Proof-of-concept proving the secure-storage exit criterion from docs/architecture/proof-of-concept-plan.md §2: "Secret write/read/delete works through platform secure storage." Implements a typed SecretStorageRepository trait per ADR-006 (SecureStore + per-platform adapters) and a Linux adapter (the only adapter in PoC scope) that supports both equivalent Linux backends per SysRS-053/SysRS-162: Secret Service (libsecret) and kernel keyutils. The audit test suite covers: SS-AUD-001 identity secret absent from local DB (raw file scan) SS-AUD-002 server password absent from local DB SS-AUD-003 secrets absent from logs (Secret newtype redaction) SS-AUD-005 failure returns safe typed error (NotFound) SS-AUD-006 delete removes entry SS-TC-003 Linux round-trip set/get/delete Verified on 2026-05-13 against the local keyutils backend (cargo test runs need 'keyctl session -' to provide a valid session keyring under non-interactive shells, documented in the spike README). The CLI driver additionally observed a real locked gnome-keyring collection and exercised the typed-error → fallback path live. Surfaced finding for the decision register: DEC-013 does not pin a Linux secure-storage backend policy. Both Secret Service and keyutils are 'equivalent' per the requirements; production code needs an owner ruling. Out of scope: Windows DPAPI, macOS/iOS Keychain, Android Keystore, SS-AUD-004 (covered by diagnostics-redaction spike), SS-AUD-007/008 (process / migration items). Authority: PoC plan §2, ADR-006, SDD-078, SRS-091..095, SysRS-158..162. Not product code; not promoted into chanora_storage.
29 lines
1.5 KiB
Rust
29 lines
1.5 KiB
Rust
//! Chanora PoC — secure storage spike.
|
|
//!
|
|
//! Authority:
|
|
//! * `docs/architecture/proof-of-concept-plan.md` §2 — Secure storage spike.
|
|
//! * `docs/security/secure-storage-audit-report.md` — audit checks
|
|
//! SS-AUD-001..008 and test cases SS-TC-001..005.
|
|
//! * `docs/architecture/sysdes.md` ADR-006 — "SecureStore trait and
|
|
//! per-platform adapters".
|
|
//! * SRS-091..095, SysRS-158..162.
|
|
//!
|
|
//! This crate models the production shape, in miniature:
|
|
//!
|
|
//! ┌─────────────────────────┐ ┌─────────────────────────────────┐
|
|
//! │ LocalDatabaseRepository │ │ SecretStorageRepository (trait) │
|
|
//! │ (rusqlite, non-secret) │ │ ── per-platform adapters ── │
|
|
//! └─────────────────────────┘ └─────────────────────────────────┘
|
|
//! SRS-089 / SDD-077 SRS-092 / SDD-078 / ADR-006
|
|
//!
|
|
//! Scope: Linux adapter only (Secret Service via the `keyring` crate).
|
|
//! Other platforms (Windows DPAPI, macOS/iOS Keychain, Android Keystore)
|
|
//! are out of scope here and live in their own spikes/adapters.
|
|
|
|
pub mod secret;
|
|
pub mod sqlite_repo;
|
|
pub mod test_logger;
|
|
|
|
pub use secret::{SecretStorageRepository, SecureStoreError};
|
|
pub use sqlite_repo::LocalDatabaseRepository;
|