docs(security): placeholder key ids so required gitleaks passes - #142
Merged
Merged
Conversation
gitleaks generic-api-key matched the sample UUIDs under "key_id" and "new_key_id" in KEY_LIFECYCLE.adoc (lines 487-488), turning the required "scan / gitleaks" check red on main and every PR. They were example values, not secrets; replace them with obvious low-entropy placeholders. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4
Contributor
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Oct 2, 2026
hyperpolymath
added a commit
that referenced
this pull request
Oct 2, 2026
#144) ## Why Two Rust jobs are red on `main` (539e6f9). The claims ledger (ULTRAPLAN P1-0) needs a `cargo test` that CI actually runs, so these are fixed first. | Check on main | First failing cause (from the job log) | |---|---| | Rust Build + Unit Tests | `error: invalid value 'v1' for '[TOOLCHAIN]...': invalid toolchain name: 'v1'` (`e2e.yml:24`) | | rust-ci / Cargo check + clippy + fmt | `cargo fmt --check` diff in `attestation.rs`, `keys_cli.rs`. Behind it, a stack of clippy `-D warnings` errors, each target masking the next | ## What - **`e2e.yml`**: - `toolchain: stable` with the clippy and rustfmt components. - Removed `|| true` from the Clippy and Format steps, which previously could not fail. - Clippy now runs with `--all-targets`, matching rust-ci. - **`cargo fmt`**. - **All `clippy --all-targets -D warnings` lints cleared**: - rand 0.9 `thread_rng` → `rng`. - Needless `mut`, borrows, parentheses and `format!`. - `&PathBuf` → `&Path` (20 sites). - Removed the dead `KeyManager.root_path` field and a dead store in the bench. - **`jk-keys` now imports `attestation`/`keys` from the lib.** It used to compile them as private modules via `mod`. That made the lib's public methods read as dead code, and it ran 10 unit tests twice. ## Evidence (local, Rust 1.97.1) - `cargo fmt --all --check` → clean - `cargo clippy --locked --workspace --all-targets -- -D warnings` → rc 0 - `cargo test --locked --workspace` → **107 passed, 0 failed** - `--list` diff against `main`: - Before: 117 entries. After: 107. - The 10 removed entries are exactly the `src/keys_cli.rs` copies of `attestation::tests::*` (6) and `keys::tests::*` (4). - Each was checked to still run under `src/lib.rs`, so no test was lost. - `cargo bench --no-run` → builds. ## Not in this PR `e2e.yml:98` runs `python3` (banned estate-wide), behind `|| true`. It is recorded in `dev-notes/inbox/findings.md`, not changed here. ## Second push (e6fee67) - **`e2e.yml`**: the Criterion, E2E Lifecycle and Panic Attack jobs called `dtolnay/rust-toolchain@v1` with no `toolchain` input. That step failed with "'toolchain' is a required input", so these jobs now pass `toolchain: stable`. - **`tests/aspect/cross_cutting_test.sh`**: - The repo moved SECURITY, ARCHITECTURE, PROOF-NEEDS and TOPOLOGY to `.adoc`, but the checks still looked for `.md`, so 4 of 29 failed. - Each check now accepts either extension, as the README check already did. Result: **29/29**. - Negative control: with `TOPOLOGY.adoc` removed, the check fails (28/29). - **`attestation.rs`**: the HMAC key error is now propagated with `map_err(std::io::Error::other)?` instead of `expect()`. Hypatia flagged it as `expect_in_hot_path`, and the function already returns `io::Result`. Partly addresses #135 (acceptance items 1 and 2 and `Run aspect tests`) and #133 (clippy/fmt `|| true`). Neither issue is closed. ## Red checks on e6fee67: deferred, not introduced here Every red below also fails on `main` 539e6f9. The only required context is `scan / gitleaks`, which is green. - `governance / Workflow security linter`: deferred to #135 (acceptance item 5) - `lint-workflows`: deferred to #135 (acceptance item 5) - `governance / Allowlist Preflight`: deferred to #135 (acceptance item 6, `Check live Actions policy`) - `Validate DEED manifests`: deferred to #135 (acceptance item 6) - `estate-audit`: deferred to #135 (acceptance item 6, `Code Hygiene Gate`) - `idris-abi (expected red until J1-3)`: expected red by design (#142) until #145 (ULTRAPLAN J1-3) makes Types.idr typecheck. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4 --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath
added a commit
that referenced
this pull request
Oct 2, 2026
…counts (#146) ULTRAPLAN **P1-0, PR B of three** (B: ledger + counts; C: escape-hatch counter; D: `workflow_call`). > **Stacked on #144.** This branch contains #144's commit e6fee67, so review only **6f31e89** and the docs follow-up. It stays a draft until #144 merges; then it is rebased onto main and marked ready. ## What it does `PROOF-NEEDS.adoc` gains a `=== Claims ledger` table. Each row is `claim | status | artefact | command`, with status PROVEN / TESTED / ASSUMED / DESIGNED / OPEN, and each row fits on one line. `dashboard-check --check .` (already run by `dashboard-check.yml`) now does the following: | Status | Rule | |---|---| | TESTED | The artefact `file::test` must exist and name the test. The command must exit 0, **and** some output line must show that test passing (`ok`/`PASS`). That rejects `true` and a filter that runs 0 tests. | | PROVEN | The file must name the theorem, and the checker command must exit 0. | | ASSUMED / DESIGNED / OPEN | The command must be `-`. The artefact must be an existing file or `#N`. | | any | A wrapped row, an unknown status, or a missing table fails and names the line. | **Dashboard counts.** On README / EXPLAINME / TOPOLOGY / READINESS, a number followed within two words by *test(s)* must equal `cargo test --workspace --locked -- --list` (lines ending `: test`). A number followed by *proof(s)/theorem(s)* must equal the number of PROVEN rows. Percentages are excluded, and so are numbers in another table cell. **Ledger contents:** 7 TESTED rows (obliteration ×3, execute∘undo, content-store round-trip, rollback, audit-chain verify) and 2 OPEN rows (#145). **0 PROVEN**, because the Idris2 ABI does not typecheck. ## Doc corrections the checker forced | Where | Was | Now | |---|---|---| | READINESS:11, :67; TOPOLOGY:82 | 67 tests | 119 tests | | READINESS:11, :63, :67; TOPOLOGY:80 | 30 (Idris2) proofs, row 16 ✓ | 0 checked (#145), row 16 ✗ | TOPOLOGY "Last updated" → 2026-10-02. ## Scope limits (stated, not implied) - **Only test/proof counts are reconciled here.** The OVERALL percentage is reconciled against STATE as before, but the per-component `N%` figures on TOPOLOGY are **not** checked. - **The 119 tests are workspace-wide and include dashboard-check's own 31.** Adding a test anywhere now requires updating the dashboard count in the same PR. That is the intended ratchet. - **PROVEN is exercised only by unit tests (fake runner), not by a real row**, because the repo has none. ASSUMED/DESIGNED have no rows either. - **Escape-hatch counting** (Axiom/Admitted/sorry/believe_me/postulate) is PR C, not this one. ## Verification (local, rust 1.97.1) - `cargo fmt --all -- --check` ✓; `cargo clippy --workspace --all-targets --locked -- -D warnings` ✓; `cargo test --workspace --locked`: 119 passed, 0 failed. - `cargo run -p dashboard-check -- --check .` → rc=0: `✓ 119 tests measured, 0 PROVEN claims`, all 7 TESTED rows ran and passed. - **Positive control 1:** on the old docs the checker printed 6 divergences (67 vs 118, 30 vs 0 ×3, plus READINESS:11) with rc=1. - **Positive control 2:** adding one unit test made it report `claims 118 but there are 119` on three lines with rc=1. It was green again after the update. - **Fixtures** (in `claims.rs`): `lying_verifier_fails` (exit 0, no output), `unchecked_skip_fails` (`running 0 tests`), `inflated_counts_fail_and_true_counts_pass`, `wrapped_row_is_rejected`, `proven_row_needs_theorem_and_passing_checker`, `open_rows_run_nothing_and_need_a_real_artefact`. - **CI:** dashboard-check run 37010504568 passed in **39 s** (13:03:41Z to 13:04:20Z), well under the job's 15 min timeout. Its log shows all 7 `✓ Tested` rows, both `✓ Open` rows and `✓ 119 tests measured, 0 PROVEN claims`. ## Red checks: inherited from #144 (e6fee67), deferred, not introduced here The red set on this head equals #144's, which equals main 539e6f9's. The ledger commit adds none. - `lint-workflows`: deferred to #135 (acceptance item 5) - `governance / Workflow security linter`: deferred to #135 (acceptance item 5) - `governance / Allowlist Preflight`: deferred to #135 (acceptance item 6, `Check live Actions policy`) - `Validate DEED manifests`: deferred to #135 (acceptance item 6) - `estate-audit`: deferred to #135 (acceptance item 6, `Code Hygiene Gate`) - `idris-abi (expected red until J1-3)`: expected red by design (#142) until #145 (ULTRAPLAN J1-3) makes Types.idr typecheck. **CodeRabbit** posted the status "Review rate limited" on 6f31e89 and has not reviewed this PR yet. Its review will be read before this PR is marked ready. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4 --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Unblocks the required
scan / gitleakscheck, which is red onmain(0613e69) and therefore on every open januskey PR, including ULTRAPLAN P0-1 (#141) and P0-2 (#140).Cause
The estate secret scanner mirrors
.adocfiles, which default gitleaks never scans. Itsgeneric-api-keyrule matched two example UUIDs in a JSON sample indocs/security/KEY_LIFECYCLE.adoc:"key_id": "123e4567-e89b-12d3-a456-426614174000""new_key_id": "789e0123-e89b-12d3-a456-426614174000"These are documentation placeholders, not secrets.
Change
Both values are replaced with obvious low-entropy placeholders (
00000000-0000-4000-8000-000000000001and…0002). One file, 2 lines changed.Evidence
Run locally with gitleaks and the estate baseline
standards:config/gitleaks/estate-baseline.toml(origin/main):leaks found: 2, generic-api-key at lines 487 and 488, the same two lines CI reportsno leaks found.adocfiles in the repo, mirroredno leaks found🤖 Generated with Claude Code
https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4