Skip to content

feat(silo): incubate the secret-silo design (ALARP handle/vault) - #50

Merged
hyperpolymath merged 1 commit into
mainfrom
feat/silo
Jul 15, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
feat/silo

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Adds silo/ — the practical counterpart to
epistemic-types/docs/secret-types.adoc. An ALARP consequence-reducer for the non-expert, low-effort user who leaks secrets in plaintext and never rotates.

Design: every secret becomes a uniform SILO-<uuid>-<hmac> handle that contains no secret material (tokenisation) — a leaked handle is inert. The uniformity denies an attacker the value-triage that distinctive prefixes (AKIA/ghp_/sk_live_) hand them; a single Gitleaks rule on the envelope shape keeps leak detection while withholding value disclosure. RMO becomes crypto-shred-by-handle (destroy the 32-byte vault key), which is sound on SSDs where 3-pass overwrite is not — closing valence-shell's open obliterate_overwrites_all_blocks by changing the mechanism.

  • MOTIVATION.adoc — ALARP framing; problems→basis table; explicit non-goals.
  • docs/DESIGN.adoc — handle format, vault per platform, HMAC envelope, Echo-graded partial release, threat model, idea→alpha build order.

Includes the load-bearing correctness note: a public permute+checksum is obfuscation; indistinguishability requires a key (FPE) or, better, no secret in the envelope at all (handle).

🤖 Generated with Claude Code

Summary

Changes

RSR Quality Checklist

Required

  • Tests pass (just test or equivalent)
  • Code is formatted (just fmt or equivalent)
  • Linter is clean (no new warnings or errors)
  • No banned language patterns (no TypeScript, no npm/bun, no Go/Python)
  • No unsafe blocks without // SAFETY: comments
  • No banned functions (believe_me, unsafeCoerce, Obj.magic, Admitted, sorry)
  • SPDX license headers present on all new/modified source files
  • No secrets, credentials, or .env files included

As Applicable

  • .machine_readable/STATE.a2ml updated (if project state changed)
  • .machine_readable/ECOSYSTEM.a2ml updated (if integrations changed)
  • .machine_readable/META.a2ml updated (if architectural decisions changed)
  • Documentation updated for user-facing changes
  • TOPOLOGY.md updated (if architecture changed)
  • CHANGELOG or release notes updated
  • New dependencies reviewed for license compatibility (MPL-2.0 / MPL-2.0)
  • ABI/FFI changes validated (src/interface/abi/ and src/interface/ffi/ consistent)

Testing

Screenshots

Adds `silo/` — the practical counterpart to
epistemic-types/docs/secret-types.adoc. An ALARP consequence-reducer for the
non-expert, low-effort user who leaks secrets in plaintext and never rotates.

Design: every secret becomes a uniform `SILO-<uuid>-<hmac>` handle that
contains *no* secret material (tokenisation) — a leaked handle is inert. The
uniformity denies an attacker the value-triage that distinctive prefixes
(AKIA/ghp_/sk_live_) hand them; a single Gitleaks rule on the envelope shape
keeps leak *detection* while withholding value *disclosure*. RMO becomes
crypto-shred-by-handle (destroy the 32-byte vault key), which is sound on SSDs
where 3-pass overwrite is not — closing valence-shell's open
`obliterate_overwrites_all_blocks` by changing the mechanism.

- MOTIVATION.adoc  — ALARP framing; problems→basis table; explicit non-goals.
- docs/DESIGN.adoc — handle format, vault per platform, HMAC envelope,
  Echo-graded partial release, threat model, idea→alpha build order.

Includes the load-bearing correctness note: a *public* permute+checksum is
obfuscation; indistinguishability requires a key (FPE) or, better, no secret
in the envelope at all (handle).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit 1d4ee4a into main Jul 15, 2026
11 checks passed
@hyperpolymath
hyperpolymath deleted the feat/silo branch July 15, 2026 18:52
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant