feat BREAKING auth feat/kn-auth-lane-d-b #1 / 1
aaronrene · 10 days ago · Aug 24, 2026 · Diff

feat(auth): KN-AUTH-LANE-D-b machine-lane operability (BV pass)

Implement KN-AUTH-LANE-D-FREEZE: health list fields, recordCredentialFailure, store meta isolation (D1–D11), Netlify blob-only, 503 AGENT_CREDENTIAL_STORE_* codes, Hub agent-cred-store-banner, docs/OpenAPI. Freeze + BV r1 pass. Seven-tier 36/36. No live revoke. No Scooling edits.

sha256:b8c418d87e4140b4003b80da384f18b824e9960c084c50b6e0e6fd6174a281d7 sha
+83 ~73 −9 symbols
sha256:646592c05427b065a5769fc47feeb7bbaabda73402dfe9afce153f02713aa932 snapshot
+83
symbols added
~73
symbols modified
−9
symbols removed
0
dead code introduced
Semantic Changes 165 symbols
~ docs/KN-AUTH-LANE-D-FREEZE.md .md 46 symbols added
+ KN-AUTH-LANE-D — machine-lane operability (health + isolation) section KN-AUTH-LANE-D — machine-lane operability (health + isolation) L12–506
+ Plain-language summary section 1. Plain-language summary L133–143
+ Technical summary section Technical summary L137–143
+ Tier-3 gates (do not execute in Auto) section 10. Tier-3 gates (do not execute in Auto) L483–494
+ Definition of Done (Phase D Auto) — after this freeze passes review section 11. Definition of Done (Phase D Auto) — after this freeze passes review L494–506
+ Ground truth — what the code does today (file+line) section 2. Ground truth — what the code does today (file+line) L143–174
+ table section table L147–169
+ Incident diagnosis — why operability failed section 3. Incident diagnosis — why operability failed L174–206
+ 1 Error classes (do not collapse) class section 3.1 Error classes (do not collapse) L176–194
+ table section table L178–185
+ 2 What Phase C already got right (do not reopen) section 3.2 What Phase C already got right (do not reopen) L194–206
+ Frozen product goal section 4. Frozen product goal L206–220
+ Interfaces (frozen) section 5. Interfaces (frozen) L220–418
+ 1 Health fields (list + UI) section 5.1 Health fields (list + UI) L222–244
+ table section table L226–235
+ 2 When to persist a failure section 5.2 When to persist a failure L244–278
+ table@L256 section table@L256 L256–263
+ table@L266 section table@L266 L266–275
+ 3 List envelope (banner signal) section 5.3 List envelope (banner signal) L278–311
+ code[json] variable variable code[json] L282–291
+ table section table L294–302
+ 4 Hub UI section 5.4 Hub UI L311–330
+ 5 Store isolation (hard) section 5.5 Store isolation (hard) L330–378
+ code[json] variable variable code[json] L364–373
+ table section table L332–336
+ 6 Exchange and session 503 (robots) section 5.6 Exchange and session 503 (robots) L378–394
+ table section table L382–389
+ 7 One automation path (docs + UI) section 5.7 One automation path (docs + UI) L394–418
+ table@L398 section table@L398 L398–402
+ table@L407 section table@L407 L407–413
+ Explicit non-goals (out) section 6. Explicit non-goals (out) L418–435
+ Fail-closed rules (checklist) section 7. Fail-closed rules (checklist) L435–452
+ Implementation map (Auto; no redesign) section 8. Implementation map (Auto; no redesign) L452–467
+ table section table L454–464
+ Test matrix (seven-tier — Aaron standard) section 9. Test matrix (seven-tier — Aaron standard) L467–483
+ table section table L471–480
+ Citation discipline section Citation discipline L124–133
+ Review record section Review record L90–124
+ Round 1 findings (cited — file+line) section Round 1 findings (cited — file+line) L100–110
+ table section table L102–109
+ Round 2 findings (cited — file+line) section Round 2 findings (cited — file+line) L110–118
+ table section table L112–117
+ Round 3 findings (cited — file+line) section Round 3 findings (cited — file+line) L118–124
+ table section table L120–123
+ table section table L92–99
+ code[yaml] variable variable code[yaml] L16–87
+ Build verification — KN-AUTH-LANE-D-b round 1 section Build verification — KN-AUTH-LANE-D-b round 1 L13–41
+ Checklist section Checklist L29–41
