feat(state): make production authority explicit - #193
seonghobae wants to merge 14 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh parent-state correction, 2026-09-17 KST: the body’s #430 helper-only status is superseded. Serialized child #430 is exact |
Refs #80 #192. Draft child of Runtime Configuration foundation #140.
Bounded production-authority contract
Wardnet must never infer deployment intent from listener topology: production may bind loopback behind a proxy/sidecar. This slice makes mutable-state authority explicit while leaving PostgreSQL repository/migrations/RLS/recovery under #80/#192.
It does not claim PostgreSQL durability, RLS, tenant isolation, migration/recovery, backup/restore, source-generation uniqueness or release readiness.
Hostile RED -> repair history
Test-only
37f5c8cb73ed45a003e1d4ca69771d649db5a5f7produced semantic RED in CI34175687088/ rust101904485782; minimum implementation established explicit deployment/state-authority semantics. Test-only2d57983d38a8e712a6103f6898906ed88b569be0then provedStateAuthority::FileacceptedPathBuf::from(""); repairf50e7204df5e6467297969eddff70891358e4bff, followed by semantics-preserving Clippy repair88e54cd18fb686a6b61525c400531820f7a014b4, closed that child finding.Exact child head remains
7a93322c9a824e6e939a8143b1f20eccaeac856d. Its CI34234733846and Fuzz34234733840were SUCCESS when its recorded #140 base was93a51f9706cf8a9704f69aed4a69df5be16c84e4; those are historical child receipts only.Parent moved — parked, not restacked
Current #140 is exact
7d98725cc51b259b0be940385b2245758d098081, still pre-#155/non-mergeable while #310 performs the protected-base synthesis.src/credentials.rsis already reconciled;src/lib.rswas the semantic source conflict.Serialized hostile synthesis child #430 has advanced to exact
65b887e347d47e3cd29071342c353408c3f14e4a. Test-only exact062ea6ab787d0a1d864e429a95f7ed1642fbf37eestablished semantic RED: Fuzz35029440921is terminal SUCCESS; CI35029440905/ rust job104584220679passed checkout/toolchain/format and proved stalerun_from_envcould bind public0.0.0.0:44429without a write-capable administrator. The same run exposed protected-auth helpers as non-test dead code, corroborating the missing #155 integration.An intervening attempted repair
408e8b8de90d061e6ef01414f298f2156d2466dfreplaced almost all ofsrc/lib.rs(221additions /6777deletions) and was not a valid synthesis. It was reverted at61790e2a46e8c45467f57558673e5a1b8a2e0490; no evidence from that source may transfer.The bounded deterministic synthesis helper subsequently completed successfully on exact helper input
cc8f721775e808ff00961dc8e29540e34720b1c2. One-shot run35160876925, job105011075007, reconstructed from protected complete source, applied only the reviewed Runtime Configuration/authentication composition, rancargo fmt,git diff --check,cargo test --locked --test runtime_configuration_auth_synthesis, andcargo test --locked --lib, then committed onlysrc/lib.rsas0e0f01efbd6e21874c94eed987192534e234f211. The temporary helper was removed by ordinary fast-forward follow-up at current exact65b887e....Current #430 therefore contains the bounded production synthesis: one immutable non-secret
RuntimeConfiguration, secret bootstrap throughCredentialRegistry, strictADMIN_TOKEN/ADMIN_TOKENS, header-presentable write-capable administrator derivation, constant-time auth,require_write_auth_for_bindbefore public listener bind, listener/readinessauth_mode, management 401/403, body/rate/state/credential/flush/shutdown semantics, and single-sourced parse helpers. Construction GREEN is not current admission GREEN: exact-current CI35180770661/ rust job105072217366and Fuzz35180770659/ fuzz job105072216969remain QUEUED at the latest fresh read.GitHub records this #193 Draft as mechanically non-mergeable against its historical parent. That is a dependency-status finding, not a reason to close the child or force/rebase it. Do not source-restack #193 while #140/#310/#430 is still awaiting exact-current admission. Once the Runtime Configuration foundation has one unchanged synthesized exact head with repository-native hostile/authentication GREEN and required security/review/base evidence, merge #430 normally into #140, reconcile the root non-force against protected main, then adopt that settled parent into #193 by ordinary non-force integration and reacquire exact-head evidence.
Integration order
Keep
#140 -> #193 -> #194 -> #196 -> #198 -> #199 -> #200 -> #207 -> #208 -> #209 -> #212 -> #216 -> #217 -> #219 -> #221 -> #223 -> #224 -> #225 -> #226 -> #228 -> #229 -> #231 -> #233 -> #234 -> #236 -> #241 -> #242 -> #244. Any parent movement invalidates dependent gate evidence.No force update, destructive rebase, self/model approval, routine administrator bypass, gate weakening, mutable foreign dependency, source copy, cross-service SQL, no-op dispatch churn or predecessor-evidence transfer.