diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md new file mode 100644 index 0000000..09bf690 --- /dev/null +++ b/docs/product-technical-gap-baseline.md @@ -0,0 +1,75 @@ +# Product and technical gap baseline + +Snapshot date: 2026-09-06. Re-read live refs, PRs, reviews/threads, exact-head checks, rulesets, security evidence and releases before any merge, release, restack or foreign-owner handoff. This is Wardnet's sole commercial/product-technical current-state ledger, not an archive of predecessor evidence. + +## Authority boundary + +Wardnet owns the Rust-first gateway/SOC control plane and the Gateway, Admission Policy, Artifact Identity, Security Analysis Integration, Network-Egress integration, SOC Evidence, Runtime Control, Audit-Provenance and Agent Artifact Admission bounded contexts. `quarantine-sandbox-runtime` owns hostile execution isolation/cleanup; `contextual-orchestrator` owns Agent/LLM/provider orchestration; EgressWeave owns reusable outbound HTTP destination/address policy; `appguardrail` owns static package/security analysis. Wardnet consumes released/versioned ports or ACLs only: no source copy, cross-service SQL or mutable sibling production dependency. + +`context-graph-contracts` is the provider-neutral Context Fabric Shared Kernel and `enterprise-architecture-core` is the EA Decision Plane. Both remain read-only from this Wardnet writer while their Context Fabric owner is active. Wardnet findings/verdicts remain Wardnet evidence; EA may retain verified evidence references for technology risk/remediation/initiative context but must not copy raw security verdicts into authoritative architecture truth. + +Fresh GitHub release inventories remain empty for Wardnet, Context Graph Contracts, EA Core, EgressWeave, contextual-orchestrator, quarantine-sandbox-runtime and AppGuardrail. The Wardnet integration contract therefore continues to require future immutable compatible releases rather than mutable sibling heads. No open foreign-owner PR is production/release authority. + +## Protected truth and control plane + +Protected/default Wardnet truth remains protected squash merge #171 at `main@a52ccd0a24a727d9349bb32def7713882d8cad1e`, whose verified parent is prior protected `5829a0f08d78de464dd24393ce5d0f25fba9d126`. #159 remains the protected workflow-control foundation. #171 adds the protected bounded-context decision that browser acquisition/session/challenge/CAPTCHA handling stays outside Wardnet while destination maliciousness/reputation policy and security evidence remain Wardnet-owned; arbitrary metadata fetching must not be reintroduced into Wardnet, and required outbound retrieval must traverse a released EgressWeave authorization boundary or fail closed. + +Organization ruleset `18156473` remains active on `~DEFAULT_BRANCH`. Fresh payload still requires `required_approving_review_count=1` with `required_reviewers=[]`, no code-owner or last-push approval requirement, stale-review dismissal and review-thread resolution, seven central required workflows, deletion/non-fast-forward protection, and `OrganizationAdmin/always` bypass available to the current principal. Under the declared solo-maintainer model, self-approval and bot/model-as-human approval remain forbidden. + +#171 remains the concrete governance defect specimen: a standard expected-head squash merge reached protected truth while the same live ruleset still exposed both the unsatisfiable generic approval count and routine admin bypass. `.github#772` remains the causal owner path. Its latest Wardnet canary records protected `main@a52ccd0...` and current-base #174; the accepted repair remains removal/replacement only of the impossible generic count and routine-bypass ambiguity while deterministic workflow/security/coverage/package/SBOM/provenance/thread/deletion/non-fast-forward controls remain fail closed. Wardnet will not issue further merge calls merely to probe governance. + +Delegated model/code-analysis verdict execution also remains a central owner path. `.github#1932` and `.github#1926` repaired parser/matrix source, but `.github#1929` is still open. Fresh owner evidence now distinguishes three producer identities rather than a simple two-bot allowlist: OpenCode/CodeQL app-token dispatches use `opencode-agent[bot]`, a legacy machine path has emitted `github-actions[bot]`, and measured review-fix dispatches have arrived as the human account. The least-widening central repair is to migrate review-fix dispatch off the user token onto a dedicated repository-scoped machine principal, then authorize only machine identities still intentionally emitted while preserving `actor == sender` and exact repository/PR/base/head/wake binding. Wardnet must not add a human account to a machine-dispatch allowlist or broaden a leaf gate. + +Protected-main push validation remains converged without source churn. On exact `main@a52ccd0...`, CI `33998430723`, Scorecard `33998430707`, and dynamic CodeQL push run `33998430384` are terminal success. This is protected-head execution evidence only: governance admission remains ambiguous, Wardnet has no immutable release, and mandatory product/security gaps remain candidate-only. + +## Agent Artifact Admission + +PR #129 remains exact `db921e7f855f52870b23de52a4e23f11ff996644`, mergeable but intentionally Draft. Four repository/security lanes are terminal GREEN on that source head: CI `33977431401`, Fuzz `33977431523`, Security Scan `33977431400`, and SAST Semgrep `33977431547`. CodeQL PR `33977431418` is a central delegated-verdict failure, not an Agent Artifact Admission source finding. Preserve those GREEN lanes and reacquire only then-required delegated evidence after the central producer can publish an authenticated exact-head verdict. + +The bounded context is pre-execution structured installer security admission only. It binds reviewed workspace manifest/artifact identity, exact ecosystem/name/version/registry/owner/SHA-256, executable family, declared operands, policy revision and bounded provenance; it does not fetch, decrypt, install, execute, isolate, activate or route workloads. An `allow` receipt is admission authority, not downloaded-byte proof or runtime activation. + +Current hostile TDD includes the PyPI hash-mode contradiction: RED `032d74e060e778add00a2cc757ce3582c1135232` proves `--require-hashes` plus hostile `--no-require-hashes` must not remain admissible; classifier `4c0de8a3445d6b062b69440507cd3c81a3323308` isolates pip/pip3 hash-mode authority; causal repair `bba656c1d776da38a7315d9ec8e6cb5bdfd621d1` fails the contradictory request closed. Earlier package-manager, Cargo, npm-family, OCI-cardinality/platform and Podman trust/auth/decryption hostile contracts remain preserved. + +`context-graph-contracts#27` owns future provider-neutral external-capability artifact/evidence/admission/activation grammar. Package-manager argv/parser semantics and Wardnet reason codes remain Wardnet-local. EA projection must retain Wardnet evidence references without making Wardnet findings authoritative EA facts. AppGuardrail owns deterministic static plugin/package scanning and scan receipts; quarantine owns hostile dynamic execution evidence; Noema owns activation/rollback. None of those mutable owner heads is production authority. + +## Immediate product/security lanes + +- **#167 MISP admission + shared DNSBL snapshot ownership** — exact current Draft head `0c83cd5956f512d79c6600e823fcfa6d6f32af4e` is on protected `main@a52ccd0...`. The causal DNSBL repair remains `7042aa19267886e3af9c378dddd879929837877b`, preserving shared feed/operator ownership, operator payloads, stale withdrawal, restart and rollback/retry semantics. Temporary repair/restack GREEN is retained only as causal evidence. Fresh normal exact-head evidence has now converged for CI `34000987921`, Fuzz `34000988028`, Security Scan `34000987843`, and SAST Semgrep `34000987891`; all four are terminal success. CodeQL PR `34000987911` is terminal failure only after exact-head checkout and a successful current-head dispatch request, because the delegated verdict was unavailable at the fail-closed enforcement step. Keep Draft until the central verdict path and governance are terminal-valid; do not rerun-storm or promote temporary workflow evidence. +- **#170 MISP threat-level severity child** — exact `2c8d499a5772b0be64d7cc3fc42ed2825ba1499e`, Draft, base exactly parent #167 `0c83cd5956f512d79c6600e823fcfa6d6f32af4e`. The retained RED/GREEN maps MISP `1/2/3` to Wardnet `High/Medium/Low` and preserves the documented Undefined/missing compatibility behavior without touching the parent admission/DNSBL boundary. Full parent adoption/restack run `34001140916` is causal evidence only. Current child CI `34001236320` and Fuzz `34001236319` are now terminal success. Parent #167 must first reach protected truth; after retarget/restack the child must reacquire its own then-live security/review/governance evidence. +- **#174 CodeQL SARIF uploader successor** — Draft/mergeable exact head `028caa05167f9e8f2589b681a8f79c633f406c30` is exactly one commit ahead and zero behind protected `main@a52ccd0...`. It changes only `.github/workflows/scorecard-analysis.yml`, pinning `github/codeql-action/upload-sarif` from immutable v4.37.7 SHA to v4.37.9 `cdf488f595d80d6e07e03d4674febd5ab45fa938`; #141 remains predecessor evidence until complete transfer reaches protected truth. Repository CI `34005444829` is terminal success. Security classifier, CodeQL language detection and Semgrep classifier have each acquired hosted runners and succeeded, while downstream `scorecard` `101416546887`, `trivy-fs` `101416546904`, CodeQL compatibility `101416634299`, and Semgrep `101416892247` remain queued with `steps=[]` and `runner_id=0`. Exact evidence and RED/GREEN acceptance are on `.github#712`; no no-op push or sole-current-head cancellation is valid. +- **#77 Rust toolchain/reproducibility foundation** — exact `d386d6f57e0c8de3e4839d6c61b593e41f9d7e20`, Ready on its source head. CI `33907688502`, Security `33907688421`, and Semgrep `33907688360` are terminal success; prior CodeQL is delegated-control-plane evidence rather than toolchain-source GREEN. Protected main has advanced since the source head, so fresh candidate-base compatibility remains required. Child #164 stays Draft until #77 or a verified successor reaches protected truth and current package/SBOM/provenance evidence is reacquired. +- **#166 Wardnet-local PR queue policy** — exact `13fc6a1b9b3f5af0b7c6acfb79de6c46fd72de3a`, Ready on its source head. Repository CI/Fuzz are terminal success; central worker lanes remain owner-plane evidence. Protected main has advanced, and ordinary queue wait or base drift is not bypass authority. +- **#173 outbound site reputation** — exact `a14b28a10ea87dbcc1939fe0fdca6ce5b02259ed`, Ready/documentation-only. Its source-head repository lanes were terminal success but the required OpenCode verdict failed to arrive, and its evidence predates the protected-base movement. Wardnet owns destination maliciousness/reputation evidence lifecycle, organizational admission policy and SOC accountability; EgressWeave owns executable URL/address/DNS/peer/redirect/proxy/TLS/resource authorization. Production transport composition still requires an immutable compatible EgressWeave Rust-consumer boundary; current EgressWeave GitHub Releases remain empty. +- **#155 management auth** — exact `f74ff25a321dfb1d7109719e2a1fc77e47dc4898`; source-head CI/Fuzz/Security/Semgrep are terminal success while prior CodeQL belongs to the central delegated-verdict class. The feature fails closed before readiness when a non-loopback listener lacks a write-capable administrator credential; fresh current-base compatibility remains required. +- **#93 deterministic persistence failure injection** — exact `4775abc66e5350bdbf07ccefca74c10ddb03701a`. The deterministic write-temp/rename fault seam remains the owner-correct replacement for permission-dependent failure injection. Prior CodeQL belongs to the same central delegated-verdict class; re-read all exact-current gates and current-base compatibility before integration. +- **#140 Runtime Configuration** — canonical supporting-boundary owner at exact `054c11aafe835e497d6149efb09f1ccdee9d03bd`. Hostile RED `0f22aaff...` rejects zero positive bounds; causal repair `d28a0119...` fixes the positive-u64 bootstrap parser while preserving the distinct `RATE_LIMIT=0` disable semantic. Feature lanes adopt #140 rather than create a competing process-environment authority. +- **#157/#165 trusted client attribution** — #165 remains the current production feature owner; #157 is a preservation lane for unique trusted-proxy fuzz/corpus/invariant evidence. #165 must adopt #140 after that foundation reaches protected truth and prove complete #157 evidence transfer before #157 retires. +- **#135 bounded local limiter** — repository-owned CI/Fuzz are terminal success while central security/delegated lanes remain non-passing. Its local cardinality/rate-limit contract remains separate from #165 trusted-proxy attribution and future distributed quota authority. +- **#136 outbound policy** — preservation Draft only. Keep Wardnet-owned purpose/call-site/deadline/evidence hostile tests, but do not integrate local reusable destination/DNS/redirect/proxy/TLS authority. EgressWeave issue #237 remains the canonical immutable Rust-consumable authorization/evidence owner path. +- **#115 official threat-source refresh** — preservation Draft. Preserve Wardnet-owned source registry/parser/conditional-validator/last-known-good/SOC evidence delta, but reconstruct outbound authorization through a released EgressWeave port/ACL. +- **#88 contextual-orchestrator consumer** — architecture-gated preservation. Preserve unique fail-closed credential/header/streaming negative evidence, remove LiteLLM/provider-routing/virtual-key ownership when reconstructing, and consume only a released CO API/client/schema/Agent boundary. Contextual-orchestrator GitHub Releases remain empty. +- **#164 release evidence** — Draft stacked on #77. It separates PR build/SBOM evidence from protected-main OIDC attestation authority. Do not publish from a feature branch. +- **#127 material UI/a11y** — intentionally Draft. Before Ready it still requires production-like browser E2E for keyboard skip/focus, accessible names/descriptions, KPI live-region behavior, responsive widths, and applicable normal/loading/error/permission states; source-string tests alone are not WCAG 2.2 AA evidence. +- **#90 SIEM/OpenTelemetry preservation** — Draft/non-mergeable mixed aggregate branch. Preserve unique Wardnet-owned OCSF/OTLP/RFC 5424 exporter/input/fuzz/security evidence through a bounded successor from fresh protected main; do not inherit unrelated owner surfaces wholesale. Close only after complete verified successor transfer. + +## Open PR inventory and single-writer discipline + +Fresh GitHub search reports 30 open Wardnet PRs. The prior 29-lane inventory is superseded by new current-base successor #174. #159 and #171 remain excluded because they are protected-main truth. PR #130 remains the sole writer for this file; other lanes hand exact evidence into #130 rather than editing this path. PR retirement still requires protected merge, explicit user instruction, malicious/no-valid delta, or verified complete successor transfer of every useful code/test/fixture/contract/evidence delta. + +## Context Fabric read-only inventory + +Context Graph Contracts still reports `default_branch=develop`. Protected `develop@99cb5468ba3c15c5e79688f53dee74724fae2d13` remains live while current accepted integration/default is protected `main`; GitHub Releases remain empty. The intended dependency order remains `#4 -> #6 -> #7 -> #8 -> #12 -> #13 -> #14 -> #16 -> #17 -> #18 -> #19 -> #25 -> #20 -> #21`. Live root #4 is `7503b7da50efcad8256e5b6d3214e438c829cd50`; source-provenance prerequisite #25 is `10e5f4abc430437cfd15f79142703ac2b1fc612e`; DDD fitness #20 is `b04fa4f82bb2e8007dd5f1c660e305ffc286f1cb`; current Context Assertion/CloudEvent child #21 is `b4dced3d0d0e758b5624f3cbfe513c723a788f97`. #21 now binds repository CI/package/reproducibility/supply-chain checkout to the immutable source head, but fresh exact-head Actions inventory remains empty. `.github#1137` owns protect-main-first/default migration, `.github#772` owns the solo-review rule, and `.github#712` owns remaining materialization/runner defects after repository causes are removed. Wardnet does not mutate this stack. + +EA Core still reports `default_branch=develop`; protected `develop@dd71e40a86385fb7861b0f1be19891a3f3e29ece` remains live while product `main@ca6889497728e1a3f09d68790a9096576e13a3ff` is outside the intended protected/default topology. GitHub Releases remain empty. DDD parent #39 remains `c063570bd9177578fa75be69defd81c99e6ba2f3`; Context Fabric/quarantine projection child #40 is now exact `c6b38732754fdea9ee45c0cabcc49c6a62fbb118`, still Draft with obsolete recorded #39 ancestry and zero exact-head workflow runs. Its source now binds repository-owned CI/runtime/supply-chain checkout to the immutable PR source head and retains the adopted tenant-GUC restoration repair. The machine contract requires exactly one non-EA-owned inbound Wardnet Context Assertion evidence boundary, permits only `observed` Wardnet projection truth, forbids `malware_verdict` and `artifact_risk_score` as authoritative EA facts, and forbids direct database/source copying. Mutable CGC/EA heads remain compatibility evidence only; Wardnet does not mutate either owner repository. + +## Buyer-visible gap order + +Current order remains authority/security before breadth: protected management authentication (#78/#155); immutable outbound policy/evidence integration (#79/#136 + EgressWeave release); Wardnet-owned outbound destination reputation evidence/policy with transport composition through the same immutable EgressWeave authority (#173); real attack-path CI and deployable public path (#11/#75); Agent Artifact Admission (#128/#129); PostgreSQL authority/tenant isolation (#80) then transactional outbox (#81); Keyverse identity/approval (#82) and distributed admission/trusted attribution (#83); proven Coraza/CRS and Suricata detection (#86); immutable release evidence (#84); telemetry/SLO/incident/restore (#85); final readiness against one immutable protected release identity (#87). + +The USD 20 billion ambition is a product-quality bar, not a customer contract value, billing field or runtime pricing authority. #162 owns that documentation separation. Root `src/lib.rs` remains a modularity pressure point, not evidence by itself for a deployable service split; prefer a modular monolith until transaction/isolation/scale/deployment/reusable-owner evidence pays for another boundary. + +## Standards and release gate + +Security and runtime decisions remain traceable to current authoritative NIST/OWASP/CWE/IETF/OCI/Linux sources and primary/peer-reviewed research where implementation depends on them. Citation is design evidence, not proof that a control is shipped. Wardnet-owned production targets 100% statement/branch/edge-case coverage and complete public rustdoc/docstrings, with realistic bypass/replay/race/DoS/network/cleanup tests where applicable. + +No Wardnet release is authorized at this snapshot. Release requires one exact integrated protected head with terminal current CI/security/coverage/docstrings/package/SBOM/provenance/reproducibility/review/migration/rollback/recovery/operability evidence, immutable artifact/source identity and a verified publication path. Protected `main@a52ccd0...` has observed push validations terminal GREEN, but governance normal-vs-bypass admission remains unresolved, GitHub Releases is empty, and multiple mandatory product/security gaps remain candidate-only. Feature-branch artifacts or attestations remain candidate evidence only. \ No newline at end of file