+ table section table L31–41
+ Evidence section Evidence L23–29
+ table section table L25–28
+ Findings section Findings L19–23
~ docs/HUB-API.md .md 2 symbols added, 3 symbols modified
+ 1 Machine vs browser error codes (503 vs 401) section 1.1.1 Machine vs browser error codes (503 vs 401) L15–31
+ table section table L19–26
~ docs/OVERSEER-HANDOVER.md .md 9 symbols added, 4 symbols removed, 13 symbols modified
PRODUCT RELAY — Operator F20 HELPER-SMOKE re-smoke after F32b (PRIMARY lives on the Scooling board) section PRODUCT RELAY — Operator F20 HELPER-SMOKE re-smoke after F32b (PRIMARY lives on the Scooling board) L21–105
Paste-ready prompt — Operator F20 after F32b (Scooling) section Paste-ready prompt — Operator F20 after F32b (Scooling) L40–51
code[text] variable variable code[text] L42–50
THE ONE NEXT STEP — Model: Operator + Auto (Scooling) section THE ONE NEXT STEP — Model: Operator + Auto (Scooling) L36–40
+ NEXT SESSION — SD-21 land KN-AUTH-LANE-D-b (Knowtation PRIMARY) section NEXT SESSION — SD-21 land KN-AUTH-LANE-D-b (Knowtation PRIMARY) L21–64
+ Paste-ready prompt — F28a (Scooling sibling — paste in a Scooling chat) section Paste-ready prompt — F28a (Scooling sibling — paste in a Scooling chat) L48–64
+ code[text] variable variable code[text] L50–60
+ Paste-ready prompt — SD-21 land (when operator says land) section Paste-ready prompt — SD-21 land (when operator says land) L38–48
+ code[text] variable variable code[text] L40–47
+ THE ONE NEXT STEP — Model: Operator (Knowtation) section THE ONE NEXT STEP — Model: Operator (Knowtation) L30–34
+ This session — KN-AUTH-LANE-D-b Auto DONE (2026-08-24) section This session — KN-AUTH-LANE-D-b Auto DONE (2026-08-24) L34–38
+ PRODUCT RELAY — F28 AUTH-LANE-HONESTY (PRIMARY lives on the Scooling board) section PRODUCT RELAY — F28 AUTH-LANE-HONESTY (PRIMARY lives on the Scooling board) L64–133
+ THE ONE NEXT STEP — product order — Model: Thinking (Scooling F28a) section THE ONE NEXT STEP — product order — Model: Thinking (Scooling F28a) L75–79
~ docs/ROADMAP.md .md 2 symbols added, 2 symbols removed, 3 symbols modified
Current status (2026-08-20) section Current status (2026-08-20) L25–36
table section table L27–35
+ Current status (2026-08-24) section Current status (2026-08-24) L25–36
+ table section table L27–35
~ table
~ hub/gateway/agent-credential-routes.mjs .mjs 1 symbol added, 1 symbol modified
+ respondStoreError function function respondStoreError L70–83
~ hub/gateway/agent-credential-store.mjs .mjs 13 symbols added, 2 symbols removed, 3 symbols modified
getBlobStore function function getBlobStore L34–36
normalizeRecords function function normalizeRecords L38–50
+ assertNotInconsistent function function assertNotInconsistent L165–170
+ emptyEnvelope function function emptyEnvelope L46–54
+ inconsistentError function function inconsistentError L63–67
+ isNetlify function function isNetlify L32–34
+ metaFilePath function function metaFilePath L41–44
+ normalizeCredentialRecords function function normalizeCredentialRecords L87–96
+ normalizeEnvelope function function normalizeEnvelope L101–114
+ normalizeMeta function function normalizeMeta L119–127
+ readEnvelope function async_function readEnvelope L172–202
+ readMeta function async_function readMeta L129–145
+ resolveStorageBackend function function resolveStorageBackend L72–85
+ wrapStoreError function function wrapStoreError L56–61
+ writeMeta function async_function writeMeta L147–163
~ load
~ save
~ hub/lib/agent-credential-core.mjs .mjs 1 symbol added, 3 symbols modified
+ recordCredentialFailure function function recordCredentialFailure L255–264
~ web/hub/hub.js .js 1 symbol added, 1 symbol modified
+ syncAgentCredStoreBanner function function syncAgentCredStoreBanner L5817–5823
← Older Oldest on feat/kn-auth-lane-d-b
All commits
Newer → Latest on feat/kn-auth-lane-d-b

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:b8c418d87e4140b4003b80da384f18b824e9960c084c50b6e0e6fd6174a281d7 --body "your comment"