docs(auth): document runtime projection operations

This commit is contained in:
User
2026-08-22 01:51:26 +02:00
parent 3d9a9f0675
commit ef7ae7053c
10 changed files with 415 additions and 1 deletions
+47
View File
@@ -157,4 +157,51 @@ if rg -n -i --pcre2 '(?:unmapped|additional|extra)[^.\r\n]{0,160}groups?[^.\r\n]
exit 1
fi
# Projected server authentication documentation contract.
projection_docs=(
"$root/docs/install/server.md"
"$root/docs/install/authentication-local.md"
"$root/docs/testing/authentication-manual-acceptance.md"
"$root/docs/testing/psd-server-project-a-manual.md"
"$root/docs/plans/2026-08-20-psd-server-project-a-standalone.md"
"$root/PROJECT_STATE.md"
)
projection_corpus=$(mktemp)
trap 'rm -f "$corpus" "$projection_corpus"' EXIT
cat "${projection_docs[@]}" >"$projection_corpus"
projection_required=(
"canonical authentication root" "runtime projection" "CURRENT" "generations"
"root:root 0700/0600" "10001:10001 0700/0600"
"THT_AUTH_RUNTIME_ROOT"
"auth status --json" "auth publish"
"candidate or recovery" "Mac, Windows, and local direct-file authentication"
"explicit authorization"
)
for term in "${projection_required[@]}"; do
rg -Fqi "$term" "$projection_corpus" || {
echo "auth docs smoke: missing runtime-projection term: $term" >&2
exit 1
}
done
if rg -n -i --pcre2 "(?:useradd|groupadd)[^\n]{0,100}10001|10001[^\n]{0,100}(?:useradd|groupadd)" "$projection_corpus"; then
echo "auth docs smoke: runtime projection creates a host 10001 identity" >&2
exit 1
fi
if rg -n -i --pcre2 '(?:^|[.!?]\s+)(?:(?:mount|bind)\s+(?:the\s+)?(?:canonical authentication root|auth-canonical)\b[^\n]{0,120}(?:core|/run/thothii-auth)|(?:core|the core service)\s+(?:mounts?|binds?)\s+(?:the\s+)?(?:canonical authentication root|auth-canonical)\b)|auth-canonical[^\n]{0,120}:/run/thothii-auth' "$projection_corpus"; then
echo "auth docs smoke: canonical authentication is mounted into core" >&2
exit 1
fi
if rg -n -i --pcre2 '(?:(?:operators?\s+)?(?:may|can|should|must)\s+(?!not\b|never\b)(?:edit|write|modify|prune)|^\s*(?:sudo\s+)?(?:vi|vim|nano|sed|cp|mv|rm|tee|printf|echo)\b)[^\n]*(?:CURRENT|generations)' "$projection_corpus"; then
echo "auth docs smoke: runtime projection permits direct selector or generation edits" >&2
exit 1
fi
if rg -n -i --pcre2 '(?:^\s*(?:sudo\s+nginx\s+-T|(?:sudo\s+)?(?:printenv|env)(?:\s|$)|(?:sudo\s+)?(?:diff|cat|less|more|head|tail|yq)\s+[^\n]*(?:secret|auth\.yaml|users\.yaml))|(?:may|can|should|must)\s+(?!not\b|never\b)(?:dump|print|capture|attach|include|run)\b[^\n]*(?:password|auth\.yaml|users\.yaml|YAML|raw environment|nginx\s+-T|secret-bearing diff))' "$projection_corpus"; then
echo "auth docs smoke: runtime projection documents unsafe evidence collection" >&2
exit 1
fi
if rg -n -i --pcre2 'Project A (?:has been|was|is) started|legacy[- ]stack (?:has been|was|is) changed' "$projection_corpus"; then
echo "auth docs smoke: runtime projection claims live Project A or legacy mutation" >&2
exit 1
fi
echo "auth docs smoke: required terms and forbidden wording checks passed"