Skip to content

docs(security): placeholder key ids so required gitleaks passes - #142

Merged
hyperpolymath merged 2 commits into
mainfrom
docs/key-lifecycle-placeholder-uuids
Oct 2, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
docs/key-lifecycle-placeholder-uuids

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Unblocks the required scan / gitleaks check, which is red on main (0613e69) and therefore on every open januskey PR, including ULTRAPLAN P0-1 (#141) and P0-2 (#140).

Cause

The estate secret scanner mirrors .adoc files, which default gitleaks never scans. Its generic-api-key rule matched two example UUIDs in a JSON sample in docs/security/KEY_LIFECYCLE.adoc:

  • :487 "key_id": "123e4567-e89b-12d3-a456-426614174000"
  • :488 "new_key_id": "789e0123-e89b-12d3-a456-426614174000"

These are documentation placeholders, not secrets.

Change

Both values are replaced with obvious low-entropy placeholders (00000000-0000-4000-8000-000000000001 and …0002). One file, 2 lines changed.

Evidence

Run locally with gitleaks and the estate baseline standards:config/gitleaks/estate-baseline.toml (origin/main):

Input Result
original file (positive control) leaks found: 2, generic-api-key at lines 487 and 488, the same two lines CI reports
edited file no leaks found
all .adoc files in the repo, mirrored no leaks found

🤖 Generated with Claude Code

https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4

gitleaks generic-api-key matched the sample UUIDs under "key_id" and
"new_key_id" in KEY_LIFECYCLE.adoc (lines 487-488), turning the required
"scan / gitleaks" check red on main and every PR. They were example
values, not secrets; replace them with obvious low-entropy placeholders.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 54b16847-4537-4903-bd3c-29315a2bb16b

📥 Commits

Reviewing files that changed from the base of the PR and between faac22e and e7819ba.

📒 Files selected for processing (1)
  • docs/security/KEY_LIFECYCLE.adoc
 _____________________________
< Reviewing code like a boss. >
 -----------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit b1fc4ed into main Oct 2, 2026
7 of 17 checks passed
@hyperpolymath
hyperpolymath deleted the docs/key-lifecycle-placeholder-uuids branch October 2, 2026 12:15
hyperpolymath added a commit that referenced this pull request Oct 2, 2026
#144)

## Why
Two Rust jobs are red on `main` (539e6f9). The claims ledger (ULTRAPLAN
P1-0) needs a `cargo test` that CI actually runs, so these are fixed
first.

| Check on main | First failing cause (from the job log) |
|---|---|
| Rust Build + Unit Tests | `error: invalid value 'v1' for
'[TOOLCHAIN]...': invalid toolchain name: 'v1'` (`e2e.yml:24`) |
| rust-ci / Cargo check + clippy + fmt | `cargo fmt --check` diff in
`attestation.rs`, `keys_cli.rs`. Behind it, a stack of clippy `-D
warnings` errors, each target masking the next |

## What
- **`e2e.yml`**:
  - `toolchain: stable` with the clippy and rustfmt components.
- Removed `|| true` from the Clippy and Format steps, which previously
could not fail.
  - Clippy now runs with `--all-targets`, matching rust-ci.
- **`cargo fmt`**.
- **All `clippy --all-targets -D warnings` lints cleared**:
  - rand 0.9 `thread_rng` → `rng`.
  - Needless `mut`, borrows, parentheses and `format!`.
  - `&PathBuf` → `&Path` (20 sites).
- Removed the dead `KeyManager.root_path` field and a dead store in the
bench.
- **`jk-keys` now imports `attestation`/`keys` from the lib.** It used
to compile them as private modules via `mod`. That made the lib's public
methods read as dead code, and it ran 10 unit tests twice.

## Evidence (local, Rust 1.97.1)
- `cargo fmt --all --check` → clean
- `cargo clippy --locked --workspace --all-targets -- -D warnings` → rc
0
- `cargo test --locked --workspace` → **107 passed, 0 failed**
- `--list` diff against `main`:
  - Before: 117 entries. After: 107.
- The 10 removed entries are exactly the `src/keys_cli.rs` copies of
`attestation::tests::*` (6) and `keys::tests::*` (4).
- Each was checked to still run under `src/lib.rs`, so no test was lost.
- `cargo bench --no-run` → builds.

## Not in this PR
`e2e.yml:98` runs `python3` (banned estate-wide), behind `|| true`. It
is recorded in `dev-notes/inbox/findings.md`, not changed here.

## Second push (e6fee67)
- **`e2e.yml`**: the Criterion, E2E Lifecycle and Panic Attack jobs
called `dtolnay/rust-toolchain@v1` with no `toolchain` input. That step
failed with "'toolchain' is a required input", so these jobs now pass
`toolchain: stable`.
- **`tests/aspect/cross_cutting_test.sh`**:
- The repo moved SECURITY, ARCHITECTURE, PROOF-NEEDS and TOPOLOGY to
`.adoc`, but the checks still looked for `.md`, so 4 of 29 failed.
- Each check now accepts either extension, as the README check already
did. Result: **29/29**.
- Negative control: with `TOPOLOGY.adoc` removed, the check fails
(28/29).
- **`attestation.rs`**: the HMAC key error is now propagated with
`map_err(std::io::Error::other)?` instead of `expect()`. Hypatia flagged
it as `expect_in_hot_path`, and the function already returns
`io::Result`.

Partly addresses #135 (acceptance items 1 and 2 and `Run aspect tests`)
and #133 (clippy/fmt `|| true`). Neither issue is closed.

## Red checks on e6fee67: deferred, not introduced here
Every red below also fails on `main` 539e6f9. The only required context
is `scan / gitleaks`, which is green.
- `governance / Workflow security linter`: deferred to #135 (acceptance
item 5)
- `lint-workflows`: deferred to #135 (acceptance item 5)
- `governance / Allowlist Preflight`: deferred to #135 (acceptance item
6, `Check live Actions policy`)
- `Validate DEED manifests`: deferred to #135 (acceptance item 6)
- `estate-audit`: deferred to #135 (acceptance item 6, `Code Hygiene
Gate`)
- `idris-abi (expected red until J1-3)`: expected red by design (#142)
until #145 (ULTRAPLAN J1-3) makes Types.idr typecheck.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 2, 2026
…counts (#146)

ULTRAPLAN **P1-0, PR B of three** (B: ledger + counts; C: escape-hatch
counter; D: `workflow_call`).

> **Stacked on #144.** This branch contains #144's commit e6fee67, so
review only **6f31e89** and the docs follow-up. It stays a draft until
#144 merges; then it is rebased onto main and marked ready.

## What it does
`PROOF-NEEDS.adoc` gains a `=== Claims ledger` table. Each row is `claim
| status | artefact | command`, with status PROVEN / TESTED / ASSUMED /
DESIGNED / OPEN, and each row fits on one line. `dashboard-check --check
.` (already run by `dashboard-check.yml`) now does the following:

| Status | Rule |
|---|---|
| TESTED | The artefact `file::test` must exist and name the test. The
command must exit 0, **and** some output line must show that test
passing (`ok`/`PASS`). That rejects `true` and a filter that runs 0
tests. |
| PROVEN | The file must name the theorem, and the checker command must
exit 0. |
| ASSUMED / DESIGNED / OPEN | The command must be `-`. The artefact must
be an existing file or `#N`. |
| any | A wrapped row, an unknown status, or a missing table fails and
names the line. |

**Dashboard counts.** On README / EXPLAINME / TOPOLOGY / READINESS, a
number followed within two words by *test(s)* must equal `cargo test
--workspace --locked -- --list` (lines ending `: test`). A number
followed by *proof(s)/theorem(s)* must equal the number of PROVEN rows.
Percentages are excluded, and so are numbers in another table cell.

**Ledger contents:** 7 TESTED rows (obliteration ×3, execute∘undo,
content-store round-trip, rollback, audit-chain verify) and 2 OPEN rows
(#145). **0 PROVEN**, because the Idris2 ABI does not typecheck.

## Doc corrections the checker forced
| Where | Was | Now |
|---|---|---|
| READINESS:11, :67; TOPOLOGY:82 | 67 tests | 119 tests |
| READINESS:11, :63, :67; TOPOLOGY:80 | 30 (Idris2) proofs, row 16 ✓ | 0
checked (#145), row 16 ✗ |

TOPOLOGY "Last updated" → 2026-10-02.

## Scope limits (stated, not implied)
- **Only test/proof counts are reconciled here.** The OVERALL percentage
is reconciled against STATE as before, but the per-component `N%`
figures on TOPOLOGY are **not** checked.
- **The 119 tests are workspace-wide and include dashboard-check's own
31.** Adding a test anywhere now requires updating the dashboard count
in the same PR. That is the intended ratchet.
- **PROVEN is exercised only by unit tests (fake runner), not by a real
row**, because the repo has none. ASSUMED/DESIGNED have no rows either.
- **Escape-hatch counting** (Axiom/Admitted/sorry/believe_me/postulate)
is PR C, not this one.

## Verification (local, rust 1.97.1)
- `cargo fmt --all -- --check` ✓; `cargo clippy --workspace
--all-targets --locked -- -D warnings` ✓; `cargo test --workspace
--locked`: 119 passed, 0 failed.
- `cargo run -p dashboard-check -- --check .` → rc=0: `✓ 119 tests
measured, 0 PROVEN claims`, all 7 TESTED rows ran and passed.
- **Positive control 1:** on the old docs the checker printed 6
divergences (67 vs 118, 30 vs 0 ×3, plus READINESS:11) with rc=1.
- **Positive control 2:** adding one unit test made it report `claims
118 but there are 119` on three lines with rc=1. It was green again
after the update.
- **Fixtures** (in `claims.rs`): `lying_verifier_fails` (exit 0, no
output), `unchecked_skip_fails` (`running 0 tests`),
`inflated_counts_fail_and_true_counts_pass`, `wrapped_row_is_rejected`,
`proven_row_needs_theorem_and_passing_checker`,
`open_rows_run_nothing_and_need_a_real_artefact`.
- **CI:** dashboard-check run 37010504568 passed in **39 s** (13:03:41Z
to 13:04:20Z), well under the job's 15 min timeout. Its log shows all 7
`✓ Tested` rows, both `✓ Open` rows and `✓ 119 tests measured, 0 PROVEN
claims`.


## Red checks: inherited from #144 (e6fee67), deferred, not introduced
here
The red set on this head equals #144's, which equals main 539e6f9's. The
ledger commit adds none.
- `lint-workflows`: deferred to #135 (acceptance item 5)
- `governance / Workflow security linter`: deferred to #135 (acceptance
item 5)
- `governance / Allowlist Preflight`: deferred to #135 (acceptance item
6, `Check live Actions policy`)
- `Validate DEED manifests`: deferred to #135 (acceptance item 6)
- `estate-audit`: deferred to #135 (acceptance item 6, `Code Hygiene
Gate`)
- `idris-abi (expected red until J1-3)`: expected red by design (#142)
until #145 (ULTRAPLAN J1-3) makes Types.idr typecheck.

**CodeRabbit** posted the status "Review rate limited" on 6f31e89 and
has not reviewed this PR yet. Its review will be read before this PR is
marked ready.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant