Skip to content

[P0] Fail closed when management credentials are absent #78

Description

@seonghobae

Production blocker

Wardnet must not become ready with unauthenticated management writes on a non-loopback listener. Credential-free operation is permitted only for explicit loopback development and must be visible as non-production state. Protected main@5829a0f08d78de464dd24393ce5d0f25fba9d126 already contains the externally provisioned administrator-Secret boundary from #137 plus the protected runner/concurrency repair from #159; the remaining product outcome is runtime fail-closed authentication/authorization through the owning candidate.

Current owning candidate — 2026-09-05

PR #155 is the protected-main candidate at exact f74ff25a321dfb1d7109719e2a1fc77e47dc4898 on main@5829a0f08d78de464dd24393ce5d0f25fba9d126. GitHub reports it Ready and mergeable. The branch adopted the intervening protected-main #159 delta non-destructively; fresh compare remains behind_by=0, and predecessor evidence from e6f05d77858e91c176cff25c4b11e790bc5dcdd1, historical #94, and temporary-branch #138 does not transfer.

The exact #155 head:

  • fails startup before readiness on non-loopback bind without a write-capable admin credential;
  • preserves explicit loopback credential-free development and exposes auth_mode=development in health evidence;
  • rejects blank/ambiguous credential bootstrap;
  • performs constant-time shared/RBAC token comparison;
  • separates 401 unauthenticated from 403 readonly-write denial;
  • covers malformed/duplicate/role/startup/property/fuzz/smoke cases;
  • preserves the protected external administrator-Secret lifecycle.

Fresh exact-head review inventory contains three informational Devin threads. All are resolved and remain current/non-outdated; they verify credential precedence, numeric-loopback-only credential-free handling, and token normalization. They are not independent human approval and expose no unresolved valid finding.

Current exact-head execution

Exact f74ff25a321dfb1d7109719e2a1fc77e47dc4898 now has terminal GREEN for each Wardnet-owned repository/security lane that executed:

  • CI 33904633002 — terminal success;
  • Fuzz 33904632999 — terminal success;
  • Security Scan 33904633208 — terminal success;
  • SAST Semgrep 33904633082 — terminal success.

The remaining non-passing state is central control-plane evidence rather than a Wardnet auth-source defect:

  • CodeQL PR 33904632978 is terminal failure. Detect-language succeeded; compatibility job 101187573567 successfully requested the current-head CodeQL scan dispatch and then failed closed because no current-head dispatch verdict arrived.
  • Required OpenCode run 33904630655 progressed through bootstrap/current-head admission and coverage-source-tree; coverage-evidence job 101247706677 remains queued and non-passing.

The same exact control-plane failure class is independently reproduced by #93 and has been handed to .github#712 with exact RED/GREEN acceptance. Do not churn this source head, change runner labels, rerun-storm, or create a no-op commit merely to manufacture dispatch evidence. Central GREEN requires a terminal verdict attached to this exact SHA plus materialized coverage evidence, after which only the failed/required central jobs should be reacquired as needed.

Live organization ruleset 18156473 still requires one generic approving review while naming no required reviewer/team and exposes routine OrganizationAdmin/always bypass. Under the declared solo-maintainer model, self-approval and model/bot-as-human approval remain forbidden. .github#772 and current owner-plane successor #1644 own the causal policy repair to generic approval count 0 while deterministic workflow/security/coverage/thread/branch-integrity gates remain fail closed. A conflicting central candidate that proposes raising the generic count to two has been handed an explicit Wardnet RED/GREEN finding. Ordinary approval deadlock is not emergency-bypass authority.

Completion gate

Close only after #155 or a verified successor carrying every unique auth/runtime/security delta reaches protected main, the resulting protected source is revalidated, the unchanged integration candidate has terminal-valid current repository/security/coverage/package/SBOM/provenance/review/governance evidence, and live governance is satisfiable without self/model approval, routine bypass, wrong-PR/same-SHA predecessor evidence, gate weakening or false-green infrastructure output. Queued review/security infrastructure does not qualify for guarded bypass.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions