feat(stage2): bind Lab2 authorization before replay - #84
Merged
Robinlee0929 merged 1 commit intoSep 12, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
1. Summary / scope
Extend ONLY S2-RO-05 authorization-envelope and pre-replay binding policy to exactly two approved target/credential pairs.
Changed files exactly:
No S2-RO-01 through S2-RO-04 or S2-RO-06 or later production module is changed. No workflow, dependency metadata, or AGENTS.md change.
Base: 496eb5d (tree 050dd06f6bdd3dc20a442e3b4106fed2dca4cbc9).
Head: 44aead1 (tree 2a3305b0c9a95a86d0e654e9d78dd5ca9e456cd6).
Exactly one commit above base.
2. Exact authority model
S2-RO-03 resolve_for_target(...) remains the canonical target/credential pair authority. No duplicate independent pair authority was introduced. There is no wildcard, fallback, normalization, or default-to-Lab1. Caller-supplied bindings cannot override the resolver.
3. Pre-replay fail-closed property
Any Lab1/Lab2 mixed or invalid pairing rejects BEFORE replay-ledger I/O.
Covered rejection cases include:
For invalid binding paths, tests prove:
Synthetic ledger bytes, size, mtime, and directory entries remain unchanged after rejection. Binding validation precedes envelope time validation.
4. Valid path
Lab1 exact binding remains valid. Lab2 exact binding is valid with the same policy semantics.
Disposable, pre-provisioned synthetic ledgers prove:
5. Replay engine unchanged
Replay/storage machinery below the binding boundary is unchanged.
No change to SQLite schema, authorization UUID replay key, envelope SHA as audit metadata, BEGIN IMMEDIATE, synchronous=EXTRA, trusted_schema=OFF, foreign_keys=ON, DELETE journal, normal locking, busy_timeout=0, plain parameterized INSERT, commit semantics (including COMMIT_UNCERTAIN), permanent consumption, capacity handling, or the documented anti-rollback limitation.
No retry, reconnect, UPSERT, UPDATE, DELETE, reset, unconsume, reclaim, or pruning was introduced. There is no new ledger initializer or fallback ledger.
6. Owner / execution authority boundary
SCHEMA_VERSION remains 1.0. Owner payload domain remains unchanged:
Network_Automation_Lab/S2-RO-05/authorization-envelope/v1 followed by the original NUL byte.
owner_verification_payload remains DOMAIN + canonical envelope bytes.
S2-RO-05 still does NOT authenticate Owner, verify a signature, access a trust root, or grant execution authority.
Both remain:
A valid envelope is not Owner approval; successful consumption is not execution authority.
7. Real authority / private data boundary
No real replay ledger was accessed. No real authorization was consumed. No real authorization package was accessed.
No Windows Credential Manager access or real CredReadW call occurred in Stage-2/Lab implementation or validation. No private key or Owner trust-root data was accessed. No Lab1/Lab2 live device was contacted. No SSH, NETCONF, or RESTCONF occurred.
No Lab IP, private runtime path, real replay UUID, real authorization ID, or real credential is included. Test data is synthetic. No real credential or authorization material is included in this PR.
GitHub operations use only the existing Git/GitHub CLI authentication mechanism; credential stores and its underlying storage implementation were not inspected. No token, environment dump, or raw traceback is included.
8. Validation
Fresh pre-PR Safe CI #34683914652:
The two Linux platform-condition skips are unchanged and are not candidate-induced weakening.
Independent review: PASS. Findings: NONE.
Separate offline review validation: focused S2-RO-05 166 passed; Stage-2 1849 passed; full pytest 3975 passed, 0 failed; report-index accepted WARN; candidate diff check PASS. These local results do not substitute for the fresh CI evidence above. No skip/xfail, assertion weakening, or collection weakening was introduced.
9. Open warnings
Unresolved:
No remediation is included in this PR.
10. Deferred scope
Explicitly deferred:
This PR does not authorize any live attempt, merge, auto-merge, or later slice. Independent PR review and any later merge require separate Owner authorization.