diff --git a/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.md b/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.md index f28740e..16b4ce5 100644 --- a/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.md +++ b/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_04_windows_credential_backend.md @@ -4,20 +4,24 @@ S2-RO-04 validates the trusted Stage-2 Windows password representation as strict UTF-16LE and returns the same password as strict UTF-8 transport bytes. This -offline remediation corrects the credential handoff to the unchanged S2-RO-09 -transport. It does not authorize a live retry or claim compatibility PASS. +remediation corrects the credential handoff to the unchanged S2-RO-09 +transport. Implementation and independent review passed, and PR #88 integrated +the remediation into main. Separately authorized Lab2 compatibility validation +passed pin verification, password authentication, and the exact read-only +command. This evidence grants no new credential access or live authority. The trusted policy wrapper continues to accept the two exact S2-RO-03 target/credential bindings, each with its matching trusted locator. Legacy `read(binding)` remains Lab1-only; `read_for_target(target_ref, binding)` checks the exact pair through S2-RO-03 before comparing configuration identity. -The native Windows reader is unchanged. This is an **offline remediation**, -not permission to read a credential store or contact either lab. +The native Windows reader is unchanged. S2-RO-04 remains the credential +retrieval / representation validation boundary; S2-RO-09 owns pinned SSH +transport. Neither this document nor the backend authorizes live execution. -Status: implementation candidate ready for independent review after validation. - -No real Windows credential was read while implementing or validating this -slice. Every behavioral test uses an injected fake Windows API. +Status: remediation integrated; accepted Lab2 live authentication PASS. +No real Windows credential was read during offline implementation or tests. +Every behavioral test uses an injected fake Windows API. The later, separately +authorized live evidence is distinguished from those offline tests below. ## Position in the flow @@ -181,15 +185,64 @@ but failed password authentication; no remote command executed. An authorized offline Owner-secret comparison established that the stored bytes matched UTF-16LE and did not match UTF-8. The accepted source returned raw Windows bytes from S2-RO-04 and supplied them unchanged to S2-RO-09 authentication. -This remediation corrects only that representation handoff. No credential -store or device is accessed during this offline implementation or validation. +The root cause was +`S2_RO_04_TO_S2_RO_09_CREDENTIAL_ENCODING_CONTRACT_MISMATCH`. +The bounded remediation corrected only that representation handoff, with no +credential-store or device access during offline implementation and tests. + +### Historical pre-live status + +Before the separately authorized review and live retry, the recorded status was +`POST_REMEDIATION_LIVE_AUTHENTICATION_RESULT = NOT_YET_VERIFIED`. +At that point independent review and a live retry still required separate +Owner authorization; offline test success alone did not prove compatibility. +This historical status is superseded by the accepted evidence below. -`POST_REMEDIATION_LIVE_AUTHENTICATION_RESULT = NOT_YET_VERIFIED` +## Current accepted Lab2 status -Independent read-only review and any later live retry require separate Owner -authorization. Offline test success does not establish S2-RO-09 compatibility. +```text +S2_RO_04_REMEDIATION_IMPLEMENTATION = PASS +S2_RO_04_INDEPENDENT_REVIEW = PASS +UNRESOLVED_MATERIAL_FINDINGS = 0 +S2_RO_04_MAINLINE_INTEGRATION = COMPLETE +POST_REMEDIATION_LIVE_AUTHENTICATION_RESULT = PASS +POST_REMEDIATION_LIVE_AUTHENTICATION_TARGET = target.mikrotik.lab02 +POST_REMEDIATION_LIVE_AUTHENTICATION_SCOPE = BOUNDED_S2_RO_09_COMPATIBILITY_VALIDATION +``` -## Offline reviewer evidence +The accepted Lab2 run used strict UTF-16LE validation/decode followed by strict +UTF-8 transport bytes from S2-RO-04. Exact S2-RO-07 Ed25519 pin verification +passed before password authentication succeeded in unchanged S2-RO-09. +The exact read-only command `/interface vrrp print detail` then succeeded once, +with remote exit status 0 and no stderr. There were zero retries, no RouterOS +configuration mutations, and no secret exposure. + +Independent review passed with zero unresolved material findings. This is +bounded Lab2 compatibility evidence, not authority for another credential read, +live attempt, runtime composition, or later slice. See the +[S2-RO-09 accepted evidence](stage2_vrrp_readonly_s2_ro_09_pinned_ssh_transport.md#current-accepted-lab2-compatibility) +for the exact operation and limits. + +### Mainline and CI traceability + +The accepted live evidence was produced on remediation candidate +`cbf90a98dee6e11b6b125ad778e73f5ca7f6d1d3`. [PR #88](https://github.com/Robinlee0929/Network_Automation_Lab/pull/88) +integrated it through normal merge commit +`7a244c42d5d6f8de0499cd0e4619aee89bba6d9c`. The candidate and merge commit +have the exact same complete tree, `0f47bb855bcf40c46b14c6feab8aa11c0eda6456`; +therefore the accepted compatibility evidence applies to the integrated +mainline content without another live run. + +[Post-merge Safe CI 34824181847](https://github.com/Robinlee0929/Network_Automation_Lab/actions/runs/34824181847) +completed successfully for that exact merge SHA on the `push` event for +`main`. Python: 4,003 collected, 4,001 passed, two skipped, zero failed. +Node: 128 passed across nine files. Report-index: WARN, with one pass, +13 optional reports missing, zero mandatory reports missing, zero failures, +and zero unknown results. Typecheck, lint, Next.js build, and tracked-file +immutability checks passed. These are retained results, not new validation +performed by this documentation correction. + +## Historical offline reviewer evidence Focused tests use only a synthetic target, username, and secret with an injected fake API. They prove: @@ -222,7 +275,7 @@ fake API. They prove: test guard denies real Windows library loading unless a test installs its deterministic fake boundary. -Validation order is focused S2-RO-04 tests, unchanged focused S2-RO-09 tests, +The implementation validation order was focused S2-RO-04 tests, unchanged focused S2-RO-09 tests, all `tests/stage2`, full pytest, report-index, and `git diff --check`. Python runs use `-B`; pytest disables its cache provider. Validation uses an external disposable copy of the exact candidate, without dependency downloads or source-worktree runtime artifacts. @@ -251,9 +304,11 @@ RESTCONF, HTTP, live commands, live-device access, evidence serialization, or S2-RO-05 and later capabilities. No real Credential Manager target, username, password, or secret is committed. -No real credential store was probed. The bounded implementation authorization -permits one local commit only after validation passes. Push, pull request, -merge, branch/worktree cleanup, and S2-RO-05 or later Lab2 work still require -separate Owner authorization. No Lab2 credential record, known-host data, +No real credential store was probed during offline implementation or tests. +The historical implementation authorization allowed one local commit after +validation; PR #88 integration and the later bounded live validation occurred +under separate Owner authorizations. Any further push, pull request, merge, +branch/worktree cleanup, or later Lab2 work requires separate Owner +authorization. No Lab2 credential record, known-host data, authorization package, replay access, private-key access, live attempt, or Stage-3 work is authorized here. diff --git a/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_09_pinned_ssh_transport.md b/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_09_pinned_ssh_transport.md index 185ea3a..7d2b71c 100644 --- a/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_09_pinned_ssh_transport.md +++ b/docs/automation_readiness/stage2_vrrp_readonly_s2_ro_09_pinned_ssh_transport.md @@ -3,13 +3,19 @@ ## Decision summary S2-RO-09 implements one bounded pinned SSH transport primitive for the exact -command `/interface vrrp print detail`. The current compatibility remediation -adds only `diffie-hellman-group-exchange-sha256`, with a 2048-bit minimum for -both the request and the server's actual group. Status: validated offline -remediation candidate; independent security review PASS, zero unresolved -material findings. Ready for separate local-commit authorization. The original -slice's delivery evidence is retained below as historical context. -No live operation is authorized by this document or by a successful result. +command `/interface vrrp print detail`. Bounded Lab2 compatibility is proven: +pinned Ed25519 verification, password authentication, and the exact command +passed after the S2-RO-04 credential representation remediation. PR #88 +integrated the exact live-validated tree; post-merge Safe CI passed. +Status: implementation and compatibility validation complete; +ready for canonical closure. No live operation or next slice is authorized +by this document or by a successful result. + +The earlier bounded KEX remediation added only +`diffie-hellman-group-exchange-sha256`, with a 2048-bit minimum for both the +request and the server's actual group. Its independent security review passed +with zero unresolved material findings. Original delivery and offline +remediation evidence remain historical context below. The Owner approved a private Paramiko `Transport.preferred_keys` override to enforce raw `ssh-ed25519` negotiation. This correction is part of this slice; @@ -19,7 +25,7 @@ installed dependencies or global Paramiko state. ## Allowed scope -Exactly three files comprise this candidate: +The historical transport implementation/remediation candidate comprised three files: - [Transport](../../validation_framework/stage2_pinned_ssh_transport.py) - [Offline tests](../../tests/stage2/test_pinned_ssh_transport.py) @@ -45,7 +51,9 @@ Arbitrary privileged in-process mutation remains outside the Python contract. There is no target resolution, Credential Manager call, known-host acquisition, Owner verification, approval acquisition, replay consumption, VRRP parsing, final S2-RO-01 evidence construction, or runtime orchestration. S2-RO-10 and -S2-RO-11 remain separately gated. S2-RO-01 through S2-RO-08 are unchanged. +S2-RO-11 remain separately gated. The transport remediation did not change +S2-RO-01 through S2-RO-08; the later S2-RO-04 representation remediation was a +separately bounded change and left S2-RO-09 source and tests unchanged. No DNS, hostname, alternate address, retry, reconnect, system/user known_hosts, TOFU, host-key rotation fallback, SSH agent, keyfile, public-key authentication, @@ -108,10 +116,74 @@ exactly `diffie-hellman-group-exchange-sha256` while retaining was added. The remediation did not add `mlkem768x25519-sha256`, `curve25519-sha256`, `curve25519-sha256@libssh.org`, or any SHA-1 KEX. +### Historical pre-live status + +After the offline KEX remediation, the recorded status was `POST_REMEDIATION_LIVE_CONNECTION_RESULT = NOT_YET_VERIFIED`. -Post-remediation live success is not yet verified; this evidence does not -establish a successful SSH handshake, host-key observation or known-host trust, -authentication, RouterOS command execution, or a Stage-2 real live run. +That historical evidence alone did not establish a successful handshake, +host-key trust, authentication, command execution, or a Stage-2 real live run. +The current bounded Lab2 result is recorded below. + +### Current accepted Lab2 compatibility + +Following Lab2 Ed25519 trust provisioning, later Lab2 validation reached +`AUTHENTICATION_FAILED`. An authorized offline UTF-16LE diagnostic traced this +to `S2_RO_04_TO_S2_RO_09_CREDENTIAL_ENCODING_CONTRACT_MISMATCH`. +The bounded S2-RO-04 remediation validated/decoded trusted Windows UTF-16LE +CredentialBlob bytes and returned strict UTF-8 transport bytes to unchanged +S2-RO-09. Independent review passed with zero unresolved material findings. +The separately authorized post-remediation live run then passed: + +| Evidence | Accepted result | +| --- | --- | +| Target / endpoint | `target.mikrotik.lab02` / `192.168.88.3:22` | +| Host key / exact S2-RO-07 pin verification | `ssh-ed25519` / PASS | +| Password authentication | PASS | +| Exact remote command / dispatch | `/interface vrrp print detail` / PASS | +| Remote exit status / stderr | 0 / absent | +| Connection / password authentication attempts in the successful task | 1 / 1 | +| Remote command executions / retries | 1 / 0 | +| RouterOS configuration mutation / secret exposure | none / none | + +```text +POST_REMEDIATION_LIVE_CONNECTION_RESULT = PASS +POST_REMEDIATION_LIVE_AUTHENTICATION_RESULT = PASS +POST_REMEDIATION_LIVE_COMMAND_RESULT = PASS +LAB2_REVALIDATION_RESULT = PASS +S2_RO_09_LAB2_COMPATIBILITY = PASS +S2_RO_09_TECHNICAL_COMPATIBILITY_STATUS = PROVEN_ON_INTEGRATED_MAINLINE_CONTENT +S2_RO_09_TECHNICAL_COMPATIBILITY = PROVEN +S2_RO_09_IMPLEMENTATION_AND_COMPATIBILITY_VALIDATION = COMPLETE +S2_RO_09_STATUS = READY_FOR_CANONICAL_CLOSURE +NEXT_SLICE_AUTHORIZATION = SEPARATE_OWNER_DECISION_REQUIRED +``` + +This evidence proves bounded S2-RO-09 Lab2 compatibility. It does not prove +S2-RO-10 runtime composition, S2-RO-11 live entrypoint, full Stage-2 end-to-end +live execution, production readiness, or configuration mutation capability. +It adds no Lab1 authentication claim and does not alter the separately recorded +historical Lab1 closure or S2-RO-10/11 status in the integration plan. +No password, raw credential blob, raw RouterOS stdout, private key, or secret +hash is included. No new live validation is needed for this status correction. + +### Mainline and CI traceability + +The accepted live evidence was produced on remediation candidate +`cbf90a98dee6e11b6b125ad778e73f5ca7f6d1d3`. [PR #88](https://github.com/Robinlee0929/Network_Automation_Lab/pull/88) +integrated it through normal merge commit +`7a244c42d5d6f8de0499cd0e4619aee89bba6d9c`. The candidate and merge commit +have the exact same complete tree, `0f47bb855bcf40c46b14c6feab8aa11c0eda6456`; +therefore the accepted compatibility evidence applies to the integrated +mainline content without another live run. + +[Post-merge Safe CI 34824181847](https://github.com/Robinlee0929/Network_Automation_Lab/actions/runs/34824181847) +completed successfully for that exact merge SHA on the `push` event for +`main`. Python: 4,003 collected, 4,001 passed, two skipped, zero failed. +Node: 128 passed across nine files. Report-index: WARN, with one pass, +13 optional reports missing, zero mandatory reports missing, zero failures, +and zero unknown results. Typecheck, lint, Next.js build, and tracked-file +immutability checks passed. These are retained results, not new validation +performed by this documentation correction. ### Bounded GEX SHA-256 compatibility @@ -241,7 +313,7 @@ The two real Win32 trust-root tests and the Flask process/socket lifecycle test remain explicitly classified safety skips. No S2-RO-09 test may skip. No dependency or requirements change is needed. -### Current KEX remediation evidence +### Historical offline KEX remediation evidence - Base commit: `2a71dc8eb5d7dcb12f5c3b1e533a339d2744ecea`. - Base tree: `48eec05773e8a731ad953f5e86ab5a4e80ec67d1`.