Production blocker
Wardnet must not become ready with unauthenticated management writes on a non-loopback listener. Credential-free operation is permitted only for explicit loopback development and must be visible as non-production state. Protected main@5829a0f08d78de464dd24393ce5d0f25fba9d126 already contains the externally provisioned administrator-Secret boundary from #137 plus the protected runner/concurrency repair from #159; the remaining product outcome is runtime fail-closed authentication/authorization through the owning candidate.
Current owning candidate — 2026-09-05
PR #155 is the protected-main candidate at exact f74ff25a321dfb1d7109719e2a1fc77e47dc4898 on main@5829a0f08d78de464dd24393ce5d0f25fba9d126. GitHub reports it Ready and mergeable. The branch adopted the intervening protected-main #159 delta non-destructively; fresh compare remains behind_by=0, and predecessor evidence from e6f05d77858e91c176cff25c4b11e790bc5dcdd1, historical #94, and temporary-branch #138 does not transfer.
The exact #155 head:
- fails startup before readiness on non-loopback bind without a write-capable admin credential;
- preserves explicit loopback credential-free development and exposes
auth_mode=development in health evidence;
- rejects blank/ambiguous credential bootstrap;
- performs constant-time shared/RBAC token comparison;
- separates
401 unauthenticated from 403 readonly-write denial;
- covers malformed/duplicate/role/startup/property/fuzz/smoke cases;
- preserves the protected external administrator-Secret lifecycle.
Fresh exact-head review inventory contains three informational Devin threads. All are resolved and remain current/non-outdated; they verify credential precedence, numeric-loopback-only credential-free handling, and token normalization. They are not independent human approval and expose no unresolved valid finding.
Current exact-head execution
Exact f74ff25a321dfb1d7109719e2a1fc77e47dc4898 now has terminal GREEN for each Wardnet-owned repository/security lane that executed:
- CI
33904633002 — terminal success;
- Fuzz
33904632999 — terminal success;
- Security Scan
33904633208 — terminal success;
- SAST Semgrep
33904633082 — terminal success.
The remaining non-passing state is central control-plane evidence rather than a Wardnet auth-source defect:
- CodeQL PR
33904632978 is terminal failure. Detect-language succeeded; compatibility job 101187573567 successfully requested the current-head CodeQL scan dispatch and then failed closed because no current-head dispatch verdict arrived.
- Required OpenCode run
33904630655 progressed through bootstrap/current-head admission and coverage-source-tree; coverage-evidence job 101247706677 remains queued and non-passing.
The same exact control-plane failure class is independently reproduced by #93 and has been handed to .github#712 with exact RED/GREEN acceptance. Do not churn this source head, change runner labels, rerun-storm, or create a no-op commit merely to manufacture dispatch evidence. Central GREEN requires a terminal verdict attached to this exact SHA plus materialized coverage evidence, after which only the failed/required central jobs should be reacquired as needed.
Live organization ruleset 18156473 still requires one generic approving review while naming no required reviewer/team and exposes routine OrganizationAdmin/always bypass. Under the declared solo-maintainer model, self-approval and model/bot-as-human approval remain forbidden. .github#772 and current owner-plane successor #1644 own the causal policy repair to generic approval count 0 while deterministic workflow/security/coverage/thread/branch-integrity gates remain fail closed. A conflicting central candidate that proposes raising the generic count to two has been handed an explicit Wardnet RED/GREEN finding. Ordinary approval deadlock is not emergency-bypass authority.
Completion gate
Close only after #155 or a verified successor carrying every unique auth/runtime/security delta reaches protected main, the resulting protected source is revalidated, the unchanged integration candidate has terminal-valid current repository/security/coverage/package/SBOM/provenance/review/governance evidence, and live governance is satisfiable without self/model approval, routine bypass, wrong-PR/same-SHA predecessor evidence, gate weakening or false-green infrastructure output. Queued review/security infrastructure does not qualify for guarded bypass.
Production blocker
Wardnet must not become ready with unauthenticated management writes on a non-loopback listener. Credential-free operation is permitted only for explicit loopback development and must be visible as non-production state. Protected
main@5829a0f08d78de464dd24393ce5d0f25fba9d126already contains the externally provisioned administrator-Secret boundary from #137 plus the protected runner/concurrency repair from #159; the remaining product outcome is runtime fail-closed authentication/authorization through the owning candidate.Current owning candidate — 2026-09-05
PR #155 is the protected-main candidate at exact
f74ff25a321dfb1d7109719e2a1fc77e47dc4898onmain@5829a0f08d78de464dd24393ce5d0f25fba9d126. GitHub reports it Ready and mergeable. The branch adopted the intervening protected-main #159 delta non-destructively; fresh compare remainsbehind_by=0, and predecessor evidence frome6f05d77858e91c176cff25c4b11e790bc5dcdd1, historical #94, and temporary-branch #138 does not transfer.The exact #155 head:
auth_mode=developmentin health evidence;401unauthenticated from403readonly-write denial;Fresh exact-head review inventory contains three informational Devin threads. All are resolved and remain current/non-outdated; they verify credential precedence, numeric-loopback-only credential-free handling, and token normalization. They are not independent human approval and expose no unresolved valid finding.
Current exact-head execution
Exact
f74ff25a321dfb1d7109719e2a1fc77e47dc4898now has terminal GREEN for each Wardnet-owned repository/security lane that executed:33904633002— terminal success;33904632999— terminal success;33904633208— terminal success;33904633082— terminal success.The remaining non-passing state is central control-plane evidence rather than a Wardnet auth-source defect:
33904632978is terminal failure. Detect-language succeeded; compatibility job101187573567successfully requested the current-head CodeQL scan dispatch and then failed closed because no current-head dispatch verdict arrived.33904630655progressed through bootstrap/current-head admission andcoverage-source-tree;coverage-evidencejob101247706677remains queued and non-passing.The same exact control-plane failure class is independently reproduced by #93 and has been handed to
.github#712with exact RED/GREEN acceptance. Do not churn this source head, change runner labels, rerun-storm, or create a no-op commit merely to manufacture dispatch evidence. Central GREEN requires a terminal verdict attached to this exact SHA plus materialized coverage evidence, after which only the failed/required central jobs should be reacquired as needed.Live organization ruleset
18156473still requires one generic approving review while naming no required reviewer/team and exposes routineOrganizationAdmin/alwaysbypass. Under the declared solo-maintainer model, self-approval and model/bot-as-human approval remain forbidden..github#772and current owner-plane successor #1644 own the causal policy repair to generic approval count 0 while deterministic workflow/security/coverage/thread/branch-integrity gates remain fail closed. A conflicting central candidate that proposes raising the generic count to two has been handed an explicit Wardnet RED/GREEN finding. Ordinary approval deadlock is not emergency-bypass authority.Completion gate
Close only after #155 or a verified successor carrying every unique auth/runtime/security delta reaches protected
main, the resulting protected source is revalidated, the unchanged integration candidate has terminal-valid current repository/security/coverage/package/SBOM/provenance/review/governance evidence, and live governance is satisfiable without self/model approval, routine bypass, wrong-PR/same-SHA predecessor evidence, gate weakening or false-green infrastructure output. Queued review/security infrastructure does not qualify for guarded bypass.