Skip to content

fix(stage2): normalize Windows credential blob for SSH auth - #88

Merged
Robinlee0929 merged 1 commit into
mainfrom
codex/stage2-s2-ro-04-credential-encoding-remediation
Sep 14, 2026
Merged

Robinlee0929 merged 1 commit into
mainfrom
codex/stage2-s2-ro-04-credential-encoding-remediation

Conversation

@Robinlee0929

Copy link
Copy Markdown
Owner

Summary

Fixes the confirmed Stage-2 credential representation mismatch between the Windows Credential Manager backend and pinned SSH transport. The trusted Stage-2 Generic Credential provisioning contract stores password data as strict UTF-16LE. S2-RO-04 now validates that representation and returns the same logical password as strict UTF-8 transport bytes, preserving whitespace and Unicode form. Malformed, BOM-bearing, NUL-containing, or oversized data fails closed without encoding fallback.

S2-RO-09 and the native Windows reader remain unchanged.

Root cause

Two separately authorized Lab2 attempts passed Ed25519 pin verification and SSH negotiation but failed password authentication. A separately authorized offline comparison confirmed the stored representation was UTF-16LE rather than UTF-8. The old backend passed those raw bytes to the transport.

Scope

Exactly three files at cbf90a98dee6e11b6b125ad778e73f5ca7f6d1d3, directly based on 69aae5f7f87c89adf0602172032ec865013721d9:

  • validation_framework/stage2_windows_credential_backend.py
  • tests/stage2/test_windows_credential_backend.py
  • docs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.md

No dependency, S2-RO-09, runtime-composition, or device-configuration change. This PR grants no new execution authority or Stage advancement.

Validation

Accepted offline implementation validation used the guarded external-copy launcher with bytecode/plugin autoload/cache disabled:

  • python -m pytest tests/stage2/test_windows_credential_backend.py: 119 passed, no skips or failures.
  • python -m pytest tests/stage2/test_pinned_ssh_transport.py: 156 passed, no skips or failures.
  • python -m pytest tests/stage2: 1875 passed, 2 accepted safety skips, 0 failed.
  • python -m pytest: 4000 passed, 3 accepted safety skips, 0 failed.
  • python network_lab.py --task report-index: accepted WARN; 1 pass, 13 optional missing, 0 mandatory missing, 0 failures.
  • git diff --check 69aae5f7f87c89adf0602172032ec865013721d9..cbf90a98dee6e11b6b125ad778e73f5ca7f6d1d3: PASS.

The listed pytest commands identify the suite targets; accepted execution used the guarded launcher rather than raw Windows pytest. Independent read-only review: PASS, zero material or unresolved material findings. Fresh hosted Safe CI for this exact PR head is required before merge. Local suites are not repeated during integration.

Evidence

Separately Owner-authorized post-remediation Lab2 transport verification passed on the exact candidate: one credential read, one snapshot acquisition, one SSH connection, Ed25519 pin verified, one successful password authentication, and one /interface vrrp print detail execution. Exit status 0, no stderr, zero retries, and no configuration mutation. This establishes transport compatibility only; parser/runtime composition and later Lab2 slices remain separately gated. This integration task does not repeat live access.

The committed document retains its implementation-time evidence state. Subsequent independent review and bounded live results are recorded here; no candidate content was changed for integration.

Safety checklist

  • CONTRIBUTING.md and SECURITY.md reviewed.
  • Exact authorized three-file scope; no unrelated changes.
  • No real credentials, secret values, private infrastructure data, personal paths, or runtime artifacts included.
  • Rejected paths remain fail-closed; synthetic negative tests cover the representation contract.
  • No automatic Stage advancement, standing live authority, provider integration, or configuration execution introduced.
  • Branches and worktrees must be retained; local main synchronization and final closure require separate authorization.

@Robinlee0929
Robinlee0929 merged commit 7a244c4 into main Sep 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant