Validate cadence contract and require functional MFA verification
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ea3-7939-7b63-8125-699f8b50bedd
This commit is contained in:
parent
d4d61b722e
commit
4e07d60ff1
34 changed files with 1640 additions and 364 deletions
|
|
@ -4,10 +4,11 @@ type: workplan
|
|||
title: "Make the SSO/MFA verification actually verify"
|
||||
domain: infotech
|
||||
repo: net-kingdom
|
||||
status: proposed
|
||||
status: blocked
|
||||
owner: codex
|
||||
topic_slug: infotech
|
||||
created: "2026-08-28"
|
||||
updated: "2026-09-05"
|
||||
related:
|
||||
- NK-WP-0033
|
||||
- CUST-ADR-012
|
||||
|
|
@ -45,7 +46,7 @@ is broken, which is worse than no check, because it is believed.
|
|||
|
||||
```task
|
||||
id: NK-WP-0034-T01
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "9b5d8034-0ef1-53f9-ad4d-37de536bdc62"
|
||||
```
|
||||
|
|
@ -65,7 +66,7 @@ them restored, it passes. Demonstrated in both directions, not argued.
|
|||
|
||||
```task
|
||||
id: NK-WP-0034-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "0bd09a40-8b4d-5f9d-8d4c-81c55aa0c565"
|
||||
```
|
||||
|
|
@ -83,7 +84,7 @@ Acceptance: one table — script, intended property, actual assertion, verdict.
|
|||
|
||||
```task
|
||||
id: NK-WP-0034-T03
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "becb4dce-4971-5755-888f-5276c4a56fe7"
|
||||
```
|
||||
|
|
@ -103,7 +104,7 @@ runbook are listed as a separate finding.
|
|||
|
||||
```task
|
||||
id: NK-WP-0034-T04
|
||||
status: todo
|
||||
status: done
|
||||
priority: low
|
||||
state_hub_task_id: "d43ae8e8-eda6-5c1d-9e1b-01966b0e92da"
|
||||
```
|
||||
|
|
@ -118,3 +119,46 @@ applied to a copy is a fix that expires the next time someone writes a script.
|
|||
Acceptance: one implementation of the privacyIDEA request path in
|
||||
`sso-mfa/k8s/privacyidea/`; both callers use it; the GET behaviour has a test
|
||||
that fails if the header returns.
|
||||
|
||||
|
||||
## Review and implementation — 2026-09-05
|
||||
|
||||
Reviewed the proposal against current code and implemented all repository-local
|
||||
changes. T01 waits only for the attended scratch/provider exercise required by
|
||||
its acceptance. No live credentials were requested and no production resolver
|
||||
was changed.
|
||||
|
||||
- T01: replaced warning-only T06 success with an attended known-user and
|
||||
TOTP/HOTP verifier, requiring realm binding, numeric tuning, exact user and
|
||||
resolver, and token-backed success. Credentials are prompted in process;
|
||||
missing attendance fails. Updated realm-repair and DR callers. Eighteen
|
||||
tests exercise the actual shared HTTP transport, including clearing and
|
||||
restoring every tuning field and rejecting passthrough/static passwords.
|
||||
See `docs/verify-t06.md` for the remaining attended acceptance and limits.
|
||||
- T02: completed the per-script property/assertion/verdict table in
|
||||
`docs/verification-audit-2026-09-05.md`. Other verify scripts retain their
|
||||
implementations; their gaps are explicitly recorded for follow-up.
|
||||
- T03: inventoried every shell script under `sso-mfa/k8s/`, added exercise
|
||||
headers to component runbooks, recorded unknown history and scripts without
|
||||
runbooks in `docs/attended-procedure-inventory.md`. Corrected the reconciliation
|
||||
runbook's attempted-run claim: no successful completion receipt exists.
|
||||
- T04: `privacyidea/pi_api.py` now supplies the request transport to both realm
|
||||
bootstrap and resolver reconciliation (and T06). Authentication also uses the
|
||||
shared transport in bootstrap. Its shell adapter keeps the token/body off
|
||||
argv. Fixed bootstrap's first-success `set -e` counter exit found during the
|
||||
review. The HTTP fixture rejects JSON Content-Type on GET and verifies the
|
||||
real Python and shell adapter requests.
|
||||
|
||||
Remaining gate: an attended operator runs the scratch target failure/restoration
|
||||
procedure and records receipts. An automated fixture is not reported as an
|
||||
exercised provider run. NK-WP-0033 still needs its own incident receipt and
|
||||
predecessor-disposition ruling.
|
||||
|
||||
Validation: `python3 -m pytest tests tools -q` passed 106 tests, including 18
|
||||
privacyIDEA and 15 cadence cases. Ruff lint/format, shell syntax, embedded Python
|
||||
compilation and `git diff --check` passed.
|
||||
|
||||
State Hub reconciliation was attempted with both the installed CLI and current
|
||||
checkout. Full reconciliation remains pending because API queries/writes timed
|
||||
out or returned connection-refused errors. Generated index/intake metadata was
|
||||
reviewed; the source files remain authoritative.
|
||||
|
|
|
|||
117
workplans/NK-WP-0035-emission-cadence-security-profile.md
Normal file
117
workplans/NK-WP-0035-emission-cadence-security-profile.md
Normal file
|
|
@ -0,0 +1,117 @@
|
|||
---
|
||||
id: NK-WP-0035
|
||||
type: workplan
|
||||
title: "Publish the NetKingdom emission-cadence security profile"
|
||||
domain: infotech
|
||||
repo: net-kingdom
|
||||
status: blocked
|
||||
owner: codex
|
||||
topic_slug: netkingdom
|
||||
planning_priority: P1
|
||||
created: "2026-09-04"
|
||||
updated: "2026-09-05"
|
||||
related:
|
||||
- GH-DEC-2026-004
|
||||
- canon/standards/security-layer-model_v0.7.md
|
||||
---
|
||||
|
||||
# NK-WP-0035 — NetKingdom emission-cadence security profile
|
||||
|
||||
GH-DEC-2026-004 assigns the ecosystem-wide
|
||||
`EmissionCadenceDeclaration` contract to `info-tech-canon` and the importing
|
||||
NetKingdom security profile to this repository. This work accepts that split.
|
||||
It must not copy the generic schema drafted by `kings-guard` or make the
|
||||
observer the owner of source classifications.
|
||||
|
||||
## Define the importing security profile
|
||||
|
||||
```task
|
||||
id: NK-WP-0035-T01
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Publish the NetKingdom MUST/SHOULD obligations over the generic contract:
|
||||
load-bearing classes declare cadence, attributive classes should, and rare
|
||||
load-bearing classes use heartbeat plus reconciliation with rate monitoring
|
||||
forbidden. Keep source classification owner-authored and preserve the residual
|
||||
that cadence detects omission only after the fact.
|
||||
|
||||
Implemented as proposed canon at
|
||||
`canon/standards/emission-cadence-security-profile_v0.1.md`. The profile accepts
|
||||
the GH-DEC-2026-004 split, requires source-owned classification, distinguishes
|
||||
MUST from SHOULD coverage, and records that omission detection is after the
|
||||
fact rather than proof of completeness.
|
||||
|
||||
## Implement mechanical profile validation
|
||||
|
||||
```task
|
||||
id: NK-WP-0035-T02
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
Validate a declaration against an explicitly supplied InfoTechCanon JSON
|
||||
Schema before applying the NetKingdom overlay. The checker must not ship a
|
||||
fallback generic schema, infer evidence class or rarity from event contents, or
|
||||
treat a SHOULD finding as a MUST failure by default.
|
||||
|
||||
Implemented at
|
||||
`tools/emission-cadence-profile/emission_cadence_profile.py`. It requires
|
||||
`--contract-schema`, performs generic validation first, then checks the
|
||||
NetKingdom overlay against caller-supplied source inventory assertions. No
|
||||
generic fallback schema or owner declaration instance was added here.
|
||||
|
||||
## Verify the boundary and failure cases
|
||||
|
||||
```task
|
||||
id: NK-WP-0035-T03
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
Cover contract-first validation, missing and mismatched class declarations,
|
||||
the allowed high-volume load-bearing rate form, the forbidden rare-event rate
|
||||
form, both positive controls for rare load-bearing classes, duplicate classes,
|
||||
and advisory attributive coverage.
|
||||
|
||||
Verification on 2026-09-04: eight focused tests pass; the 81-test root
|
||||
`tests/` + `tools/` regression suite passes; Ruff lint and format checks pass;
|
||||
Python compilation and `git diff --check` pass.
|
||||
|
||||
## Bind and hand off the published contract
|
||||
|
||||
```task
|
||||
id: NK-WP-0035-T04
|
||||
status: wait
|
||||
priority: high
|
||||
```
|
||||
|
||||
When `info-tech-canon` publishes its versioned contract and schema, replace the
|
||||
pending import locator with its canonical coordinates and digest, validate the
|
||||
owner-source instances, and notify `kings-guard` to replace its draft-shaped
|
||||
fixture. This task cannot be completed from NetKingdom without the upstream
|
||||
artifact and must not be worked around by copying the draft.
|
||||
|
||||
2026-09-05 review: the upstream publication blocker is resolved by
|
||||
InfoTechCanon 0.7.0 / contract 0.1.0. Bound the profile to the schema coordinates,
|
||||
revision and SHA-256; fixed the checker to read `extensions.netkingdom`, removed
|
||||
draft reconciliation aliases, and enforced unique source IDs. Fifteen focused
|
||||
tests pass, including direct integration with the published owner schema and
|
||||
CLI exit-policy coverage.
|
||||
|
||||
The current owner instances (`approval-engine/cadence.yaml` and
|
||||
`qonto-assistant/specs/audit-emission-cadence.yaml`) were reviewed and checked;
|
||||
both still fail generic contract validation because they use draft envelopes.
|
||||
No source instance was rewritten by NetKingdom. T04 remains `wait` for each
|
||||
owner's migration and subsequent profile validation, followed by the King's
|
||||
Guard handoff. The profile remains proposed.
|
||||
|
||||
Validation: `python3 -m pytest tests tools -q` passed 106 tests, including 18
|
||||
privacyIDEA and 15 cadence cases. Ruff lint/format, shell syntax, embedded Python
|
||||
compilation and `git diff --check` passed.
|
||||
|
||||
State Hub reconciliation was attempted with both the installed CLI and current
|
||||
checkout. Full reconciliation remains pending because API queries/writes timed
|
||||
out or returned connection-refused errors. Generated index/intake metadata was
|
||||
reviewed; the source files remain authoritative.
|
||||
Loading…
Add table
Add a link
Reference in a new issue