Skip to content

Commit fe920f5

Browse files
committed
fix: preserve secret-safe custody across managed-auth cleanup
Close the bounded ANDON 225-228 repair tranche for failed-launch managed-auth cleanup and capture finalization. Root cause: - key-only structural-marker matching aliased expected managed-auth transport structure with credential-value residue and ambiguous scan outcomes; - destructive cleanup could remove admitted worker custody before independently proven secret-free JSONL, stderr, raw output, and receipt bytes were retained; - downstream success and failure consumers trusted scan metadata without independently revalidating every worker-bound carrier. Repair: - add the shared v3 semantic residue contract while preserving v1/v2 validation; - classify decoded JSON keys and values, duplicate-key ambiguity, redactions, UTF-8/UTF-16 variants, and malformed escaped-key fragments fail-closed; - scan structured admission before publication and retain only role-bound, content-addressed, independently secret-free carriers outside the purge root; - re-scan failure and normal-success carriers in orchestration and capture finalization, preserving exact case, worker, authority, reservation, tooling, source, candidate, and completion identities; - keep terminal cleanup total, ordered, idempotent, and replay-safe without weakening real-secret detection. Verification: - reviewed-campaign orchestration: 161/161 PASS; - producer capture finalization: 6/6 PASS; - producer structural completion: 20/20 PASS; - exact-tree no-model preflight: 25/25 PASS; - exact-tree local CI: 179/179 PASS; - generated/package role: 7/7 PASS; - independent whole-tree review: ACCEPT, Critical 0 / Important 0 / Minor 0. Nonclaims: - no provider call, reservation, campaign authority, candidate, or paid usage is created by this commit; - ANDON 182, 207, and 225 terminal histories and unknown usage/cost remain immutable and unresolved exactly as owner-disposed; - this commit does not claim exact-SHA GitHub CI, candidate maturity, campaign readiness, release readiness, merge, tag, publication, or owner acceptance.
1 parent f33cb91 commit fe920f5

