Skip to content

fix(v0.6): complete W43 SCRAM admission contract - #159

Merged
akhiabanchian merged 31 commits into
mainfrom
fix/v0.6-w43-admission-remediation
Sep 25, 2026
Merged

akhiabanchian merged 31 commits into
mainfrom
fix/v0.6-w43-admission-remediation

Conversation

@ammarheidari

@ammarheidari ammarheidari commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Authority

Follow-up remediation for W43 under #157 / tracker #146. Scope #145 remains accepted/closed; planning #147 is admitted. PR #158 merged an incomplete SCRAM slice whose own body still marked W43 NOT MERGE READY; final W43 admission therefore remains withheld until this remediation passes governed evidence.

Remediation implemented on current head

Current head: 1dc96474ca0b2526e9a38678c86fe3997f82a7a3, base main@bd6dd6c007ded83e65775934c4defa1b3e928368.

  • preserves the legacy v0.5 operation/hash path while adding a server-preallocated durable OperationId overload for operation-bound SCRAM planning;
  • adds the common server-owned CRITICAL risk floor for ScramAlter;
  • binds canonical SCRAM plan to durable operation/requester/policy/cluster/resource/authorization/precondition/material identity;
  • adds one-shot request-scoped upsert finalization material through the existing MutationDispatchService -> MutationExecutor path; no delayed plaintext storage;
  • adds typed delete finalization without secret material;
  • adds digest-key rotation and metadata-drift pre-dispatch invalidation;
  • adds live original-requester + distinct currently eligible direct-subject approver revalidation; no OIDC group rehydration;
  • adds durable SCRAM conflict obligations before provider I/O and no-redispatch behavior for previously admitted effects;
  • ambiguous upsert remains ExecutionUnknown even when mechanism/iteration metadata later matches; metadata never proves password equality;
  • delete ambiguity may be promoted only by observed credential absence;
  • exact missing SCRAM user maps narrowly from Confluent Local_Partial per-user ResourceNotFound to empty exact-user metadata; other partial/error shapes remain failures;
  • adds real Kafka synthetic create/upsert -> authenticate -> rotate -> reject-old/authenticate-new -> delete -> reject-new lifecycle evidence to the existing smoke/compatibility matrix;
  • adds architecture/fault regressions for operation identity, finalization, drift, current authorization, obligations and ambiguity.

Activation boundary

No public REST/OpenAPI/UI route and no default SCRAM handler/validator DI activation is introduced. W39 remains fail-closed unless W43 dependencies are explicitly injected; W49 retains public activation.

Final admission gate

W43 remains NOT YET ADMITTED COMPLETE until current-head applicable CI is green, substantive review is complete, required threads are resolved, and a fresh current-head CODEOWNER approval from akhiabanchian exists.

No release/tag/OCI publication is authorized.

Refs #157 #146 #145

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-25T12:18:19.989446Z 1dc9647 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 75b5ce3947

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/backend/Kafdeck.Api/MutationAdmissionService.cs
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact source head 225329347b745cdf732afb2d84773b5a1b1b967a, with particular attention to W43 SCRAM operation-ID/HMAC binding, one-shot requester finalization, current independent-approver revalidation, durable conflict obligations, no-redispatch after ambiguous upsert, and real Kafka lifecycle evidence. Do not infer password equality from metadata.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
…cope

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 225329347b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/backend/Kafdeck.Api/W39MutationPreDispatchGuard.cs
akhiabanchian
akhiabanchian previously approved these changes Sep 25, 2026
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@akhiabanchian
akhiabanchian self-requested a review September 25, 2026 11:34
akhiabanchian
akhiabanchian previously approved these changes Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head 536dd1a0a35bf2b76a0a6d988e75ec712c61466d after the W43 deterministic SCRAM observation/delete/authentication fixes and the resolved review dispositions. Focus on correctness, ambiguity semantics, secret handling, and governed W43/W49 activation boundaries.

- normalize exact-user ResourceNotFound to empty SCRAM metadata
- require full mechanism absence before delete verification can resolve uncertainty
- prove create/rotate/delete credentials with real SCRAM authentication
- disambiguate provider SaslMechanism in the integration harness

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
@ammarheidari
ammarheidari force-pushed the fix/v0.6-w43-admission-remediation branch from 536dd1a to a9c6822 Compare September 25, 2026 11:44

Copy link
Copy Markdown
Contributor Author

@codex review

Fresh exact-head review requested after DCO-safe history repair. Please review a9c6822cd1f8a50739b501b32370da1c81af8ebd (not the superseded heads) for W43 correctness, ambiguity handling, credential lifecycle evidence, and W49 activation-boundary compliance.

Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Please review fresh exact head d8e3ea93707720b837336576fab735fabd899c14. The latest fix classifies Confluent exact-user SCRAM absence from the per-user exception.Results error (the outer exception is Local_Partial), while keeping all other shapes fail-closed. Re-check W43 ambiguity/secret/authorization and W49 activation boundaries.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d8e3ea9370

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/backend/Kafdeck.Api/MutationDispatchService.cs
akhiabanchian
akhiabanchian previously approved these changes Sep 25, 2026
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
Signed-off-by: Ammar Heidari <ammar@arad-itc.org>

Copy link
Copy Markdown
Contributor Author

@codex review

Please review fresh exact head 1dc96474ca0b2526e9a38678c86fe3997f82a7a3 after the execution-material claim-failure/expiry remediation. Verify zeroization ownership, TOCTOU behavior, and that no W49 activation boundary was crossed.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Delightful!

Reviewed commit: 1dc96474ca

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@akhiabanchian
akhiabanchian merged commit 714f5e8 into main Sep 25, 2026
14 checks passed
@akhiabanchian
akhiabanchian deleted the fix/v0.6-w43-admission-remediation branch September 25, 2026 13:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants