Skip to content

security(core/R-15): Gate 6 — packaged shadow/compatibility qualification on Linux, Windows and macOS #924

Description

@qnbs

Program position

Child owner of #445 for R-15 Gate 6.

TARGET_RELEASE = v1.30.0
PREDECESSOR = Gate 5 terminal
MODE = SHADOW / COMPATIBILITY ONLY
AUTHORITY_SWITCH = FORBIDDEN IN THIS GATE
PACKAGED_HARNESS_OWNER = #906

Objective

Prove the new Core secure-storage path against real packaged Tauri artifacts and realistic persisted-state scenarios before it becomes authoritative.

Gate 6 compares Core verdicts/results with current production behavior. It does not switch ownership.

Required packaged evidence

Use exact-SHA built artifacts and integrate/extend #906 rather than creating an unrelated second harness. Cover as platform semantics require: Linux Secret Service present/absent (absent must fail closed), Windows Credential Manager, macOS Keychain, fresh profile, upgrade profiles, locked/unlocked lifecycle, wrong key/recovery material, modified ciphertext/tag, substitution, interrupted durable write, crash during migration/rotation, restart/resume, autosave/concurrent-write fencing, snapshots/recovery/quarantine, representative large/chunked records, and relevant #332 background/durability/performance signal.

Record source SHA, artifact identity/hash, fixture identity/hash and result. ENVIRONMENT_LIMITED is not PASS.

Evidence maturity

Gate 1b currently has Linux CI_ONLY+LOCAL_ONLY, macOS/Windows CI_ONLY and no packaged secure-store evidence. Gate 6 must close the release-relevant gap.

Acceptance

Non-goals

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions