Skip to content

security(core/R-15): Gate 7 — explicit production authority switch, legacy migration and cutover #925

Description

@qnbs

Program position

Child owner of #445 for R-15 Gate 7 — the final semantic production cutover.

TARGET_RELEASE = v1.30.0
PREDECESSOR = Gate 6 terminal
CURRENT_AUTHORIZATION = NO
REQUIRES_EXPLICIT_MAINTAINER_AUTHORIZATION = YES

Objective

After Gates 1–6 are terminal and packaged evidence is clean, perform the separately authorized release migration that makes renderer-neutral Rust Core secure storage the authoritative packaged-desktop at-rest path. Browser/PWA remains independent.

Preconditions

Cutover requirements

  • route all packaged-desktop protected readers/writers through Core authority;
  • replace filename/directory-trusting enumeration with authenticated list_records/record catalog where contract requires;
  • preserve-first legacy migration;
  • retain recoverable prior source until target durable verification permits cleanup;
  • forbid silent fallback to old plaintext/legacy writers;
  • explicit recovery/downgrade semantics;
  • truthful UI/runtime locked/recovery states;
  • preserve data through restart/crash/rollback boundaries.

Acceptance

  • packaged upgrades from supported prior versions;
  • every protected class encrypted at rest or explicitly retained under an approved separate protected authority;
  • no plaintext authoritative siblings/remnants outside approved recovery/retention;
  • exact artifact qualification on supported desktop platforms;
  • rollback/recovery drills;
  • security/privacy/docs claims match observed product truth;
  • only then R-15 production authority may be declared terminal.

This issue must never self-authorize the switch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions