
|
||||||
options: CredentialGrantServiceOptions,
|
|
||||||
): Promise<CredentialGrantResultDto> {
|
|
||||||
const journal = await CredentialAuditJournal.open(options.stateRoot, {
|
|
||||||
operation: 'grant',
|
|
||||||
actor: options.actor,
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
});
|
|
||||||
await journal.recordIntent('provider-grant');
|
|
||||||
let mutation: 'none' | 'unknown' | 'applied' = 'none';
|
|
||||||
try {
|
|
||||||
const authorityIdentity = await grantProvider.readBasicIdentity(authority);
|
|
||||||
if (authorityIdentity.login !== options.actor) {
|
|
||||||
await journal.seal('refused', 'provider-identity-mismatch');
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation: 'grant',
|
|
||||||
outcome: 'refused',
|
|
||||||
exitCode: 10,
|
|
||||||
retryable: false,
|
|
||||||
subject: {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
},
|
|
||||||
mutation: 'none',
|
|
||||||
reason: {
|
|
||||||
code: 'provider-identity-mismatch',
|
|
||||||
message: 'Delegated grant authority did not authenticate as the explicit audit actor.',
|
|
||||||
},
|
|
||||||
evidence: {
|
|
||||||
providerIdentity: authorityIdentity,
|
|
||||||
tokenCapabilities: {
|
|
||||||
state: 'not-measured',
|
|
||||||
scopes: [],
|
|
||||||
source: 'runtime-not-authorized',
|
|
||||||
},
|
|
||||||
repositoryPermission: null,
|
|
||||||
writeDifferential: null,
|
|
||||||
collaboratorPermission: null,
|
|
||||||
organizationMembership: null,
|
|
||||||
},
|
|
||||||
audit: { journalId: journal.journalId(), state: 'sealed' },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: authorityIdentity.endpoint,
|
|
||||||
contentType: authorityIdentity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
mutation = 'unknown';
|
|
||||||
await grantProvider.grantCollaborator(
|
|
||||||
authority,
|
|
||||||
request.identity,
|
|
||||||
request.repo,
|
|
||||||
request.permission,
|
|
||||||
);
|
|
||||||
mutation = 'applied';
|
|
||||||
await journal.recordMutation('collaborator-grant-applied');
|
|
||||||
|
|
||||||
const collaborator = await grantProvider.readCollaboratorPermission(
|
|
||||||
authority,
|
|
||||||
request.identity,
|
|
||||||
request.repo,
|
|
||||||
);
|
|
||||||
const subject = await validationDependencies.resolver.resolve(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
);
|
|
||||||
const organization = request.repo.split('/')[0] ?? '';
|
|
||||||
const organizationMembership =
|
|
||||||
subject === undefined
|
|
||||||
? null
|
|
||||||
: await grantProvider.readOrganizationMembership(subject, organization);
|
|
||||||
const validation =
|
|
||||||
request.permission === 'read'
|
|
||||||
? await evaluateGiteaReadValidation(request, validationDependencies)
|
|
||||||
: await evaluateGiteaWriteValidation(request, validationDependencies);
|
|
||||||
|
|
||||||
if (organizationMembership !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: organizationMembership.endpoint,
|
|
||||||
contentType: organizationMembership.contentType,
|
|
||||||
decision:
|
|
||||||
organizationMembership.state === 'present'
|
|
||||||
? 'organization-member-present'
|
|
||||||
: 'organization-member-absent',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.providerIdentity !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: validation.evidence.providerIdentity.endpoint,
|
|
||||||
contentType: validation.evidence.providerIdentity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.repositoryPermission !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: validation.evidence.repositoryPermission.endpoint,
|
|
||||||
contentType: validation.evidence.repositoryPermission.contentType,
|
|
||||||
decision: `permission-${validation.evidence.repositoryPermission.effective}`,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.writeDifferential !== null) {
|
|
||||||
await journal.recordMutation('transport-write-verified');
|
|
||||||
}
|
|
||||||
|
|
||||||
const readBackMatches =
|
|
||||||
collaborator.identity === request.identity &&
|
|
||||||
collaborator.permission === request.permission &&
|
|
||||||
validation.outcome === 'ok' &&
|
|
||||||
validation.evidence.repositoryPermission?.effective === request.permission;
|
|
||||||
const outcome: CredentialGrantResultDto['outcome'] = readBackMatches ? 'ok' : 'indeterminate';
|
|
||||||
const reasonCode = readBackMatches ? 'grant-verified' : 'permission-evidence-disagrees';
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: collaborator.endpoint,
|
|
||||||
contentType: collaborator.contentType,
|
|
||||||
decision: `permission-${collaborator.permission}`,
|
|
||||||
});
|
|
||||||
await journal.seal(outcome, reasonCode);
|
|
||||||
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation: 'grant',
|
|
||||||
outcome,
|
|
||||||
exitCode: exitFor(outcome),
|
|
||||||
retryable: false,
|
|
||||||
subject: {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
},
|
|
||||||
mutation: 'applied',
|
|
||||||
reason: {
|
|
||||||
code: reasonCode,
|
|
||||||
message: readBackMatches
|
|
||||||
? 'Grant matched every required provider read-back.'
|
|
||||||
: 'Grant mutation completed but provider permission evidence disagreed.',
|
|
||||||
},
|
|
||||||
evidence: {
|
|
||||||
...validation.evidence,
|
|
||||||
collaboratorPermission: collaborator,
|
|
||||||
organizationMembership,
|
|
||||||
},
|
|
||||||
audit: { journalId: journal.journalId(), state: 'sealed' },
|
|
||||||
};
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof CredentialJournalError) {
|
|
||||||
throw new CredentialGrantExecutionError(error.code, mutation, journal.journalId());
|
|
||||||
}
|
|
||||||
const reasonCode = mutation === 'applied' ? 'readback-missing' : 'mutation-state-unknown';
|
|
||||||
try {
|
|
||||||
await journal.seal('indeterminate', reasonCode);
|
|
||||||
} catch (journalError: unknown) {
|
|
||||||
if (journalError instanceof CredentialJournalError) {
|
|
||||||
throw new CredentialGrantExecutionError(journalError.code, mutation, journal.journalId());
|
|
||||||
}
|
|
||||||
throw journalError;
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation: 'grant',
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
exitCode: 30,
|
|
||||||
retryable: false,
|
|
||||||
subject: {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
},
|
|
||||||
mutation,
|
|
||||||
reason: {
|
|
||||||
code: reasonCode,
|
|
||||||
message: 'Grant mutation state was preserved after provider evidence failed.',
|
|
||||||
},
|
|
||||||
evidence: {
|
|
||||||
providerIdentity: null,
|
|
||||||
tokenCapabilities: {
|
|
||||||
state: 'not-measured',
|
|
||||||
scopes: [],
|
|
||||||
source: 'runtime-not-authorized',
|
|
||||||
},
|
|
||||||
repositoryPermission: null,
|
|
||||||
writeDifferential: null,
|
|
||||||
collaboratorPermission: null,
|
|
||||||
organizationMembership: null,
|
|
||||||
},
|
|
||||||
audit: { journalId: journal.journalId(), state: 'sealed' },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,49 +0,0 @@
|
|||||||
import type { CredentialOutcome } from './credential-result.dto.js';
|
|
||||||
|
|
||||||
export type CredentialLifecycleOperation =
|
|
||||||
| 'provision'
|
|
||||||
| 'wire'
|
|
||||||
| 'get'
|
|
||||||
| 'whoami'
|
|
||||||
| 'list'
|
|
||||||
| 'rotate'
|
|
||||||
| 'revoke'
|
|
||||||
| 'audit';
|
|
||||||
|
|
||||||
export interface TokenObjectEvidenceDto {
|
|
||||||
readonly name: string;
|
|
||||||
readonly scopes: readonly string[];
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialLifecycleResultDto {
|
|
||||||
readonly schemaVersion: 1;
|
|
||||||
readonly operation: CredentialLifecycleOperation;
|
|
||||||
readonly outcome: CredentialOutcome;
|
|
||||||
readonly exitCode: 0 | 10 | 20 | 30;
|
|
||||||
readonly retryable: boolean;
|
|
||||||
readonly subject: {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly repo: null;
|
|
||||||
};
|
|
||||||
readonly mutation: 'none' | 'unknown' | 'applied';
|
|
||||||
readonly reason: { readonly code: string; readonly message: string };
|
|
||||||
readonly evidence: {
|
|
||||||
readonly providerIdentity: string | null;
|
|
||||||
readonly token: TokenObjectEvidenceDto | null;
|
|
||||||
readonly teaLogin: {
|
|
||||||
readonly name: string;
|
|
||||||
readonly host: string;
|
|
||||||
readonly state: 'registered' | 'not-measured';
|
|
||||||
} | null;
|
|
||||||
readonly identities: readonly string[];
|
|
||||||
readonly journalIds: readonly string[];
|
|
||||||
};
|
|
||||||
readonly audit: {
|
|
||||||
readonly journalId: string | null;
|
|
||||||
readonly state: 'not-started' | 'open' | 'sealed';
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,645 +0,0 @@
|
|||||||
import { spawnSync } from 'node:child_process';
|
|
||||||
import { mkdtemp, mkdir, rm, symlink, unlink, writeFile } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
import { CredentialAuditJournal, CredentialJournalError } from './audit-journal.js';
|
|
||||||
import { parseCredentialEstateRegistry } from './estate-registry.js';
|
|
||||||
import { FileCredentialStore } from './file-credential-store.js';
|
|
||||||
import {
|
|
||||||
acquireCredentialLifecycleLock,
|
|
||||||
CREDENTIAL_LIFECYCLE_LOCK_SECURITY_MODEL,
|
|
||||||
credentialLifecycleLocksDirectory,
|
|
||||||
provisionCredential,
|
|
||||||
revokeCredential,
|
|
||||||
type GiteaLifecycleProvider,
|
|
||||||
} from './lifecycle.js';
|
|
||||||
import { TeaLoginStore } from './tea-login-store.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
vi.restoreAllMocks();
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
async function fixture(): Promise<{
|
|
||||||
root: string;
|
|
||||||
store: FileCredentialStore;
|
|
||||||
teaStore: TeaLoginStore;
|
|
||||||
}> {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-lifecycle-'));
|
|
||||||
const tokens = join(cleanup, 'tokens');
|
|
||||||
await mkdir(tokens, { mode: 0o700 });
|
|
||||||
const registry = parseCredentialEstateRegistry(
|
|
||||||
JSON.stringify({
|
|
||||||
version: 1,
|
|
||||||
estates: [
|
|
||||||
{
|
|
||||||
name: 'homelab',
|
|
||||||
readOnlyControlIdentity: 'control',
|
|
||||||
hosts: [
|
|
||||||
{
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
provider: 'gitea',
|
|
||||||
apiBaseUrl: 'https://git.example.invalid',
|
|
||||||
tokenPrefix: 'gitea-example',
|
|
||||||
},
|
|
||||||
],
|
|
||||||
},
|
|
||||||
],
|
|
||||||
}),
|
|
||||||
);
|
|
||||||
return {
|
|
||||||
root: join(cleanup, 'state'),
|
|
||||||
store: new FileCredentialStore(tokens, registry),
|
|
||||||
teaStore: new TeaLoginStore(join(cleanup, 'tea', 'config.yml')),
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
const authority: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'basic-authority',
|
|
||||||
secret: new TextEncoder().encode('password-canary'),
|
|
||||||
});
|
|
||||||
|
|
||||||
function provider(): GiteaLifecycleProvider {
|
|
||||||
return {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return { login: 'seat', endpoint: 'GET /api/v1/user', contentType: 'application/json' };
|
|
||||||
},
|
|
||||||
async mintToken(_authority, _identity, name, scopes) {
|
|
||||||
return {
|
|
||||||
secret: new TextEncoder().encode('minted-token-canary'),
|
|
||||||
evidence: {
|
|
||||||
name,
|
|
||||||
scopes,
|
|
||||||
endpoint: 'POST /api/v1/users/seat/tokens',
|
|
||||||
contentType: 'application/json',
|
|
||||||
},
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readToken(_authority, _identity, name) {
|
|
||||||
return {
|
|
||||||
name,
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
endpoint: 'GET /api/v1/users/seat/tokens',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async revokeToken(): Promise<void> {},
|
|
||||||
async tokenExists(): Promise<boolean> {
|
|
||||||
return false;
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
describe('credential lifecycle', (): void => {
|
|
||||||
it('pins lifecycle flock as cooperative serialization rather than authorization', (): void => {
|
|
||||||
expect(CREDENTIAL_LIFECYCLE_LOCK_SECURITY_MODEL).toStrictEqual({
|
|
||||||
purpose: 'cooperative-serialization',
|
|
||||||
authorizationBoundary: 'provider-authority',
|
|
||||||
generationPreconditions: 'optimistic-cooperating-mutators',
|
|
||||||
hostileSameUidFilesystem: 'out-of-scope-deferred',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a concurrent same-identity lifecycle mutation across state roots', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
const lock = await acquireCredentialLifecycleLock('seat', 'homelab', 'git.example.invalid');
|
|
||||||
try {
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-contended',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{
|
|
||||||
stateRoot: `${root}-other`,
|
|
||||||
actor: 'seat',
|
|
||||||
lifecycleLock: {
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
async release(): Promise<void> {},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'refused',
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: 'concurrent-mutation' },
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
await lock.release();
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('keeps cooperative lifecycle locks below the validated user home, not shared tmp', (): void => {
|
|
||||||
const locksDirectory = credentialLifecycleLocksDirectory();
|
|
||||||
expect(locksDirectory).not.toMatch(/^\/tmp(?:\/|$)/);
|
|
||||||
expect(locksDirectory).toMatch(/\/\.local\/state\/mosaic\/credential-lifecycle-locks$/);
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each([
|
|
||||||
['../seat', 'homelab', 'git.example.invalid'],
|
|
||||||
['seat', '../homelab', 'git.example.invalid'],
|
|
||||||
['seat', 'homelab', '../git.example.invalid'],
|
|
||||||
])(
|
|
||||||
'rejects traversal before constructing a lifecycle lock path',
|
|
||||||
async (identity, estate, host): Promise<void> => {
|
|
||||||
await expect(acquireCredentialLifecycleLock(identity, estate, host)).rejects.toMatchObject({
|
|
||||||
code: 'mutation-lock-unavailable',
|
|
||||||
});
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('returns a structured error when the lifecycle lock path cannot be opened', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
const locksDirectory = credentialLifecycleLocksDirectory();
|
|
||||||
await mkdir(locksDirectory, { recursive: true, mode: 0o700 });
|
|
||||||
const lockPath = join(locksDirectory, 'homelab--git.example.invalid--open-failure-seat.lock');
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
await symlink('/dev/null', lockPath);
|
|
||||||
try {
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'open-failure-seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-open-failure-seat',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'open-failure-seat' },
|
|
||||||
);
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: 'mutation-lock-unavailable' },
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['provision', 'revoke'] as const)(
|
|
||||||
'returns an open structured %s result when lock failure cannot be sealed',
|
|
||||||
async (operation): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
const identity = `seal-failure-${operation}`;
|
|
||||||
const locksDirectory = credentialLifecycleLocksDirectory();
|
|
||||||
await mkdir(locksDirectory, { recursive: true, mode: 0o700 });
|
|
||||||
const lockPath = join(locksDirectory, `homelab--git.example.invalid--${identity}.lock`);
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
await symlink('/dev/null', lockPath);
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'seal').mockRejectedValue(
|
|
||||||
new CredentialJournalError('journal-recovery-required', 'injected final seal failure'),
|
|
||||||
);
|
|
||||||
try {
|
|
||||||
const result =
|
|
||||||
operation === 'provision'
|
|
||||||
? await provisionCredential(
|
|
||||||
{
|
|
||||||
identity,
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: `mosaic-${identity}`,
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
{ ...authority, identity },
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: identity },
|
|
||||||
)
|
|
||||||
: await revokeCredential(
|
|
||||||
{ identity, estate: 'homelab', host: 'git.example.invalid' },
|
|
||||||
{ ...authority, identity },
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: identity },
|
|
||||||
);
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: 'journal-recovery-required' },
|
|
||||||
audit: { state: 'open' },
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('returns a sealed structured error when the Tea pre-state cannot be snapshotted', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
await teaStore.put('seat', 'git.example.invalid', new TextEncoder().encode('prior-tea-token'));
|
|
||||||
await writeFile(join(cleanup!, 'tea', 'config.yml'), 'logins: not-an-array\n', { mode: 0o600 });
|
|
||||||
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-snapshot-failure',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: 'credential-snapshot-unavailable' },
|
|
||||||
audit: { state: 'sealed' },
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('accepts provision only after exact principal and scope read-back', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-1',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat', now: (): string => '2026-08-05T00:00:00.000Z' },
|
|
||||||
);
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
await expect(
|
|
||||||
store.readBinding('seat', 'homelab', 'git.example.invalid'),
|
|
||||||
).resolves.toMatchObject({ providerLogin: 'seat', scopes: ['write:repository'] });
|
|
||||||
expect(JSON.stringify(result)).not.toContain('minted-token-canary');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('rolls back a minted token when exact scope read-back disagrees', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
let revoked = false;
|
|
||||||
const lifecycleProvider = provider();
|
|
||||||
lifecycleProvider.readToken = async (_authority, _identity, name) => ({
|
|
||||||
name,
|
|
||||||
scopes: ['admin'],
|
|
||||||
endpoint: 'GET /api/v1/users/seat/tokens',
|
|
||||||
contentType: 'application/json',
|
|
||||||
});
|
|
||||||
lifecycleProvider.revokeToken = async (): Promise<void> => {
|
|
||||||
revoked = true;
|
|
||||||
};
|
|
||||||
lifecycleProvider.tokenExists = async (): Promise<boolean> => false;
|
|
||||||
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-bad',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
lifecycleProvider,
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('error');
|
|
||||||
expect(result.mutation).toBe('none');
|
|
||||||
expect(revoked).toBe(true);
|
|
||||||
await expect(store.list('homelab', 'git.example.invalid')).resolves.toEqual([]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['store', 'tea'] as const)(
|
|
||||||
'removes %s state committed before a post-commit storage failure',
|
|
||||||
async (target): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
if (target === 'store') {
|
|
||||||
const put = store.put.bind(store);
|
|
||||||
store.put = async (binding, secret): Promise<void> => {
|
|
||||||
await put(binding, secret);
|
|
||||||
throw new Error('injected store post-commit failure');
|
|
||||||
};
|
|
||||||
} else {
|
|
||||||
const put = teaStore.put.bind(teaStore);
|
|
||||||
teaStore.put = async (identity, host, secret): Promise<void> => {
|
|
||||||
await put(identity, host, secret);
|
|
||||||
throw new Error('injected Tea post-commit failure');
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: `mosaic-seat-${target}-fault`,
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result).toMatchObject({ outcome: 'error', mutation: 'none' });
|
|
||||||
await expect(
|
|
||||||
store.snapshot('seat', 'homelab', 'git.example.invalid'),
|
|
||||||
).resolves.toBeUndefined();
|
|
||||||
expect(teaStore.readBack('seat', 'git.example.invalid')).toBeUndefined();
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('rejects a stale lifecycle write when a competing generation bypasses serialization', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
const put = store.put.bind(store);
|
|
||||||
let injected = false;
|
|
||||||
store.put = async (binding, secret, expectedGeneration): Promise<void> => {
|
|
||||||
if (!injected) {
|
|
||||||
injected = true;
|
|
||||||
await put(
|
|
||||||
{
|
|
||||||
...binding,
|
|
||||||
tokenName: 'competing-generation',
|
|
||||||
createdAt: '2026-08-05T00:00:01.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('competing-token'),
|
|
||||||
expectedGeneration,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await put(binding, secret, expectedGeneration);
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'stale-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation: 'applied',
|
|
||||||
reason: { code: 'rollback-incomplete' },
|
|
||||||
});
|
|
||||||
const current = await store.snapshot('seat', 'homelab', 'git.example.invalid');
|
|
||||||
try {
|
|
||||||
expect(current?.binding.tokenName).toBe('competing-generation');
|
|
||||||
expect(Buffer.from(current?.secret ?? []).toString('utf8')).toBe('competing-token');
|
|
||||||
} finally {
|
|
||||||
current?.secret.fill(0);
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['absent', 'divergent'] as const)(
|
|
||||||
'restores an independently %s pre-operation Tea state exactly',
|
|
||||||
async (teaState): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
await store.put(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
providerLogin: 'seat',
|
|
||||||
tokenName: 'old-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
createdAt: '2026-08-05T00:00:00.000Z',
|
|
||||||
},
|
|
||||||
new TextEncoder().encode('old-store-token'),
|
|
||||||
);
|
|
||||||
if (teaState === 'divergent') {
|
|
||||||
await teaStore.put(
|
|
||||||
'seat',
|
|
||||||
'git.example.invalid',
|
|
||||||
new TextEncoder().encode('divergent-tea-token'),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const journal = await CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'provision',
|
|
||||||
actor: 'seat',
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
});
|
|
||||||
let evidenceWrites = 0;
|
|
||||||
const recordProviderEvidence = journal.recordProviderEvidence.bind(journal);
|
|
||||||
journal.recordProviderEvidence = async (evidence): Promise<void> => {
|
|
||||||
evidenceWrites += 1;
|
|
||||||
if (evidenceWrites === 2) throw new Error('injected post-registration failure');
|
|
||||||
await recordProviderEvidence(evidence);
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'replacement-generation',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat', journal, allowReplace: true },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result).toMatchObject({ outcome: 'error', mutation: 'none' });
|
|
||||||
if (teaState === 'absent') {
|
|
||||||
expect(teaStore.readBack('seat', 'git.example.invalid')).toBeUndefined();
|
|
||||||
} else {
|
|
||||||
expect(
|
|
||||||
teaStore.matchesSecret(
|
|
||||||
'seat',
|
|
||||||
'git.example.invalid',
|
|
||||||
new TextEncoder().encode('divergent-tea-token'),
|
|
||||||
),
|
|
||||||
).toBe(true);
|
|
||||||
}
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('reports an incomplete rollback when Tea removal cannot be verified', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
const journal = await CredentialAuditJournal.open(root, {
|
|
||||||
operation: 'provision',
|
|
||||||
actor: 'seat',
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: null,
|
|
||||||
});
|
|
||||||
let evidenceWrites = 0;
|
|
||||||
const recordProviderEvidence = journal.recordProviderEvidence.bind(journal);
|
|
||||||
journal.recordProviderEvidence = async (evidence): Promise<void> => {
|
|
||||||
evidenceWrites += 1;
|
|
||||||
if (evidenceWrites === 2) throw new Error('injected post-registration failure');
|
|
||||||
await recordProviderEvidence(evidence);
|
|
||||||
};
|
|
||||||
teaStore.restore = async (): Promise<void> => {
|
|
||||||
throw new Error('injected Tea restoration failure');
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-rollback',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat', journal },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation: 'applied',
|
|
||||||
reason: { code: 'rollback-incomplete' },
|
|
||||||
});
|
|
||||||
expect(teaStore.readBack('seat', 'git.example.invalid')).toBeDefined();
|
|
||||||
});
|
|
||||||
|
|
||||||
it('revokes at provider before removing the local binding', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-1',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
let revoked = false;
|
|
||||||
const lifecycleProvider = provider();
|
|
||||||
lifecycleProvider.revokeToken = async (): Promise<void> => {
|
|
||||||
revoked = true;
|
|
||||||
};
|
|
||||||
const result = await revokeCredential(
|
|
||||||
{ identity: 'seat', estate: 'homelab', host: 'git.example.invalid' },
|
|
||||||
authority,
|
|
||||||
lifecycleProvider,
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
expect(revoked).toBe(true);
|
|
||||||
await expect(store.list('homelab', 'git.example.invalid')).resolves.toEqual([]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('releases an internally owned journal lock after an append failure', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-lock-release',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
const recordProviderEvidence = CredentialAuditJournal.prototype.recordProviderEvidence;
|
|
||||||
CredentialAuditJournal.prototype.recordProviderEvidence = async (): Promise<void> => {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected append failure');
|
|
||||||
};
|
|
||||||
try {
|
|
||||||
const result = await revokeCredential(
|
|
||||||
{ identity: 'seat', estate: 'homelab', host: 'git.example.invalid' },
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
expect(result).toMatchObject({
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation: 'none',
|
|
||||||
audit: { state: 'open' },
|
|
||||||
});
|
|
||||||
if (result.audit.journalId === null) throw new Error('journal id was not returned');
|
|
||||||
const lockPath = join(root, 'journal-locks', `${result.audit.journalId}.lock`);
|
|
||||||
const lockProbe = spawnSync('/usr/bin/flock', ['-n', lockPath, '/bin/true']);
|
|
||||||
expect(lockProbe.status).toBe(0);
|
|
||||||
} finally {
|
|
||||||
CredentialAuditJournal.prototype.recordProviderEvidence = recordProviderEvidence;
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
it('preserves the local recovery binding when provider revocation read-back still finds the token', async (): Promise<void> => {
|
|
||||||
const { root, store, teaStore } = await fixture();
|
|
||||||
await provisionCredential(
|
|
||||||
{
|
|
||||||
identity: 'seat',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
tokenName: 'mosaic-seat-1',
|
|
||||||
scopes: ['write:repository'],
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider(),
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
const lifecycleProvider = provider();
|
|
||||||
lifecycleProvider.tokenExists = async (): Promise<boolean> => true;
|
|
||||||
const result = await revokeCredential(
|
|
||||||
{ identity: 'seat', estate: 'homelab', host: 'git.example.invalid' },
|
|
||||||
authority,
|
|
||||||
lifecycleProvider,
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
{ stateRoot: root, actor: 'seat' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
await expect(store.list('homelab', 'git.example.invalid')).resolves.toEqual(['seat']);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,736 +0,0 @@
|
|||||||
import { spawnSync } from 'node:child_process';
|
|
||||||
import { timingSafeEqual } from 'node:crypto';
|
|
||||||
import { constants, lstatSync } from 'node:fs';
|
|
||||||
import { open } from 'node:fs/promises';
|
|
||||||
import { homedir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { ensureManagedDirectory } from '../fleet/secure-file.js';
|
|
||||||
import { CredentialAuditJournal, CredentialJournalError } from './audit-journal.js';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
import { credentialBindingGeneration, type FileCredentialStore } from './file-credential-store.js';
|
|
||||||
import type { TeaLoginStore } from './tea-login-store.js';
|
|
||||||
import type {
|
|
||||||
CredentialLifecycleOperation,
|
|
||||||
CredentialLifecycleResultDto,
|
|
||||||
TokenObjectEvidenceDto,
|
|
||||||
} from './lifecycle.dto.js';
|
|
||||||
|
|
||||||
export interface MintedToken {
|
|
||||||
readonly secret: Uint8Array;
|
|
||||||
readonly evidence: TokenObjectEvidenceDto;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface GiteaLifecycleProvider {
|
|
||||||
readBasicIdentity(authority: ResolvedCredential): Promise<{
|
|
||||||
readonly login: string;
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}>;
|
|
||||||
mintToken(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
name: string,
|
|
||||||
scopes: readonly string[],
|
|
||||||
): Promise<MintedToken>;
|
|
||||||
readToken(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
identity: string,
|
|
||||||
name: string,
|
|
||||||
): Promise<TokenObjectEvidenceDto>;
|
|
||||||
revokeToken(authority: ResolvedCredential, identity: string, name: string): Promise<void>;
|
|
||||||
tokenExists(authority: ResolvedCredential, identity: string, name: string): Promise<boolean>;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface LifecycleRequest {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface ProvisionRequest extends LifecycleRequest {
|
|
||||||
readonly tokenName: string;
|
|
||||||
readonly scopes: readonly string[];
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface LifecycleOptions {
|
|
||||||
readonly stateRoot: string;
|
|
||||||
readonly actor: string;
|
|
||||||
readonly now?: () => string;
|
|
||||||
readonly allowReplace?: boolean;
|
|
||||||
readonly journal?: CredentialAuditJournal;
|
|
||||||
readonly deferSuccessSeal?: boolean;
|
|
||||||
readonly lifecycleLock?: CredentialLifecycleLock;
|
|
||||||
readonly expectedStoreGeneration?: string | null;
|
|
||||||
readonly expectedTeaGeneration?: string | null;
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface CredentialLifecycleLock {
|
|
||||||
readonly identity: string;
|
|
||||||
readonly estate: string;
|
|
||||||
readonly host: string;
|
|
||||||
release(): Promise<void>;
|
|
||||||
}
|
|
||||||
|
|
||||||
const activeLifecycleLocks = new WeakSet<CredentialLifecycleLock>();
|
|
||||||
|
|
||||||
/**
|
|
||||||
* This flock coordinates cooperating `mosaic cred` processes only. A process
|
|
||||||
* sharing the Unix uid can replace the pathname/inode, so the lock is never
|
|
||||||
* authorization evidence. Provider authority is the authorization boundary;
|
|
||||||
* generation preconditions are optimistic concurrency for cooperating store
|
|
||||||
* mutators, not atomic CAS against a hostile same-uid filesystem writer.
|
|
||||||
*/
|
|
||||||
export const CREDENTIAL_LIFECYCLE_LOCK_SECURITY_MODEL = Object.freeze({
|
|
||||||
purpose: 'cooperative-serialization',
|
|
||||||
authorizationBoundary: 'provider-authority',
|
|
||||||
generationPreconditions: 'optimistic-cooperating-mutators',
|
|
||||||
hostileSameUidFilesystem: 'out-of-scope-deferred',
|
|
||||||
} as const);
|
|
||||||
|
|
||||||
export class CredentialLifecycleLockError extends Error {
|
|
||||||
constructor(public readonly code: 'concurrent-mutation' | 'mutation-lock-unavailable') {
|
|
||||||
super(code);
|
|
||||||
this.name = 'CredentialLifecycleLockError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Do not promote this advisory lock into a same-uid authorization boundary;
|
|
||||||
// CREDENTIAL_LIFECYCLE_LOCK_SECURITY_MODEL is a tested public invariant.
|
|
||||||
export function credentialLifecycleLocksDirectory(): string {
|
|
||||||
return join(homedir(), '.local', 'state', 'mosaic', 'credential-lifecycle-locks');
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function acquireCredentialLifecycleLock(
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
): Promise<CredentialLifecycleLock> {
|
|
||||||
if (
|
|
||||||
!/^[A-Za-z0-9][A-Za-z0-9_.-]*$/.test(identity) ||
|
|
||||||
!/^[A-Za-z0-9][A-Za-z0-9_.-]*$/.test(estate) ||
|
|
||||||
!/^[a-z0-9][a-z0-9.-]*$/.test(host)
|
|
||||||
) {
|
|
||||||
throw new CredentialLifecycleLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
const uid = process.getuid?.();
|
|
||||||
if (uid === undefined) throw new CredentialLifecycleLockError('mutation-lock-unavailable');
|
|
||||||
const home = homedir();
|
|
||||||
const homeDirectory = lstatSync(home);
|
|
||||||
if (
|
|
||||||
!homeDirectory.isDirectory() ||
|
|
||||||
homeDirectory.isSymbolicLink() ||
|
|
||||||
homeDirectory.uid !== uid ||
|
|
||||||
(homeDirectory.mode & 0o022) !== 0
|
|
||||||
) {
|
|
||||||
throw new CredentialLifecycleLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
const locksDirectory = credentialLifecycleLocksDirectory();
|
|
||||||
ensureManagedDirectory(home, locksDirectory);
|
|
||||||
const directory = lstatSync(locksDirectory);
|
|
||||||
if (
|
|
||||||
!directory.isDirectory() ||
|
|
||||||
directory.isSymbolicLink() ||
|
|
||||||
directory.uid !== uid ||
|
|
||||||
(directory.mode & 0o077) !== 0
|
|
||||||
) {
|
|
||||||
throw new CredentialLifecycleLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
const lockPath = join(locksDirectory, `${estate}--${host}--${identity}.lock`);
|
|
||||||
let handle: Awaited<ReturnType<typeof open>> | undefined;
|
|
||||||
try {
|
|
||||||
handle = await open(
|
|
||||||
lockPath,
|
|
||||||
constants.O_CREAT | constants.O_RDWR | constants.O_NOFOLLOW,
|
|
||||||
0o600,
|
|
||||||
);
|
|
||||||
const file = await handle.stat();
|
|
||||||
if (!file.isFile() || file.uid !== uid || (file.mode & 0o077) !== 0) {
|
|
||||||
throw new Error('credential lifecycle lock file is unsafe');
|
|
||||||
}
|
|
||||||
} catch {
|
|
||||||
await handle?.close().catch((): void => undefined);
|
|
||||||
throw new CredentialLifecycleLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
if (handle === undefined) throw new CredentialLifecycleLockError('mutation-lock-unavailable');
|
|
||||||
const acquired = spawnSync('/usr/bin/flock', ['-n', '3'], {
|
|
||||||
stdio: ['ignore', 'ignore', 'ignore', handle.fd],
|
|
||||||
});
|
|
||||||
if (acquired.error !== undefined || acquired.status !== 0) {
|
|
||||||
await handle.close().catch((): void => undefined);
|
|
||||||
throw new CredentialLifecycleLockError(
|
|
||||||
acquired.status === 1 ? 'concurrent-mutation' : 'mutation-lock-unavailable',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
let released = false;
|
|
||||||
const lock: CredentialLifecycleLock = {
|
|
||||||
identity,
|
|
||||||
estate,
|
|
||||||
host,
|
|
||||||
async release(): Promise<void> {
|
|
||||||
if (released) return;
|
|
||||||
released = true;
|
|
||||||
activeLifecycleLocks.delete(lock);
|
|
||||||
await handle.close();
|
|
||||||
},
|
|
||||||
};
|
|
||||||
activeLifecycleLocks.add(lock);
|
|
||||||
return lock;
|
|
||||||
}
|
|
||||||
|
|
||||||
function holdsCredentialLifecycleLock(
|
|
||||||
lock: CredentialLifecycleLock | undefined,
|
|
||||||
identity: string,
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
): boolean {
|
|
||||||
return (
|
|
||||||
lock !== undefined &&
|
|
||||||
activeLifecycleLocks.has(lock) &&
|
|
||||||
lock.identity === identity &&
|
|
||||||
lock.estate === estate &&
|
|
||||||
lock.host === host
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function lifecycleResult(
|
|
||||||
operation: CredentialLifecycleOperation,
|
|
||||||
request: LifecycleRequest,
|
|
||||||
options: {
|
|
||||||
readonly outcome: CredentialLifecycleResultDto['outcome'];
|
|
||||||
readonly mutation: CredentialLifecycleResultDto['mutation'];
|
|
||||||
readonly code: string;
|
|
||||||
readonly message: string;
|
|
||||||
readonly journalId: string | null;
|
|
||||||
readonly auditState: 'not-started' | 'open' | 'sealed';
|
|
||||||
readonly providerIdentity?: string | null;
|
|
||||||
readonly token?: TokenObjectEvidenceDto | null;
|
|
||||||
readonly teaLogin?: CredentialLifecycleResultDto['evidence']['teaLogin'];
|
|
||||||
},
|
|
||||||
): CredentialLifecycleResultDto {
|
|
||||||
const exits = { ok: 0, refused: 10, error: 20, indeterminate: 30 } as const;
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation,
|
|
||||||
outcome: options.outcome,
|
|
||||||
exitCode: exits[options.outcome],
|
|
||||||
retryable: false,
|
|
||||||
subject: { ...request, repo: null },
|
|
||||||
mutation: options.mutation,
|
|
||||||
reason: { code: options.code, message: options.message },
|
|
||||||
evidence: {
|
|
||||||
providerIdentity: options.providerIdentity ?? null,
|
|
||||||
token: options.token ?? null,
|
|
||||||
teaLogin: options.teaLogin ?? null,
|
|
||||||
identities: [],
|
|
||||||
journalIds: [],
|
|
||||||
},
|
|
||||||
audit: { journalId: options.journalId, state: options.auditState },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function lifecycleLockFailureResult(
|
|
||||||
operation: 'provision' | 'revoke',
|
|
||||||
request: LifecycleRequest,
|
|
||||||
journal: CredentialAuditJournal,
|
|
||||||
code: 'concurrent-mutation' | 'mutation-lock-unavailable',
|
|
||||||
): Promise<CredentialLifecycleResultDto> {
|
|
||||||
try {
|
|
||||||
await journal.seal(code === 'concurrent-mutation' ? 'refused' : 'error', code);
|
|
||||||
return lifecycleResult(operation, request, {
|
|
||||||
outcome: code === 'concurrent-mutation' ? 'refused' : 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
code,
|
|
||||||
message: 'Credential lifecycle mutation lock could not be acquired.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
} catch (sealError: unknown) {
|
|
||||||
await journal.closeIncomplete().catch((): void => undefined);
|
|
||||||
return lifecycleResult(operation, request, {
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
code: sealError instanceof CredentialJournalError ? sealError.code : 'journal-unavailable',
|
|
||||||
message: 'Mutation lock failure could not be sealed durably.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'open',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function openLifecycleJournal(
|
|
||||||
operation: 'provision' | 'rotate' | 'revoke',
|
|
||||||
request: LifecycleRequest,
|
|
||||||
options: LifecycleOptions,
|
|
||||||
): Promise<CredentialAuditJournal> {
|
|
||||||
const journal = await CredentialAuditJournal.open(options.stateRoot, {
|
|
||||||
operation,
|
|
||||||
actor: options.actor,
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: null,
|
|
||||||
});
|
|
||||||
try {
|
|
||||||
await journal.recordIntent(`${operation}-requested`);
|
|
||||||
return journal;
|
|
||||||
} catch (error: unknown) {
|
|
||||||
await journal.closeIncomplete().catch((): void => undefined);
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function provisionCredential(
|
|
||||||
request: ProvisionRequest,
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
provider: GiteaLifecycleProvider,
|
|
||||||
store: FileCredentialStore,
|
|
||||||
teaStore: TeaLoginStore,
|
|
||||||
options: LifecycleOptions,
|
|
||||||
): Promise<CredentialLifecycleResultDto> {
|
|
||||||
const ownsJournal = options.journal === undefined;
|
|
||||||
const journal = options.journal ?? (await openLifecycleJournal('provision', request, options));
|
|
||||||
let ownedLock: CredentialLifecycleLock | undefined;
|
|
||||||
if (
|
|
||||||
!holdsCredentialLifecycleLock(
|
|
||||||
options.lifecycleLock,
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
)
|
|
||||||
) {
|
|
||||||
try {
|
|
||||||
ownedLock = await acquireCredentialLifecycleLock(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
const code =
|
|
||||||
error instanceof CredentialLifecycleLockError ? error.code : 'mutation-lock-unavailable';
|
|
||||||
return lifecycleLockFailureResult('provision', request, journal, code);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
return await provisionCredentialLocked(
|
|
||||||
request,
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
store,
|
|
||||||
teaStore,
|
|
||||||
options,
|
|
||||||
journal,
|
|
||||||
);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (ownsJournal) await journal.closeIncomplete().catch((): void => undefined);
|
|
||||||
throw error;
|
|
||||||
} finally {
|
|
||||||
await ownedLock?.release();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function provisionCredentialLocked(
|
|
||||||
request: ProvisionRequest,
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
provider: GiteaLifecycleProvider,
|
|
||||||
store: FileCredentialStore,
|
|
||||||
teaStore: TeaLoginStore,
|
|
||||||
options: LifecycleOptions,
|
|
||||||
journal: CredentialAuditJournal,
|
|
||||||
): Promise<CredentialLifecycleResultDto> {
|
|
||||||
let mutation: 'none' | 'unknown' | 'applied' = 'none';
|
|
||||||
let minted: MintedToken | undefined;
|
|
||||||
let failureCode = 'mutation-state-unknown';
|
|
||||||
let mintedStoreGeneration: string | undefined;
|
|
||||||
let prior: Awaited<ReturnType<FileCredentialStore['snapshot']>> = undefined;
|
|
||||||
let priorTea: ReturnType<TeaLoginStore['snapshot']> = undefined;
|
|
||||||
try {
|
|
||||||
prior = await store.snapshot(request.identity, request.estate, request.host);
|
|
||||||
priorTea = teaStore.snapshot(request.identity, request.host);
|
|
||||||
} catch {
|
|
||||||
prior?.secret.fill(0);
|
|
||||||
priorTea?.secret.fill(0);
|
|
||||||
try {
|
|
||||||
await journal.seal('error', 'credential-snapshot-unavailable');
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
code: 'credential-snapshot-unavailable',
|
|
||||||
message: 'Pre-operation credential state could not be snapshotted safely.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
} catch (sealError: unknown) {
|
|
||||||
await journal.closeIncomplete().catch((): void => undefined);
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'error',
|
|
||||||
mutation: 'none',
|
|
||||||
code: sealError instanceof CredentialJournalError ? sealError.code : 'journal-unavailable',
|
|
||||||
message: 'Credential snapshot failure could not be sealed durably.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'open',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
(options.expectedStoreGeneration !== undefined &&
|
|
||||||
(prior?.generation ?? null) !== options.expectedStoreGeneration) ||
|
|
||||||
(options.expectedTeaGeneration !== undefined &&
|
|
||||||
(priorTea?.generation ?? null) !== options.expectedTeaGeneration)
|
|
||||||
) {
|
|
||||||
prior?.secret.fill(0);
|
|
||||||
priorTea?.secret.fill(0);
|
|
||||||
await journal.seal('refused', 'concurrent-mutation');
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'refused',
|
|
||||||
mutation: 'none',
|
|
||||||
code: 'concurrent-mutation',
|
|
||||||
message: 'Credential generation changed before the lifecycle transaction began.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (prior !== undefined && options.allowReplace !== true) {
|
|
||||||
try {
|
|
||||||
await journal.seal('refused', 'credential-already-exists');
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'refused',
|
|
||||||
mutation: 'none',
|
|
||||||
code: 'credential-already-exists',
|
|
||||||
message: 'A governed credential already exists; use rotate.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
prior.secret.fill(0);
|
|
||||||
priorTea?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
const identity = await provider.readBasicIdentity(authority);
|
|
||||||
if (identity.login !== request.identity || authority.identity !== request.identity) {
|
|
||||||
await journal.seal('refused', 'provider-identity-mismatch');
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'refused',
|
|
||||||
mutation: 'none',
|
|
||||||
code: 'provider-identity-mismatch',
|
|
||||||
message: 'Delegated Basic authority did not bind the requested principal.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
providerIdentity: identity.login,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: identity.endpoint,
|
|
||||||
contentType: identity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
mutation = 'unknown';
|
|
||||||
minted = await provider.mintToken(
|
|
||||||
authority,
|
|
||||||
request.identity,
|
|
||||||
request.tokenName,
|
|
||||||
request.scopes,
|
|
||||||
);
|
|
||||||
mutation = 'applied';
|
|
||||||
await journal.recordMutation('token-mint-applied');
|
|
||||||
const readBack = await provider.readToken(authority, request.identity, request.tokenName);
|
|
||||||
const expected = [...request.scopes].sort();
|
|
||||||
const actual = [...readBack.scopes].sort();
|
|
||||||
if (JSON.stringify(expected) !== JSON.stringify(actual)) {
|
|
||||||
failureCode = 'scope-not-evaluable';
|
|
||||||
throw new Error('scope read-back disagreed');
|
|
||||||
}
|
|
||||||
const mintedBinding = {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
providerLogin: identity.login,
|
|
||||||
tokenName: request.tokenName,
|
|
||||||
scopes: readBack.scopes,
|
|
||||||
createdAt: options.now?.() ?? new Date().toISOString(),
|
|
||||||
};
|
|
||||||
mintedStoreGeneration = credentialBindingGeneration(mintedBinding, minted.secret);
|
|
||||||
await store.put(mintedBinding, minted.secret, prior?.generation ?? null);
|
|
||||||
await journal.recordMutation('token-binding-stored');
|
|
||||||
await teaStore.put(request.identity, request.host, minted.secret, priorTea?.generation ?? null);
|
|
||||||
const teaLogin = teaStore.readBack(request.identity, request.host);
|
|
||||||
if (
|
|
||||||
teaLogin === undefined ||
|
|
||||||
!teaStore.matchesSecret(request.identity, request.host, minted.secret)
|
|
||||||
) {
|
|
||||||
failureCode = 'tea-login-missing';
|
|
||||||
throw new Error('Tea login did not resolve exactly');
|
|
||||||
}
|
|
||||||
await journal.recordMutation('tea-login-stored');
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: readBack.endpoint,
|
|
||||||
contentType: readBack.contentType,
|
|
||||||
decision: 'scope-verified',
|
|
||||||
});
|
|
||||||
if (options.deferSuccessSeal !== true) {
|
|
||||||
await journal.seal('ok', 'provision-verified');
|
|
||||||
}
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'ok',
|
|
||||||
mutation: 'applied',
|
|
||||||
code: options.deferSuccessSeal === true ? 'replacement-staged' : 'provision-verified',
|
|
||||||
message:
|
|
||||||
options.deferSuccessSeal === true
|
|
||||||
? 'Replacement was read back and staged under the open rotation transaction.'
|
|
||||||
: 'Provider principal and exact token scopes were read back and stored.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: options.deferSuccessSeal === true ? 'open' : 'sealed',
|
|
||||||
providerIdentity: identity.login,
|
|
||||||
token: readBack,
|
|
||||||
teaLogin: { ...teaLogin, state: 'registered' },
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
const journalFailure = error instanceof CredentialJournalError;
|
|
||||||
if (minted === undefined) {
|
|
||||||
if (journalFailure) throw error;
|
|
||||||
await journal.seal('indeterminate', 'provider-unavailable');
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation,
|
|
||||||
code: 'provider-unavailable',
|
|
||||||
message: 'Provider token mint did not complete.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
let rollbackComplete = false;
|
|
||||||
try {
|
|
||||||
await provider.revokeToken(authority, request.identity, request.tokenName);
|
|
||||||
if (await provider.tokenExists(authority, request.identity, request.tokenName)) {
|
|
||||||
throw new Error('minted token still exists after rollback');
|
|
||||||
}
|
|
||||||
const expectedStoreGeneration = prior?.generation ?? null;
|
|
||||||
const current = await store.snapshot(request.identity, request.estate, request.host);
|
|
||||||
try {
|
|
||||||
if ((current?.generation ?? null) !== expectedStoreGeneration) {
|
|
||||||
if (
|
|
||||||
mintedStoreGeneration === undefined ||
|
|
||||||
current?.generation !== mintedStoreGeneration
|
|
||||||
) {
|
|
||||||
throw new Error('credential generation changed during rollback');
|
|
||||||
}
|
|
||||||
if (prior === undefined) {
|
|
||||||
await store.remove(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
mintedStoreGeneration,
|
|
||||||
);
|
|
||||||
} else {
|
|
||||||
await store.put(prior.binding, prior.secret, mintedStoreGeneration);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
current?.secret.fill(0);
|
|
||||||
}
|
|
||||||
const expectedTeaGeneration = priorTea?.generation ?? null;
|
|
||||||
const currentTea = teaStore.snapshot(request.identity, request.host);
|
|
||||||
try {
|
|
||||||
if ((currentTea?.generation ?? null) !== expectedTeaGeneration) {
|
|
||||||
if (
|
|
||||||
currentTea === undefined ||
|
|
||||||
currentTea.secret.byteLength !== minted.secret.byteLength ||
|
|
||||||
!timingSafeEqual(Buffer.from(currentTea.secret), Buffer.from(minted.secret))
|
|
||||||
) {
|
|
||||||
throw new Error('Tea login generation changed during rollback');
|
|
||||||
}
|
|
||||||
await teaStore.restore(request.identity, request.host, priorTea, currentTea.generation);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
currentTea?.secret.fill(0);
|
|
||||||
}
|
|
||||||
const restored = await store.snapshot(request.identity, request.estate, request.host);
|
|
||||||
try {
|
|
||||||
const storeRestored =
|
|
||||||
prior === undefined
|
|
||||||
? restored === undefined
|
|
||||||
: restored !== undefined &&
|
|
||||||
JSON.stringify(restored.binding) === JSON.stringify(prior.binding) &&
|
|
||||||
restored.secret.byteLength === prior.secret.byteLength &&
|
|
||||||
timingSafeEqual(Buffer.from(restored.secret), Buffer.from(prior.secret));
|
|
||||||
if (!storeRestored || !teaStore.matchesSnapshot(request.identity, request.host, priorTea)) {
|
|
||||||
throw new Error('pre-operation credential state was not restored exactly');
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
restored?.secret.fill(0);
|
|
||||||
}
|
|
||||||
rollbackComplete = true;
|
|
||||||
} catch {
|
|
||||||
rollbackComplete = false;
|
|
||||||
} finally {
|
|
||||||
prior?.secret.fill(0);
|
|
||||||
priorTea?.secret.fill(0);
|
|
||||||
}
|
|
||||||
if (journalFailure) {
|
|
||||||
if (rollbackComplete) {
|
|
||||||
await journal.recordMutation('provision-rollback-verified').catch((): void => undefined);
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
const code = rollbackComplete ? failureCode : 'rollback-incomplete';
|
|
||||||
if (rollbackComplete) await journal.recordMutation('provision-rollback-verified');
|
|
||||||
await journal.seal(rollbackComplete ? 'error' : 'indeterminate', code);
|
|
||||||
return lifecycleResult('provision', request, {
|
|
||||||
outcome: rollbackComplete ? 'error' : 'indeterminate',
|
|
||||||
mutation: rollbackComplete ? 'none' : mutation,
|
|
||||||
code,
|
|
||||||
message: rollbackComplete
|
|
||||||
? 'Provisioning failed and every completed mutation was rolled back.'
|
|
||||||
: 'Provisioning failed and rollback could not be proven complete.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
minted?.secret.fill(0);
|
|
||||||
prior?.secret.fill(0);
|
|
||||||
priorTea?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function revokeCredential(
|
|
||||||
request: LifecycleRequest,
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
provider: GiteaLifecycleProvider,
|
|
||||||
store: FileCredentialStore,
|
|
||||||
teaStore: TeaLoginStore,
|
|
||||||
options: LifecycleOptions,
|
|
||||||
): Promise<CredentialLifecycleResultDto> {
|
|
||||||
const journal = await openLifecycleJournal('revoke', request, options);
|
|
||||||
let ownedLock: CredentialLifecycleLock | undefined;
|
|
||||||
if (
|
|
||||||
!holdsCredentialLifecycleLock(
|
|
||||||
options.lifecycleLock,
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
)
|
|
||||||
) {
|
|
||||||
try {
|
|
||||||
ownedLock = await acquireCredentialLifecycleLock(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
const code =
|
|
||||||
error instanceof CredentialLifecycleLockError ? error.code : 'mutation-lock-unavailable';
|
|
||||||
return lifecycleLockFailureResult('revoke', request, journal, code);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
return await revokeCredentialLocked(request, authority, provider, store, teaStore, journal);
|
|
||||||
} finally {
|
|
||||||
await ownedLock?.release();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function revokeCredentialLocked(
|
|
||||||
request: LifecycleRequest,
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
provider: GiteaLifecycleProvider,
|
|
||||||
store: FileCredentialStore,
|
|
||||||
teaStore: TeaLoginStore,
|
|
||||||
journal: CredentialAuditJournal,
|
|
||||||
): Promise<CredentialLifecycleResultDto> {
|
|
||||||
let mutation: 'none' | 'unknown' | 'applied' = 'none';
|
|
||||||
let credentialSnapshot: Awaited<ReturnType<FileCredentialStore['snapshot']>> = undefined;
|
|
||||||
let teaSnapshot: ReturnType<TeaLoginStore['snapshot']> = undefined;
|
|
||||||
try {
|
|
||||||
credentialSnapshot = await store.snapshot(request.identity, request.estate, request.host);
|
|
||||||
if (credentialSnapshot === undefined) {
|
|
||||||
await journal.seal('refused', 'no-token-for-identity');
|
|
||||||
return lifecycleResult('revoke', request, {
|
|
||||||
outcome: 'refused',
|
|
||||||
mutation: 'none',
|
|
||||||
code: 'no-token-for-identity',
|
|
||||||
message: 'No governed token binding exists for the identity.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
const binding = credentialSnapshot.binding;
|
|
||||||
teaSnapshot = teaStore.snapshot(request.identity, request.host);
|
|
||||||
const identity = await provider.readBasicIdentity(authority);
|
|
||||||
if (identity.login !== request.identity || authority.identity !== request.identity) {
|
|
||||||
await journal.seal('refused', 'provider-identity-mismatch');
|
|
||||||
return lifecycleResult('revoke', request, {
|
|
||||||
outcome: 'refused',
|
|
||||||
mutation: 'none',
|
|
||||||
code: 'provider-identity-mismatch',
|
|
||||||
message: 'Delegated Basic authority did not bind the requested principal.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
providerIdentity: identity.login,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: identity.endpoint,
|
|
||||||
contentType: identity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
mutation = 'unknown';
|
|
||||||
await provider.revokeToken(authority, request.identity, binding.tokenName);
|
|
||||||
mutation = 'applied';
|
|
||||||
await journal.recordMutation('token-revoke-applied');
|
|
||||||
if (await provider.tokenExists(authority, request.identity, binding.tokenName)) {
|
|
||||||
await journal.seal('indeterminate', 'revoke-readback-missing');
|
|
||||||
return lifecycleResult('revoke', request, {
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation,
|
|
||||||
code: 'revoke-readback-missing',
|
|
||||||
message: 'Provider still returned the token after revocation acknowledgement.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
await teaStore.remove(request.identity, request.host, teaSnapshot?.generation ?? null);
|
|
||||||
if (teaStore.readBack(request.identity, request.host) !== undefined) {
|
|
||||||
throw new Error('Tea login still exists after revocation');
|
|
||||||
}
|
|
||||||
await journal.recordMutation('tea-login-removed');
|
|
||||||
await store.remove(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
credentialSnapshot.generation,
|
|
||||||
);
|
|
||||||
await journal.seal('ok', 'revoke-verified');
|
|
||||||
return lifecycleResult('revoke', request, {
|
|
||||||
outcome: 'ok',
|
|
||||||
mutation,
|
|
||||||
code: 'revoke-verified',
|
|
||||||
message: 'Provider token revocation completed before local binding removal.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof CredentialJournalError) {
|
|
||||||
await journal.closeIncomplete().catch((): void => undefined);
|
|
||||||
return lifecycleResult('revoke', request, {
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation,
|
|
||||||
code: error.code,
|
|
||||||
message: 'Audit persistence failed; inspect the durable open journal before recovery.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'open',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
await journal.seal('indeterminate', 'mutation-state-unknown');
|
|
||||||
return lifecycleResult('revoke', request, {
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
mutation,
|
|
||||||
code: 'mutation-state-unknown',
|
|
||||||
message: 'Revocation mutation state could not be established completely.',
|
|
||||||
journalId: journal.journalId(),
|
|
||||||
auditState: 'sealed',
|
|
||||||
});
|
|
||||||
} finally {
|
|
||||||
credentialSnapshot?.secret.fill(0);
|
|
||||||
teaSnapshot?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,189 +0,0 @@
|
|||||||
import { chmod, mkdtemp, readFile, readdir, rm, writeFile } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it } from 'vitest';
|
|
||||||
import { TeaLoginStore, TeaLoginStoreError } from './tea-login-store.js';
|
|
||||||
|
|
||||||
let root: string | undefined;
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
if (root !== undefined) await rm(root, { recursive: true, force: true });
|
|
||||||
root = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('host-bound Tea login store', (): void => {
|
|
||||||
it('coordinates concurrent cooperating updates and preserves one identity on two hosts', async (): Promise<void> => {
|
|
||||||
root = await mkdtemp(join(tmpdir(), 'mosaic-tea-store-'));
|
|
||||||
const store = new TeaLoginStore(join(root, 'tea', 'config.yml'));
|
|
||||||
await Promise.all([
|
|
||||||
store.put('seat', 'git.one.invalid', new TextEncoder().encode('token-one')),
|
|
||||||
store.put('seat', 'git.two.invalid', new TextEncoder().encode('token-two')),
|
|
||||||
]);
|
|
||||||
|
|
||||||
expect(
|
|
||||||
store.matchesSecret('seat', 'git.one.invalid', new TextEncoder().encode('token-one')),
|
|
||||||
).toBe(true);
|
|
||||||
expect(
|
|
||||||
store.matchesSecret('seat', 'git.two.invalid', new TextEncoder().encode('token-two')),
|
|
||||||
).toBe(true);
|
|
||||||
await store.remove('seat', 'git.one.invalid');
|
|
||||||
expect(store.readBack('seat', 'git.one.invalid')).toBeUndefined();
|
|
||||||
expect(store.readBack('seat', 'git.two.invalid')).toEqual({
|
|
||||||
name: 'seat--git.two.invalid',
|
|
||||||
host: 'git.two.invalid',
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
it('snapshots and restores the exact host-bound Tea record fields', async (): Promise<void> => {
|
|
||||||
root = await mkdtemp(join(tmpdir(), 'mosaic-tea-store-'));
|
|
||||||
const configPath = join(root, 'tea', 'config.yml');
|
|
||||||
const store = new TeaLoginStore(configPath);
|
|
||||||
await store.put('seat', 'git.one.invalid', new TextEncoder().encode('original-token'));
|
|
||||||
const customized = (await readFile(configPath, 'utf8')).replace(
|
|
||||||
'default: false',
|
|
||||||
'default: true\n extension-field: preserved',
|
|
||||||
);
|
|
||||||
await writeFile(configPath, customized, { mode: 0o600 });
|
|
||||||
const snapshot = store.snapshot('seat', 'git.one.invalid');
|
|
||||||
expect(snapshot).toBeDefined();
|
|
||||||
|
|
||||||
await store.put('seat', 'git.one.invalid', new TextEncoder().encode('replacement-token'));
|
|
||||||
await store.restore('seat', 'git.one.invalid', snapshot);
|
|
||||||
|
|
||||||
expect(store.matchesSnapshot('seat', 'git.one.invalid', snapshot)).toBe(true);
|
|
||||||
expect(await readFile(configPath, 'utf8')).toContain('extension-field: preserved');
|
|
||||||
snapshot?.secret.fill(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('keeps generation stable across recursive metadata key reordering', async (): Promise<void> => {
|
|
||||||
root = await mkdtemp(join(tmpdir(), 'mosaic-tea-store-'));
|
|
||||||
const configPath = join(root, 'tea', 'config.yml');
|
|
||||||
const store = new TeaLoginStore(configPath);
|
|
||||||
await store.put('seat', 'git.one.invalid', new TextEncoder().encode('token-one'));
|
|
||||||
const baseline = await readFile(configPath, 'utf8');
|
|
||||||
await writeFile(
|
|
||||||
configPath,
|
|
||||||
baseline.replace(
|
|
||||||
'default: false',
|
|
||||||
'default: false\n extension:\n zebra: last\n __proto__: one\n nested:\n second: 2\n first: 1',
|
|
||||||
),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const first = store.snapshot('seat', 'git.one.invalid');
|
|
||||||
await writeFile(
|
|
||||||
configPath,
|
|
||||||
baseline.replace(
|
|
||||||
'default: false',
|
|
||||||
'extension:\n nested:\n first: 1\n second: 2\n __proto__: one\n zebra: last\n default: false',
|
|
||||||
),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const reordered = store.snapshot('seat', 'git.one.invalid');
|
|
||||||
await writeFile(
|
|
||||||
configPath,
|
|
||||||
baseline.replace(
|
|
||||||
'default: false',
|
|
||||||
'extension:\n nested:\n first: 9\n second: 2\n zebra: last\n default: false',
|
|
||||||
),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const changed = store.snapshot('seat', 'git.one.invalid');
|
|
||||||
await writeFile(
|
|
||||||
configPath,
|
|
||||||
baseline.replace(
|
|
||||||
'default: false',
|
|
||||||
'extension:\n nested:\n first: 1\n second: 2\n __proto__: two\n zebra: last\n default: false',
|
|
||||||
),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const prototypeNamedFieldChanged = store.snapshot('seat', 'git.one.invalid');
|
|
||||||
|
|
||||||
expect(reordered?.generation).toBe(first?.generation);
|
|
||||||
expect(changed?.generation).not.toBe(first?.generation);
|
|
||||||
expect(prototypeNamedFieldChanged?.generation).not.toBe(first?.generation);
|
|
||||||
first?.secret.fill(0);
|
|
||||||
reordered?.secret.fill(0);
|
|
||||||
changed?.secret.fill(0);
|
|
||||||
prototypeNamedFieldChanged?.secret.fill(0);
|
|
||||||
});
|
|
||||||
|
|
||||||
it.each(['.nan', '.inf', '-.inf'] as const)(
|
|
||||||
'rejects non-finite YAML metadata value %s while accepting explicit null',
|
|
||||||
async (nonFiniteValue): Promise<void> => {
|
|
||||||
root = await mkdtemp(join(tmpdir(), 'mosaic-tea-store-'));
|
|
||||||
const configPath = join(root, 'tea', 'config.yml');
|
|
||||||
const store = new TeaLoginStore(configPath);
|
|
||||||
await store.put('seat', 'git.one.invalid', new TextEncoder().encode('token-one'));
|
|
||||||
const baseline = await readFile(configPath, 'utf8');
|
|
||||||
await writeFile(
|
|
||||||
configPath,
|
|
||||||
baseline.replace(
|
|
||||||
'default: false',
|
|
||||||
`default: false\n extension-field: ${nonFiniteValue}`,
|
|
||||||
),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(() => store.snapshot('seat', 'git.one.invalid')).toThrowError(TeaLoginStoreError);
|
|
||||||
expect(() => store.snapshot('seat', 'git.one.invalid')).toThrow(/code=tea-config-invalid/);
|
|
||||||
|
|
||||||
await writeFile(
|
|
||||||
configPath,
|
|
||||||
baseline.replace('default: false', 'default: false\n extension-field: null'),
|
|
||||||
{ mode: 0o600 },
|
|
||||||
);
|
|
||||||
const explicitNull = store.snapshot('seat', 'git.one.invalid');
|
|
||||||
expect(explicitNull).toBeDefined();
|
|
||||||
explicitNull?.secret.fill(0);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it.each(['put', 'remove'] as const)(
|
|
||||||
'removes secret-bearing temporary files when %s fails before rename',
|
|
||||||
async (operation): Promise<void> => {
|
|
||||||
root = await mkdtemp(join(tmpdir(), 'mosaic-tea-store-'));
|
|
||||||
const configPath = join(root, 'tea', 'config.yml');
|
|
||||||
const baseline = new TeaLoginStore(configPath);
|
|
||||||
if (operation === 'remove') {
|
|
||||||
await baseline.put('seat', 'git.one.invalid', new TextEncoder().encode('token-one'));
|
|
||||||
}
|
|
||||||
const store = new TeaLoginStore(configPath, {
|
|
||||||
beforeRename: async (candidate): Promise<void> => {
|
|
||||||
if (candidate === operation) throw new Error('injected pre-rename failure');
|
|
||||||
},
|
|
||||||
});
|
|
||||||
|
|
||||||
if (operation === 'put') {
|
|
||||||
await expect(
|
|
||||||
store.put('seat', 'git.one.invalid', new TextEncoder().encode('token-one')),
|
|
||||||
).rejects.toThrow('injected pre-rename failure');
|
|
||||||
} else {
|
|
||||||
await expect(store.remove('seat', 'git.one.invalid')).rejects.toThrow(
|
|
||||||
'injected pre-rename failure',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
expect((await readdir(join(root, 'tea'))).filter((name) => name.endsWith('.tmp'))).toEqual(
|
|
||||||
[],
|
|
||||||
);
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
it('preserves unrelated Tea configuration and rejects permissive secret reads', async (): Promise<void> => {
|
|
||||||
root = await mkdtemp(join(tmpdir(), 'mosaic-tea-store-'));
|
|
||||||
const configPath = join(root, 'tea', 'config.yml');
|
|
||||||
const store = new TeaLoginStore(configPath);
|
|
||||||
await store.put('seat', 'git.one.invalid', new TextEncoder().encode('token-one'));
|
|
||||||
const original = await readFile(configPath, 'utf8');
|
|
||||||
await writeFile(configPath, `preferences:\n color: true\n${original}`, { mode: 0o600 });
|
|
||||||
|
|
||||||
await store.put('seat', 'git.two.invalid', new TextEncoder().encode('token-two'));
|
|
||||||
await store.remove('seat', 'git.one.invalid');
|
|
||||||
expect(await readFile(configPath, 'utf8')).toContain('color: true');
|
|
||||||
|
|
||||||
await chmod(configPath, 0o644);
|
|
||||||
expect(() => store.resolve('seat', 'homelab', 'git.two.invalid')).toThrow(
|
|
||||||
/tea-config-insecure/,
|
|
||||||
);
|
|
||||||
expect(() => store.readBack('seat', 'git.two.invalid')).toThrow(/tea-config-insecure/);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,468 +0,0 @@
|
|||||||
import { createHash, randomUUID, timingSafeEqual } from 'node:crypto';
|
|
||||||
import { open, rename, unlink } from 'node:fs/promises';
|
|
||||||
import { dirname } from 'node:path';
|
|
||||||
import { isDeepStrictEqual } from 'node:util';
|
|
||||||
import { parse, stringify } from 'yaml';
|
|
||||||
import { z } from 'zod';
|
|
||||||
import { ensureManagedDirectory, readRegularFileSecure } from '../fleet/secure-file.js';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
|
|
||||||
const SAFE_NAME = /^[A-Za-z0-9][A-Za-z0-9_.-]*$/;
|
|
||||||
|
|
||||||
export class TeaLoginStoreError extends Error {
|
|
||||||
constructor(
|
|
||||||
public readonly code: string,
|
|
||||||
message: string,
|
|
||||||
) {
|
|
||||||
super(`Tea login store rejected: code=${code} ${message}`);
|
|
||||||
this.name = 'TeaLoginStoreError';
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
interface TeaLoginRecord {
|
|
||||||
readonly name: string;
|
|
||||||
readonly url: string;
|
|
||||||
readonly token: string;
|
|
||||||
readonly user: string;
|
|
||||||
readonly default: boolean;
|
|
||||||
readonly [key: string]: unknown;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface TeaConfig {
|
|
||||||
readonly logins: TeaLoginRecord[];
|
|
||||||
readonly [key: string]: unknown;
|
|
||||||
}
|
|
||||||
|
|
||||||
const loginSchema = z
|
|
||||||
.object({
|
|
||||||
name: z.string().regex(SAFE_NAME),
|
|
||||||
url: z.string().url(),
|
|
||||||
token: z.string().min(1),
|
|
||||||
user: z.string().regex(SAFE_NAME),
|
|
||||||
default: z.boolean().default(false),
|
|
||||||
})
|
|
||||||
.passthrough();
|
|
||||||
const configSchema = z.object({ logins: z.array(loginSchema).default([]) }).passthrough();
|
|
||||||
|
|
||||||
async function syncDirectory(path: string): Promise<void> {
|
|
||||||
const handle = await open(path, 'r');
|
|
||||||
try {
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function acquireLock(path: string): Promise<Awaited<ReturnType<typeof open>>> {
|
|
||||||
for (let attempt = 0; attempt < 500; attempt += 1) {
|
|
||||||
try {
|
|
||||||
return await open(path, 'wx', 0o600);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!(error instanceof Error && 'code' in error && error.code === 'EEXIST')) throw error;
|
|
||||||
await new Promise<void>((resolve): void => {
|
|
||||||
setTimeout(resolve, 10);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
throw new TeaLoginStoreError(
|
|
||||||
'conflicting-credential-mutation',
|
|
||||||
'Tea configuration lock did not become available',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function loginName(identity: string, host: string): string {
|
|
||||||
return `${identity}--${host}`;
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertPrivate(snapshot: { readonly mode: number; readonly uid: number }): void {
|
|
||||||
if ((snapshot.mode & 0o077) !== 0 || snapshot.uid !== process.getuid?.()) {
|
|
||||||
throw new TeaLoginStoreError('tea-config-insecure', 'Tea config is not private');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function missing(error: unknown): boolean {
|
|
||||||
return error instanceof Error && 'code' in error && error.code === 'ENOENT';
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface TeaLoginSnapshot {
|
|
||||||
readonly fields: Readonly<Record<string, unknown>>;
|
|
||||||
readonly secret: Uint8Array;
|
|
||||||
readonly generation: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
type CanonicalJsonValue =
|
|
||||||
| string
|
|
||||||
| number
|
|
||||||
| boolean
|
|
||||||
| null
|
|
||||||
| CanonicalJsonValue[]
|
|
||||||
| CanonicalJsonObject;
|
|
||||||
|
|
||||||
interface CanonicalJsonObject {
|
|
||||||
[key: string]: CanonicalJsonValue;
|
|
||||||
}
|
|
||||||
|
|
||||||
function canonicalizeGenerationValue(value: unknown): CanonicalJsonValue {
|
|
||||||
if (value === null || typeof value === 'string' || typeof value === 'boolean') return value;
|
|
||||||
if (typeof value === 'number') {
|
|
||||||
if (!Number.isFinite(value)) {
|
|
||||||
throw new TeaLoginStoreError(
|
|
||||||
'tea-config-invalid',
|
|
||||||
'Tea login metadata contains a non-finite number',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return value;
|
|
||||||
}
|
|
||||||
if (Array.isArray(value)) {
|
|
||||||
return value.map((entry: unknown): CanonicalJsonValue => canonicalizeGenerationValue(entry));
|
|
||||||
}
|
|
||||||
if (typeof value === 'object') {
|
|
||||||
const entries = Object.entries(value)
|
|
||||||
.sort(([left], [right]): number => (left < right ? -1 : left > right ? 1 : 0))
|
|
||||||
.flatMap(([key, entry]): [string, CanonicalJsonValue][] =>
|
|
||||||
entry === undefined ? [] : [[key, canonicalizeGenerationValue(entry)]],
|
|
||||||
);
|
|
||||||
return Object.fromEntries(entries);
|
|
||||||
}
|
|
||||||
throw new TeaLoginStoreError(
|
|
||||||
'tea-config-invalid',
|
|
||||||
'Tea login metadata is outside canonical JSON values',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
function canonicalGenerationJson(value: object): string {
|
|
||||||
return JSON.stringify(canonicalizeGenerationValue(value));
|
|
||||||
}
|
|
||||||
|
|
||||||
function snapshotFromConfig(
|
|
||||||
config: TeaConfig,
|
|
||||||
identity: string,
|
|
||||||
host: string,
|
|
||||||
): TeaLoginSnapshot | undefined {
|
|
||||||
const matches = config.logins.filter(
|
|
||||||
(login): boolean => login.name === loginName(identity, host) && login.url === `https://${host}`,
|
|
||||||
);
|
|
||||||
if (matches.length === 0) return undefined;
|
|
||||||
if (matches.length !== 1 || matches[0] === undefined) {
|
|
||||||
throw new TeaLoginStoreError('tea-config-invalid', 'Tea login binding is ambiguous');
|
|
||||||
}
|
|
||||||
const { token, ...fields } = matches[0];
|
|
||||||
const secret = new TextEncoder().encode(token);
|
|
||||||
const generation = createHash('sha256')
|
|
||||||
.update(canonicalGenerationJson(fields))
|
|
||||||
.update('\0')
|
|
||||||
.update(secret)
|
|
||||||
.digest('hex');
|
|
||||||
return { fields: structuredClone(fields), secret, generation };
|
|
||||||
}
|
|
||||||
|
|
||||||
function assertExpectedGeneration(
|
|
||||||
config: TeaConfig,
|
|
||||||
identity: string,
|
|
||||||
host: string,
|
|
||||||
expectedGeneration: string | null | undefined,
|
|
||||||
): void {
|
|
||||||
if (expectedGeneration === undefined) return;
|
|
||||||
const current = snapshotFromConfig(config, identity, host);
|
|
||||||
try {
|
|
||||||
if ((current?.generation ?? null) !== expectedGeneration) {
|
|
||||||
throw new TeaLoginStoreError(
|
|
||||||
'tea-generation-mismatch',
|
|
||||||
'Tea login generation changed before mutation',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
} finally {
|
|
||||||
current?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
export interface TeaLoginStoreRuntimeOptions {
|
|
||||||
readonly beforeRename?: (
|
|
||||||
operation: 'put' | 'remove' | 'restore',
|
|
||||||
tempPath: string,
|
|
||||||
) => Promise<void>;
|
|
||||||
}
|
|
||||||
|
|
||||||
export class TeaLoginStore {
|
|
||||||
constructor(
|
|
||||||
private readonly configPath: string,
|
|
||||||
private readonly runtime: TeaLoginStoreRuntimeOptions = {},
|
|
||||||
) {}
|
|
||||||
|
|
||||||
private async commit(
|
|
||||||
operation: 'put' | 'remove' | 'restore',
|
|
||||||
config: TeaConfig,
|
|
||||||
directory: string,
|
|
||||||
): Promise<void> {
|
|
||||||
const temp = `${this.configPath}.${randomUUID()}.tmp`;
|
|
||||||
try {
|
|
||||||
const handle = await open(temp, 'wx', 0o600);
|
|
||||||
try {
|
|
||||||
await handle.writeFile(stringify(config), 'utf8');
|
|
||||||
await handle.sync();
|
|
||||||
} finally {
|
|
||||||
await handle.close();
|
|
||||||
}
|
|
||||||
await this.runtime.beforeRename?.(operation, temp);
|
|
||||||
await rename(temp, this.configPath);
|
|
||||||
await syncDirectory(directory);
|
|
||||||
} finally {
|
|
||||||
await unlink(temp).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async put(
|
|
||||||
identity: string,
|
|
||||||
host: string,
|
|
||||||
secret: Uint8Array,
|
|
||||||
expectedGeneration?: string | null,
|
|
||||||
): Promise<void> {
|
|
||||||
if (!SAFE_NAME.test(identity) || !/^[a-z0-9][a-z0-9.-]*$/.test(host)) {
|
|
||||||
throw new TeaLoginStoreError('invalid-input', 'identity or host is outside the grammar');
|
|
||||||
}
|
|
||||||
const directory = dirname(this.configPath);
|
|
||||||
ensureManagedDirectory(directory, directory);
|
|
||||||
const lockPath = `${this.configPath}.lock`;
|
|
||||||
const lock = await acquireLock(lockPath);
|
|
||||||
try {
|
|
||||||
let current: TeaConfig = { logins: [] };
|
|
||||||
try {
|
|
||||||
const snapshot = readRegularFileSecure(this.configPath, {
|
|
||||||
root: directory,
|
|
||||||
maxBytes: 1024 * 1024,
|
|
||||||
});
|
|
||||||
assertPrivate(snapshot);
|
|
||||||
const decoded = configSchema.safeParse(parse(snapshot.content.toString('utf8')));
|
|
||||||
if (!decoded.success) {
|
|
||||||
throw new TeaLoginStoreError('tea-config-invalid', 'Tea config failed schema validation');
|
|
||||||
}
|
|
||||||
current = decoded.data;
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!missing(error)) throw error;
|
|
||||||
}
|
|
||||||
assertExpectedGeneration(current, identity, host, expectedGeneration);
|
|
||||||
const token = Buffer.from(secret).toString('utf8');
|
|
||||||
const record: TeaLoginRecord = {
|
|
||||||
name: loginName(identity, host),
|
|
||||||
url: `https://${host}`,
|
|
||||||
token,
|
|
||||||
user: identity,
|
|
||||||
default: false,
|
|
||||||
};
|
|
||||||
const logins = current.logins.filter(
|
|
||||||
(login): boolean =>
|
|
||||||
!(login.name === loginName(identity, host) && login.url === `https://${host}`),
|
|
||||||
);
|
|
||||||
logins.push(record);
|
|
||||||
await this.commit('put', { ...current, logins }, directory);
|
|
||||||
} finally {
|
|
||||||
await lock.close();
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
snapshot(identity: string, host: string): TeaLoginSnapshot | undefined {
|
|
||||||
const directory = dirname(this.configPath);
|
|
||||||
let snapshot;
|
|
||||||
try {
|
|
||||||
snapshot = readRegularFileSecure(this.configPath, {
|
|
||||||
root: directory,
|
|
||||||
maxBytes: 1024 * 1024,
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (missing(error)) return undefined;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
assertPrivate(snapshot);
|
|
||||||
const decoded = configSchema.safeParse(parse(snapshot.content.toString('utf8')));
|
|
||||||
if (!decoded.success) {
|
|
||||||
throw new TeaLoginStoreError('tea-config-invalid', 'Tea config failed schema validation');
|
|
||||||
}
|
|
||||||
return snapshotFromConfig(decoded.data, identity, host);
|
|
||||||
}
|
|
||||||
|
|
||||||
matchesSnapshot(identity: string, host: string, expected: TeaLoginSnapshot | undefined): boolean {
|
|
||||||
const actual = this.snapshot(identity, host);
|
|
||||||
try {
|
|
||||||
if (actual === undefined || expected === undefined) return actual === expected;
|
|
||||||
return (
|
|
||||||
isDeepStrictEqual(actual.fields, expected.fields) &&
|
|
||||||
actual.secret.byteLength === expected.secret.byteLength &&
|
|
||||||
timingSafeEqual(Buffer.from(actual.secret), Buffer.from(expected.secret))
|
|
||||||
);
|
|
||||||
} finally {
|
|
||||||
actual?.secret.fill(0);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async restore(
|
|
||||||
identity: string,
|
|
||||||
host: string,
|
|
||||||
snapshot: TeaLoginSnapshot | undefined,
|
|
||||||
expectedGeneration?: string | null,
|
|
||||||
): Promise<void> {
|
|
||||||
if (!SAFE_NAME.test(identity) || !/^[a-z0-9][a-z0-9.-]*$/.test(host)) {
|
|
||||||
throw new TeaLoginStoreError('invalid-input', 'identity or host is outside the grammar');
|
|
||||||
}
|
|
||||||
const directory = dirname(this.configPath);
|
|
||||||
ensureManagedDirectory(directory, directory);
|
|
||||||
const lockPath = `${this.configPath}.lock`;
|
|
||||||
const lock = await acquireLock(lockPath);
|
|
||||||
try {
|
|
||||||
let current: TeaConfig = { logins: [] };
|
|
||||||
try {
|
|
||||||
const currentSnapshot = readRegularFileSecure(this.configPath, {
|
|
||||||
root: directory,
|
|
||||||
maxBytes: 1024 * 1024,
|
|
||||||
});
|
|
||||||
assertPrivate(currentSnapshot);
|
|
||||||
const decoded = configSchema.safeParse(parse(currentSnapshot.content.toString('utf8')));
|
|
||||||
if (!decoded.success) {
|
|
||||||
throw new TeaLoginStoreError('tea-config-invalid', 'Tea config failed schema validation');
|
|
||||||
}
|
|
||||||
current = decoded.data;
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!missing(error)) throw error;
|
|
||||||
if (
|
|
||||||
snapshot === undefined &&
|
|
||||||
(expectedGeneration === undefined || expectedGeneration === null)
|
|
||||||
)
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
assertExpectedGeneration(current, identity, host, expectedGeneration);
|
|
||||||
const logins = current.logins.filter(
|
|
||||||
(login): boolean =>
|
|
||||||
!(login.name === loginName(identity, host) && login.url === `https://${host}`),
|
|
||||||
);
|
|
||||||
if (snapshot !== undefined) {
|
|
||||||
const restored = loginSchema.parse({
|
|
||||||
...structuredClone(snapshot.fields),
|
|
||||||
token: Buffer.from(snapshot.secret).toString('utf8'),
|
|
||||||
});
|
|
||||||
if (restored.name !== loginName(identity, host) || restored.url !== `https://${host}`) {
|
|
||||||
throw new TeaLoginStoreError(
|
|
||||||
'tea-config-invalid',
|
|
||||||
'Tea snapshot does not match the requested identity and host',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
logins.push(restored);
|
|
||||||
}
|
|
||||||
await this.commit('restore', { ...current, logins }, directory);
|
|
||||||
} finally {
|
|
||||||
await lock.close();
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
resolve(identity: string, estate: string, host: string): ResolvedCredential | undefined {
|
|
||||||
const directory = dirname(this.configPath);
|
|
||||||
let snapshot;
|
|
||||||
try {
|
|
||||||
snapshot = readRegularFileSecure(this.configPath, {
|
|
||||||
root: directory,
|
|
||||||
maxBytes: 1024 * 1024,
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (missing(error)) return undefined;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
assertPrivate(snapshot);
|
|
||||||
const decoded = configSchema.safeParse(parse(snapshot.content.toString('utf8')));
|
|
||||||
if (!decoded.success) return undefined;
|
|
||||||
const matches = decoded.data.logins.filter(
|
|
||||||
(login): boolean =>
|
|
||||||
login.name === loginName(identity, host) &&
|
|
||||||
login.url === `https://${host}` &&
|
|
||||||
login.user === identity,
|
|
||||||
);
|
|
||||||
if (matches.length !== 1 || matches[0] === undefined) return undefined;
|
|
||||||
return Object.freeze({
|
|
||||||
identity,
|
|
||||||
estate,
|
|
||||||
host,
|
|
||||||
resolutionId: randomUUID(),
|
|
||||||
secret: new TextEncoder().encode(matches[0].token),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
matchesSecret(identity: string, host: string, secret: Uint8Array): boolean {
|
|
||||||
const resolved = this.resolve(identity, 'binding-check', host);
|
|
||||||
if (resolved === undefined || resolved.secret.byteLength !== secret.byteLength) return false;
|
|
||||||
return timingSafeEqual(Buffer.from(resolved.secret), Buffer.from(secret));
|
|
||||||
}
|
|
||||||
|
|
||||||
async remove(identity: string, host: string, expectedGeneration?: string | null): Promise<void> {
|
|
||||||
const directory = dirname(this.configPath);
|
|
||||||
const lockPath = `${this.configPath}.lock`;
|
|
||||||
const lock = await acquireLock(lockPath);
|
|
||||||
try {
|
|
||||||
let snapshot;
|
|
||||||
try {
|
|
||||||
snapshot = readRegularFileSecure(this.configPath, {
|
|
||||||
root: directory,
|
|
||||||
maxBytes: 1024 * 1024,
|
|
||||||
});
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (missing(error)) {
|
|
||||||
if (expectedGeneration !== undefined && expectedGeneration !== null) {
|
|
||||||
throw new TeaLoginStoreError(
|
|
||||||
'tea-generation-mismatch',
|
|
||||||
'Tea login generation changed before removal',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
assertPrivate(snapshot);
|
|
||||||
const decoded = configSchema.safeParse(parse(snapshot.content.toString('utf8')));
|
|
||||||
if (!decoded.success) {
|
|
||||||
throw new TeaLoginStoreError('tea-config-invalid', 'Tea config failed schema validation');
|
|
||||||
}
|
|
||||||
assertExpectedGeneration(decoded.data, identity, host, expectedGeneration);
|
|
||||||
const logins = decoded.data.logins.filter(
|
|
||||||
(login): boolean =>
|
|
||||||
!(login.name === loginName(identity, host) && login.url === `https://${host}`),
|
|
||||||
);
|
|
||||||
await this.commit('remove', { ...decoded.data, logins }, directory);
|
|
||||||
} finally {
|
|
||||||
await lock.close();
|
|
||||||
await unlink(lockPath).catch((): void => undefined);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
readBack(
|
|
||||||
identity: string,
|
|
||||||
host: string,
|
|
||||||
): { readonly name: string; readonly host: string } | undefined {
|
|
||||||
const directory = dirname(this.configPath);
|
|
||||||
let snapshot;
|
|
||||||
try {
|
|
||||||
snapshot = readRegularFileSecure(this.configPath, { root: directory, maxBytes: 1024 * 1024 });
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (missing(error)) return undefined;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
assertPrivate(snapshot);
|
|
||||||
const decoded: unknown = parse(snapshot.content.toString('utf8'));
|
|
||||||
if (
|
|
||||||
typeof decoded !== 'object' ||
|
|
||||||
decoded === null ||
|
|
||||||
!('logins' in decoded) ||
|
|
||||||
!Array.isArray(decoded.logins)
|
|
||||||
)
|
|
||||||
return undefined;
|
|
||||||
const matches = decoded.logins.filter((value: unknown): value is TeaLoginRecord => {
|
|
||||||
if (typeof value !== 'object' || value === null) return false;
|
|
||||||
return (
|
|
||||||
'name' in value &&
|
|
||||||
value.name === loginName(identity, host) &&
|
|
||||||
'url' in value &&
|
|
||||||
value.url === `https://${host}` &&
|
|
||||||
'user' in value &&
|
|
||||||
value.user === identity
|
|
||||||
);
|
|
||||||
});
|
|
||||||
return matches.length === 1 ? { name: loginName(identity, host), host } : undefined;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,926 +0,0 @@
|
|||||||
import { mkdtemp, readFile, readdir, rm } from 'node:fs/promises';
|
|
||||||
import { tmpdir } from 'node:os';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { afterEach, describe, expect, it, vi } from 'vitest';
|
|
||||||
import { CredentialAuditJournal, CredentialJournalError } from './audit-journal.js';
|
|
||||||
import { grantTeamRepositoryPermission, type GiteaTeamGrantProvider } from './team-grant.js';
|
|
||||||
import type { ResolvedCredential } from './credential-provider.dto.js';
|
|
||||||
import type { CredentialValidationDependencies } from './validate.js';
|
|
||||||
|
|
||||||
let cleanup: string | undefined;
|
|
||||||
afterEach(async (): Promise<void> => {
|
|
||||||
vi.restoreAllMocks();
|
|
||||||
if (cleanup !== undefined) await rm(cleanup, { recursive: true, force: true });
|
|
||||||
cleanup = undefined;
|
|
||||||
});
|
|
||||||
|
|
||||||
const authority: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'provisioner',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'authority',
|
|
||||||
secret: new TextEncoder().encode('authority-canary'),
|
|
||||||
});
|
|
||||||
const subject: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'subject',
|
|
||||||
secret: new TextEncoder().encode('subject-canary'),
|
|
||||||
});
|
|
||||||
const control: ResolvedCredential = Object.freeze({
|
|
||||||
identity: 'read-control',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
resolutionId: 'control',
|
|
||||||
secret: new TextEncoder().encode('control-canary'),
|
|
||||||
});
|
|
||||||
|
|
||||||
function validation(): CredentialValidationDependencies {
|
|
||||||
return {
|
|
||||||
estateRegistry: { matches: (): boolean => true },
|
|
||||||
resolver: {
|
|
||||||
async resolve(identity: string) {
|
|
||||||
return identity === 'seat-name' ? subject : control;
|
|
||||||
},
|
|
||||||
},
|
|
||||||
provider: {
|
|
||||||
async readIdentity(resolved: ResolvedCredential) {
|
|
||||||
return {
|
|
||||||
login: resolved.identity,
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readRepositoryPermission(resolved: ResolvedCredential) {
|
|
||||||
return {
|
|
||||||
effective: resolved.identity === 'seat-name' ? 'write' : 'read',
|
|
||||||
endpoint: 'GET /api/v1/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async probeReceivePack(resolved: ResolvedCredential | undefined) {
|
|
||||||
const write = resolved?.identity === 'seat-name';
|
|
||||||
return {
|
|
||||||
state: write ? 'advertised' : 'refused',
|
|
||||||
principal: resolved?.identity ?? null,
|
|
||||||
resolutionId: resolved?.resolutionId ?? null,
|
|
||||||
contentType: write ? 'application/x-git-receive-pack-advertisement' : 'text/plain',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
},
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
describe('team repository grant', (): void => {
|
|
||||||
it('reads team permission, org membership, member attachment, repo attachment, and effective subject permission', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let repositoryReads = 0;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
repositoryReads += 1;
|
|
||||||
return {
|
|
||||||
repositories: repositoryReads === 1 ? [] : ['owner/repo'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {},
|
|
||||||
async removeTeamMember(): Promise<void> {},
|
|
||||||
async attachTeamRepository(): Promise<void> {},
|
|
||||||
async detachTeamRepository(): Promise<void> {},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{ stateRoot: join(cleanup, 'state'), actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
expect(result.evidence.organizationMembership?.state).toBe('present');
|
|
||||||
expect(result.evidence.teamMembership?.state).toBe('present');
|
|
||||||
expect(result.evidence.teamRepository?.state).toBe('present');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('durably reports indeterminate when team-lock release cannot be verified', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let repositoryReads = 0;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
repositoryReads += 1;
|
|
||||||
return {
|
|
||||||
repositories: repositoryReads === 1 ? [] : ['owner/repo'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {},
|
|
||||||
async removeTeamMember(): Promise<void> {},
|
|
||||||
async attachTeamRepository(): Promise<void> {},
|
|
||||||
async detachTeamRepository(): Promise<void> {},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
const stateRoot = join(cleanup, 'state');
|
|
||||||
|
|
||||||
const result = await grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{
|
|
||||||
stateRoot,
|
|
||||||
actor: 'provisioner',
|
|
||||||
acquireTeamLock: async (): Promise<() => Promise<void>> => async (): Promise<void> => {
|
|
||||||
throw new Error('injected close failure');
|
|
||||||
},
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('mutation-lock-release-failed');
|
|
||||||
expect(result.mutation).toBe('applied');
|
|
||||||
const [journalName] = await readdir(join(stateRoot, 'journals'));
|
|
||||||
const journal = await readFile(join(stateRoot, 'journals', journalName!), 'utf8');
|
|
||||||
expect(journal).toContain('"outcome":"indeterminate"');
|
|
||||||
expect(journal).toContain('"reasonCode":"mutation-lock-release-failed"');
|
|
||||||
expect(journal).toContain('"decision":"permission-write"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('never compensates a later cooperating mutation after release when final seal fails', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let repositoryReads = 0;
|
|
||||||
let memberPresent = false;
|
|
||||||
let repositoryPresent = false;
|
|
||||||
let memberRemovals = 0;
|
|
||||||
let repositoryDetachments = 0;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
repositoryReads += 1;
|
|
||||||
return {
|
|
||||||
repositories: repositoryReads === 1 ? [] : ['owner/repo'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {
|
|
||||||
memberPresent = true;
|
|
||||||
},
|
|
||||||
async removeTeamMember(): Promise<void> {
|
|
||||||
memberRemovals += 1;
|
|
||||||
memberPresent = false;
|
|
||||||
},
|
|
||||||
async attachTeamRepository(): Promise<void> {
|
|
||||||
repositoryPresent = true;
|
|
||||||
},
|
|
||||||
async detachTeamRepository(): Promise<void> {
|
|
||||||
repositoryDetachments += 1;
|
|
||||||
repositoryPresent = false;
|
|
||||||
},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: memberPresent ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: repositoryPresent ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
const originalSeal = CredentialAuditJournal.prototype.seal;
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'seal').mockImplementation(async function (
|
|
||||||
this: CredentialAuditJournal,
|
|
||||||
outcome,
|
|
||||||
reasonCode,
|
|
||||||
): Promise<string> {
|
|
||||||
if (outcome === 'ok') {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected final seal failure');
|
|
||||||
}
|
|
||||||
return originalSeal.call(this, outcome, reasonCode);
|
|
||||||
});
|
|
||||||
|
|
||||||
await expect(
|
|
||||||
grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{
|
|
||||||
stateRoot: join(cleanup, 'state'),
|
|
||||||
actor: 'provisioner',
|
|
||||||
acquireTeamLock: async (): Promise<() => Promise<void>> => async (): Promise<void> => {
|
|
||||||
// Simulate the next cooperating owner establishing the same state
|
|
||||||
// immediately after acquiring the released lock.
|
|
||||||
memberPresent = true;
|
|
||||||
repositoryPresent = true;
|
|
||||||
},
|
|
||||||
},
|
|
||||||
),
|
|
||||||
).rejects.toMatchObject({ code: 'journal-unavailable', mutation: 'applied' });
|
|
||||||
expect(memberRemovals).toBe(0);
|
|
||||||
expect(repositoryDetachments).toBe(0);
|
|
||||||
expect(memberPresent).toBe(true);
|
|
||||||
expect(repositoryPresent).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('never compensates successor state after lock release begins but release and audit sealing fail', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let repositoryReads = 0;
|
|
||||||
let memberPresent = false;
|
|
||||||
let repositoryPresent = false;
|
|
||||||
let memberRemovals = 0;
|
|
||||||
let repositoryDetachments = 0;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
repositoryReads += 1;
|
|
||||||
return {
|
|
||||||
repositories: repositoryReads === 1 ? [] : ['owner/repo'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {
|
|
||||||
memberPresent = true;
|
|
||||||
},
|
|
||||||
async removeTeamMember(): Promise<void> {
|
|
||||||
memberRemovals += 1;
|
|
||||||
memberPresent = false;
|
|
||||||
},
|
|
||||||
async attachTeamRepository(): Promise<void> {
|
|
||||||
repositoryPresent = true;
|
|
||||||
},
|
|
||||||
async detachTeamRepository(): Promise<void> {
|
|
||||||
repositoryDetachments += 1;
|
|
||||||
repositoryPresent = false;
|
|
||||||
},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: memberPresent ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: repositoryPresent ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
const originalSeal = CredentialAuditJournal.prototype.seal;
|
|
||||||
vi.spyOn(CredentialAuditJournal.prototype, 'seal').mockImplementation(async function (
|
|
||||||
this: CredentialAuditJournal,
|
|
||||||
outcome,
|
|
||||||
reasonCode,
|
|
||||||
): Promise<string> {
|
|
||||||
if (reasonCode === 'mutation-lock-release-failed') {
|
|
||||||
throw new CredentialJournalError('journal-unavailable', 'injected release audit failure');
|
|
||||||
}
|
|
||||||
return originalSeal.call(this, outcome, reasonCode);
|
|
||||||
});
|
|
||||||
|
|
||||||
await expect(
|
|
||||||
grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{
|
|
||||||
stateRoot: join(cleanup, 'state'),
|
|
||||||
actor: 'provisioner',
|
|
||||||
acquireTeamLock: async (): Promise<() => Promise<void>> => async (): Promise<void> => {
|
|
||||||
memberPresent = true;
|
|
||||||
repositoryPresent = true;
|
|
||||||
throw new Error('injected release failure after successor mutation');
|
|
||||||
},
|
|
||||||
},
|
|
||||||
),
|
|
||||||
).rejects.toMatchObject({ code: 'journal-unavailable', mutation: 'applied' });
|
|
||||||
expect(memberRemovals).toBe(0);
|
|
||||||
expect(repositoryDetachments).toBe(0);
|
|
||||||
expect(memberPresent).toBe(true);
|
|
||||||
expect(repositoryPresent).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a shared team already attached to any repository outside the request', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let mutated = false;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
return {
|
|
||||||
repositories: ['owner/unrelated'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {
|
|
||||||
mutated = true;
|
|
||||||
},
|
|
||||||
async removeTeamMember(): Promise<void> {
|
|
||||||
mutated = true;
|
|
||||||
},
|
|
||||||
async attachTeamRepository(): Promise<void> {
|
|
||||||
mutated = true;
|
|
||||||
},
|
|
||||||
async detachTeamRepository(): Promise<void> {
|
|
||||||
mutated = true;
|
|
||||||
},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{ stateRoot: join(cleanup, 'state'), actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('team-scope-exceeds-request');
|
|
||||||
expect(mutated).toBe(false);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('journals absent team objects as absent rather than present', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let repositoryReads = 0;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
repositoryReads += 1;
|
|
||||||
return {
|
|
||||||
repositories: repositoryReads === 1 ? [] : ['owner/repo'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {},
|
|
||||||
async removeTeamMember(): Promise<void> {},
|
|
||||||
async attachTeamRepository(): Promise<void> {},
|
|
||||||
async detachTeamRepository(): Promise<void> {},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const stateRoot = join(cleanup, 'state');
|
|
||||||
const result = await grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{ stateRoot, actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
const [journalName] = await readdir(join(stateRoot, 'journals'));
|
|
||||||
const journal = await readFile(join(stateRoot, 'journals', journalName!), 'utf8');
|
|
||||||
expect(journal).toContain('team-member-absent');
|
|
||||||
expect(journal).toContain('team-repository-absent');
|
|
||||||
expect(journal).not.toContain('"decision":"team-member-present"');
|
|
||||||
expect(journal).not.toContain('"decision":"team-repository-present"');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('fails closed and removes newly added membership when team scope changes during mutation', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let repositoryReads = 0;
|
|
||||||
let membershipReads = 0;
|
|
||||||
let removed = false;
|
|
||||||
let detached = false;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
repositoryReads += 1;
|
|
||||||
return {
|
|
||||||
repositories: repositoryReads === 1 ? [] : ['owner/repo', 'owner/concurrent-attachment'],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {},
|
|
||||||
async removeTeamMember(): Promise<void> {
|
|
||||||
removed = true;
|
|
||||||
},
|
|
||||||
async attachTeamRepository(): Promise<void> {},
|
|
||||||
async detachTeamRepository(): Promise<void> {
|
|
||||||
detached = true;
|
|
||||||
},
|
|
||||||
async readTeamMember() {
|
|
||||||
membershipReads += 1;
|
|
||||||
return {
|
|
||||||
state: membershipReads === 1 || removed ? 'absent' : 'present',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: detached ? 'absent' : 'present',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const stateRoot = join(cleanup, 'state');
|
|
||||||
const result = await grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{ stateRoot, actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('team-scope-changed-during-grant');
|
|
||||||
expect(result.evidence.teamRepositorySet?.repositories).toEqual([
|
|
||||||
'owner/repo',
|
|
||||||
'owner/concurrent-attachment',
|
|
||||||
]);
|
|
||||||
expect(removed).toBe(true);
|
|
||||||
expect(detached).toBe(true);
|
|
||||||
const [journalName] = await readdir(join(stateRoot, 'journals'));
|
|
||||||
const journal = await readFile(join(stateRoot, 'journals', journalName!), 'utf8');
|
|
||||||
expect(journal.indexOf('team-member-absent')).toBeLessThan(
|
|
||||||
journal.indexOf('team-member-applied'),
|
|
||||||
);
|
|
||||||
expect(journal).toContain('team-repository-rollback-applied');
|
|
||||||
expect(journal).toContain('team-repository-absent');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('compensates provider changes when repository attachment fails after applying', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let memberPresent = false;
|
|
||||||
let repositoryPresent = false;
|
|
||||||
let memberRemoved = false;
|
|
||||||
let repositoryDetached = false;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
return {
|
|
||||||
repositories: repositoryPresent ? ['owner/repo'] : [],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {
|
|
||||||
memberPresent = true;
|
|
||||||
},
|
|
||||||
async removeTeamMember(): Promise<void> {
|
|
||||||
memberPresent = false;
|
|
||||||
memberRemoved = true;
|
|
||||||
},
|
|
||||||
async attachTeamRepository(): Promise<void> {
|
|
||||||
repositoryPresent = true;
|
|
||||||
throw new Error('provider response lost after attachment');
|
|
||||||
},
|
|
||||||
async detachTeamRepository(): Promise<void> {
|
|
||||||
repositoryPresent = false;
|
|
||||||
repositoryDetached = true;
|
|
||||||
},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: memberPresent ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: repositoryPresent ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const result = await grantTeamRepositoryPermission(
|
|
||||||
{
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write',
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
},
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
{ stateRoot: join(cleanup, 'state'), actor: 'provisioner' },
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(memberPresent).toBe(false);
|
|
||||||
expect(repositoryPresent).toBe(false);
|
|
||||||
expect(memberRemoved).toBe(true);
|
|
||||||
expect(repositoryDetached).toBe(true);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a second governed mutation while the same team lock is held', async (): Promise<void> => {
|
|
||||||
cleanup = await mkdtemp(join(tmpdir(), 'mosaic-team-grant-'));
|
|
||||||
let releaseFirst!: () => void;
|
|
||||||
const firstMayFinish = new Promise<void>((resolve): void => {
|
|
||||||
releaseFirst = resolve;
|
|
||||||
});
|
|
||||||
let markFirstEntered!: () => void;
|
|
||||||
const firstEntered = new Promise<void>((resolve): void => {
|
|
||||||
markFirstEntered = resolve;
|
|
||||||
});
|
|
||||||
let addCalls = 0;
|
|
||||||
let memberAdded = false;
|
|
||||||
let repositoryAttached = false;
|
|
||||||
const provider: GiteaTeamGrantProvider = {
|
|
||||||
async readBasicIdentity() {
|
|
||||||
return {
|
|
||||||
login: 'provisioner',
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async resolveTeam() {
|
|
||||||
return {
|
|
||||||
id: 7,
|
|
||||||
name: 'writers',
|
|
||||||
permission: 'write',
|
|
||||||
endpoint: 'GET /api/v1/orgs/owner/teams',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async listTeamRepositories() {
|
|
||||||
return {
|
|
||||||
repositories: repositoryAttached ? ['owner/repo'] : [],
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async addTeamMember(): Promise<void> {
|
|
||||||
addCalls += 1;
|
|
||||||
markFirstEntered();
|
|
||||||
await firstMayFinish;
|
|
||||||
memberAdded = true;
|
|
||||||
},
|
|
||||||
async removeTeamMember(): Promise<void> {
|
|
||||||
memberAdded = false;
|
|
||||||
},
|
|
||||||
async attachTeamRepository(): Promise<void> {
|
|
||||||
repositoryAttached = true;
|
|
||||||
},
|
|
||||||
async detachTeamRepository(): Promise<void> {
|
|
||||||
repositoryAttached = false;
|
|
||||||
},
|
|
||||||
async readTeamMember() {
|
|
||||||
return {
|
|
||||||
state: memberAdded ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/members/seat-name',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readTeamRepository() {
|
|
||||||
return {
|
|
||||||
state: repositoryAttached ? 'present' : 'absent',
|
|
||||||
endpoint: 'GET /api/v1/teams/7/repos/owner/repo',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readOrganizationMembership() {
|
|
||||||
return {
|
|
||||||
state: 'present',
|
|
||||||
endpoint: 'GET /api/v1/users/seat-name/orgs',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
const request = {
|
|
||||||
identity: 'seat-name',
|
|
||||||
estate: 'homelab',
|
|
||||||
host: 'git.example.invalid',
|
|
||||||
repo: 'owner/repo',
|
|
||||||
permission: 'write' as const,
|
|
||||||
team: 'writers',
|
|
||||||
readOnlyControlIdentity: 'read-control',
|
|
||||||
};
|
|
||||||
const options = { stateRoot: join(cleanup, 'state-one'), actor: 'provisioner' };
|
|
||||||
const secondOptions = { stateRoot: join(cleanup, 'state-two'), actor: 'provisioner' };
|
|
||||||
|
|
||||||
const first = grantTeamRepositoryPermission(
|
|
||||||
request,
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
options,
|
|
||||||
);
|
|
||||||
await firstEntered;
|
|
||||||
const second = await grantTeamRepositoryPermission(
|
|
||||||
request,
|
|
||||||
authority,
|
|
||||||
provider,
|
|
||||||
validation(),
|
|
||||||
secondOptions,
|
|
||||||
);
|
|
||||||
releaseFirst();
|
|
||||||
const completedFirst = await first;
|
|
||||||
|
|
||||||
expect(completedFirst.outcome).toBe('ok');
|
|
||||||
expect(second.outcome).toBe('indeterminate');
|
|
||||||
expect(second.reason.code).toBe('concurrent-mutation');
|
|
||||||
expect(second.mutation).toBe('none');
|
|
||||||
expect(addCalls).toBe(1);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,589 +0,0 @@
|
|||||||
import { spawnSync } from 'node:child_process';
|
|
||||||
import { constants, lstatSync } from 'node:fs';
|
|
||||||
import { open } from 'node:fs/promises';
|
|
||||||
import { join } from 'node:path';
|
|
||||||
import { ensureManagedDirectory } from '../fleet/secure-file.js';
|
|
||||||
import { CredentialAuditJournal, CredentialJournalError } from './audit-journal.js';
|
|
||||||
import type {
|
|
||||||
CredentialValidationDependencies,
|
|
||||||
ResolvedCredential,
|
|
||||||
} from './credential-provider.dto.js';
|
|
||||||
import type {
|
|
||||||
CredentialGrantResultDto,
|
|
||||||
DirectGrantRequestDto,
|
|
||||||
OrganizationMembershipEvidenceDto,
|
|
||||||
} from './grant.dto.js';
|
|
||||||
import type { RepositoryPermission } from './credential-result.dto.js';
|
|
||||||
import { CredentialGrantExecutionError } from './grant.js';
|
|
||||||
import { evaluateGiteaReadValidation, evaluateGiteaWriteValidation } from './validate.js';
|
|
||||||
|
|
||||||
export interface TeamResolutionEvidence {
|
|
||||||
readonly id: number;
|
|
||||||
readonly name: string;
|
|
||||||
readonly permission: RepositoryPermission;
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
export interface PresenceEvidence {
|
|
||||||
readonly state: 'present' | 'absent';
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
export interface TeamRepositorySetEvidence {
|
|
||||||
readonly repositories: readonly string[];
|
|
||||||
readonly endpoint: string;
|
|
||||||
readonly contentType: string;
|
|
||||||
}
|
|
||||||
export interface TeamGrantRequest extends DirectGrantRequestDto {
|
|
||||||
readonly team: string;
|
|
||||||
}
|
|
||||||
export interface TeamGrantResult extends CredentialGrantResultDto {
|
|
||||||
readonly evidence: CredentialGrantResultDto['evidence'] & {
|
|
||||||
readonly team: TeamResolutionEvidence | null;
|
|
||||||
readonly teamMembership: PresenceEvidence | null;
|
|
||||||
readonly teamRepository: PresenceEvidence | null;
|
|
||||||
readonly teamRepositorySet: TeamRepositorySetEvidence | null;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
export interface GiteaTeamGrantProvider {
|
|
||||||
readBasicIdentity(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
): Promise<{ readonly login: string; readonly endpoint: string; readonly contentType: string }>;
|
|
||||||
resolveTeam(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
organization: string,
|
|
||||||
team: string,
|
|
||||||
): Promise<TeamResolutionEvidence>;
|
|
||||||
listTeamRepositories(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
): Promise<TeamRepositorySetEvidence>;
|
|
||||||
addTeamMember(authority: ResolvedCredential, teamId: number, identity: string): Promise<void>;
|
|
||||||
removeTeamMember(authority: ResolvedCredential, teamId: number, identity: string): Promise<void>;
|
|
||||||
attachTeamRepository(authority: ResolvedCredential, teamId: number, repo: string): Promise<void>;
|
|
||||||
detachTeamRepository(authority: ResolvedCredential, teamId: number, repo: string): Promise<void>;
|
|
||||||
readTeamMember(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
identity: string,
|
|
||||||
): Promise<PresenceEvidence>;
|
|
||||||
readTeamRepository(
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
teamId: number,
|
|
||||||
repo: string,
|
|
||||||
): Promise<PresenceEvidence>;
|
|
||||||
readOrganizationMembership(
|
|
||||||
subject: ResolvedCredential,
|
|
||||||
organization: string,
|
|
||||||
): Promise<OrganizationMembershipEvidenceDto>;
|
|
||||||
}
|
|
||||||
type ReleaseTeamGrantLock = () => Promise<void>;
|
|
||||||
type AcquireTeamGrantLock = (
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
teamId: number,
|
|
||||||
) => Promise<ReleaseTeamGrantLock>;
|
|
||||||
|
|
||||||
export interface TeamGrantOptions {
|
|
||||||
readonly stateRoot: string;
|
|
||||||
readonly actor: string;
|
|
||||||
readonly acquireTeamLock?: AcquireTeamGrantLock;
|
|
||||||
}
|
|
||||||
|
|
||||||
interface TeamGrantFinalization {
|
|
||||||
readonly outcome: 'ok' | 'refused' | 'indeterminate';
|
|
||||||
readonly reasonCode: string;
|
|
||||||
}
|
|
||||||
|
|
||||||
class TeamGrantLockError extends Error {
|
|
||||||
constructor(public readonly code: 'concurrent-mutation' | 'mutation-lock-unavailable') {
|
|
||||||
super(code);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function acquireTeamGrantLock(
|
|
||||||
estate: string,
|
|
||||||
host: string,
|
|
||||||
teamId: number,
|
|
||||||
): Promise<() => Promise<void>> {
|
|
||||||
const uid = process.getuid?.();
|
|
||||||
if (uid === undefined) throw new TeamGrantLockError('mutation-lock-unavailable');
|
|
||||||
const locksDirectory = `/tmp/mosaic-cred-team-locks-${uid.toString()}`;
|
|
||||||
ensureManagedDirectory(locksDirectory, locksDirectory);
|
|
||||||
const directory = lstatSync(locksDirectory);
|
|
||||||
if (
|
|
||||||
!directory.isDirectory() ||
|
|
||||||
directory.isSymbolicLink() ||
|
|
||||||
directory.uid !== uid ||
|
|
||||||
(directory.mode & 0o077) !== 0
|
|
||||||
) {
|
|
||||||
throw new TeamGrantLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
const lockPath = join(locksDirectory, `${estate}--${host}--team-${teamId.toString()}.lock`);
|
|
||||||
let handle: Awaited<ReturnType<typeof open>>;
|
|
||||||
try {
|
|
||||||
handle = await open(
|
|
||||||
lockPath,
|
|
||||||
constants.O_CREAT | constants.O_RDWR | constants.O_NOFOLLOW,
|
|
||||||
0o600,
|
|
||||||
);
|
|
||||||
} catch {
|
|
||||||
throw new TeamGrantLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
const file = await handle.stat();
|
|
||||||
if (!file.isFile() || file.uid !== uid || (file.mode & 0o077) !== 0) {
|
|
||||||
throw new Error('team mutation lock file is unsafe');
|
|
||||||
}
|
|
||||||
} catch {
|
|
||||||
await handle.close().catch((): void => undefined);
|
|
||||||
throw new TeamGrantLockError('mutation-lock-unavailable');
|
|
||||||
}
|
|
||||||
// The child's fd 3 is a dup of the parent's open file description. Linux
|
|
||||||
// flock(2) associates the lock with that description, so it remains held
|
|
||||||
// after the helper exits until this process closes `handle` below.
|
|
||||||
const acquired = spawnSync('/usr/bin/flock', ['-n', '3'], {
|
|
||||||
stdio: ['ignore', 'ignore', 'ignore', handle.fd],
|
|
||||||
});
|
|
||||||
if (acquired.error !== undefined || acquired.status !== 0) {
|
|
||||||
await handle.close().catch((): void => undefined);
|
|
||||||
throw new TeamGrantLockError(
|
|
||||||
acquired.status === 1 ? 'concurrent-mutation' : 'mutation-lock-unavailable',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return async (): Promise<void> => {
|
|
||||||
await handle.close();
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function grantTeamRepositoryPermission(
|
|
||||||
request: TeamGrantRequest,
|
|
||||||
authority: ResolvedCredential,
|
|
||||||
provider: GiteaTeamGrantProvider,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
options: TeamGrantOptions,
|
|
||||||
): Promise<TeamGrantResult> {
|
|
||||||
const journal = await CredentialAuditJournal.open(options.stateRoot, {
|
|
||||||
operation: 'grant',
|
|
||||||
actor: options.actor,
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
});
|
|
||||||
await journal.recordIntent('provider-grant');
|
|
||||||
let mutation: 'none' | 'unknown' | 'applied' = 'none';
|
|
||||||
let releaseTeamLock: (() => Promise<void>) | undefined;
|
|
||||||
let teamLockReleaseStarted = false;
|
|
||||||
let rollbackTeam: TeamResolutionEvidence | undefined;
|
|
||||||
let membershipBeforeMutation: PresenceEvidence | undefined;
|
|
||||||
let repositoryAttachedBeforeMutation = false;
|
|
||||||
let memberMutationAttempted = false;
|
|
||||||
let repositoryMutationAttempted = false;
|
|
||||||
const sealFinalVerdict = async (
|
|
||||||
providerOutcome: 'ok' | 'refused' | 'indeterminate',
|
|
||||||
providerReasonCode: string,
|
|
||||||
): Promise<TeamGrantFinalization> => {
|
|
||||||
const release = releaseTeamLock;
|
|
||||||
releaseTeamLock = undefined;
|
|
||||||
if (release !== undefined) {
|
|
||||||
teamLockReleaseStarted = true;
|
|
||||||
try {
|
|
||||||
await release();
|
|
||||||
} catch {
|
|
||||||
await journal.seal('indeterminate', 'mutation-lock-release-failed');
|
|
||||||
return { outcome: 'indeterminate', reasonCode: 'mutation-lock-release-failed' };
|
|
||||||
}
|
|
||||||
}
|
|
||||||
await journal.seal(providerOutcome, providerReasonCode);
|
|
||||||
return { outcome: providerOutcome, reasonCode: providerReasonCode };
|
|
||||||
};
|
|
||||||
try {
|
|
||||||
const authorityIdentity = await provider.readBasicIdentity(authority);
|
|
||||||
const organization = request.repo.split('/')[0] ?? '';
|
|
||||||
const team = await provider.resolveTeam(authority, organization, request.team);
|
|
||||||
rollbackTeam = team;
|
|
||||||
if (authorityIdentity.login !== options.actor || team.permission !== request.permission) {
|
|
||||||
await journal.seal('refused', 'provider-identity-mismatch');
|
|
||||||
return result(
|
|
||||||
request,
|
|
||||||
journal,
|
|
||||||
'refused',
|
|
||||||
'none',
|
|
||||||
'provider-identity-mismatch',
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: authorityIdentity.endpoint,
|
|
||||||
contentType: authorityIdentity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: team.endpoint,
|
|
||||||
contentType: team.contentType,
|
|
||||||
decision: `permission-${team.permission}`,
|
|
||||||
});
|
|
||||||
try {
|
|
||||||
releaseTeamLock = await (options.acquireTeamLock ?? acquireTeamGrantLock)(
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
team.id,
|
|
||||||
);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (!(error instanceof TeamGrantLockError)) throw error;
|
|
||||||
await journal.seal('indeterminate', error.code);
|
|
||||||
return result(
|
|
||||||
request,
|
|
||||||
journal,
|
|
||||||
'indeterminate',
|
|
||||||
'none',
|
|
||||||
error.code,
|
|
||||||
null,
|
|
||||||
team,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const teamRepositorySet = await provider.listTeamRepositories(authority, team.id);
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: teamRepositorySet.endpoint,
|
|
||||||
contentType: teamRepositorySet.contentType,
|
|
||||||
decision: 'team-repository-set-verified',
|
|
||||||
});
|
|
||||||
if (teamRepositorySet.repositories.some((repo): boolean => repo !== request.repo)) {
|
|
||||||
const finalization = await sealFinalVerdict('refused', 'team-scope-exceeds-request');
|
|
||||||
return result(
|
|
||||||
request,
|
|
||||||
journal,
|
|
||||||
finalization.outcome,
|
|
||||||
'none',
|
|
||||||
finalization.reasonCode,
|
|
||||||
null,
|
|
||||||
team,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
teamRepositorySet,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const repositoryAttachedBefore = teamRepositorySet.repositories.includes(request.repo);
|
|
||||||
repositoryAttachedBeforeMutation = repositoryAttachedBefore;
|
|
||||||
const membershipBefore = await provider.readTeamMember(authority, team.id, request.identity);
|
|
||||||
membershipBeforeMutation = membershipBefore;
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: membershipBefore.endpoint,
|
|
||||||
contentType: membershipBefore.contentType,
|
|
||||||
decision: membershipBefore.state === 'present' ? 'team-member-present' : 'team-member-absent',
|
|
||||||
});
|
|
||||||
mutation = 'unknown';
|
|
||||||
memberMutationAttempted = true;
|
|
||||||
await provider.addTeamMember(authority, team.id, request.identity);
|
|
||||||
mutation = 'applied';
|
|
||||||
await journal.recordMutation('team-member-applied');
|
|
||||||
repositoryMutationAttempted = true;
|
|
||||||
await provider.attachTeamRepository(authority, team.id, request.repo);
|
|
||||||
await journal.recordMutation('team-repository-applied');
|
|
||||||
let teamMembership = await provider.readTeamMember(authority, team.id, request.identity);
|
|
||||||
let teamRepository = await provider.readTeamRepository(authority, team.id, request.repo);
|
|
||||||
const finalTeamRepositorySet = await provider.listTeamRepositories(authority, team.id);
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: teamMembership.endpoint,
|
|
||||||
contentType: teamMembership.contentType,
|
|
||||||
decision: teamMembership.state === 'present' ? 'team-member-present' : 'team-member-absent',
|
|
||||||
});
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: teamRepository.endpoint,
|
|
||||||
contentType: teamRepository.contentType,
|
|
||||||
decision:
|
|
||||||
teamRepository.state === 'present' ? 'team-repository-present' : 'team-repository-absent',
|
|
||||||
});
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: finalTeamRepositorySet.endpoint,
|
|
||||||
contentType: finalTeamRepositorySet.contentType,
|
|
||||||
decision: 'team-repository-set-verified',
|
|
||||||
});
|
|
||||||
const scopeRemainedExact =
|
|
||||||
finalTeamRepositorySet.repositories.length === 1 &&
|
|
||||||
finalTeamRepositorySet.repositories[0] === request.repo;
|
|
||||||
if (!scopeRemainedExact) {
|
|
||||||
if (membershipBefore.state === 'absent') {
|
|
||||||
await provider.removeTeamMember(authority, team.id, request.identity);
|
|
||||||
await journal.recordMutation('team-member-rollback-applied');
|
|
||||||
teamMembership = await provider.readTeamMember(authority, team.id, request.identity);
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: teamMembership.endpoint,
|
|
||||||
contentType: teamMembership.contentType,
|
|
||||||
decision:
|
|
||||||
teamMembership.state === 'present' ? 'team-member-present' : 'team-member-absent',
|
|
||||||
});
|
|
||||||
if (teamMembership.state !== 'absent') throw new Error('team member rollback disagreed');
|
|
||||||
}
|
|
||||||
if (!repositoryAttachedBefore) {
|
|
||||||
await provider.detachTeamRepository(authority, team.id, request.repo);
|
|
||||||
await journal.recordMutation('team-repository-rollback-applied');
|
|
||||||
teamRepository = await provider.readTeamRepository(authority, team.id, request.repo);
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: teamRepository.endpoint,
|
|
||||||
contentType: teamRepository.contentType,
|
|
||||||
decision:
|
|
||||||
teamRepository.state === 'present'
|
|
||||||
? 'team-repository-present'
|
|
||||||
: 'team-repository-absent',
|
|
||||||
});
|
|
||||||
if (teamRepository.state !== 'absent') {
|
|
||||||
throw new Error('team repository rollback disagreed');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
const finalization = await sealFinalVerdict(
|
|
||||||
'indeterminate',
|
|
||||||
'team-scope-changed-during-grant',
|
|
||||||
);
|
|
||||||
return result(
|
|
||||||
request,
|
|
||||||
journal,
|
|
||||||
finalization.outcome,
|
|
||||||
'applied',
|
|
||||||
finalization.reasonCode,
|
|
||||||
null,
|
|
||||||
team,
|
|
||||||
teamMembership,
|
|
||||||
teamRepository,
|
|
||||||
null,
|
|
||||||
finalTeamRepositorySet,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const subject = await dependencies.resolver.resolve(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
);
|
|
||||||
const organizationMembership =
|
|
||||||
subject === undefined
|
|
||||||
? null
|
|
||||||
: await provider.readOrganizationMembership(subject, organization);
|
|
||||||
const validation =
|
|
||||||
request.permission === 'read'
|
|
||||||
? await evaluateGiteaReadValidation(request, dependencies)
|
|
||||||
: await evaluateGiteaWriteValidation(request, dependencies);
|
|
||||||
if (organizationMembership !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: organizationMembership.endpoint,
|
|
||||||
contentType: organizationMembership.contentType,
|
|
||||||
decision:
|
|
||||||
organizationMembership.state === 'present'
|
|
||||||
? 'organization-member-present'
|
|
||||||
: 'organization-member-absent',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.providerIdentity !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: validation.evidence.providerIdentity.endpoint,
|
|
||||||
contentType: validation.evidence.providerIdentity.contentType,
|
|
||||||
decision: 'identity-verified',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.repositoryPermission !== null) {
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: validation.evidence.repositoryPermission.endpoint,
|
|
||||||
contentType: validation.evidence.repositoryPermission.contentType,
|
|
||||||
decision: `permission-${validation.evidence.repositoryPermission.effective}`,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
if (validation.evidence.writeDifferential !== null) {
|
|
||||||
await journal.recordMutation('transport-write-verified');
|
|
||||||
}
|
|
||||||
const ok =
|
|
||||||
teamMembership.state === 'present' &&
|
|
||||||
teamRepository.state === 'present' &&
|
|
||||||
organizationMembership?.state === 'present' &&
|
|
||||||
validation.outcome === 'ok' &&
|
|
||||||
validation.evidence.repositoryPermission?.effective === request.permission;
|
|
||||||
const finalization = await sealFinalVerdict(
|
|
||||||
ok ? 'ok' : 'indeterminate',
|
|
||||||
ok ? 'grant-verified' : 'permission-evidence-disagrees',
|
|
||||||
);
|
|
||||||
return result(
|
|
||||||
request,
|
|
||||||
journal,
|
|
||||||
finalization.outcome,
|
|
||||||
'applied',
|
|
||||||
finalization.reasonCode,
|
|
||||||
validation,
|
|
||||||
team,
|
|
||||||
teamMembership,
|
|
||||||
teamRepository,
|
|
||||||
organizationMembership,
|
|
||||||
finalTeamRepositorySet,
|
|
||||||
);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
let compensationError: unknown;
|
|
||||||
try {
|
|
||||||
if (
|
|
||||||
!teamLockReleaseStarted &&
|
|
||||||
rollbackTeam !== undefined &&
|
|
||||||
membershipBeforeMutation?.state === 'absent' &&
|
|
||||||
memberMutationAttempted
|
|
||||||
) {
|
|
||||||
let current = await provider.readTeamMember(authority, rollbackTeam.id, request.identity);
|
|
||||||
if (current.state === 'present') {
|
|
||||||
await provider.removeTeamMember(authority, rollbackTeam.id, request.identity);
|
|
||||||
await journal.recordMutation('team-member-rollback-applied');
|
|
||||||
current = await provider.readTeamMember(authority, rollbackTeam.id, request.identity);
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: current.endpoint,
|
|
||||||
contentType: current.contentType,
|
|
||||||
decision: current.state === 'present' ? 'team-member-present' : 'team-member-absent',
|
|
||||||
});
|
|
||||||
if (current.state !== 'absent') throw new Error('team member rollback disagreed');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
!teamLockReleaseStarted &&
|
|
||||||
rollbackTeam !== undefined &&
|
|
||||||
!repositoryAttachedBeforeMutation &&
|
|
||||||
repositoryMutationAttempted
|
|
||||||
) {
|
|
||||||
let current = await provider.readTeamRepository(authority, rollbackTeam.id, request.repo);
|
|
||||||
if (current.state === 'present') {
|
|
||||||
await provider.detachTeamRepository(authority, rollbackTeam.id, request.repo);
|
|
||||||
await journal.recordMutation('team-repository-rollback-applied');
|
|
||||||
current = await provider.readTeamRepository(authority, rollbackTeam.id, request.repo);
|
|
||||||
await journal.recordProviderEvidence({
|
|
||||||
endpoint: current.endpoint,
|
|
||||||
contentType: current.contentType,
|
|
||||||
decision:
|
|
||||||
current.state === 'present' ? 'team-repository-present' : 'team-repository-absent',
|
|
||||||
});
|
|
||||||
if (current.state !== 'absent') throw new Error('team repository rollback disagreed');
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} catch (rollbackError: unknown) {
|
|
||||||
compensationError = rollbackError;
|
|
||||||
}
|
|
||||||
const auditError =
|
|
||||||
compensationError instanceof CredentialJournalError
|
|
||||||
? compensationError
|
|
||||||
: error instanceof CredentialJournalError
|
|
||||||
? error
|
|
||||||
: undefined;
|
|
||||||
if (auditError !== undefined) {
|
|
||||||
throw new CredentialGrantExecutionError(auditError.code, mutation, journal.journalId());
|
|
||||||
}
|
|
||||||
const reasonCode =
|
|
||||||
compensationError !== undefined
|
|
||||||
? 'rollback-incomplete'
|
|
||||||
: mutation === 'applied'
|
|
||||||
? 'readback-missing'
|
|
||||||
: 'mutation-state-unknown';
|
|
||||||
let finalization: Awaited<ReturnType<typeof sealFinalVerdict>>;
|
|
||||||
try {
|
|
||||||
finalization = await sealFinalVerdict('indeterminate', reasonCode);
|
|
||||||
} catch (journalError: unknown) {
|
|
||||||
if (journalError instanceof CredentialJournalError) {
|
|
||||||
throw new CredentialGrantExecutionError(journalError.code, mutation, journal.journalId());
|
|
||||||
}
|
|
||||||
throw journalError;
|
|
||||||
}
|
|
||||||
return result(
|
|
||||||
request,
|
|
||||||
journal,
|
|
||||||
finalization.outcome,
|
|
||||||
mutation,
|
|
||||||
finalization.reasonCode,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
null,
|
|
||||||
);
|
|
||||||
} finally {
|
|
||||||
const release = releaseTeamLock;
|
|
||||||
releaseTeamLock = undefined;
|
|
||||||
if (release !== undefined) {
|
|
||||||
teamLockReleaseStarted = true;
|
|
||||||
try {
|
|
||||||
await release();
|
|
||||||
} catch {
|
|
||||||
try {
|
|
||||||
await journal.seal('indeterminate', 'mutation-lock-release-failed');
|
|
||||||
} catch (journalError: unknown) {
|
|
||||||
if (journalError instanceof CredentialJournalError) {
|
|
||||||
throw new CredentialGrantExecutionError(
|
|
||||||
journalError.code,
|
|
||||||
mutation,
|
|
||||||
journal.journalId(),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
throw journalError;
|
|
||||||
}
|
|
||||||
throw new CredentialGrantExecutionError(
|
|
||||||
'mutation-lock-release-failed',
|
|
||||||
mutation,
|
|
||||||
journal.journalId(),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
function result(
|
|
||||||
request: TeamGrantRequest,
|
|
||||||
journal: CredentialAuditJournal,
|
|
||||||
outcome: 'ok' | 'refused' | 'indeterminate',
|
|
||||||
mutation: 'none' | 'unknown' | 'applied',
|
|
||||||
code: string,
|
|
||||||
validation: Awaited<ReturnType<typeof evaluateGiteaWriteValidation>> | null,
|
|
||||||
team: TeamResolutionEvidence | null,
|
|
||||||
teamMembership: PresenceEvidence | null,
|
|
||||||
teamRepository: PresenceEvidence | null,
|
|
||||||
organizationMembership: OrganizationMembershipEvidenceDto | null,
|
|
||||||
teamRepositorySet: TeamRepositorySetEvidence | null,
|
|
||||||
): TeamGrantResult {
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation: 'grant',
|
|
||||||
outcome,
|
|
||||||
exitCode: outcome === 'ok' ? 0 : outcome === 'refused' ? 10 : 30,
|
|
||||||
retryable: false,
|
|
||||||
subject: {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
},
|
|
||||||
mutation,
|
|
||||||
reason: {
|
|
||||||
code,
|
|
||||||
message:
|
|
||||||
outcome === 'ok'
|
|
||||||
? 'Team grant matched every provider read-back.'
|
|
||||||
: 'Team grant was refused or could not be established.',
|
|
||||||
},
|
|
||||||
evidence: {
|
|
||||||
providerIdentity: validation?.evidence.providerIdentity ?? null,
|
|
||||||
tokenCapabilities: validation?.evidence.tokenCapabilities ?? {
|
|
||||||
state: 'not-measured',
|
|
||||||
scopes: [],
|
|
||||||
source: 'runtime-not-authorized',
|
|
||||||
},
|
|
||||||
repositoryPermission: validation?.evidence.repositoryPermission ?? null,
|
|
||||||
writeDifferential: validation?.evidence.writeDifferential ?? null,
|
|
||||||
collaboratorPermission: null,
|
|
||||||
organizationMembership,
|
|
||||||
team,
|
|
||||||
teamMembership,
|
|
||||||
teamRepository,
|
|
||||||
teamRepositorySet,
|
|
||||||
},
|
|
||||||
audit: { journalId: journal.journalId(), state: 'sealed' },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,413 +0,0 @@
|
|||||||
import { describe, expect, it } from 'vitest';
|
|
||||||
import { CredentialProviderEvidenceError } from './gitea-provider.js';
|
|
||||||
import {
|
|
||||||
evaluateGiteaReadValidation,
|
|
||||||
evaluateGiteaWriteValidation,
|
|
||||||
type CredentialResolver,
|
|
||||||
type CredentialValidationDependencies,
|
|
||||||
type GiteaCredentialProvider,
|
|
||||||
type ProviderIdentityEvidence,
|
|
||||||
type ReceivePackEvidence,
|
|
||||||
type RepositoryPermissionEvidence,
|
|
||||||
type ResolvedCredential,
|
|
||||||
} from './validate.js';
|
|
||||||
|
|
||||||
interface FixtureOptions {
|
|
||||||
readonly subjectProviderIdentity?: string;
|
|
||||||
readonly subjectPermission?: 'none' | 'read' | 'write' | 'admin';
|
|
||||||
readonly subjectTransportState?: 'advertised' | 'refused';
|
|
||||||
readonly subjectTransportPrincipal?: string;
|
|
||||||
readonly subjectTransportResolutionId?: string;
|
|
||||||
readonly controlProviderIdentity?: string;
|
|
||||||
readonly controlPermission?: 'none' | 'read' | 'write' | 'admin';
|
|
||||||
readonly controlTransportState?: 'advertised' | 'refused';
|
|
||||||
readonly controlTransportPrincipal?: string;
|
|
||||||
readonly unauthenticatedTransportState?: 'advertised' | 'refused';
|
|
||||||
readonly omitControl?: boolean;
|
|
||||||
readonly requiredPermission?: 'read' | 'write' | 'admin';
|
|
||||||
}
|
|
||||||
|
|
||||||
interface Fixture {
|
|
||||||
readonly dependencies: CredentialValidationDependencies;
|
|
||||||
readonly resolverCalls: string[];
|
|
||||||
readonly identityHandles: ResolvedCredential[];
|
|
||||||
readonly permissionHandles: ResolvedCredential[];
|
|
||||||
readonly receivePackHandles: Array<ResolvedCredential | undefined>;
|
|
||||||
}
|
|
||||||
|
|
||||||
const SUBJECT = 'seat-name';
|
|
||||||
const CONTROL = 'read-only-control';
|
|
||||||
const ESTATE = 'homelab';
|
|
||||||
const HOST = 'git.example.invalid';
|
|
||||||
const REPO = 'owner/repo';
|
|
||||||
|
|
||||||
function credential(identity: string, resolutionId: string): ResolvedCredential {
|
|
||||||
return Object.freeze({
|
|
||||||
identity,
|
|
||||||
estate: ESTATE,
|
|
||||||
host: HOST,
|
|
||||||
resolutionId,
|
|
||||||
secret: new Uint8Array([99, 97, 110, 97, 114, 121]),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
function fixture(options: FixtureOptions = {}): Fixture {
|
|
||||||
const subjectCredential = credential(SUBJECT, 'subject-resolution');
|
|
||||||
const controlCredential = credential(CONTROL, 'control-resolution');
|
|
||||||
const resolverCalls: string[] = [];
|
|
||||||
const identityHandles: ResolvedCredential[] = [];
|
|
||||||
const permissionHandles: ResolvedCredential[] = [];
|
|
||||||
const receivePackHandles: Array<ResolvedCredential | undefined> = [];
|
|
||||||
|
|
||||||
const resolver: CredentialResolver = {
|
|
||||||
async resolve(identity: string): Promise<ResolvedCredential | undefined> {
|
|
||||||
resolverCalls.push(identity);
|
|
||||||
if (identity === SUBJECT) return subjectCredential;
|
|
||||||
if (identity === CONTROL && options.omitControl !== true) return controlCredential;
|
|
||||||
return undefined;
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
const provider: GiteaCredentialProvider = {
|
|
||||||
async readIdentity(resolved: ResolvedCredential): Promise<ProviderIdentityEvidence> {
|
|
||||||
identityHandles.push(resolved);
|
|
||||||
const login =
|
|
||||||
resolved.identity === SUBJECT
|
|
||||||
? (options.subjectProviderIdentity ?? SUBJECT)
|
|
||||||
: (options.controlProviderIdentity ?? CONTROL);
|
|
||||||
return {
|
|
||||||
login,
|
|
||||||
endpoint: 'GET /api/v1/user',
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async readRepositoryPermission(
|
|
||||||
resolved: ResolvedCredential,
|
|
||||||
): Promise<RepositoryPermissionEvidence> {
|
|
||||||
permissionHandles.push(resolved);
|
|
||||||
const effective =
|
|
||||||
resolved.identity === SUBJECT
|
|
||||||
? (options.subjectPermission ?? 'write')
|
|
||||||
: (options.controlPermission ?? 'read');
|
|
||||||
return {
|
|
||||||
effective,
|
|
||||||
endpoint: `GET /api/v1/repos/${REPO}`,
|
|
||||||
contentType: 'application/json',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
async probeReceivePack(resolved: ResolvedCredential | undefined): Promise<ReceivePackEvidence> {
|
|
||||||
receivePackHandles.push(resolved);
|
|
||||||
if (resolved === undefined) {
|
|
||||||
return {
|
|
||||||
state: options.unauthenticatedTransportState ?? 'refused',
|
|
||||||
principal: null,
|
|
||||||
resolutionId: null,
|
|
||||||
contentType: 'text/plain',
|
|
||||||
};
|
|
||||||
}
|
|
||||||
if (resolved.identity === SUBJECT) {
|
|
||||||
return {
|
|
||||||
state: options.subjectTransportState ?? 'advertised',
|
|
||||||
principal: options.subjectTransportPrincipal ?? SUBJECT,
|
|
||||||
resolutionId: options.subjectTransportResolutionId ?? resolved.resolutionId,
|
|
||||||
contentType: 'application/x-git-receive-pack-advertisement',
|
|
||||||
};
|
|
||||||
}
|
|
||||||
return {
|
|
||||||
state: options.controlTransportState ?? 'refused',
|
|
||||||
principal: options.controlTransportPrincipal ?? CONTROL,
|
|
||||||
resolutionId: resolved.resolutionId,
|
|
||||||
contentType: 'text/plain',
|
|
||||||
};
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
return {
|
|
||||||
dependencies: {
|
|
||||||
resolver,
|
|
||||||
provider,
|
|
||||||
estateRegistry: {
|
|
||||||
matches(estate: string, host: string): boolean {
|
|
||||||
return estate === ESTATE && host === HOST;
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
resolverCalls,
|
|
||||||
identityHandles,
|
|
||||||
permissionHandles,
|
|
||||||
receivePackHandles,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function validate(options: FixtureOptions = {}): Promise<{
|
|
||||||
readonly result: Awaited<ReturnType<typeof evaluateGiteaWriteValidation>>;
|
|
||||||
readonly observed: Fixture;
|
|
||||||
}> {
|
|
||||||
const observed = fixture(options);
|
|
||||||
const result = await evaluateGiteaWriteValidation(
|
|
||||||
{
|
|
||||||
identity: SUBJECT,
|
|
||||||
estate: ESTATE,
|
|
||||||
host: HOST,
|
|
||||||
repo: REPO,
|
|
||||||
readOnlyControlIdentity: CONTROL,
|
|
||||||
requiredPermission: options.requiredPermission,
|
|
||||||
},
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
return { result, observed };
|
|
||||||
}
|
|
||||||
|
|
||||||
describe('Gitea read validation', (): void => {
|
|
||||||
it('reads the explicit provider identity and repository permission without a write control', async (): Promise<void> => {
|
|
||||||
const observed = fixture({ subjectPermission: 'read' });
|
|
||||||
const result = await evaluateGiteaReadValidation(
|
|
||||||
{ identity: SUBJECT, estate: ESTATE, host: HOST, repo: REPO },
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
expect(result.evidence.providerIdentity?.login).toBe(SUBJECT);
|
|
||||||
expect(result.evidence.repositoryPermission?.effective).toBe('read');
|
|
||||||
expect(result.evidence.writeDifferential).toBeNull();
|
|
||||||
expect(observed.resolverCalls).toEqual([SUBJECT]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a repository object whose permission flags establish no read access', async (): Promise<void> => {
|
|
||||||
const observed = fixture({ subjectPermission: 'none' });
|
|
||||||
const result = await evaluateGiteaReadValidation(
|
|
||||||
{ identity: SUBJECT, estate: ESTATE, host: HOST, repo: REPO },
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('permission-denied');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('classifies the provider rejecting the subject credential as an authoritative refusal', async (): Promise<void> => {
|
|
||||||
const observed = fixture({ subjectPermission: 'read' });
|
|
||||||
observed.dependencies.provider.readIdentity = async (): Promise<ProviderIdentityEvidence> => {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'credential-rejected',
|
|
||||||
'provider rejected the supplied credential',
|
|
||||||
);
|
|
||||||
};
|
|
||||||
const result = await evaluateGiteaReadValidation(
|
|
||||||
{ identity: SUBJECT, estate: ESTATE, host: HOST, repo: REPO },
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.exitCode).toBe(10);
|
|
||||||
expect(result.reason.code).toBe('credential-rejected');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('confirms in-scope capability while reporting identity as not measured', async (): Promise<void> => {
|
|
||||||
const observed = fixture({ subjectPermission: 'write' });
|
|
||||||
observed.dependencies.provider.readIdentity = async (): Promise<ProviderIdentityEvidence> => {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'identity-read-forbidden',
|
|
||||||
'identity endpoint requires a scope this token does not hold',
|
|
||||||
);
|
|
||||||
};
|
|
||||||
const result = await evaluateGiteaReadValidation(
|
|
||||||
{ identity: SUBJECT, estate: ESTATE, host: HOST, repo: REPO },
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('identity-not-measured');
|
|
||||||
expect(result.evidence.providerIdentity).toBeNull();
|
|
||||||
expect(result.evidence.repositoryPermission?.effective).toBe('write');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a shared fallback rather than reporting a different principal as the subject', async (): Promise<void> => {
|
|
||||||
const observed = fixture({
|
|
||||||
subjectProviderIdentity: 'shared-owner',
|
|
||||||
subjectPermission: 'read',
|
|
||||||
});
|
|
||||||
const result = await evaluateGiteaReadValidation(
|
|
||||||
{ identity: SUBJECT, estate: ESTATE, host: HOST, repo: REPO },
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('provider-identity-mismatch');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('principal-bound Gitea write validation contract v1.1', (): void => {
|
|
||||||
it('confirms write capability when identity is scope-forbidden without exposing the internal reason', async (): Promise<void> => {
|
|
||||||
const observed = fixture();
|
|
||||||
const readIdentity = observed.dependencies.provider.readIdentity.bind(
|
|
||||||
observed.dependencies.provider,
|
|
||||||
);
|
|
||||||
observed.dependencies.provider.readIdentity = async (
|
|
||||||
resolved,
|
|
||||||
): Promise<ProviderIdentityEvidence> => {
|
|
||||||
if (resolved.identity === SUBJECT) {
|
|
||||||
throw new CredentialProviderEvidenceError(
|
|
||||||
'identity-read-forbidden',
|
|
||||||
'identity endpoint scope forbidden',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return readIdentity(resolved);
|
|
||||||
};
|
|
||||||
const result = await evaluateGiteaWriteValidation(
|
|
||||||
{
|
|
||||||
identity: SUBJECT,
|
|
||||||
estate: ESTATE,
|
|
||||||
host: HOST,
|
|
||||||
repo: REPO,
|
|
||||||
readOnlyControlIdentity: CONTROL,
|
|
||||||
},
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('identity-not-measured');
|
|
||||||
expect(result.evidence.repositoryPermission?.effective).toBe('write');
|
|
||||||
expect(observed.receivePackHandles).toEqual([
|
|
||||||
expect.objectContaining({ identity: SUBJECT }),
|
|
||||||
expect.objectContaining({ identity: CONTROL }),
|
|
||||||
undefined,
|
|
||||||
]);
|
|
||||||
});
|
|
||||||
it('uses one immutable subject credential handle for identity, permission, and receive-pack', async (): Promise<void> => {
|
|
||||||
const { result, observed } = await validate();
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
expect(observed.resolverCalls).toEqual([SUBJECT, CONTROL]);
|
|
||||||
expect(observed.identityHandles[0]).toBe(observed.permissionHandles[0]);
|
|
||||||
expect(observed.identityHandles[0]).toBe(observed.receivePackHandles[0]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses a subject credential whose provider identity is a shared fallback', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ subjectProviderIdentity: 'shared-owner' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('provider-identity-mismatch');
|
|
||||||
expect(result.mutation).toBe('none');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('routes a transport principal mismatch to indeterminate, not refused', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ subjectTransportPrincipal: 'shared-owner' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('transport-principal-mismatch');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('routes a transport credential-handle mismatch to indeterminate', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ subjectTransportResolutionId: 'fallback-resolution' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('transport-principal-mismatch');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses when the provider repository object authoritatively denies write', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ subjectPermission: 'read' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('permission-denied');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('is indeterminate when repo permission says write but receive-pack refuses', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ subjectTransportState: 'refused' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('permission-evidence-disagrees');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses write permission when admin permission is explicitly required', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({
|
|
||||||
requiredPermission: 'admin',
|
|
||||||
subjectPermission: 'write',
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('permission-denied');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('accepts admin permission when admin is explicitly required', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({
|
|
||||||
requiredPermission: 'admin',
|
|
||||||
subjectPermission: 'admin',
|
|
||||||
});
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('makes a write-capable read-only control invalidate the entire result', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ controlPermission: 'write' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('read-only-control-invalid');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('makes an identity-mismatched read-only control invalidate the entire result', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ controlProviderIdentity: 'other-control' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('read-only-control-invalid');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('makes a read-only control that receives write transport invalidate the result', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ controlTransportState: 'advertised' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('read-only-control-invalid');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('is indeterminate when the configured read-only control credential is absent', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ omitControl: true });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('read-only-control-invalid');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('keeps the unauthenticated arm and rejects an advertisement there', async (): Promise<void> => {
|
|
||||||
const { result } = await validate({ unauthenticatedTransportState: 'advertised' });
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('indeterminate');
|
|
||||||
expect(result.reason.code).toBe('permission-evidence-disagrees');
|
|
||||||
});
|
|
||||||
|
|
||||||
it('refuses an estate-host mismatch before resolving any credential', async (): Promise<void> => {
|
|
||||||
const observed = fixture();
|
|
||||||
const result = await evaluateGiteaWriteValidation(
|
|
||||||
{
|
|
||||||
identity: SUBJECT,
|
|
||||||
estate: 'usc',
|
|
||||||
host: HOST,
|
|
||||||
repo: REPO,
|
|
||||||
readOnlyControlIdentity: CONTROL,
|
|
||||||
},
|
|
||||||
observed.dependencies,
|
|
||||||
);
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('refused');
|
|
||||||
expect(result.reason.code).toBe('estate-host-mismatch');
|
|
||||||
expect(observed.resolverCalls).toEqual([]);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('returns structured proof bounds only after every principal-bound arm passes', async (): Promise<void> => {
|
|
||||||
const { result } = await validate();
|
|
||||||
|
|
||||||
expect(result.outcome).toBe('ok');
|
|
||||||
expect(result.evidence.writeDifferential).toMatchObject({
|
|
||||||
state: 'can-write',
|
|
||||||
credentialBinding: 'same-resolution',
|
|
||||||
transportPrincipal: SUBJECT,
|
|
||||||
authenticatedReceivePack: 'advertised',
|
|
||||||
readOnlyControl: {
|
|
||||||
identity: CONTROL,
|
|
||||||
providerPermission: 'read',
|
|
||||||
receivePack: 'refused',
|
|
||||||
},
|
|
||||||
unauthenticatedReceivePack: 'refused',
|
|
||||||
artifactCreated: false,
|
|
||||||
});
|
|
||||||
expect(result.evidence.writeDifferential?.proves).toContain('declared subject credential');
|
|
||||||
expect(result.evidence.writeDifferential?.doesNotProve).toContain('branch protection');
|
|
||||||
});
|
|
||||||
});
|
|
||||||
@@ -1,521 +0,0 @@
|
|||||||
import { CredentialProviderEvidenceError } from './gitea-provider.js';
|
|
||||||
import type {
|
|
||||||
CredentialValidationDependencies,
|
|
||||||
GiteaReadValidationRequestDto,
|
|
||||||
GiteaWriteValidationRequestDto,
|
|
||||||
ResolvedCredential,
|
|
||||||
} from './credential-provider.dto.js';
|
|
||||||
import type {
|
|
||||||
CredentialOutcome,
|
|
||||||
CredentialReasonDto,
|
|
||||||
CredentialValidationEvidenceDto,
|
|
||||||
CredentialValidationResultDto,
|
|
||||||
ProviderIdentityEvidenceDto,
|
|
||||||
ReceivePackEvidenceDto,
|
|
||||||
RepositoryPermissionEvidenceDto,
|
|
||||||
WriteDifferentialEvidenceDto,
|
|
||||||
} from './credential-result.dto.js';
|
|
||||||
|
|
||||||
export type {
|
|
||||||
CredentialResolver,
|
|
||||||
CredentialValidationDependencies,
|
|
||||||
GiteaCredentialProvider,
|
|
||||||
GiteaReadValidationRequestDto,
|
|
||||||
GiteaWriteValidationRequestDto,
|
|
||||||
ResolvedCredential,
|
|
||||||
} from './credential-provider.dto.js';
|
|
||||||
export type {
|
|
||||||
ProviderIdentityEvidenceDto as ProviderIdentityEvidence,
|
|
||||||
ReceivePackEvidenceDto as ReceivePackEvidence,
|
|
||||||
RepositoryPermissionEvidenceDto as RepositoryPermissionEvidence,
|
|
||||||
} from './credential-result.dto.js';
|
|
||||||
|
|
||||||
const JSON_CONTENT_TYPE = 'application/json';
|
|
||||||
const RUNTIME_SCOPE_NOT_MEASURED = {
|
|
||||||
state: 'not-measured' as const,
|
|
||||||
scopes: [] as readonly string[],
|
|
||||||
source: 'runtime-not-authorized' as const,
|
|
||||||
};
|
|
||||||
const RECEIVE_PACK_CONTENT_TYPE = 'application/x-git-receive-pack-advertisement';
|
|
||||||
|
|
||||||
interface ResultOptions {
|
|
||||||
readonly outcome: CredentialOutcome;
|
|
||||||
readonly code: string;
|
|
||||||
readonly message: string;
|
|
||||||
readonly retryable?: boolean;
|
|
||||||
readonly evidence?: CredentialValidationEvidenceDto;
|
|
||||||
}
|
|
||||||
|
|
||||||
function subject(request: GiteaReadValidationRequestDto): CredentialValidationResultDto['subject'] {
|
|
||||||
return {
|
|
||||||
identity: request.identity,
|
|
||||||
estate: request.estate,
|
|
||||||
host: request.host,
|
|
||||||
repo: request.repo,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
function result(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
options: ResultOptions,
|
|
||||||
): CredentialValidationResultDto {
|
|
||||||
const exits: Readonly<Record<CredentialOutcome, 0 | 10 | 20 | 30>> = {
|
|
||||||
ok: 0,
|
|
||||||
refused: 10,
|
|
||||||
error: 20,
|
|
||||||
indeterminate: 30,
|
|
||||||
};
|
|
||||||
return {
|
|
||||||
schemaVersion: 1,
|
|
||||||
operation: 'validate',
|
|
||||||
outcome: options.outcome,
|
|
||||||
exitCode: exits[options.outcome],
|
|
||||||
retryable: options.retryable ?? false,
|
|
||||||
subject: subject(request),
|
|
||||||
mutation: 'none',
|
|
||||||
reason: { code: options.code, message: options.message },
|
|
||||||
evidence: options.evidence ?? {
|
|
||||||
providerIdentity: null,
|
|
||||||
tokenCapabilities: RUNTIME_SCOPE_NOT_MEASURED,
|
|
||||||
repositoryPermission: null,
|
|
||||||
writeDifferential: null,
|
|
||||||
},
|
|
||||||
audit: { journalId: null, state: 'not-started' },
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
function refused(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
reason: CredentialReasonDto,
|
|
||||||
evidence?: CredentialValidationEvidenceDto,
|
|
||||||
): CredentialValidationResultDto {
|
|
||||||
return result(request, {
|
|
||||||
outcome: 'refused',
|
|
||||||
code: reason.code,
|
|
||||||
message: reason.message,
|
|
||||||
...(evidence === undefined ? {} : { evidence }),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
function indeterminate(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
reason: CredentialReasonDto,
|
|
||||||
evidence?: CredentialValidationEvidenceDto,
|
|
||||||
): CredentialValidationResultDto {
|
|
||||||
return result(request, {
|
|
||||||
outcome: 'indeterminate',
|
|
||||||
code: reason.code,
|
|
||||||
message: reason.message,
|
|
||||||
...(evidence === undefined ? {} : { evidence }),
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
function providerEvidenceFailure(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
error: CredentialProviderEvidenceError,
|
|
||||||
): CredentialValidationResultDto {
|
|
||||||
if (error.code === 'credential-rejected') {
|
|
||||||
return refused(request, {
|
|
||||||
code: error.code,
|
|
||||||
message: 'The provider authoritatively rejected the supplied subject credential.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
return indeterminate(request, {
|
|
||||||
code: error.code,
|
|
||||||
message: 'Provider evidence could not be evaluated completely.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
function identityContentTypeValid(evidence: ProviderIdentityEvidenceDto): boolean {
|
|
||||||
return evidence.contentType.toLowerCase().startsWith(JSON_CONTENT_TYPE);
|
|
||||||
}
|
|
||||||
|
|
||||||
function permissionContentTypeValid(evidence: RepositoryPermissionEvidenceDto): boolean {
|
|
||||||
return evidence.contentType.toLowerCase().startsWith(JSON_CONTENT_TYPE);
|
|
||||||
}
|
|
||||||
|
|
||||||
function advertised(evidence: ReceivePackEvidenceDto): boolean {
|
|
||||||
return (
|
|
||||||
evidence.state === 'advertised' &&
|
|
||||||
evidence.contentType.toLowerCase().startsWith(RECEIVE_PACK_CONTENT_TYPE)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function resolveCredential(
|
|
||||||
request: GiteaWriteValidationRequestDto,
|
|
||||||
identity: string,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
): Promise<ResolvedCredential | undefined> {
|
|
||||||
return dependencies.resolver.resolve(identity, request.estate, request.host);
|
|
||||||
}
|
|
||||||
|
|
||||||
function successfulEvidence(
|
|
||||||
subjectLogin: string,
|
|
||||||
subjectIdentity: ProviderIdentityEvidenceDto | null,
|
|
||||||
subjectPermission: RepositoryPermissionEvidenceDto,
|
|
||||||
subjectReceivePack: ReceivePackEvidenceDto,
|
|
||||||
controlIdentity: ProviderIdentityEvidenceDto,
|
|
||||||
controlPermission: RepositoryPermissionEvidenceDto,
|
|
||||||
controlReceivePack: ReceivePackEvidenceDto,
|
|
||||||
): CredentialValidationEvidenceDto {
|
|
||||||
const writeDifferential: WriteDifferentialEvidenceDto = {
|
|
||||||
state: 'can-write',
|
|
||||||
credentialBinding: 'same-resolution',
|
|
||||||
transportPrincipal: subjectLogin,
|
|
||||||
authenticatedReceivePack: 'advertised',
|
|
||||||
readOnlyControl: {
|
|
||||||
identity: controlIdentity.login,
|
|
||||||
providerPermission: controlPermission.effective,
|
|
||||||
receivePack: controlReceivePack.state,
|
|
||||||
},
|
|
||||||
unauthenticatedReceivePack: 'refused',
|
|
||||||
artifactCreated: false,
|
|
||||||
proves:
|
|
||||||
'The declared subject credential authenticated provider identity, repository permission, and write transport while a distinct provider-confirmed read-only principal and an unauthenticated caller were refused.',
|
|
||||||
doesNotProve:
|
|
||||||
'A particular ref update will pass branch protection, hooks, races, or content policy.',
|
|
||||||
};
|
|
||||||
return {
|
|
||||||
providerIdentity: subjectIdentity,
|
|
||||||
tokenCapabilities: RUNTIME_SCOPE_NOT_MEASURED,
|
|
||||||
repositoryPermission: subjectPermission,
|
|
||||||
writeDifferential,
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
async function evaluateGiteaReadValidationUnsafe(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
if (!dependencies.estateRegistry.matches(request.estate, request.host)) {
|
|
||||||
return refused(request, {
|
|
||||||
code: 'estate-host-mismatch',
|
|
||||||
message: 'The declared estate does not contain the declared host.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
const resolved = await dependencies.resolver.resolve(
|
|
||||||
request.identity,
|
|
||||||
request.estate,
|
|
||||||
request.host,
|
|
||||||
);
|
|
||||||
if (resolved === undefined) {
|
|
||||||
return refused(request, {
|
|
||||||
code: 'no-token-for-identity',
|
|
||||||
message: 'The explicit identity has no credential in the declared estate.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
let providerIdentity: ProviderIdentityEvidenceDto | null;
|
|
||||||
try {
|
|
||||||
providerIdentity = await dependencies.provider.readIdentity(resolved);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (
|
|
||||||
error instanceof CredentialProviderEvidenceError &&
|
|
||||||
error.code === 'identity-read-forbidden'
|
|
||||||
) {
|
|
||||||
const repositoryPermission = await dependencies.provider.readRepositoryPermission(
|
|
||||||
resolved,
|
|
||||||
request.repo,
|
|
||||||
);
|
|
||||||
const evidence: CredentialValidationEvidenceDto = {
|
|
||||||
providerIdentity: null,
|
|
||||||
tokenCapabilities: RUNTIME_SCOPE_NOT_MEASURED,
|
|
||||||
repositoryPermission,
|
|
||||||
writeDifferential: null,
|
|
||||||
};
|
|
||||||
if (!permissionContentTypeValid(repositoryPermission)) {
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'unexpected-content-type',
|
|
||||||
message: 'In-scope capability evidence was not JSON.',
|
|
||||||
},
|
|
||||||
evidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (repositoryPermission.effective === 'none') {
|
|
||||||
return refused(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'permission-denied',
|
|
||||||
message: 'The in-scope provider object denies repository access.',
|
|
||||||
},
|
|
||||||
evidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'identity-not-measured',
|
|
||||||
message:
|
|
||||||
'Repository capability was confirmed, but identity was not measured because this least-privilege token cannot read /user.',
|
|
||||||
},
|
|
||||||
evidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
const repositoryPermission = await dependencies.provider.readRepositoryPermission(
|
|
||||||
resolved,
|
|
||||||
request.repo,
|
|
||||||
);
|
|
||||||
const evidence: CredentialValidationEvidenceDto = {
|
|
||||||
providerIdentity,
|
|
||||||
tokenCapabilities: RUNTIME_SCOPE_NOT_MEASURED,
|
|
||||||
repositoryPermission,
|
|
||||||
writeDifferential: null,
|
|
||||||
};
|
|
||||||
if (
|
|
||||||
!identityContentTypeValid(providerIdentity) ||
|
|
||||||
!permissionContentTypeValid(repositoryPermission)
|
|
||||||
) {
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'unexpected-content-type',
|
|
||||||
message: 'Provider read evidence was not JSON.',
|
|
||||||
},
|
|
||||||
evidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (repositoryPermission.effective === 'none') {
|
|
||||||
return refused(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'permission-denied',
|
|
||||||
message: 'The provider repository object denies read permission.',
|
|
||||||
},
|
|
||||||
evidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (providerIdentity.login !== request.identity) {
|
|
||||||
return refused(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'provider-identity-mismatch',
|
|
||||||
message: 'The provider credential identity does not equal the declared subject.',
|
|
||||||
},
|
|
||||||
evidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
return result(request, {
|
|
||||||
outcome: 'ok',
|
|
||||||
code: 'validation-verified',
|
|
||||||
message: 'Provider identity and repository permission were read back.',
|
|
||||||
evidence,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function evaluateGiteaReadValidation(
|
|
||||||
request: GiteaReadValidationRequestDto,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
try {
|
|
||||||
return await evaluateGiteaReadValidationUnsafe(request, dependencies);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof CredentialProviderEvidenceError) {
|
|
||||||
return providerEvidenceFailure(request, error);
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function evaluateGiteaWriteValidationUnsafe(
|
|
||||||
request: GiteaWriteValidationRequestDto,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
if (!dependencies.estateRegistry.matches(request.estate, request.host)) {
|
|
||||||
return refused(request, {
|
|
||||||
code: 'estate-host-mismatch',
|
|
||||||
message: 'The declared estate does not contain the declared host.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const resolved = await resolveCredential(request, request.identity, dependencies);
|
|
||||||
if (resolved === undefined) {
|
|
||||||
return refused(request, {
|
|
||||||
code: 'no-token-for-identity',
|
|
||||||
message: 'The explicit identity has no credential in the declared estate.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
let subjectIdentity: ProviderIdentityEvidenceDto | null = null;
|
|
||||||
try {
|
|
||||||
subjectIdentity = await dependencies.provider.readIdentity(resolved);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (
|
|
||||||
!(error instanceof CredentialProviderEvidenceError) ||
|
|
||||||
error.code !== 'identity-read-forbidden'
|
|
||||||
) {
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
const subjectPermission = await dependencies.provider.readRepositoryPermission(
|
|
||||||
resolved,
|
|
||||||
request.repo,
|
|
||||||
);
|
|
||||||
const subjectReceivePack = await dependencies.provider.probeReceivePack(resolved, request.repo);
|
|
||||||
const baseEvidence: CredentialValidationEvidenceDto = {
|
|
||||||
providerIdentity: subjectIdentity,
|
|
||||||
tokenCapabilities: RUNTIME_SCOPE_NOT_MEASURED,
|
|
||||||
repositoryPermission: subjectPermission,
|
|
||||||
writeDifferential: null,
|
|
||||||
};
|
|
||||||
|
|
||||||
if (subjectIdentity !== null && !identityContentTypeValid(subjectIdentity)) {
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'unexpected-content-type',
|
|
||||||
message: 'The provider identity response was not JSON.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (subjectIdentity !== null && subjectIdentity.login !== request.identity) {
|
|
||||||
return refused(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'provider-identity-mismatch',
|
|
||||||
message: 'The provider credential identity does not equal the declared subject.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (!permissionContentTypeValid(subjectPermission)) {
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'unexpected-content-type',
|
|
||||||
message: 'The provider repository response was not JSON.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (request.requiredPermission === 'admin' && subjectPermission.effective !== 'admin') {
|
|
||||||
return refused(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'permission-denied',
|
|
||||||
message: 'The provider repository object denies required admin permission.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (subjectPermission.effective === 'read' || subjectPermission.effective === 'none') {
|
|
||||||
return refused(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'permission-denied',
|
|
||||||
message: 'The provider repository object denies write permission.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (
|
|
||||||
subjectReceivePack.principal !== request.identity ||
|
|
||||||
subjectReceivePack.resolutionId !== resolved.resolutionId
|
|
||||||
) {
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'transport-principal-mismatch',
|
|
||||||
message: 'The write transport evidence is not bound to the declared subject credential.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
if (!advertised(subjectReceivePack)) {
|
|
||||||
return indeterminate(
|
|
||||||
request,
|
|
||||||
{
|
|
||||||
code: 'permission-evidence-disagrees',
|
|
||||||
message: 'Repository permission and write transport evidence disagree.',
|
|
||||||
},
|
|
||||||
baseEvidence,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const control = await resolveCredential(request, request.readOnlyControlIdentity, dependencies);
|
|
||||||
if (control === undefined) {
|
|
||||||
return indeterminate(request, {
|
|
||||||
code: 'read-only-control-invalid',
|
|
||||||
message: 'The configured read-only control credential could not be resolved.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
const controlIdentity = await dependencies.provider.readIdentity(control);
|
|
||||||
const controlPermission = await dependencies.provider.readRepositoryPermission(
|
|
||||||
control,
|
|
||||||
request.repo,
|
|
||||||
);
|
|
||||||
const controlReceivePack = await dependencies.provider.probeReceivePack(control, request.repo);
|
|
||||||
|
|
||||||
const controlIsDistinct =
|
|
||||||
request.readOnlyControlIdentity !== request.identity &&
|
|
||||||
control.resolutionId !== resolved.resolutionId;
|
|
||||||
const controlIdentityMatches =
|
|
||||||
identityContentTypeValid(controlIdentity) &&
|
|
||||||
controlIdentity.login === request.readOnlyControlIdentity;
|
|
||||||
const controlPermissionIsReadOnly =
|
|
||||||
permissionContentTypeValid(controlPermission) && controlPermission.effective === 'read';
|
|
||||||
const controlTransportIsBoundAndRefused =
|
|
||||||
controlReceivePack.state === 'refused' &&
|
|
||||||
controlReceivePack.principal === request.readOnlyControlIdentity &&
|
|
||||||
controlReceivePack.resolutionId === control.resolutionId &&
|
|
||||||
!controlReceivePack.contentType.toLowerCase().startsWith(RECEIVE_PACK_CONTENT_TYPE);
|
|
||||||
if (
|
|
||||||
!controlIsDistinct ||
|
|
||||||
!controlIdentityMatches ||
|
|
||||||
!controlPermissionIsReadOnly ||
|
|
||||||
!controlTransportIsBoundAndRefused
|
|
||||||
) {
|
|
||||||
return indeterminate(request, {
|
|
||||||
code: 'read-only-control-invalid',
|
|
||||||
message:
|
|
||||||
'The read-only control was absent, identity-mismatched, write-capable, unbound, or admitted to write transport.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const unauthenticated = await dependencies.provider.probeReceivePack(undefined, request.repo);
|
|
||||||
if (
|
|
||||||
unauthenticated.state !== 'refused' ||
|
|
||||||
unauthenticated.contentType.toLowerCase().startsWith(RECEIVE_PACK_CONTENT_TYPE)
|
|
||||||
) {
|
|
||||||
return indeterminate(request, {
|
|
||||||
code: 'permission-evidence-disagrees',
|
|
||||||
message: 'The unauthenticated write-transport control was not refused.',
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const evidence = successfulEvidence(
|
|
||||||
request.identity,
|
|
||||||
subjectIdentity,
|
|
||||||
subjectPermission,
|
|
||||||
subjectReceivePack,
|
|
||||||
controlIdentity,
|
|
||||||
controlPermission,
|
|
||||||
controlReceivePack,
|
|
||||||
);
|
|
||||||
return result(request, {
|
|
||||||
outcome: subjectIdentity === null ? 'indeterminate' : 'ok',
|
|
||||||
code: subjectIdentity === null ? 'identity-not-measured' : 'validation-verified',
|
|
||||||
message:
|
|
||||||
subjectIdentity === null
|
|
||||||
? 'Write capability and both controls were confirmed, but identity was not measured because this least-privilege token cannot read /user.'
|
|
||||||
: 'Every required provider evidence layer agreed.',
|
|
||||||
evidence,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function evaluateGiteaWriteValidation(
|
|
||||||
request: GiteaWriteValidationRequestDto,
|
|
||||||
dependencies: CredentialValidationDependencies,
|
|
||||||
): Promise<CredentialValidationResultDto> {
|
|
||||||
try {
|
|
||||||
return await evaluateGiteaWriteValidationUnsafe(request, dependencies);
|
|
||||||
} catch (error: unknown) {
|
|
||||||
if (error instanceof CredentialProviderEvidenceError) {
|
|
||||||
return providerEvidenceFailure(request, error);
|
|
||||||
}
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -22,8 +22,6 @@ export interface SecureFileSnapshot {
|
|||||||
mode: number;
|
mode: number;
|
||||||
dev: number | bigint;
|
dev: number | bigint;
|
||||||
ino: number | bigint;
|
ino: number | bigint;
|
||||||
uid: number;
|
|
||||||
gid: number;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function sameIdentity(
|
function sameIdentity(
|
||||||
@@ -237,8 +235,6 @@ export function readRegularFileSecure(
|
|||||||
mode: Number(opened.mode),
|
mode: Number(opened.mode),
|
||||||
dev: opened.dev,
|
dev: opened.dev,
|
||||||
ino: opened.ino,
|
ino: opened.ino,
|
||||||
uid: opened.uid,
|
|
||||||
gid: opened.gid,
|
|
||||||
};
|
};
|
||||||
} finally {
|
} finally {
|
||||||
closeDescriptors(openedFile.descriptors);
|
closeDescriptors(openedFile.descriptors);
|
||||||
|
|||||||
@@ -1,146 +0,0 @@
|
|||||||
#!/usr/bin/env node
|
|
||||||
|
|
||||||
import { spawn } from 'node:child_process';
|
|
||||||
import { createHash, randomUUID } from 'node:crypto';
|
|
||||||
import { lstat, mkdir, readFile, rename, rm, writeFile } from 'node:fs/promises';
|
|
||||||
import { fileURLToPath } from 'node:url';
|
|
||||||
import path from 'node:path';
|
|
||||||
|
|
||||||
import { generatedSymlinkManifest, sourceFingerprint } from './preflight.mjs';
|
|
||||||
|
|
||||||
const scriptRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
|
|
||||||
|
|
||||||
function run(command, args, options) {
|
|
||||||
return new Promise((resolve, reject) => {
|
|
||||||
const child = spawn(command, args, options);
|
|
||||||
child.once('error', reject);
|
|
||||||
child.once('exit', (code, signal) => {
|
|
||||||
if (code === 0) resolve();
|
|
||||||
else
|
|
||||||
reject(
|
|
||||||
new Error(signal ? `next build terminated by ${signal}` : `next build exited ${code}`),
|
|
||||||
);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const delay = (milliseconds) => new Promise((resolve) => setTimeout(resolve, milliseconds));
|
|
||||||
|
|
||||||
async function requireRealDirectory(target, { allowMissing = false } = {}) {
|
|
||||||
try {
|
|
||||||
const stats = await lstat(target);
|
|
||||||
if (!stats.isDirectory() || stats.isSymbolicLink()) {
|
|
||||||
throw new Error(`${target} must be a real directory, not a symbolic link.`);
|
|
||||||
}
|
|
||||||
} catch (error) {
|
|
||||||
if (allowMissing && error.code === 'ENOENT') return;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function acquireBuildLock(root) {
|
|
||||||
const workRoot = path.join(root, '.mosaic-test-work');
|
|
||||||
const lock = path.join(workRoot, 'web-build.lock');
|
|
||||||
const nonce = randomUUID();
|
|
||||||
const owner = JSON.stringify({ pid: process.pid, nonce });
|
|
||||||
const deadline = Date.now() + 120_000;
|
|
||||||
await mkdir(workRoot, { recursive: true });
|
|
||||||
|
|
||||||
while (Date.now() < deadline) {
|
|
||||||
try {
|
|
||||||
await mkdir(lock);
|
|
||||||
await writeFile(path.join(lock, 'owner.json'), owner, { mode: 0o600 });
|
|
||||||
return async () => {
|
|
||||||
const current = await readFile(path.join(lock, 'owner.json'), 'utf8');
|
|
||||||
if (current !== owner) throw new Error('Web build lock ownership changed before release.');
|
|
||||||
const released = `${lock}.released-${nonce}`;
|
|
||||||
await rename(lock, released);
|
|
||||||
await rm(released, { recursive: true, force: true });
|
|
||||||
};
|
|
||||||
} catch (error) {
|
|
||||||
if (error.code !== 'EEXIST') throw error;
|
|
||||||
let lockOwner;
|
|
||||||
try {
|
|
||||||
lockOwner = JSON.parse(await readFile(path.join(lock, 'owner.json'), 'utf8'));
|
|
||||||
} catch (ownerError) {
|
|
||||||
if (ownerError.code === 'ENOENT') {
|
|
||||||
await delay(25);
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
throw new Error(`Web build lock is unreadable at ${lock}.`, { cause: ownerError });
|
|
||||||
}
|
|
||||||
try {
|
|
||||||
process.kill(lockOwner.pid, 0);
|
|
||||||
} catch (processError) {
|
|
||||||
if (processError.code !== 'ESRCH') throw processError;
|
|
||||||
const stale = `${lock}.stale-${nonce}`;
|
|
||||||
try {
|
|
||||||
await rename(lock, stale);
|
|
||||||
await rm(stale, { recursive: true, force: true });
|
|
||||||
} catch (renameError) {
|
|
||||||
if (renameError.code !== 'ENOENT') throw renameError;
|
|
||||||
}
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
await delay(25);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
throw new Error(`Timed out waiting for the web build lock at ${lock}.`);
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function buildWeb({
|
|
||||||
root = scriptRoot,
|
|
||||||
fingerprint = sourceFingerprint,
|
|
||||||
runBuild = async (webDir) =>
|
|
||||||
run(path.join(webDir, 'node_modules', '.bin', 'next'), ['build'], {
|
|
||||||
cwd: webDir,
|
|
||||||
stdio: 'inherit',
|
|
||||||
}),
|
|
||||||
} = {}) {
|
|
||||||
const releaseLock = await acquireBuildLock(root);
|
|
||||||
try {
|
|
||||||
const webDir = path.join(root, 'apps', 'web');
|
|
||||||
const nextDir = path.join(webDir, '.next');
|
|
||||||
const certificationMarker = path.join(nextDir, '.mosaic-source-hash');
|
|
||||||
const symlinkManifest = path.join(nextDir, '.mosaic-symlink-manifest');
|
|
||||||
const certificationTemporary = `${certificationMarker}.${randomUUID()}.tmp`;
|
|
||||||
const manifestTemporary = `${symlinkManifest}.${randomUUID()}.tmp`;
|
|
||||||
const before = await fingerprint(root);
|
|
||||||
|
|
||||||
await requireRealDirectory(nextDir, { allowMissing: true });
|
|
||||||
await Promise.all([
|
|
||||||
rm(certificationMarker, { force: true }),
|
|
||||||
rm(symlinkManifest, { force: true }),
|
|
||||||
]);
|
|
||||||
await runBuild(webDir);
|
|
||||||
await requireRealDirectory(nextDir);
|
|
||||||
|
|
||||||
const after = await fingerprint(root);
|
|
||||||
if (after !== before) {
|
|
||||||
throw new Error(
|
|
||||||
'Web build inputs changed during next build; generated output was not certified.',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const manifestContents = await generatedSymlinkManifest(nextDir);
|
|
||||||
const certificationContents = `${JSON.stringify({
|
|
||||||
version: 1,
|
|
||||||
sourceFingerprint: before,
|
|
||||||
symlinkManifestHash: createHash('sha256').update(manifestContents).digest('hex'),
|
|
||||||
})}\n`;
|
|
||||||
await Promise.all([
|
|
||||||
writeFile(certificationTemporary, certificationContents, { mode: 0o600 }),
|
|
||||||
writeFile(manifestTemporary, manifestContents, { mode: 0o600 }),
|
|
||||||
]);
|
|
||||||
// The certification marker is the commit point. Publishing the manifest first
|
|
||||||
// leaves interrupted builds untrusted because the marker remains absent.
|
|
||||||
await rename(manifestTemporary, symlinkManifest);
|
|
||||||
await rename(certificationTemporary, certificationMarker);
|
|
||||||
} finally {
|
|
||||||
await releaseLock();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
|
|
||||||
await buildWeb();
|
|
||||||
}
|
|
||||||
@@ -1,149 +0,0 @@
|
|||||||
import assert from 'node:assert/strict';
|
|
||||||
import { access, mkdir, readFile, rm, symlink, writeFile } from 'node:fs/promises';
|
|
||||||
import path from 'node:path';
|
|
||||||
import test from 'node:test';
|
|
||||||
|
|
||||||
import { buildWeb } from './build-web.mjs';
|
|
||||||
|
|
||||||
const fixtureRoot = path.join(process.cwd(), '.mosaic-test-work', `build-web-${process.pid}`);
|
|
||||||
|
|
||||||
async function fixture(name) {
|
|
||||||
const root = path.join(fixtureRoot, name);
|
|
||||||
await mkdir(path.join(root, 'apps', 'web', '.next'), { recursive: true });
|
|
||||||
return root;
|
|
||||||
}
|
|
||||||
|
|
||||||
async function exists(target) {
|
|
||||||
try {
|
|
||||||
await access(target);
|
|
||||||
return true;
|
|
||||||
} catch {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
test.after(async () => {
|
|
||||||
await rm(fixtureRoot, { recursive: true, force: true });
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a successful web build atomically publishes its source and symlink certification', async () => {
|
|
||||||
const root = await fixture('success');
|
|
||||||
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
|
|
||||||
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
|
|
||||||
|
|
||||||
await buildWeb({ root, fingerprint: async () => 'certified', runBuild: async () => {} });
|
|
||||||
|
|
||||||
assert.deepEqual(JSON.parse(await readFile(marker, 'utf8')), {
|
|
||||||
version: 1,
|
|
||||||
sourceFingerprint: 'certified',
|
|
||||||
symlinkManifestHash: '8a5a375cea6a55d24bd5f875856da63feba33adbefb15a92a0007719b84bcf11',
|
|
||||||
});
|
|
||||||
assert.equal(await readFile(manifest, 'utf8'), '{"version":1,"links":[]}\n');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a failed web build leaves no certification marker', async () => {
|
|
||||||
const root = await fixture('failure');
|
|
||||||
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
|
|
||||||
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
|
|
||||||
await writeFile(marker, 'stale\n');
|
|
||||||
await writeFile(manifest, 'stale\n');
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
buildWeb({
|
|
||||||
root,
|
|
||||||
fingerprint: async () => 'before',
|
|
||||||
runBuild: async () => {
|
|
||||||
throw new Error('build failed');
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
/build failed/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await exists(marker), false);
|
|
||||||
assert.equal(await exists(manifest), false);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('overlapping web builds are serialized while the marker remains absent', async () => {
|
|
||||||
const root = await fixture('overlap');
|
|
||||||
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
|
|
||||||
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
|
|
||||||
await writeFile(marker, 'stale\n');
|
|
||||||
await writeFile(manifest, 'stale\n');
|
|
||||||
let releaseFirst;
|
|
||||||
let secondEntered = false;
|
|
||||||
const firstEntered = new Promise((resolve) => {
|
|
||||||
releaseFirst = resolve;
|
|
||||||
});
|
|
||||||
let markFirstEntered;
|
|
||||||
const firstStarted = new Promise((resolve) => {
|
|
||||||
markFirstEntered = resolve;
|
|
||||||
});
|
|
||||||
|
|
||||||
const first = buildWeb({
|
|
||||||
root,
|
|
||||||
fingerprint: async () => 'certified',
|
|
||||||
runBuild: async () => {
|
|
||||||
markFirstEntered();
|
|
||||||
await firstEntered;
|
|
||||||
},
|
|
||||||
});
|
|
||||||
await firstStarted;
|
|
||||||
const second = buildWeb({
|
|
||||||
root,
|
|
||||||
fingerprint: async () => 'certified',
|
|
||||||
runBuild: async () => {
|
|
||||||
secondEntered = true;
|
|
||||||
},
|
|
||||||
});
|
|
||||||
await new Promise((resolve) => setTimeout(resolve, 75));
|
|
||||||
assert.equal(secondEntered, false);
|
|
||||||
assert.equal(await exists(marker), false);
|
|
||||||
assert.equal(await exists(manifest), false);
|
|
||||||
|
|
||||||
releaseFirst();
|
|
||||||
await Promise.all([first, second]);
|
|
||||||
assert.equal(secondEntered, true);
|
|
||||||
assert.equal(JSON.parse(await readFile(marker, 'utf8')).sourceFingerprint, 'certified');
|
|
||||||
assert.equal(await readFile(manifest, 'utf8'), '{"version":1,"links":[]}\n');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a build that replaces .next with a symbolic link cannot publish outside the checkout', async () => {
|
|
||||||
const root = await fixture('symbolic-next');
|
|
||||||
const nextDir = path.join(root, 'apps', 'web', '.next');
|
|
||||||
const outside = path.join(root, 'outside-generated');
|
|
||||||
await mkdir(outside);
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
buildWeb({
|
|
||||||
root,
|
|
||||||
fingerprint: async () => 'certified',
|
|
||||||
runBuild: async () => {
|
|
||||||
await rm(nextDir, { recursive: true });
|
|
||||||
await symlink(outside, nextDir);
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
/must be a real directory/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await exists(path.join(outside, '.mosaic-source-hash')), false);
|
|
||||||
assert.equal(await exists(path.join(outside, '.mosaic-symlink-manifest')), false);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('inputs changed during a web build are not certified', async () => {
|
|
||||||
const root = await fixture('changed-inputs');
|
|
||||||
const marker = path.join(root, 'apps', 'web', '.next', '.mosaic-source-hash');
|
|
||||||
const manifest = path.join(root, 'apps', 'web', '.next', '.mosaic-symlink-manifest');
|
|
||||||
const fingerprints = ['before', 'after'];
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
buildWeb({
|
|
||||||
root,
|
|
||||||
fingerprint: async () => fingerprints.shift(),
|
|
||||||
runBuild: async () => {},
|
|
||||||
}),
|
|
||||||
/inputs changed during next build/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await exists(marker), false);
|
|
||||||
assert.equal(await exists(manifest), false);
|
|
||||||
});
|
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
#!/usr/bin/env node
|
|
||||||
|
|
||||||
import { access, mkdir, rename, rm } from 'node:fs/promises';
|
|
||||||
import path from 'node:path';
|
|
||||||
|
|
||||||
const root = process.cwd();
|
|
||||||
const generated = path.join(root, 'apps', 'web', '.next');
|
|
||||||
const quarantineRoot = path.join(root, '.mosaic-test-work', 'generated-quarantine');
|
|
||||||
|
|
||||||
try {
|
|
||||||
await access(generated);
|
|
||||||
} catch (error) {
|
|
||||||
if (error.code === 'ENOENT') process.exit(0);
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
|
|
||||||
await mkdir(quarantineRoot, { recursive: true });
|
|
||||||
const quarantine = path.join(quarantineRoot, `web-next-${Date.now()}-${process.pid}`);
|
|
||||||
try {
|
|
||||||
await rename(generated, quarantine);
|
|
||||||
} catch (error) {
|
|
||||||
console.error(
|
|
||||||
`MOSAIC_GENERATED_CLEAN_FAILED: could not quarantine apps/web/.next. Fix: sudo rm -rf '${generated}', then rerun pnpm preflight`,
|
|
||||||
);
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
await rm(quarantine, { recursive: true, force: true });
|
|
||||||
} catch {
|
|
||||||
console.warn(
|
|
||||||
`Generated state was deactivated but could not be deleted; quarantined at ${quarantine}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
@@ -1,146 +0,0 @@
|
|||||||
#!/usr/bin/env node
|
|
||||||
|
|
||||||
import { access, lstat, mkdir, readFile, readdir, rename, rm } from 'node:fs/promises';
|
|
||||||
import { execFile, spawn } from 'node:child_process';
|
|
||||||
import { promisify } from 'node:util';
|
|
||||||
import { fileURLToPath } from 'node:url';
|
|
||||||
import path from 'node:path';
|
|
||||||
|
|
||||||
const execFileAsync = promisify(execFile);
|
|
||||||
|
|
||||||
function run(command, args, options) {
|
|
||||||
return new Promise((resolve, reject) => {
|
|
||||||
const child = spawn(command, args, options);
|
|
||||||
child.once('error', reject);
|
|
||||||
child.once('exit', (code, signal) => {
|
|
||||||
if (code === 0) resolve();
|
|
||||||
else reject(new Error(signal ? `husky terminated by ${signal}` : `husky exited ${code}`));
|
|
||||||
});
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
async function pathExists(target) {
|
|
||||||
try {
|
|
||||||
await access(target);
|
|
||||||
return true;
|
|
||||||
} catch (error) {
|
|
||||||
if (error.code === 'ENOENT') return false;
|
|
||||||
throw error;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
async function directorySnapshot(root) {
|
|
||||||
const snapshot = [];
|
|
||||||
async function walk(current) {
|
|
||||||
const children = await readdir(current, { withFileTypes: true });
|
|
||||||
for (const child of children.sort((left, right) => left.name.localeCompare(right.name))) {
|
|
||||||
const target = path.join(current, child.name);
|
|
||||||
const relative = path.relative(root, target);
|
|
||||||
const stats = await lstat(target);
|
|
||||||
if (child.isDirectory()) {
|
|
||||||
snapshot.push([relative, 'directory', stats.mode & 0o777]);
|
|
||||||
await walk(target);
|
|
||||||
} else {
|
|
||||||
snapshot.push([
|
|
||||||
relative,
|
|
||||||
'file',
|
|
||||||
stats.mode & 0o777,
|
|
||||||
(await readFile(target)).toString('base64'),
|
|
||||||
]);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
await walk(root);
|
|
||||||
return JSON.stringify(snapshot);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function directoriesMatch(left, right) {
|
|
||||||
return (await directorySnapshot(left)) === (await directorySnapshot(right));
|
|
||||||
}
|
|
||||||
|
|
||||||
export async function installHooks({
|
|
||||||
root = process.cwd(),
|
|
||||||
disabled = process.env.HUSKY === '0',
|
|
||||||
quarantineRoot = path.join(root, '.mosaic-test-work', 'husky-quarantine'),
|
|
||||||
runHusky = async (_stagingHooks, stagingRepo) => {
|
|
||||||
await execFileAsync('git', ['init', '--quiet', stagingRepo]);
|
|
||||||
await run(path.join(root, 'node_modules', '.bin', 'husky'), ['.husky'], {
|
|
||||||
cwd: stagingRepo,
|
|
||||||
stdio: 'inherit',
|
|
||||||
});
|
|
||||||
},
|
|
||||||
activateHooks = async () => {
|
|
||||||
await run('git', ['config', 'core.hooksPath', '.husky/_'], { cwd: root, stdio: 'inherit' });
|
|
||||||
},
|
|
||||||
} = {}) {
|
|
||||||
if (disabled) return;
|
|
||||||
|
|
||||||
const huskyDir = path.join(root, '.husky');
|
|
||||||
const active = path.join(huskyDir, '_');
|
|
||||||
const nonce = `${Date.now()}-${process.pid}`;
|
|
||||||
const stagingRepo = path.join(root, '.mosaic-test-work', `husky-stage-${nonce}`);
|
|
||||||
const stagingHooks = path.join(stagingRepo, '.husky');
|
|
||||||
const quarantined = path.join(quarantineRoot, `${path.basename(root)}-${nonce}`);
|
|
||||||
await mkdir(huskyDir, { recursive: true });
|
|
||||||
await mkdir(quarantineRoot, { recursive: true });
|
|
||||||
|
|
||||||
const previousComplete = (await pathExists(active)) && (await pathExists(path.join(active, 'h')));
|
|
||||||
let previousQuarantined = false;
|
|
||||||
try {
|
|
||||||
if ((await pathExists(active)) && !previousComplete) {
|
|
||||||
await rename(active, quarantined);
|
|
||||||
previousQuarantined = true;
|
|
||||||
}
|
|
||||||
await mkdir(stagingRepo, { recursive: true });
|
|
||||||
await runHusky(stagingHooks, stagingRepo);
|
|
||||||
const staged = path.join(stagingHooks, '_');
|
|
||||||
if (!(await pathExists(path.join(staged, 'h')))) {
|
|
||||||
throw new Error('husky did not produce its required h shim');
|
|
||||||
}
|
|
||||||
if (previousComplete) {
|
|
||||||
if (!(await directoriesMatch(active, staged))) {
|
|
||||||
throw new Error('existing complete hook set differs from the installed Husky version');
|
|
||||||
}
|
|
||||||
await rm(stagingRepo, { recursive: true, force: true });
|
|
||||||
} else {
|
|
||||||
await rename(staged, active);
|
|
||||||
await rm(stagingRepo, { recursive: true, force: true });
|
|
||||||
}
|
|
||||||
await activateHooks();
|
|
||||||
if (previousQuarantined) {
|
|
||||||
try {
|
|
||||||
await rm(quarantined, { recursive: true, force: true });
|
|
||||||
} catch {
|
|
||||||
console.warn(
|
|
||||||
`Previous hook state was deactivated but remains quarantined at ${quarantined}`,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} catch (error) {
|
|
||||||
const cleanupFailures = [];
|
|
||||||
try {
|
|
||||||
if (await pathExists(stagingRepo)) {
|
|
||||||
await rename(stagingRepo, `${quarantined}-staging`);
|
|
||||||
}
|
|
||||||
} catch (cleanupError) {
|
|
||||||
cleanupFailures.push(`staging hooks: ${cleanupError.message}`);
|
|
||||||
}
|
|
||||||
const cleanup =
|
|
||||||
cleanupFailures.length === 0
|
|
||||||
? 'No partial hook set was activated.'
|
|
||||||
: `Automatic cleanup was incomplete (${cleanupFailures.join('; ')}).`;
|
|
||||||
throw new Error(
|
|
||||||
`Hook installation failed: ${error.message}. ${cleanup} Fix: rm -rf .husky/_ && git config core.hooksPath .husky/_ && pnpm install --frozen-lockfile`,
|
|
||||||
{ cause: error },
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (process.argv[1] && path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
|
|
||||||
try {
|
|
||||||
await installHooks();
|
|
||||||
} catch (error) {
|
|
||||||
console.error(error.message);
|
|
||||||
process.exitCode = 1;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,208 +0,0 @@
|
|||||||
import assert from 'node:assert/strict';
|
|
||||||
import { access, mkdir, readFile, readdir, rm, writeFile } from 'node:fs/promises';
|
|
||||||
import path from 'node:path';
|
|
||||||
import test from 'node:test';
|
|
||||||
|
|
||||||
import { installHooks } from './install-hooks.mjs';
|
|
||||||
|
|
||||||
const fixtureRoot = path.join(process.cwd(), '.mosaic-test-work', `hooks-${process.pid}`);
|
|
||||||
const quarantineRoot = path.join(fixtureRoot, 'quarantine');
|
|
||||||
|
|
||||||
async function fixture(name) {
|
|
||||||
const root = path.join(fixtureRoot, name);
|
|
||||||
await mkdir(path.join(root, '.husky'), { recursive: true });
|
|
||||||
return root;
|
|
||||||
}
|
|
||||||
|
|
||||||
async function exists(target) {
|
|
||||||
try {
|
|
||||||
await access(target);
|
|
||||||
return true;
|
|
||||||
} catch {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
test.after(async () => {
|
|
||||||
await rm(fixtureRoot, { recursive: true, force: true });
|
|
||||||
});
|
|
||||||
|
|
||||||
test('an interrupted install quarantines the partial active hook set and fails loudly', async () => {
|
|
||||||
const root = await fixture('interrupted');
|
|
||||||
let restoredHooksPath = 'not-called';
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
installHooks({
|
|
||||||
root,
|
|
||||||
quarantineRoot,
|
|
||||||
runHusky: async (stagingHooks) => {
|
|
||||||
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
|
|
||||||
await writeFile(path.join(stagingHooks, '_', 'h'), 'partial');
|
|
||||||
throw new Error('simulated interruption');
|
|
||||||
},
|
|
||||||
activateHooks: async () => {},
|
|
||||||
readHooksPath: async () => null,
|
|
||||||
restoreHooksPath: async (value) => {
|
|
||||||
restoredHooksPath = value;
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
(error) => {
|
|
||||||
assert.match(error.message, /Hook installation failed/);
|
|
||||||
assert.match(error.message, /pnpm install --frozen-lockfile/);
|
|
||||||
return true;
|
|
||||||
},
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await exists(path.join(root, '.husky', '_')), false);
|
|
||||||
assert.equal(restoredHooksPath, 'not-called');
|
|
||||||
const quarantined = await readdir(quarantineRoot);
|
|
||||||
assert.equal(quarantined.length, 1);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a failed replacement restores a previously complete active hook set', async () => {
|
|
||||||
const root = await fixture('rollback');
|
|
||||||
const activeShim = path.join(root, '.husky', '_', 'h');
|
|
||||||
await mkdir(path.dirname(activeShim), { recursive: true });
|
|
||||||
await writeFile(activeShim, 'previous-complete');
|
|
||||||
let previousRemainedActiveDuringStaging = false;
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
installHooks({
|
|
||||||
root,
|
|
||||||
quarantineRoot: path.join(fixtureRoot, 'rollback-quarantine'),
|
|
||||||
runHusky: async () => {
|
|
||||||
previousRemainedActiveDuringStaging =
|
|
||||||
(await readFile(activeShim, 'utf8')) === 'previous-complete';
|
|
||||||
throw new Error('simulated replacement failure');
|
|
||||||
},
|
|
||||||
activateHooks: async () => {},
|
|
||||||
readHooksPath: async () => '.husky/_',
|
|
||||||
restoreHooksPath: async () => {},
|
|
||||||
}),
|
|
||||||
/Hook installation failed/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(previousRemainedActiveDuringStaging, true);
|
|
||||||
assert.equal(await readFile(activeShim, 'utf8'), 'previous-complete');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a mismatched complete hook set fails loudly instead of reporting a stale install as current', async () => {
|
|
||||||
const root = await fixture('mismatch');
|
|
||||||
const activeShim = path.join(root, '.husky', '_', 'h');
|
|
||||||
await mkdir(path.dirname(activeShim), { recursive: true });
|
|
||||||
await writeFile(activeShim, 'old-complete');
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
installHooks({
|
|
||||||
root,
|
|
||||||
quarantineRoot: path.join(fixtureRoot, 'mismatch-quarantine'),
|
|
||||||
runHusky: async (stagingHooks) => {
|
|
||||||
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
|
|
||||||
await writeFile(path.join(stagingHooks, '_', 'h'), 'new-complete');
|
|
||||||
},
|
|
||||||
activateHooks: async () => {},
|
|
||||||
readHooksPath: async () => '.husky/_',
|
|
||||||
restoreHooksPath: async () => {},
|
|
||||||
}),
|
|
||||||
/Hook installation failed.*pnpm install --frozen-lockfile/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await readFile(activeShim, 'utf8'), 'old-complete');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a competing successful installer is not removed by the losing process', async () => {
|
|
||||||
const root = await fixture('concurrent');
|
|
||||||
const activeShim = path.join(root, '.husky', '_', 'h');
|
|
||||||
let restored = false;
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
installHooks({
|
|
||||||
root,
|
|
||||||
quarantineRoot: path.join(fixtureRoot, 'concurrent-quarantine'),
|
|
||||||
runHusky: async (stagingHooks) => {
|
|
||||||
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
|
|
||||||
await writeFile(path.join(stagingHooks, '_', 'h'), 'ours');
|
|
||||||
await mkdir(path.dirname(activeShim), { recursive: true });
|
|
||||||
await writeFile(activeShim, 'peer');
|
|
||||||
},
|
|
||||||
activateHooks: async () => {},
|
|
||||||
readHooksPath: async () => null,
|
|
||||||
restoreHooksPath: async () => {
|
|
||||||
restored = true;
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
/Hook installation failed/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await readFile(activeShim, 'utf8'), 'peer');
|
|
||||||
assert.equal(restored, false);
|
|
||||||
});
|
|
||||||
|
|
||||||
test("a competing installer that replaces this installer's active set is preserved", async () => {
|
|
||||||
const root = await fixture('concurrent-after-rename');
|
|
||||||
const active = path.join(root, '.husky', '_');
|
|
||||||
const activeShim = path.join(active, 'h');
|
|
||||||
let restored = false;
|
|
||||||
|
|
||||||
await assert.rejects(
|
|
||||||
installHooks({
|
|
||||||
root,
|
|
||||||
quarantineRoot: path.join(fixtureRoot, 'concurrent-after-rename-quarantine'),
|
|
||||||
runHusky: async (stagingHooks) => {
|
|
||||||
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
|
|
||||||
await writeFile(path.join(stagingHooks, '_', 'h'), 'ours');
|
|
||||||
},
|
|
||||||
activateHooks: async () => {
|
|
||||||
await rm(active, { recursive: true, force: true });
|
|
||||||
await mkdir(active, { recursive: true });
|
|
||||||
await writeFile(activeShim, 'peer');
|
|
||||||
throw new Error('our activation lost to peer');
|
|
||||||
},
|
|
||||||
readHooksPath: async () => null,
|
|
||||||
restoreHooksPath: async () => {
|
|
||||||
restored = true;
|
|
||||||
},
|
|
||||||
}),
|
|
||||||
/Hook installation failed/,
|
|
||||||
);
|
|
||||||
|
|
||||||
assert.equal(await readFile(activeShim, 'utf8'), 'peer');
|
|
||||||
assert.equal(restored, false);
|
|
||||||
});
|
|
||||||
|
|
||||||
test('an explicit interactive HUSKY=0 opt-out preserves existing hooks without running installer', async () => {
|
|
||||||
const root = await fixture('disabled');
|
|
||||||
const activeShim = path.join(root, '.husky', '_', 'h');
|
|
||||||
await mkdir(path.dirname(activeShim), { recursive: true });
|
|
||||||
await writeFile(activeShim, 'preserved');
|
|
||||||
let ran = false;
|
|
||||||
|
|
||||||
await installHooks({
|
|
||||||
root,
|
|
||||||
disabled: true,
|
|
||||||
runHusky: async () => {
|
|
||||||
ran = true;
|
|
||||||
},
|
|
||||||
});
|
|
||||||
|
|
||||||
assert.equal(ran, false);
|
|
||||||
assert.equal(await readFile(activeShim, 'utf8'), 'preserved');
|
|
||||||
});
|
|
||||||
|
|
||||||
test('a successful install leaves a complete active hook set', async () => {
|
|
||||||
const root = await fixture('success');
|
|
||||||
|
|
||||||
await installHooks({
|
|
||||||
root,
|
|
||||||
quarantineRoot,
|
|
||||||
runHusky: async (stagingHooks) => {
|
|
||||||
await mkdir(path.join(stagingHooks, '_'), { recursive: true });
|
|
||||||
await writeFile(path.join(stagingHooks, '_', 'h'), 'complete');
|
|
||||||
},
|
|
||||||
activateHooks: async () => {},
|
|
||||||
readHooksPath: async () => null,
|
|
||||||
restoreHooksPath: async () => {},
|
|
||||||
});
|
|
||||||
|
|
||||||
assert.equal(await exists(path.join(root, '.husky', '_', 'h')), true);
|
|
||||||
});
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user