fix(stage2): normalize Windows credential blob for SSH auth - #88
Merged
Robinlee0929 merged 1 commit intoSep 14, 2026
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the confirmed Stage-2 credential representation mismatch between the Windows Credential Manager backend and pinned SSH transport. The trusted Stage-2 Generic Credential provisioning contract stores password data as strict UTF-16LE. S2-RO-04 now validates that representation and returns the same logical password as strict UTF-8 transport bytes, preserving whitespace and Unicode form. Malformed, BOM-bearing, NUL-containing, or oversized data fails closed without encoding fallback.
S2-RO-09 and the native Windows reader remain unchanged.
Root cause
Two separately authorized Lab2 attempts passed Ed25519 pin verification and SSH negotiation but failed password authentication. A separately authorized offline comparison confirmed the stored representation was UTF-16LE rather than UTF-8. The old backend passed those raw bytes to the transport.
Scope
Exactly three files at
cbf90a98dee6e11b6b125ad778e73f5ca7f6d1d3, directly based on69aae5f7f87c89adf0602172032ec865013721d9:validation_framework/stage2_windows_credential_backend.pytests/stage2/test_windows_credential_backend.pydocs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.mdNo dependency, S2-RO-09, runtime-composition, or device-configuration change. This PR grants no new execution authority or Stage advancement.
Validation
Accepted offline implementation validation used the guarded external-copy launcher with bytecode/plugin autoload/cache disabled:
python -m pytest tests/stage2/test_windows_credential_backend.py: 119 passed, no skips or failures.python -m pytest tests/stage2/test_pinned_ssh_transport.py: 156 passed, no skips or failures.python -m pytest tests/stage2: 1875 passed, 2 accepted safety skips, 0 failed.python -m pytest: 4000 passed, 3 accepted safety skips, 0 failed.python network_lab.py --task report-index: accepted WARN; 1 pass, 13 optional missing, 0 mandatory missing, 0 failures.git diff --check 69aae5f7f87c89adf0602172032ec865013721d9..cbf90a98dee6e11b6b125ad778e73f5ca7f6d1d3: PASS.The listed pytest commands identify the suite targets; accepted execution used the guarded launcher rather than raw Windows pytest. Independent read-only review: PASS, zero material or unresolved material findings. Fresh hosted Safe CI for this exact PR head is required before merge. Local suites are not repeated during integration.
Evidence
Separately Owner-authorized post-remediation Lab2 transport verification passed on the exact candidate: one credential read, one snapshot acquisition, one SSH connection, Ed25519 pin verified, one successful password authentication, and one
/interface vrrp print detailexecution. Exit status 0, no stderr, zero retries, and no configuration mutation. This establishes transport compatibility only; parser/runtime composition and later Lab2 slices remain separately gated. This integration task does not repeat live access.The committed document retains its implementation-time evidence state. Subsequent independent review and bounded live results are recorded here; no candidate content was changed for integration.
Safety checklist