feat(cubesys): Task 6 (B) — require HELLO identity, gate seal/open
Adopted recommendation (B): make owner authority a hard guarantee instead of the non-breaking opt-in. A mutating op now requires a stamped HELLO identity; anonymous writes are rejected. seal/open (destructive writes) are gated the same way, and seal stamps the owner onto the encrypted record. Design / non-breaking bridge: - Session gains enforce_owner: bool (default false) so library/REPL/unit tests stay permissive — the 26 prior tests + 3 Task-6 tests are unchanged. - owner_violation() gains require_identity: the (false) path keeps legacy behaviour; the (true) path rejects no-identity mutating ops. - The daemon flips enforce_owner=true on every connection (both HELLO and no-HELLO branches), implementing the default --require-identity policy. - Added --allow-anonymous escape hatch so legacy cubec/stress.sh (which send no HELLO) keep working; stress.sh now passes --allow-anonymous. - Session::set_enforce_owner() accessor so the daemon (separate bin) can set the private field. Verification: - ./check quick: EXIT=0, fmt+clippy clean, 28 cubesys lib tests (added enforce_owner_requires_identity, seal_open_respect_owner). - Ad-hoc daemon verifier (LE framing) against the rebuilt cube-server: anonymous prog/del rejected, HELLO'd owner first-claim + self-overwrite allowed, cross-owner overwrite rejected. ALL PASS. Note: seal's demo key-cell crypto path (KeyCellMissing on the synthetic key material) is a pre-existing quirk unrelated to this change; the gate fires before crypto, so the test verifies the gate, not the crypto.
This commit is contained in:
+4
-1
@@ -32,7 +32,10 @@ STORE="$TMPD/store.json"
|
||||
trap 'kill $DPID 2>/dev/null; wait $DPID 2>/dev/null; rm -rf "$TMPD"' EXIT
|
||||
|
||||
echo "starting stress daemon on $SOCK ..."
|
||||
"$SRV" --socket "$SOCK" --store "$STORE" >"$TMPD/daemon.log" 2>&1 &
|
||||
# Legacy clients (cubec in this script) send no HELLO, so run the daemon in
|
||||
# anonymous-allowed mode; owner enforcement is exercised by the unit/ad-hoc
|
||||
# verifiers, not the stress harness.
|
||||
"$SRV" --socket "$SOCK" --store "$STORE" --allow-anonymous >"$TMPD/daemon.log" 2>&1 &
|
||||
DPID=$!
|
||||
# wait for socket (max ~15s)
|
||||
for i in $(seq 1 15); do [ -S "$SOCK" ] && break; sleep 1; done
|
||||
|
||||
Reference in New Issue
Block a user