Skip to content

security(core/R-15): Gate 2 — complete identity-bound adapters and AAD closure #920

Description

@qnbs

Program position

Child owner of #445 (R-15). This issue owns the remainder of Gate 2 after PR #917's typed identity-registry slice.

TARGET_RELEASE = v1.30.0
PARENT = #445
PREDECESSOR = PR #917 (Gate 2 slice 1)
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Current execution — M1 / Gate 2 — 2026-10-01

PREDECESSOR #917 = TERMINAL
BASE_MAIN = cf45da58ea8ba8edee38f1d8a0db8edb2160ce58
SLICE_A = PR #928 ACTIVE
SLICE_A_HEAD = e299c325bd05597baec5d2947990404ad59d5c7e
SLICE_A_SCOPE = identity-bound record codec + structural asset-pair relations
SLICE_B = legacy source-locator adapters
SLICE_C = Gate 2 closure + #361 reconciliation
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Slice A is intentionally headless and bounded. It does not own I/O, durable replacement, journal/admission, migration or app wiring. The first review epoch completed and correction wave 1 landed. The current exact-head review has two open Codex P2s (component-copy allocation discipline; §20 tamper/unsupported-schema wording) that must be resolved or dispositioned before merge.

After Slice A merges and its resulting-main proof/housekeeping is terminal, continue automatically to Slice B from proven main; do not append Slice B into #928.

Objective

Finish Gate 2 exactly as defined by the binding R-15 contract: strict parsing and canonical AAD remain authoritative; every protected record class that needs an implementation adapter has one explicit renderer-neutral adapter/result; stable logical identity and scope are preserved without narrowing legacy ID domains; cross-record substitution is rejected; current TS/Tauri production authority remains unchanged.

This is the implementation closure for the identity-binding problem historically tracked by #361; close #361 only when R-15 evidence actually proves its acceptance surface.

Required scope

  1. Re-read current main after feat(core): add the Gate 2 typed record-identity registry (#445) #917 terminal.
  2. Enumerate all v1 protected record classes from §3/§5 and classify implemented adapter, fixed literal identity, structured composite identity, explicit refusal, or no packaged persisted record yet.
  3. Add the smallest coherent adapters required to move Gate 2 from registry-only to usable record identities.
  4. Prove canonical AAD and substitution resistance across project/global/install scopes, asset pairs, snapshots, RAG, recovery, migration and control records.
  5. Preserve arbitrary legal legacy component strings through an unambiguous canonical representation; never remap or silently narrow existing IDs.
  6. Keep credentials/raw key material outside ordinary record envelopes per contract.

Acceptance

Non-goals

Prefer small sequential PRs if the remainder exceeds normal reviewability. Do not create another XXL PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions