Skip to content

feat(stage2): add Lab2 credential backend binding policy - #83

Merged
Robinlee0929 merged 1 commit into
mainfrom
codex/stage2-lab2-s2-ro-04-credential-backend-policy
Sep 11, 2026
Merged

Robinlee0929 merged 1 commit into
mainfrom
codex/stage2-lab2-s2-ro-04-credential-backend-policy

Conversation

@Robinlee0929

Copy link
Copy Markdown
Owner

Summary

Extend only the S2-RO-04 trusted Windows credential backend binding policy for the two exact Lab1/Lab2 identities. This PR is ready for independent review; opening or merging it grants no live-access or Stage-advancement authority.

Scope

Exactly one commit above main, changing only these three files:

  • validation_framework/stage2_windows_credential_backend.py
  • tests/stage2/test_windows_credential_backend.py
  • docs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.md

No S2-RO-05 or later production module, workflow, dependency, or AGENTS.md changes.

Base: 303d487dbde4798756d9a43595c1fd8ba67d56ba.
Head: 0d7c8734d82f9f0584bd7c591a0b2a49cf7bd28a.
Head tree: 050dd06f6bdd3dc20a442e3b4106fed2dca4cbc9.

Exact authority model

The only valid conceptual tuples are:

  • Lab1 target + Lab1 credential binding + Lab1 trusted locator.
  • Lab2 target + Lab2 credential binding + distinct Lab2 trusted locator.

read_for_target(target_ref, binding) checks the exact target/credential pair through S2-RO-03 and requires both the supplied binding locator and the immutable trusted configuration locator to match that canonical binding. The operational caller cannot override the configured Windows record or locator. Distinct logical locators do not establish that real credential records have been provisioned.

Cross-Lab safety and valid behavior

These reject BEFORE any native credential read:

  • Lab1 binding + Lab2 locator; Lab2 binding + Lab1 locator.
  • Lab1 target + Lab2 credential; Lab2 target + Lab1 credential.
  • Unknown target, unknown credential, unknown locator, and all-unknown combinations.
  • Alias, prefix, and case-confused values.

Rejected requests invoke the fake/injected native reader zero times. For each valid exact binding, the fake/injected reader is invoked exactly once. There is no retry, fallback/default locator, wildcard, dynamic registration, or generic secret-store lookup. The 16-case target/credential/binding-locator/configuration-locator matrix admits only the two fully matched combinations.

Native reader boundary and backward compatibility

The native Windows credential-reader primitive was unchanged and was NOT broadened. During implementation and validation, real CredReadW was NOT called, real Windows Credential Manager was NOT accessed, no real Lab2 credential record was created, and no real username/password was retrieved. Behavioral tests inject a fake reader; native-layout tests use a fake DLL and test-owned memory.

Historical Lab1 read(binding) remains Lab1-only and compatible; it cannot retrieve Lab2 or use Lab2 configuration for Lab1. The new target-aware path does not make the backend a generic caller-controlled credential reader. Immutable output shape and sanitized errors remain preserved.

No real credential data is included in this PR.

Related issue

N/A - separately Owner-authorized bounded S2-RO-04 extension.

Validation

Fresh pre-PR Safe CI #34611792027 completed SUCCESS on exact head 0d7c8734d82f9f0584bd7c591a0b2a49cf7bd28a. These are CI results, not substitutes from local tests.

Command Verified result
python -m pytest PASS: 3919 collected; 3917 passed, 2 skipped, 0 failed
npm run test:unit PASS: 128 tests passed, 9 test files passed
npm run typecheck PASS
npm run lint PASS
npm run build PASS
python network_lab.py --task report-index Accepted WARN: 1 pass, 13 optional missing, 0 fail; no mandatory failure
git diff --exit-code PASS: no tracked-file mutation

The two CI skips are existing Linux/Win32 platform-condition skips (os.name != "nt"); no candidate-added skip/xfail or weakened collection/assertion is used.

Open warnings - unresolved

  • npm: 5 vulnerabilities (2 moderate, 2 high, 1 critical).
  • Next.js/Turbopack: 7 filesystem-tracing warnings.
  • Report-index: 13 optional missing runtime artifacts.

These warnings remain OPEN. This PR claims no remediation and does not backfill optional runtime reports.

Evidence

Exact candidate independent local review passed with no findings. The canonical S2-RO-04 document and focused fake-only tests describe the policy boundary. Only non-sensitive summarized validation evidence is included; no raw traceback or environment dump is attached.

Deferred scope

Separate authorization is still required for:

  • S2-RO-05 authorization/replay binding.
  • S2-RO-06 Owner verifier.
  • S2-RO-07 known-host handling.
  • S2-RO-08/09 command-policy or transport extension.
  • S2-RO-10 runtime composition and S2-RO-11 live entrypoint.
  • Creation or read of real Lab2 credentials.
  • Lab2 live validation and dual-device aggregation.
  • Stage 3.

This PR authorizes no Lab1/Lab2 contact, SSH/NETCONF/RESTCONF, replay access/mutation, Owner private-key access, authorization package, merge, auto-merge, or branch/worktree cleanup.

Safety checklist

  • I read CONTRIBUTING.md and SECURITY.md.
  • This pull request is limited to the scope described above.
  • No secrets, real credentials, private infrastructure data, personal paths, or private runtime artifacts are included.
  • Rejected and unapproved paths remain fail-closed, with negative safety tests.
  • This pull request does not claim Stage advancement merely by being opened or merged.
  • This offline policy extension grants no new live, provider, or execution authority.
  • No unrelated changes are included.

@Robinlee0929
Robinlee0929 merged commit 496eb5d into main Sep 11, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant