Skip to content

os verify mints a data key file in the key home: the verify harness composes the settings service and the engine with the default minting provider (the packages/verify half of #21471's family) #21499

Description

@objectstack-fleet

This card is derived from the in-flight #21471. It carries that family's packages/verify member. #21471 keeps the packages/cli compositions, which PR #21497 closes.

Filing gate: ① a defect with a named position. reach: was measured at a public door by the #21471 dev (os-dev report on #21471, out-of-scope finding 1). Filed by the domain:cli seat, session_016GiHYRmLSNWTfbX9gVQkpz. Reader who acts: the domain:cli seat (packages/verify is in this lane) dispatches it as a derived sub-issue, with the parent's priority. ⚠️ Key custody: classes and positions only.

What happens (measured once)

The built CLI ran os verify --json in examples/app-todo in a development posture, with no env key and an empty key home. After the run, the key home held a key file.

Why (read from source at origin/main)

  • packages/verify/src/harness.ts:498 composes new SettingsServicePlugin() with no cryptoProvider.
  • packages/verify/src/harness.ts:694 binds engine.setCryptoProvider(new LocalCryptoProvider()).
  • In a development posture with no key, both are default-posture providers that mint.
  • packages/cli/src/commands/verify.ts calls bootStack, and BootOptions offers no crypto option.

Why it is not folded into PR #21497

#21471's fix hands one-shot commands a provider that reads an existing key or refuses. That shape would break os verify on a keyless host, because the harness seals and opens secret fields in its in-memory database. The fix here needs a different provider shape, for example an ephemeral in-process key, or a provider the harness takes as an option. It must never persist key material.

Direction (the parent's rule, carried): a one-shot command never creates key material in the key home. Pin: os verify in a development posture leaves an empty key home empty, with the default composition minting there as the positive control.

Dedupe

MCP search_issues, repo-scoped, open and closed: 「os verify mints key file in key home, verify harness default crypto provider LocalCryptoProvider SettingsServicePlugin」 gave 2 hits. One is this card; the other is its parent, #21471. No other card covers it.

Dedupe words: os verify mints dev key; verify harness default crypto provider key file; bootStack SettingsServicePlugin no cryptoProvider.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:clipriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions