Skip to content

security(core/R-15): Gate 5 — fence every protected writer and complete inventory/migration readiness #923

Description

@qnbs

Program position

Child owner of #445 for R-15 Gate 5 — the largest migration-readiness surface before packaged shadow qualification.

TARGET_RELEASE = v1.30.0
PREDECESSOR = Gate 4 terminal
NO_GAP_INVARIANT = REQUIRED
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO

Objective

Make the packaged desktop's full protected-data universe controllable and migratable with no unfenced writer gap.

Before a class's final migration inventory is captured, every current writer of that class must be routed through an admitted fence-participating adapter, deterministically quiesced/disabled for the migration window, or explicitly refused with truthful recovery behavior. Anything else blocks Gate 5 for that class.

Required protected-class coverage

Re-derive from live §3 inventory. At minimum disposition projects/manuscripts, snapshots, settings, images, binder bytes+metadata+asset-pair, Codex, RAG/vector indexes, quarantine/recovery, active-project marker, authority/catalog/epoch/commit metadata, migration journals, packaged WebView/IndexedDB legacy desktop sources, backups per contract boundary, credentials under their approved separate protected authority, and every new protected class added since the contract inventory.

No packaged-desktop PROTECTED class may be silently skipped, treated as harmless plaintext, or left unknown/unmigrated.

Migration proof

capture final fenced inventory
→ convert each admitted source
→ durably write target generation
→ verify envelope/AAD/digest/identity
→ update authenticated catalog/markers
→ retain prior recoverable source until target commit proof
→ only then permit cleanup

Acceptance

Prefer multiple small PRs grouped by coherent data families. Do not force this gate into one oversized PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions