This card is derived from the in-flight #21471. It carries that family's packages/verify member. #21471 keeps the packages/cli compositions, which PR #21497 closes.
Filing gate: ① a defect with a named position. reach: was measured at a public door by the #21471 dev (os-dev report on #21471, out-of-scope finding 1). Filed by the domain:cli seat, session_016GiHYRmLSNWTfbX9gVQkpz. Reader who acts: the domain:cli seat (packages/verify is in this lane) dispatches it as a derived sub-issue, with the parent's priority. ⚠️ Key custody: classes and positions only.
What happens (measured once)
The built CLI ran os verify --json in examples/app-todo in a development posture, with no env key and an empty key home. After the run, the key home held a key file.
Why (read from source at origin/main)
packages/verify/src/harness.ts:498 composes new SettingsServicePlugin() with no cryptoProvider.
packages/verify/src/harness.ts:694 binds engine.setCryptoProvider(new LocalCryptoProvider()).
- In a development posture with no key, both are default-posture providers that mint.
packages/cli/src/commands/verify.ts calls bootStack, and BootOptions offers no crypto option.
Why it is not folded into PR #21497
#21471's fix hands one-shot commands a provider that reads an existing key or refuses. That shape would break os verify on a keyless host, because the harness seals and opens secret fields in its in-memory database. The fix here needs a different provider shape, for example an ephemeral in-process key, or a provider the harness takes as an option. It must never persist key material.
Direction (the parent's rule, carried): a one-shot command never creates key material in the key home. Pin: os verify in a development posture leaves an empty key home empty, with the default composition minting there as the positive control.
Dedupe
MCP search_issues, repo-scoped, open and closed: 「os verify mints key file in key home, verify harness default crypto provider LocalCryptoProvider SettingsServicePlugin」 gave 2 hits. One is this card; the other is its parent, #21471. No other card covers it.
Dedupe words: os verify mints dev key; verify harness default crypto provider key file; bootStack SettingsServicePlugin no cryptoProvider.
Generated by Claude Code
This card is derived from the in-flight #21471. It carries that family's
packages/verifymember. #21471 keeps thepackages/clicompositions, which PR #21497 closes.Filing gate: ① a defect with a named position.⚠️ Key custody: classes and positions only.
reach:was measured at a public door by the #21471 dev (os-dev report on #21471, out-of-scope finding 1). Filed by thedomain:cliseat,session_016GiHYRmLSNWTfbX9gVQkpz. Reader who acts: thedomain:cliseat (packages/verifyis in this lane) dispatches it as a derived sub-issue, with the parent's priority.What happens (measured once)
The built CLI ran
os verify --jsoninexamples/app-todoin a development posture, with no env key and an empty key home. After the run, the key home held a key file.Why (read from source at
origin/main)packages/verify/src/harness.ts:498composesnew SettingsServicePlugin()with nocryptoProvider.packages/verify/src/harness.ts:694bindsengine.setCryptoProvider(new LocalCryptoProvider()).packages/cli/src/commands/verify.tscallsbootStack, andBootOptionsoffers no crypto option.Why it is not folded into PR #21497
#21471's fix hands one-shot commands a provider that reads an existing key or refuses. That shape would break
os verifyon a keyless host, because the harness seals and opens secret fields in its in-memory database. The fix here needs a different provider shape, for example an ephemeral in-process key, or a provider the harness takes as an option. It must never persist key material.Direction (the parent's rule, carried): a one-shot command never creates key material in the key home. Pin:
os verifyin a development posture leaves an empty key home empty, with the default composition minting there as the positive control.Dedupe
MCP
search_issues, repo-scoped, open and closed: 「os verify mints key file in key home, verify harness default crypto provider LocalCryptoProvider SettingsServicePlugin」 gave 2 hits. One is this card; the other is its parent, #21471. No other card covers it.Dedupe words: os verify mints dev key; verify harness default crypto provider key file; bootStack SettingsServicePlugin no cryptoProvider.
Generated by Claude Code