fix: harden DWH auth recovery guidance

This commit is contained in:
User
2026-08-21 05:04:37 +02:00
parent f616aab542
commit 7b86ea9ce5
5 changed files with 245 additions and 46 deletions
+34 -2
View File
@@ -34,10 +34,10 @@ for label, relative in docs.items():
text[label] = path.read_text(encoding="utf-8")
requirements = {
"server": ["manifest", "curl_cfg", "journalctl", "systemctl disable --now", "trap", "/var/lib/dwh-auth", "root:dwh-auth", "2750", ".writer.lock", "0640", "/run/dwh-auth/verify.sock", "0660", "systemd", "key create", "key list", "key status", "key revoke", "check", "backup", "rollback", "disinstallazione", "rest_api", "postgres_direct", "ssh_tunnel"],
"server": ["key_output=/root/dwh-auth-provision/psd-mac-primary.key", "legacy_key_id=legacy-shared", "v1_header_file", "legacy_header_file", "random_header_file", "--header \"@", "registry_staging", "registry_previous", "registry_restore_rollback", "journal_actual_key_scan=PASS", "sys.argv[2:]", "read_bytes()", "subprocess.run", "stderr=subprocess.DEVNULL", "returncode != 0", "socket_v1=PASS", "socket_legacy=PASS", "https_v1_post_revoke=PASS", "https_legacy_post_revoke=PASS", "key_file_bytes=PASS", "dd if=\"$1\" bs=65536 status=none", "manifest", "journalctl", "systemctl disable --now", "trap", "/var/lib/dwh-auth", "root:dwh-auth", "2750", ".writer.lock", "0640", "/run/dwh-auth/verify.sock", "0660", "systemd", "key create", "key list", "key status", "key revoke", "check", "backup", "rollback", "disinstallazione", "rest_api", "postgres_direct", "ssh_tunnel"],
"client": ["Workspace management", "Validate workspace source", "Test workspace connections", "Save entered secrets", "Forget stored value", "API_KEY_FILE", "THT_WS_PSD_CLINICAL_DWH_API_KEY_FILE", "TLS_CA_FILE", "/rpc/ping", "rest_api", "postgres_direct", "ssh_tunnel", "401", "503", "rotazione", "revoca"],
"tls": ["self-issued", ".it", ".com", "SAN", "TLS_CA_FILE", "openssl x509 -noout -fingerprint -sha256", "fuori banda", "rinnovo", "curl -k"],
"rollout": ["PASS/FAIL", "no raw diff", "Task 9", "Task 10", "IN_DISCUSSION", "postgres_direct", "rest_api", "legacy-shared", "nginx -t", "204", "401", "503", "Qdrant", "Ollama", "rollback"],
"rollout": ["v1=2xx", "legacy=2xx", "v1=2xx post-revoca", "legacy=401 post-revoca", "file header curl protetti 0600", "PASS/FAIL", "no raw diff", "Task 9", "Task 10", "IN_DISCUSSION", "postgres_direct", "rest_api", "legacy-shared", "nginx -t", "204", "401", "503", "Qdrant", "Ollama", "rollback"],
"manual": ["credenziali reali", "sintetici", "/rpc/ping", "204", "401", "503", "TLS", "registry", "postgres_direct", "ssh_tunnel"],
"evidence": ["ID pubblici", "owner", "mode", "timestamp", "checksum", "approvazione"],
}
@@ -72,6 +72,7 @@ for pattern, label in [
(r"(?i)chmod\s+0?[0-7][0-7][4-7]\s+[^\n]*(?:\.key|secret|provision)", "world-readable secret"),
(r"(?m)^\s*(?:sudo\s+)?nginx\s+-T\b", "raw Nginx capture"),
(r"(?m)^\s*(?:sudo\s+)?(?:diff\b|git\s+diff\b)", "raw diff capture"),
(r"(?m)^\s*(?:sudo\s+)?curl[^\n]*--config\b", "curl config artifact"),
(r"(?i)docker\s+compose[^\n]*\bdwh-auth\b", "Compose coupling"),
]:
if re.search(pattern, corpus):
@@ -87,5 +88,36 @@ if "tht_ws_psd_clinical_dwh_transport=rest_api" not in template.lower() or "mac/
if "TLS_CA_FILE" not in text["psd"] or re.search(r"(?i)nessuna CA|HTTPS pubblico", text["psd"]):
raise SystemExit("dwh-auth docs: PSD setup contradicts private CA TLS requirement")
restore_steps = (
'registry_staging="/var/lib/.dwh-auth-restore-$run_id"',
'registry_candidate="$registry_staging/dwh-auth"',
'sudo tar --acls --xattrs -C "$registry_staging" -xf "$registry_backup"',
'if ! sudo /usr/local/sbin/dwh-auth --registry-root "$registry_candidate" check; then',
'if ! sudo mv -T -- "$registry_root" "$registry_previous"; then',
'if ! sudo mv -T -- "$registry_candidate" "$registry_root"; then',
'if ! sudo mv -T -- "$registry_previous" "$registry_root"; then',
'if ! sudo mv -T -- "$registry_root" "$registry_staging/failed-dwh-auth"; then',
)
restore_positions = [text["server"].find(step) for step in restore_steps]
if any(position < 0 for position in restore_positions) or restore_positions != sorted(restore_positions):
raise SystemExit("dwh-auth docs: restore must stage/check then use guarded same-filesystem renames")
if text["server"].count('if ! sudo mv -T -- "$registry_previous" "$registry_root"; then') != 2:
raise SystemExit("dwh-auth docs: every restore rollback rename must use guarded mv -T --")
if re.search(r"sudo tar[^\n]*-C /var/lib[^\n]*(?:-x|--extract)[^\n]*registry_backup", text["server"]):
raise SystemExit("dwh-auth docs: restore must not overlay the live registry")
journal_steps = (
"subprocess.run(",
"[\"journalctl\", \"-u\", \"dwh-auth\", \"--since\", sys.argv[1]",
"sys.argv[2:]",
"stderr=subprocess.DEVNULL",
"if result.returncode != 0:",
"result.stdout.splitlines(keepends=True)",
"any(key in line for key in actual_keys)",
)
if any(step not in text["server"] for step in journal_steps):
raise SystemExit("dwh-auth docs: journal scan must fail closed and check the actual key bytes")
print("dwh-auth documentation contract passed")
PY