Skip to content

security(syntonia): authorize protected radio access and record model-safe write receipts #410

Description

@forkwright

Finding

Phase 02 can read protected radio configuration and perform safety-critical
program/write I/O, but its model qualification and serial-path issues do not
own human caller authority or the durable pre-effect receipt. A valid model
mapping and installation identity do not authorize an operator action.

Done when

  • Caller-initiated detect/open/handshake, protected read/export, and
    program/write consume the accepted security(runtime): authorize direct effects through one validated caller context #409 ValidatedCaller context and
    recheck distinct discovery/read/write capability plus Syntonia model scope
    immediately before access or serial I/O.
  • Non-human Syntonia collector detect/open/handshake/read carries typed
    authority from an accepted configuration/system workflow plus policy epoch;
    Syntonia immediately rechecks model-qualified discovery/read capability.
    Missing, unknown, stale, expired, revoked, or out-of-scope workflow authority
    yields zero serial I/O or inventory and a minimized denial receipt rather
    than an invented human or generic system principal.
  • Missing, unknown, untrusted, stale, expired, revoked, wrong-persona, or
    insufficient human authority yields no protected inventory/configuration,
    zero open/handshake/serial I/O, and a minimized denial receipt.
  • Each accepted protected detect/read/export produces a bounded,
    coalescible minimized receipt with canonical caller or owning workflow,
    model/artifact class, action, policy epoch, outcome, and allowed digest but
    no port/path, frequency, channel content, location, or configuration value.
  • Before program/write, a durable minimized intent binds installation and
    caller references to model/canonical-device references, image/configuration
    digest, and policy/schema epoch. Raw port/path, frequency, channel content,
    key, and secret data never enter the log.
  • Success, partial, recovery, and failure outcomes are appended; injected
    audit failure prevents a new write and partial I/O/restart proves a bounded
    model-safe recovery state.
  • Deterministic fake serial backends cover the complete contract before any
    separately operator-scheduled device qualification.

Boundary

#409 owns only the shared caller type/resolver/receipt shape. #79 and #80 own
model/protocol qualification, #195 owns canonical port validation, #400 owns
the application collector lifecycle but not Syntonia read authority, and #407
owns offline connection orchestration. This issue owns Syntonia adoption of
human/workflow authority and radio read/export/program receipts. It authorizes
no hardware use.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions