Skip to content

Re-land the README gates from PRs 107 and 114 - #222

Merged
404SecNotFound merged 1 commit into
mainfrom
claude/serene-carson-0739mv-readme-gates
Sep 27, 2026
Merged

404SecNotFound merged 1 commit into
mainfrom
claude/serene-carson-0739mv-readme-gates

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Summary

PR #107 and PR #114 show as merged, but each was merged into a branch that had itself already been merged, so neither reached main. This is the same failure CLAUDE.md records for PR #23. Their commits (de4e8b6, 79c6e1b) are preserved on claude/readme-current. Confirmed on a full (unshallowed) clone that neither is an ancestor of main and that git cherry shows both as absent.

Re-applied by hand against today's README and package.json, not cherry-picked.

Changes

  • npm run test:readme (scripts/readme-scripts-test.mjs, from Document every test script, and fail when one goes undocumented #107). Fails when package.json has a test: script the README does not mention. It now matches on a word boundary, so test:secret-erase is not satisfied by the line for test:secret-erase-core. Runs early in the ci job, after typecheck.
  • "Run it locally" listed 11 of 38 test scripts on main. It now lists all 39 (including test:readme), grouped as core suites, focused suites, release and documentation gates, and the three that need a build (verify-recipe, palette, icons, matching where CI runs them after npm run build). Each one-line description is taken from that script's own header.
  • Audit scope (from Say which parts have been audited, and which have not #114). The Security model section now says what outside review covered. SECURITY-AUDIT.md's scope line is unchanged (the KEYM v1 container, keymaker-crypto.ts, the encryptor UI, the dice tool, the CSP pipeline, CI). The paragraph names the current format as not in that scope, updated to include KEYM v4's padded payload and the audio carrier. It says external review passes exist for parts of it, and that nothing in the repo records one for v4. The Documentation table row no longer calls it the "current Keymaker v2 audit".
  • The gate binds the README disclaimer and SECURITY-AUDIT.md in both directions. Subjects are KEYM v3, KEYM v4, slot_table_mac, Shamir, passkey. KEYM v2 is left out on purpose because the audit names it only under "Remaining work".

Test plan

  • npm run test:readme passes: 39 of 39 documented, audit scope matches.
  • Negative controls, each confirmed applied before reading the result:
    • test:shamir line removed from README → fails, names test:shamir.
    • test:secret-erase line removed, test:secret-erase-core kept → fails, names test:secret-erase. The old includes() check wrongly passes this case.
    • Disclaimer paragraph removed → fails.
    • Addendum naming passkey slots and KEYM v4 appended to SECURITY-AUDIT.md → fails, names both.
  • npm run typecheck, test:release-gate, test:release-recipe, test:release-notes, test:reproduced-manifest pass; ci.yml parses.
  • All 27 newly documented scripts were run locally and exit 0.
  • Full CI run.

Generated by Claude Code

Both PRs show as merged, but each was merged into a branch that had already
been merged, so neither reached main (de4e8b6 and 79c6e1b, preserved on
claude/readme-current). Re-applied by hand against today's README and
package.json rather than cherry-picked.

From 107: npm run test:readme fails when package.json has a test: script the
README does not mention. On main the "Run it locally" block named eleven of
thirty-eight. It now names all thirty-nine, grouped as core suites, focused
suites, release and documentation gates, and the three that need a build. The
check is one-directional on purpose, and now matches on a word boundary, so
test:secret-erase is not satisfied by the line for test:secret-erase-core.
Runs early in the ci job.

From 114: the Security model section says what outside review covered.
SECURITY-AUDIT.md's scope line is unchanged (the KEYM v1 container, the core,
the encryptor UI, the dice tool, the CSP pipeline, CI), so the format the app
writes today, now including v4's padded payload and the audio carrier, is
stated as not in that scope. The documentation table row no longer calls it
the current v2 audit. The gate binds the two files in both directions, and its
subjects gain "KEYM v4". "KEYM v2" stays out of the list because the audit
names it only under Remaining work.

Negative controls, each confirmed applied before its result was read:
- test:shamir line removed from README: fails, names test:shamir.
- test:secret-erase line removed, test:secret-erase-core kept: fails, names
  test:secret-erase. The old includes() check passes this case.
- the disclaimer paragraph removed: fails, says silence reads as audited.
- an addendum naming passkey slots and KEYM v4 appended to SECURITY-AUDIT.md:
  fails, names both subjects.
@404SecNotFound
404SecNotFound merged commit 40c521b into main Sep 27, 2026
15 checks passed
@404SecNotFound
404SecNotFound deleted the claude/serene-carson-0739mv-readme-gates branch September 27, 2026 05:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant