Something went wrong. Try again.
Identities for entities did.bot
agent llm did
Something went wrong. Try again.
id: alpha-exit title: What an alpha deployment on the public internet must refuse or survive status: open crates: [didbot-serve, didbot-pds, didbot-http, didbot-tls, didbot-agentd] dependsOn: [adversarial, infra-review] exitCriterion: > The operator has reviewed this list, every item on it either names the test that proves it or is struck from the list, and no item is left marked none. #
alpha-exit #
A draft, for the operator to review. milestones.md lists security hardening
without saying what has to hold before the server is on the public internet,
and adversarial.md and infra-review.md each cover one part of it. This is
the one list.
The rows are drawn from docs/testing.md's matrix, the
security audit of ef76dfbc, and the issues that audit opened. Each names
what an alpha must refuse or survive and the command that proves it, or
none. A none is a decision for the operator: write the test, or strike
the row because this deployment accepts it.
What it must refuse #
| What | What proves it |
|---|---|
| A write while the stop stands, including after a restart | cargo test -p didbot-pds --test estop_restart |
| A credential a Revoke ended, after the latch is released | cargo test -p didbot-serve --test write_gates |
| A proof replayed inside its window, across a restart | cargo test -p didbot-serve --test proof_restart |
| A create no allowance in the operator's repository covers | cargo test -p didbot-serve --test tree |
| A create beneath a root whose operator record has lapsed | cargo test -p didbot --test handshake |
| A handle or a zone that only looks like it sits under this one | cargo test -p didbot --test zone_containment |
| A token writing outside its grant, and a ceiling tightened between writes | cargo test -p didbot-serve --test token_scope |
A client_id this deployment's policy could not match |
cargo test -p didbot-serve --test denied_app |
| An outbound fetch at a private address, on every path that takes a URL somebody else named | none |
| A body over the bound and a blob over the quota | cargo test -p didbot-pds --test blob_storage |
| A flood from one address, against every per-address budget | none |
| An unauthenticated read that costs a blocking-pool thread, past its share | none |
What it must survive #
| What | What proves it |
|---|---|
| A kill at any sync boundary, with every acknowledged write present | cargo test -p didbot-pds --test durability |
| A restore from a directory copied mid-load, with the sequence floor kept | cargo test -p didbot-pds --test restore and cargo test -p didbot-serve --test restore_drill |
| A boot against a data directory an older binary wrote | cargo test -p didbot-pds --test upgrade proves the directory is refused before it is touched; a binary that reads an older layout, none |
| Every boot refusal in the operations table, produced on purpose | cargo test -p didbot-pds --test upgrade for the three stamp refusals and --test second_writer for the lock; cargo test -p didbot-serve --test startup_refusal holds one refusal outside the table, --tls acme under .localhost |
| The operator's repository unreachable, empty, or answering something else | cargo test -p didbot-serve --test policy_poll_restart, for a restart with the repository gone and one record the build cannot honour; unreachable mid-run and empty, none. The grace window covers an outage only while the server runs: one restarted during it boots unclaimed and refuses writes and creates until the repository answers, which this deployment accepts for alpha |
| A certificate swap with the stream still attached | cargo test -p didbot-tls --test rotation, for one TLS connection held across the swap rather than subscribeRepos |
| The signal a deployment sends to stop it | cargo test -p didbot-serve --test graceful_shutdown |
| A sign-in in flight across a restart | none |