8 files changed

Lines changed: 2375 additions & 179 deletions

File tree

docs/audits/v0.4.6.0-wip-andon-closure-ledger.json

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -4442,43 +4442,43 @@
44424442
},
44434443
{
44444444
"kind": "file_sha256",
4445-
"source_ref": "ANDON 193/194/207/208/212 current bytes preserve the accepted ANDON 185-190 terminalization and identity joins while extending the failed-launch state matrix through post-capture cleanup, exact writer-generation continuity, shared typed v1/v2 credential-scan validation, and a fail-closed pre-authorization whole-checkout Python-bytecode residue gate whose traversal errors cannot reach authorization reads: exact terminal-journal semantic validation precedes usage mutation, immutable usage children are adopted exactly once, replay precedes launch-only gates, current diagnostics and execution custody are revalidated before finalization, every reproduced live post-prepare exit before reservation invokes the cleanup owner, and a retained completed capture remains monotonic when later isolation cleanup fails",
4445+
"source_ref": "ANDON 225/226/228 current bytes preserve the accepted failed-launch terminalization, identity, replay, usage, and cleanup joins while extending shared credential-scan validation to the exact v3 semantic distinction between expected managed-auth transport structure, credential-value residue, and ambiguous or unavailable classification; post-admission failure diagnostics and normal completed-capture revalidation validate exact worker-bound PASS scan evidence, independently re-scan retained structured-admission, event, stderr, and raw-output bytes, and accept content-addressed custody only when exact worker and per-role semantics agree",
44464446
"commit_sha1": null,
44474447
"blob_sha1": null,
4448-
"sha256": "1d6eac6d04a25d01e1c7885afe63d29b26b279da5ad326dc019006ff2164924b",
4448+
"sha256": "18e24ec5c671b6217f285dc03dad2c35b90f437b29f0f15ac5bf18c922f89f1b",
44494449
"command": null,
44504450
"exit_code": null,
44514451
"retained_artifact": "tools/reviewed_campaign_orchestrator.py",
44524452
"unretained_reason": null
44534453
},
44544454
{
44554455
"kind": "file_sha256",
4456-
"source_ref": "ANDON 194/196/207/212 current bytes preserve the accepted capability, isolation, process-custody, model, timeout, and execution-tooling joins while enforcing ordered structured admission, total per-case terminal causes, bounded concurrent-observer quiescence, secret-free cleanup residual witnesses, content-addressed outcome-unknown diagnostics, monotonic completed-result state before cleanup, descriptor-bound witness-generation continuity for initial creation and renewal, and fail-closed retention instead of destructive cleanup before an owner token returns; the ANDON 207/212 successor separates a dedicated Agent Identity environment credential from an unread CLI-managed ChatGPT auth-home carrier, keeps managed CLI state in a private worker SQLite home, and emits the shared-contract v2 structural residue evidence without placing credential values in adapter custody",
4456+
"source_ref": "ANDON 225/226 current bytes preserve the accepted capability, isolation, process-custody, model, timeout, execution-tooling, and structured-admission joins while replacing key-only managed-auth matching with the exact shared v3 semantic scan contract; structured-admission JSONL is classified before external publication, every independently proven secret-free terminal JSONL, stderr, and raw-output carrier is role-bound and content-addressed outside the worker before destructive cleanup, unsafe or unproven bytes remain unretained, partial publication and purge outcomes remain explicit, and replay cannot redispatch a terminal campaign",
44574457
"commit_sha1": null,
44584458
"blob_sha1": null,
4459-
"sha256": "02bdd10eb09ed6a6e0e92e6b4b4540d593e726a541cb7a98f1a2588980dd92d3",
4459+
"sha256": "f62f1ece45c7cd3f957fdea7de55a80e6984165eecce5defab5e25e4facca9fb",
44604460
"command": null,
44614461
"exit_code": null,
44624462
"retained_artifact": "tools/codex_live_producer_adapter.py",
44634463
"unretained_reason": null
44644464
},
44654465
{
44664466
"kind": "file_sha256",
4467-
"source_ref": "ANDON 212 shared secret-safe credential-residue scan semantic contract: exact v1/v2 keysets, bound worker identity, nonnegative non-Boolean counters, exact encodings, strict UTC completion, managed-auth mode, marker families, and no adapter credential-value custody",
4467+
"source_ref": "ANDON 225/227/228 shared secret-safe credential-residue scan semantic contract: historical v1/v2 validation remains exact while v3 binds worker identity, strict managed-auth pass/failure classes, ordered marker families, per-role safe-carrier outcomes, purge outcome, exact encodings, strict UTC completion, and no retained credential value; parse-valid JSON and JSONL use recursively decoded key identity and decoded string-value signatures regardless of Unicode-escape spelling, duplicate decoded sensitive keys fail ambiguous, malformed double- or single-quoted escaped-key fragments retain raw fail-closed detection, and complete governed bearer redactions remain expected transport structure",
44684468
"commit_sha1": null,
44694469
"blob_sha1": null,
4470-
"sha256": "f2a168c638db945d5060d00f1fdb1e46a7b40323bb21e67892ebd6e9cfe14061",
4470+
"sha256": "617e61788f4aefeb62e6b428b6ac66e02b4baff9bf57aca065d28194df6f1398",
44714471
"command": null,
44724472
"exit_code": null,
44734473
"retained_artifact": "tools/credential_residue_scan_contract.py",
44744474
"unretained_reason": null
44754475
},
44764476
{
44774477
"kind": "file_sha256",
4478-
"source_ref": "ANDON 212 capture-complete consumer revalidates canonical credential-scan bytes through the shared semantic contract and binds producer worker identity from the selected result ordinal before strict finalizer invocation",
4478+
"source_ref": "ANDON 225/226 capture-complete consumer revalidates canonical credential-scan bytes through the shared semantic contract, independently re-scans every v3 PASS structured-admission, raw-output, event-log, and stderr carrier before strict finalizer invocation, and binds producer worker identity from the selected result ordinal",
44794479
"commit_sha1": null,
44804480
"blob_sha1": null,
4481-
"sha256": "d93f95c7e4e5db0cf577ded92a2cfb8f1454226a1851ddc660638bab33f3e930",
4481+
"sha256": "653264c9397a294f5a4616dfe9fbeaeea454858a2e7428f839a310b9fd55a637",
44824482
"command": null,
44834483
"exit_code": null,
44844484
"retained_artifact": "tools/finalize_producer_capture_complete.py",
@@ -4662,25 +4662,25 @@
46624662
},
46634663
{
46644664
"kind": "command_result",
4665-
"source_ref": "ANDON 212 capture-finalization semantic repair; shared credential-scan contract sha256 f2a168c638db945d5060d00f1fdb1e46a7b40323bb21e67892ebd6e9cfe14061, capture bridge sha256 d93f95c7e4e5db0cf577ded92a2cfb8f1454226a1851ddc660638bab33f3e930, and permanent test sha256 8f8af7f55b307b53e8a14b4bc0ef7473c4b0d477388e83f82dc503645618dad0; status-only v1 and partial managed-auth v2 scans are rejected before strict finalizer invocation while all valid capture paths remain 3/3 GREEN",
4665+
"source_ref": "ANDON 225/226/227/228 capture-finalization compatibility; shared credential-scan contract sha256 617e61788f4aefeb62e6b428b6ac66e02b4baff9bf57aca065d28194df6f1398, capture bridge sha256 653264c9397a294f5a4616dfe9fbeaeea454858a2e7428f839a310b9fd55a637, and permanent test sha256 416eb57df3cebb3d0efa077be2ff086075cc08d07a7ef2428e5e9d476599762d; malformed v1/v2/v3 and semantically contradictory v3 scans reject before strict finalization, a valid managed-auth v3 pass scan reaches the exact finalizer, and synthetic credential-bearing stderr or structured-admission bytes including Unicode-escaped decoded sensitive-key and decoded provider-key aliases under recomputed v3 PASS metadata are rejected by byte re-scan; complete suite 6/6 GREEN in 0.785 seconds",
46664666
"commit_sha1": null,
46674667
"blob_sha1": null,
46684668
"sha256": null,
46694669
"command": "python -B tests/producer-capture-finalization/test_contract.py",
46704670
"exit_code": 0,
46714671
"retained_artifact": null,
4672-
"unretained_reason": "direct RED stdout is retained in the ignored ANDON 212 failed-attempt carrier; focused GREEN does not claim independent repair acceptance, outer qualification, exact-SHA CI, candidate maturity, authority, reservation, provider execution, or terminal closure"
4672+
"unretained_reason": "the ANDON 228 direct RED is retained in the ignored durable repair namespace as andon228-direct-red-finalizer.log; focused GREEN does not claim independent repair acceptance, outer qualification, exact-SHA CI, candidate maturity, authority, reservation, provider execution, or terminal closure"
46734673
},
46744674
{
46754675
"kind": "command_result",
4676-
"source_ref": "ANDON 212 traversal and failed-launch integration repair; orchestrator sha256 1d6eac6d04a25d01e1c7885afe63d29b26b279da5ad326dc019006ff2164924b and permanent test sha256 a0327c74aaed154e9496bab6f0b24ab5ce53d8a4e8a835244a9bf10d1bb5fff2; an unreadable subtree now terminally raises CHECKOUT_EXECUTION_RESIDUE_TRAVERSAL_UNAVAILABLE before authorization read, complete reviewed-campaign coverage is 149/149 GREEN, and an exact whole-checkout residue readback reports zero entries",
4676+
"source_ref": "ANDON 225/226/227/228 failed-launch semantic and safe-custody repair; orchestrator sha256 18e24ec5c671b6217f285dc03dad2c35b90f437b29f0f15ac5bf18c922f89f1b, adapter sha256 f62f1ece45c7cd3f957fdea7de55a80e6984165eecce5defab5e25e4facca9fb, shared scan contract sha256 617e61788f4aefeb62e6b428b6ac66e02b4baff9bf57aca065d28194df6f1398, and permanent test sha256 64419612b0f687765a289ef1b1b6130816c4cb8e29d4fd1d29e78220a95f36f4; expected managed-auth structures, complete bearer redactions, four synthetic residue families, literal and Unicode-escaped decoded sensitive keys and decoded string-value signatures across UTF-8/UTF-16, malformed single- and double-quoted key ambiguity, duplicate decoded-key ambiguity, scan unavailability, all five worker identities, structured-admission classification before publication, safe custody before purge, partial or failed publication, partial or failed purge with cleanup recovery, byte-level failure and completed-capture consumer revalidation across admission, event, stderr, and raw-output carriers, replay, and zero-provider fixtures are covered; complete reviewed-campaign suite 161/161 GREEN in 542.487 seconds",
46774677
"commit_sha1": null,
46784678
"blob_sha1": null,
46794679
"sha256": null,
46804680
"command": "python -B tests/reviewed-campaign-orchestration/test_contract.py",
46814681
"exit_code": 0,
46824682
"retained_artifact": null,
4683-
"unretained_reason": "direct RED stdout and the post-review empty-cache carrier are retained in the ignored ANDON 212 failed-attempt namespace; focused GREEN does not claim independent repair acceptance, outer qualification, exact-SHA CI, candidate maturity, authority, reservation, provider execution, or terminal closure"
4683+
"unretained_reason": "the ANDON 228 direct RED is retained in the ignored durable repair namespace as andon228-direct-red-reviewed.log; focused GREEN does not claim independent repair acceptance, outer qualification, exact-SHA CI, candidate maturity, authority, reservation, provider execution, or terminal closure"
46844684
},
46854685
{
46864686
"kind": "command_result",

0 commit comments

Comments
 (0)