diff --git a/docs/assessments/2026-09-09-helixforge-approval-consumer.json b/docs/assessments/2026-09-09-helixforge-approval-consumer.json new file mode 100644 index 0000000..075d79b --- /dev/null +++ b/docs/assessments/2026-09-09-helixforge-approval-consumer.json @@ -0,0 +1,166 @@ +{ + "date": "2026-09-09", + "owner_repositories": { + "secrets-engine": { + "commit": "89bc31460f7967fd42f4b39c180c37cd2e6ae0bd", + "remote_matches": true, + "clean": true + }, + "railiance-platform": { + "commit": "5507fac156321a2a1fedba9804e03d7b4129680a", + "remote_matches": true, + "clean": true + }, + "prj-helixforge-factory": { + "commit": "9df42992ec86f2bb2f752cd9bc959192795824e3", + "remote_matches": true, + "clean": true + } + }, + "tests_passed": 350, + "component_receipt": { + "schema_version": 1, + "target": "disposable local processes; synthetic credentials", + "started_at": "2026-09-09T01:49:09.187005+00:00", + "keycape_image": "forgejo.coulomb.social/coulomb/key-cape@sha256:7ff54c54e63ee172ae9e6e7fd2da96e427352f712343d74626ee6fe0f6f82611", + "approval_engine_commit": "b46b0f26669dc83c944ee5145426bad03d5ef720", + "keycape_contract_commit": "0f5535eed95f1223c83a28f5a0bd6fa594cecae8", + "consumer_source_sha256": { + "approval_auth.py": "6f3b033e7928e1c527bc19f5a1e01bf243540769a8646bd8cd47268da25637b5", + "approval_consume.py": "cd79b3e4534a5abf55af2b5ab2939c485a3140a1174f593e0aa7719250051d92", + "config.py": "2f2f1b60664d89bbb806aed0c768378923062077740e1f96e4c359238eb06955", + "service_auth.py": "653723ef5babce2157771416d93cb15cdbb7caca3c45509c3730520c55e4515c" + }, + "limitations": [ + "PDP sequencing double", + "local Approval Engine source, not deployed image", + "no live custody or client-side read grant", + "no OpenBao effect or model execution" + ], + "checks": { + "operator_issued_and_approved_via_verified_jwt": true, + "wrong_action_refused_before_consume": true, + "actual_consumer_claim_check_consume": true, + "same_digest_retry_idempotent": true, + "different_digest_refused": true, + "spent_claim_refused": true, + "operator_consume_scope_denied_by_issuer": true, + "wrong_secret_refused": true, + "no_access_token_file_created": true + }, + "status": "passed", + "cleanup_complete": true, + "finished_at": "2026-09-09T01:49:11.402008+00:00" + }, + "source_hub_parity": [ + { + "task": "SECRETS-WP-0008-T02", + "status": "progress", + "source_fields_match": true, + "repaired_fields": [ + "description" + ] + }, + { + "task": "SECRETS-WP-0009-T03", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [ + "description" + ] + }, + { + "task": "RPF-WP-0035-T05", + "status": "done", + "source_fields_match": true, + "repaired_fields": [ + "description", + "intervention_note" + ] + }, + { + "task": "RPF-WP-0035-T06", + "status": "todo", + "source_fields_match": true, + "repaired_fields": [ + "intervention_note" + ] + }, + { + "task": "HFACT-WP-0001-T01", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [] + }, + { + "task": "HFACT-WP-0001-T02", + "status": "progress", + "source_fields_match": true, + "repaired_fields": [] + }, + { + "task": "HFACT-WP-0001-T03", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [ + "intervention_note" + ] + }, + { + "task": "HFACT-WP-0001-T04", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [] + }, + { + "task": "HFACT-WP-0001-T05", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [] + }, + { + "task": "HFACT-WP-0001-T06", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [] + }, + { + "task": "HFACT-WP-0001-T07", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [] + }, + { + "task": "HFACT-WP-0001-T08", + "status": "wait", + "source_fields_match": true, + "repaired_fields": [] + } + ], + "progress": [ + { + "id": "76e7ad76-b858-455a-81f2-06212d51143e", + "task_id": "f8069c8a-ad6b-5d0b-9a36-c2326699437d" + }, + { + "id": "6f077bd6-7d3c-4e57-8674-dbf67e6859b5", + "task_id": "3eb9cff8-1441-5437-9e92-a2b655c82d04" + }, + { + "id": "e7b87bed-6fef-45b4-a0e1-cc4ef1857ec4", + "task_id": "e15d62c9-e5da-5721-a135-87c050f7851c" + }, + { + "id": "8e9a1c06-cd2a-496f-852a-069b532d40e9", + "task_id": "67c80db1-01ba-54f1-80ff-76398f9e7823" + } + ], + "next_local_work": "SECRETS-WP-0008-T02 / FLEX-DEC-2026-012", + "remaining_live_gates": [ + "RPF-WP-0035-T06 client-side admission", + "AUDIT-WP-0009-T09 sender/receiver custody", + "APPROVAL-WP-0002 deployment/claim/consume", + "SECRETS-WP-0009-T03 native delivery", + "HFACT-WP-0001 G0 and Railiance worker evidence" + ] +} diff --git a/docs/assessments/2026-09-09-helixforge-approval-consumer.md b/docs/assessments/2026-09-09-helixforge-approval-consumer.md new file mode 100644 index 0000000..86796db --- /dev/null +++ b/docs/assessments/2026-09-09-helixforge-approval-consumer.md @@ -0,0 +1,47 @@ +# HelixForge approval consumer — 2026-09-09 + +The consumer implementation now removes manual approval-token renewal from the +intended factory path. Secrets Engine exchanges its own client secret immediately +before claim and consume, requests only the relevant scope, and holds the access +token in memory. Live credential delivery remains separately gated. + +The pinned KeyCape image exposed a consumer incompatibility missed by its old +fixtures: `assurance.aal/method` was assumed; the issuer emits +`assurance.level/methods`. The shared consumer now validates the actual shape. +OpenBao and approval client identities retain their distinct audiences, tenants +and scopes. Mixed providers, fallback identities and credential redirects are +refused. + +Validation: **350 tests passed**. A repeatable disposable exercise also passed +**nine checks** using the pinned KeyCape image and real Approval Engine source, +JWT/JWKS verifier and SQLite store. It proved operator create/approve, consumer +claim/check/consume, idempotent retry and the specified action/claim/secret/scope +refusals. Temporary resources were removed; exact consumer module hashes are +recorded in the [evidence](2026-09-09-helixforge-approval-consumer.json). + +The PDP was a sequencing double. This proves the identity/consumer integration, +not a production authorization path, native OpenBao delivery or factory +throughput. No live credential was retrieved and no paid model ran. + +Work coordination now reflects the actual scope: + +- **RPF-WP-0035-T05 is done** against the completed verifier-only acceptance. + **RPF-WP-0035-T06** is its live client-side admission residual. The already + completed CCR reviews must not recur as blockers. +- **SECRETS-WP-0008-T02 is progress** for the returned FLEX-DEC-2026-012 contract. + The consumer must use `submitted_request_digest` for its exact request and + compare the approval digest between evaluator outputs. This is actionable + local implementation, with no outstanding interpretation question. +- **SECRETS-WP-0009-T03 remains wait** for that replay correction plus separate + client-side admission, audit custody, live approval deployment and native + credential authority/delivery. The identity exercise does not close these. + +The next implementation is the submitted-request replay and approval-digest join, +tested against independently published owner fixtures. Then complete the two +consumer admissions and audit sender/receiver custody, deploy Approval Engine, +and prove native delivery before admitting a bounded Railiance worker run. + +The first internal capability remains reuse-surface; Railiance Fabric remains a +candidate for broader reuse. vergabe-teilnahme remains the primary customer +product repository. Progress toward that goal is reduced manual integration and +fewer misleading waits; sustained factory throughput has not yet been measured.