NEC-52: Walk the stale gates in launch-readiness.md #147

Merged
nectenda-agent merged 5 commits from worktree-nec-52-walk-the-stale-gates-in-launch-readinessm into main 2026-09-24 21:59:19 +01:00
Collaborator

Task: NEC-52 — https://projectron.nerchure.com/tasks/52

Walks Gates A, B and C of docs/launch-readiness.md from observation: every ticked row now cites a dated host observation (docs/manual-testing.md) or a named test. Closes the last unchecked suspended writes (display name, device rename) and judges attachment writes against the folder owner's account too, with WIRE-072..074 stating what suspension refuses and what it never does (reads, sign-in, recovery, credentials, device removal; text sync is never blocked by a quota or non-payment). Corrects the load-bearing 'nothing derived from the passphrase' overclaim in security-model.md, identity.md and CRYPTO-025. The walk found two backup defects, filed as NEC-95 (pre-deploy copies pruned by sha) and NEC-96 (identity host shipped no database or signing keys since 15 Sep; mitigated by a hand snapshot held until ~8 Oct), and rehearsed a shard restore up to the real-client step (NEC-97).

Spec: docs/changes/NEC-52-walk-launch-gates/spec.md

Changelog

A suspended organisation can no longer change display names or rename devices, and attachment uploads into a suspended owner's folder are refused; reading, downloading, signing in and removing a device still work.

Task: NEC-52 — https://projectron.nerchure.com/tasks/52 Walks Gates A, B and C of docs/launch-readiness.md from observation: every ticked row now cites a dated host observation (docs/manual-testing.md) or a named test. Closes the last unchecked suspended writes (display name, device rename) and judges attachment writes against the folder owner's account too, with WIRE-072..074 stating what suspension refuses and what it never does (reads, sign-in, recovery, credentials, device removal; text sync is never blocked by a quota or non-payment). Corrects the load-bearing 'nothing derived from the passphrase' overclaim in security-model.md, identity.md and CRYPTO-025. The walk found two backup defects, filed as NEC-95 (pre-deploy copies pruned by sha) and NEC-96 (identity host shipped no database or signing keys since 15 Sep; mitigated by a hand snapshot held until ~8 Oct), and rehearsed a shard restore up to the real-client step (NEC-97). Spec: `docs/changes/NEC-52-walk-launch-gates/spec.md` ## Changelog A suspended organisation can no longer change display names or rename devices, and attachment uploads into a suspended owner's folder are refused; reading, downloading, signing in and removing a device still work.
Suspension already refused uploads and folder writes. PATCH /account/me and
PATCH /account/devices/:id were not checked, and an attachment write was
judged only against the caller's account — so a legacy cross-account member
could keep writing into a suspended owner's folder, which the owner is billed
for.

The routes left open are now open on purpose and pinned both ways: signing
in, recovery, changing credentials and removing a device. Each is how a
suspended customer sees why or secures their account. WIRE-072..074 state the
rule, including that a quota or non-payment never blocks text sync.

Task: NEC-52
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Kcucwhn2QtMGQM8rBSNEbo
Every ticked row now says what it was ticked from: a host observation dated
in docs/manual-testing.md, or a named test. Gate A is closed. B, C and D keep
the rows that nobody has seen work: the sign-in methods in real Obsidian, the
disk alert firing, a real device against a restored shard, and the live
identity service switched off.

The walk found the backups to be the weak point. The identity host had
shipped no identity.db or signing-keys.json since 15 September, because the
restic script took the shard branch once the deployer created data/backups
(NEC-96). A correct snapshot was taken by hand. Pre-deploy copies are deleted
by their own prune as they are made (NEC-95). A shard restore was rehearsed
up to the real-client step, which a hosted vault cannot do as written
(NEC-97).

Also corrected: identity.md claimed a database copy gives an attacker
nothing to guess at, releasing.md claimed CI exercises the JWT refusal,
RESTORE.md ran a floating tag that is stale on a host, and the egress figures
in commercial-model.md predated the repricing.

Task: NEC-52
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Kcucwhn2QtMGQM8rBSNEbo
Say exactly what the passphrase bears on, and what suspension checks
All checks were successful
Release note / release-note (pull_request) Successful in 17s
CI / build (pull_request) Successful in 5m43s
CI / e2e (pull_request) Successful in 6m3s
CI / promote (pull_request) Has been skipped
3bece43b26
Review found that the load-bearing statements of "nothing derived from the
passphrase is sent" were literally false: the wrapped private key is sent
and stored, and is as guessable offline as the vault's own copy. What is
true is narrower, and now stated: no hash or verifier is sent.
security-model.md, identity.md and CRYPTO-025 now say that; the customer-
facing and legal copies are listed on NEC-98.

Also: the suspension row claimed every REST write was judged against the
folder owner, when only attachment writes are. WIRE-073 now says signing in
includes enrolling that device. The share-key writes join the refused table.
The mutation record lives in the spec rather than being asserted without one.

Task: NEC-52
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Kcucwhn2QtMGQM8rBSNEbo
cruelacid force-pushed worktree-nec-52-walk-the-stale-gates-in-launch-readinessm from 3bece43b26
All checks were successful
Release note / release-note (pull_request) Successful in 17s
CI / build (pull_request) Successful in 5m43s
CI / e2e (pull_request) Successful in 6m3s
CI / promote (pull_request) Has been skipped
to 3327570e0a
All checks were successful
Release note / release-note (pull_request) Successful in 12s
CI / e2e (pull_request) Successful in 4m53s
CI / build (pull_request) Successful in 5m9s
CI / promote (pull_request) Has been skipped
2026-09-24 17:00:42 +01:00
Compare
cruelacid force-pushed worktree-nec-52-walk-the-stale-gates-in-launch-readinessm from 3327570e0a
All checks were successful
Release note / release-note (pull_request) Successful in 12s
CI / e2e (pull_request) Successful in 4m53s
CI / build (pull_request) Successful in 5m9s
CI / promote (pull_request) Has been skipped
to 0c1827c95d
All checks were successful
Release note / release-note (pull_request) Successful in 11s
CI / build (pull_request) Successful in 5m23s
CI / e2e (pull_request) Successful in 5m21s
CI / promote (pull_request) Has been skipped
e2e-soak / soak (push) Successful in 20m1s
2026-09-24 21:35:11 +01:00
Compare
cruelacid force-pushed worktree-nec-52-walk-the-stale-gates-in-launch-readinessm from 0c1827c95d
All checks were successful
Release note / release-note (pull_request) Successful in 11s
CI / build (pull_request) Successful in 5m23s
CI / e2e (pull_request) Successful in 5m21s
CI / promote (pull_request) Has been skipped
e2e-soak / soak (push) Successful in 20m1s
to afd2076e32
All checks were successful
Release note / release-note (pull_request) Successful in 10s
CI / build (pull_request) Successful in 5m2s
CI / e2e (pull_request) Successful in 4m2s
CI / promote (pull_request) Has been skipped
Deploy site / deploy (push) Successful in 49s
CI / e2e (push) Successful in 4m6s
CI / build (push) Successful in 4m59s
CI / promote (push) Successful in 29s
2026-09-24 21:45:16 +01:00
Compare
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Nectenda/nectenda!147
No description provided.