feat(stage2): add Lab2 credential backend binding policy - #83
Merged
Robinlee0929 merged 1 commit intoSep 11, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Extend only the S2-RO-04 trusted Windows credential backend binding policy for the two exact Lab1/Lab2 identities. This PR is ready for independent review; opening or merging it grants no live-access or Stage-advancement authority.
Scope
Exactly one commit above main, changing only these three files:
validation_framework/stage2_windows_credential_backend.pytests/stage2/test_windows_credential_backend.pydocs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.mdNo S2-RO-05 or later production module, workflow, dependency, or AGENTS.md changes.
Base:
303d487dbde4798756d9a43595c1fd8ba67d56ba.Head:
0d7c8734d82f9f0584bd7c591a0b2a49cf7bd28a.Head tree:
050dd06f6bdd3dc20a442e3b4106fed2dca4cbc9.Exact authority model
The only valid conceptual tuples are:
read_for_target(target_ref, binding)checks the exact target/credential pair through S2-RO-03 and requires both the supplied binding locator and the immutable trusted configuration locator to match that canonical binding. The operational caller cannot override the configured Windows record or locator. Distinct logical locators do not establish that real credential records have been provisioned.Cross-Lab safety and valid behavior
These reject BEFORE any native credential read:
Rejected requests invoke the fake/injected native reader zero times. For each valid exact binding, the fake/injected reader is invoked exactly once. There is no retry, fallback/default locator, wildcard, dynamic registration, or generic secret-store lookup. The 16-case target/credential/binding-locator/configuration-locator matrix admits only the two fully matched combinations.
Native reader boundary and backward compatibility
The native Windows credential-reader primitive was unchanged and was NOT broadened. During implementation and validation, real CredReadW was NOT called, real Windows Credential Manager was NOT accessed, no real Lab2 credential record was created, and no real username/password was retrieved. Behavioral tests inject a fake reader; native-layout tests use a fake DLL and test-owned memory.
Historical Lab1
read(binding)remains Lab1-only and compatible; it cannot retrieve Lab2 or use Lab2 configuration for Lab1. The new target-aware path does not make the backend a generic caller-controlled credential reader. Immutable output shape and sanitized errors remain preserved.No real credential data is included in this PR.
Related issue
N/A - separately Owner-authorized bounded S2-RO-04 extension.
Validation
Fresh pre-PR Safe CI #34611792027 completed SUCCESS on exact head
0d7c8734d82f9f0584bd7c591a0b2a49cf7bd28a. These are CI results, not substitutes from local tests.python -m pytestnpm run test:unitnpm run typechecknpm run lintnpm run buildpython network_lab.py --task report-indexgit diff --exit-codeThe two CI skips are existing Linux/Win32 platform-condition skips (
os.name != "nt"); no candidate-added skip/xfail or weakened collection/assertion is used.Open warnings - unresolved
These warnings remain OPEN. This PR claims no remediation and does not backfill optional runtime reports.
Evidence
Exact candidate independent local review passed with no findings. The canonical S2-RO-04 document and focused fake-only tests describe the policy boundary. Only non-sensitive summarized validation evidence is included; no raw traceback or environment dump is attached.
Deferred scope
Separate authorization is still required for:
This PR authorizes no Lab1/Lab2 contact, SSH/NETCONF/RESTCONF, replay access/mutation, Owner private-key access, authorization package, merge, auto-merge, or branch/worktree cleanup.
Safety checklist