Files
chanora/poc/secure-storage-spike/src/lib.rs
T
EdisonJwa 50c95b61ad feat(poc/storage): add secure-storage spike (Linux)
Proof-of-concept proving the secure-storage exit criterion from
docs/architecture/proof-of-concept-plan.md §2:
  "Secret write/read/delete works through platform secure storage."

Implements a typed SecretStorageRepository trait per ADR-006
(SecureStore + per-platform adapters) and a Linux adapter (the only
adapter in PoC scope) that supports both equivalent Linux backends
per SysRS-053/SysRS-162: Secret Service (libsecret) and kernel
keyutils.

The audit test suite covers:
  SS-AUD-001  identity secret absent from local DB (raw file scan)
  SS-AUD-002  server password absent from local DB
  SS-AUD-003  secrets absent from logs (Secret newtype redaction)
  SS-AUD-005  failure returns safe typed error (NotFound)
  SS-AUD-006  delete removes entry
  SS-TC-003   Linux round-trip set/get/delete

Verified on 2026-05-13 against the local keyutils backend (cargo
test runs need 'keyctl session -' to provide a valid session
keyring under non-interactive shells, documented in the spike
README). The CLI driver additionally observed a real locked
gnome-keyring collection and exercised the typed-error → fallback
path live.

Surfaced finding for the decision register: DEC-013 does not pin
a Linux secure-storage backend policy. Both Secret Service and
keyutils are 'equivalent' per the requirements; production code
needs an owner ruling.

Out of scope: Windows DPAPI, macOS/iOS Keychain, Android Keystore,
SS-AUD-004 (covered by diagnostics-redaction spike), SS-AUD-007/008
(process / migration items).

Authority: PoC plan §2, ADR-006, SDD-078, SRS-091..095,
SysRS-158..162.
Not product code; not promoted into chanora_storage.
2026-05-14 12:26:23 +08:00

29 lines
1.5 KiB
Rust

//! Chanora PoC — secure storage spike.
//!
//! Authority:
//! * `docs/architecture/proof-of-concept-plan.md` §2 — Secure storage spike.
//! * `docs/security/secure-storage-audit-report.md` — audit checks
//! SS-AUD-001..008 and test cases SS-TC-001..005.
//! * `docs/architecture/sysdes.md` ADR-006 — "SecureStore trait and
//! per-platform adapters".
//! * SRS-091..095, SysRS-158..162.
//!
//! This crate models the production shape, in miniature:
//!
//! ┌─────────────────────────┐ ┌─────────────────────────────────┐
//! │ LocalDatabaseRepository │ │ SecretStorageRepository (trait) │
//! │ (rusqlite, non-secret) │ │ ── per-platform adapters ── │
//! └─────────────────────────┘ └─────────────────────────────────┘
//! SRS-089 / SDD-077 SRS-092 / SDD-078 / ADR-006
//!
//! Scope: Linux adapter only (Secret Service via the `keyring` crate).
//! Other platforms (Windows DPAPI, macOS/iOS Keychain, Android Keystore)
//! are out of scope here and live in their own spikes/adapters.
pub mod secret;
pub mod sqlite_repo;
pub mod test_logger;
pub use secret::{SecretStorageRepository, SecureStoreError};
pub use sqlite_repo::LocalDatabaseRepository;