From 6802e06ccd0e5a27485b9667c1035f0d8adf0c42 Mon Sep 17 00:00:00 2001 From: Your Name Date: Fri, 5 Jun 2026 11:15:30 +0800 Subject: [PATCH] =?UTF-8?q?docs(security):=20=E8=A3=9C=20S4.9=20reviewer?= =?UTF-8?q?=20validation=20checklist=20[skip=20ci]?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/LOGBOOK.md | 26 ++++ .../S4-9-REVIEWER-VALIDATION-CHECKLIST.md | 124 ++++++++++++++++++ ...026-06-04-iwooos-security-governance-p0.md | 18 ++- 3 files changed, 167 insertions(+), 1 deletion(-) create mode 100644 docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md diff --git a/docs/LOGBOOK.md b/docs/LOGBOOK.md index b8b34d1bb..07892cb32 100644 --- a/docs/LOGBOOK.md +++ b/docs/LOGBOOK.md @@ -1,3 +1,29 @@ +## 2026-06-05|S4.9 Reviewer Validation Checklist + +**背景**:接續 S4.9 owner response intake form,本段把「owner 填表後 reviewer 如何判定」拆成可執行 checklist。平行 AwoooP Session 正在推 `P1-002 Gitea 工作流程與 runner 健康合約盤點`;本視窗仍避開 workflow / runner snapshot / API / UI 實作檔,只做 docs-only 規範,不送 request、不收 owner response、不改 Gitea / GitHub / refs / workflow / secret / runner / host / runtime。 + +**本輪完成**: +- 新增 `docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md`:固定 reviewer 分工、V0-V8 validation gates、outcome 決策表、count transition 邊界、cross-packet consistency 與 reviewer output template。 +- Reviewer 分工拆成 intake、redaction、scope、consistency、final recorder;任一 reviewer 都不得代 owner 補 decision,也不得把 note 改寫成 accepted / approved。 +- Validation gates 覆蓋基線同步、五題完整、六欄完整、decision allowlist、sensitive payload、execution request、evidence refs、cross-packet consistency 與 gate boundary。 +- Outcome 明確分流為 waiting、補件、隔離、拒收或 ready for security acceptance record;通過 reviewer validation 仍不自動進 accepted。 +- 更新 `docs/workplans/2026-06-04-iwooos-security-governance-p0.md`:同步 `gitea/main=a516d3f8`、P0-2f、S4.9 §3.7、規範分析與驗證紀錄。 + +**完成度更新**: +- S4.9 reviewer validation checklist:`100%`。 +- S4.9 owner response gate:仍 `0%`;request / received / accepted / rejected / owner response count 全部維持 `0`。 +- IwoooS 整體:維持 `64%`;active runtime gate 維持 `0`。 +- AI Agent automation backlog:仍以 P1-001 正式基準 `74%`、done `17/23`、下一步 `P1-002` 為準。 + +**驗證預計 / 邊界**: +- 必跑:`git diff --check`、`source-control-owner-response-guard.py`、`security-mirror-progress-guard.py` 與高風險授權誤寫掃描。 +- 本段是純文件規範,不改前端、不改 API、不新增 deploy;不需要新的 production desktop / mobile smoke。 +- 不建立 repo、不同步 refs、不改 workflow、不收 secret value、不啟用 runner、不做 Kali scan、不 SSH、不開 runtime action button、不切 GitHub primary。 + +**下一步**: +- 等 owner 依 intake form 提供脫敏 metadata;reviewer 依本 checklist 判定補件、隔離、拒收或可進 security acceptance record。 +- 推送後同步另一個 AwoooP Session,提醒 P1-002 提交前接上最新 S4.9 reviewer validation 文件基線。 + ## 2026-06-05|S4.9 Owner Response Intake Form **背景**:接續 S4.9 canonical owner response envelope,本段把六欄封套轉成 owner 可直接填寫的五題 intake form。平行 AwoooP Session 正在推 `P1-002 Gitea 工作流程與 runner 健康合約盤點`,本視窗避開 workflow / runner snapshot / API / UI 實作檔,只做 docs-only 規範,不送 request、不收 owner response、不改 Gitea / GitHub / refs / workflow / secret / runner / runtime。 diff --git a/docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md b/docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md new file mode 100644 index 000000000..ae6b8bc71 --- /dev/null +++ b/docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md @@ -0,0 +1,124 @@ +# S4.9 Reviewer Validation Checklist + +| 項目 | 內容 | +|------|------| +| 日期 | 2026-06-05 | +| 基準 | `gitea/main=a516d3f8 docs(security): 補 S4.9 owner response intake form [skip ci]` | +| 上游文件 | `docs/security/S4-9-CANONICAL-OWNER-RESPONSE-ENVELOPE.md`、`docs/security/S4-9-OWNER-RESPONSE-INTAKE-FORM.md` | +| 模式 | reviewer validation checklist only | +| 不可誤讀 | 本文件不是 request dispatch、不是 owner response、不是 accepted record、不是 repo / refs / workflow / secret / runner / host / runtime 執行授權 | + +## 1. 使用時機 + +本 checklist 只在 owner response intake form 進入 `ready_for_reviewer_validation` 後使用。它的目的,是讓 reviewer 逐關判斷「可進下一步」、「補件」、「隔離」或「拒收」。 + +通過本 checklist 仍不等於 runtime action、GitHub primary、Kali scan、主機維護、repo 建立、refs sync、workflow 修改或 Secret 讀取獲得批准。若需執行任何動作,必須切出獨立人工批准、rollback、post-check 與 audit record。 + +## 2. Reviewer 分工 + +| 角色 | 負責內容 | 不可做的事 | +|------|----------|------------| +| Intake reviewer | 檢查五題與六欄是否完整 | 不替 owner 補 decision | +| Redaction reviewer | 檢查 evidence refs 是否只含脫敏參照 | 不複製 raw payload 到文件、LOGBOOK 或前端 | +| Scope reviewer | 檢查 affected scope 是否能對應 source-control / host / product 範圍 | 不把 scope 判定轉成 git 或 runtime action | +| Consistency reviewer | 對照 S4.5 / S4.10 / S4.11 / S4.12 / rollback handoff 的 owner、scope、disposition | 不用單一表單覆蓋其他封包的缺口 | +| Final recorder | 記錄 reviewer outcome、補件原因與下一位 owner | 不把 reviewer note 寫成 accepted 或 approved | + +## 3. Validation Gates + +| Gate | 檢查 | 通過條件 | 失敗 outcome | +|------|------|----------|--------------| +| V0 | 基線同步 | reviewer 使用最新 `gitea/main`、最新 intake form 與最新 P0 總帳 | `keep_waiting_owner_response` 或重新同步 | +| V1 | 五題完整性 | 五題都有回覆或明確補件狀態 | `request_more_evidence` | +| V2 | 六欄完整性 | 每題都能映射到 `owner_role_or_team`、`decision`、`decision_reason`、`affected_scope`、`redacted_evidence_refs`、`followup_owner` | `request_more_evidence` | +| V3 | Decision allowlist | `decision` 只使用 `confirm`、`defer`、`reject`、`request_more_evidence` | `request_more_evidence` 或 `reject_execution_request` | +| V4 | Sensitive payload | 沒有 token、secret、private key、cookie、session、authorization header、runner token、webhook secret、DB dump、repo archive 或未脫敏截圖 | `quarantine_sensitive_payload` | +| V5 | Execution request | 沒有 repo create、visibility change、refs sync、delete refs、workflow 修改、runner 啟用、Kali scan、`/execute`、SSH、host update、runtime restart / rollout / scale / delete | `reject_execution_request` | +| V6 | Evidence refs | evidence 只保留文件路徑、snapshot id、ticket id、hash、脫敏 metadata pointer 或 quarantine pointer | `request_more_evidence` 或 `quarantine_sensitive_payload` | +| V7 | Cross-packet consistency | owner、scope、canonical source、legacy disposition、workflow / secret 名稱、rollback owner 沒有互相矛盾 | `request_more_evidence` | +| V8 | Gate boundary | 所有執行面與 primary switch 仍在獨立人工批准外 | `reject_execution_request` | + +## 4. Outcome 決策表 + +| Outcome | 使用條件 | 可更新內容 | 不得更新內容 | +|---------|----------|------------|--------------| +| `keep_waiting_owner_response` | 尚未收到表單、只有空白表、只有口頭同意、基線過期 | waiting note、followup owner | received / accepted / rejected count | +| `request_more_evidence` | 欄位缺漏、scope 不清、evidence refs 不足、跨包矛盾 | 補件原因、缺口清單、補件 owner | accepted count、runtime gate | +| `quarantine_sensitive_payload` | 含疑似敏感 payload、未脫敏 evidence、private credential URL | quarantine metadata、payload 類型、長度、收件時間 | raw payload、LOGBOOK raw text、前端顯示 | +| `reject_execution_request` | 夾帶 git / workflow / runner / host / scan / runtime 執行要求 | rejection reason、需切出的人工批准類型 | action button、runtime gate、GitHub primary | +| `ready_for_security_acceptance_record` | 五題完整、六欄完整、無敏感 payload、無執行要求、跨包一致 | reviewer validation note、下一階段 owner | 自動 accepted、自動 dispatch、自動 execution | + +## 5. Count Transition 邊界 + +| Count / Flag | 允許變更前提 | 仍需維持不變的情境 | +|--------------|--------------|--------------------| +| `request_sent_count` | 有人工送件 audit metadata,且送件內容只含脫敏表單與禁止條款 | 只有 request draft、template、handoff 或本 checklist | +| `received_response_count` | 收到非空表單,五題與六欄可讀,敏感 payload 已先分流 | 只有口頭同意、空白表、未完成映射、含 raw payload | +| `accepted_response_count` | reviewer validation 通過後,另有 security acceptance record | 只有表單、只有 reviewer note、只有 AwoooP approval、只有 UI 可見 | +| `rejected_response_count` | 有實際回覆被拒收,且 rejection reason 已記錄 | 尚未收到回覆、只需要補件、只需要隔離 | +| `redacted_payload_ingested` | 脫敏 metadata 已完成 reviewer 驗收且無 raw payload | evidence refs 未清楚、payload 未隔離、仍需補件 | +| `runtime_execution_authorized` | 另有獨立人工批准、rollback、post-check、disable plan 與 audit record | S4.9 任一文件、表單、reviewer validation 或 AwoooP approval | +| `github_primary_switch_authorized` | 另有 primary readiness、owner acceptance、rollback ADR 與 cutover approval | S4.9 owner response gate 尚未 accepted | + +## 6. Cross-packet Consistency Checklist + +| 封包 | Reviewer 必查 | 失敗處理 | +|------|---------------|----------| +| S4.5 Gitea authenticated inventory | 是否仍只收 read-only metadata 或 redacted admin export;不收 token value | 補件或隔離 | +| S4.10 GitHub target owner response | `not_found_or_private` 是否被誤讀成不存在或可建立 repo | 補件 | +| S4.11 refs truth queue | refs truth、deprecated / archive candidate、GitHub-only refs 是否有 owner 判定 | 補件 | +| S4.12 workflow / secret parity | Secret name parity 是否只含名稱與 template;沒有 value、hash fragment、partial token | 隔離或補件 | +| Rollback ADR owner handoff | rollback owner、trigger、validation window、fallback role 是否一致 | 補件 | +| IwoooS runtime gate | UI / matrix / AwoooP approval 是否被誤讀成 runtime 授權 | 拒收執行要求 | + +## 7. Reviewer Output Template + +```text +reviewer_validation_id: +baseline_commit: +intake_form_ref: +reviewer_role_or_team: +outcome: +outcome_reason: +passed_gates: +failed_gates: +missing_fields: +quarantine_refs: +cross_packet_conflicts: +followup_owner: +not_approval_statement: +``` + +`not_approval_statement` 必須明確寫出:本 reviewer output 不是 repo / refs / workflow / secret / runner / host / runtime 執行批准,也不是 GitHub primary switch 批准。 + +## 8. 驗收前狀態 + +```text +request_sent=false +request_sent_count=0 +received_response_count=0 +accepted_response_count=0 +rejected_response_count=0 +owner_response_received_count=0 +owner_response_accepted_count=0 +redacted_payload_ingested=false +active_runtime_gate_count=0 +runtime_execution_authorized=false +action_buttons_allowed=false +repo_creation_authorized=false +refs_sync_authorized=false +workflow_modification_authorized=false +github_primary_switch_authorized=false +host_update_authorized=false +active_scan_authorized=false +secret_value_collection_authorized=false +``` + +## 9. 本輪完成度 + +| 工作 | 完成度 | 說明 | +|------|--------|------| +| S4.9 reviewer validation checklist | 100% | Reviewer 分工、V0-V8 gates、outcome 決策表、count transition 與 cross-packet consistency 已固定 | +| S4.9 owner response gate | 0% | 尚未送件、尚未收到 owner response、尚未 accepted | +| IwoooS 整體 | 維持 64% | Reviewer checklist 完成不代表 runtime readiness 提升 | +| active runtime gate | 0 | 不變 | diff --git a/docs/workplans/2026-06-04-iwooos-security-governance-p0.md b/docs/workplans/2026-06-04-iwooos-security-governance-p0.md index c5875eddc..345de6081 100644 --- a/docs/workplans/2026-06-04-iwooos-security-governance-p0.md +++ b/docs/workplans/2026-06-04-iwooos-security-governance-p0.md @@ -9,7 +9,7 @@ | 工作視窗 | IwoooS / AWOOOI 資安治理 P0 | | 本次乾淨 worktree | `/private/tmp/awoooi-p1-106-offsite-escrow-readiness-20260605` | | 本次分支 | `codex/p1-305-velero-minio-freshness` | -| 最新觀察到的 `gitea/main` | `37c0e171 docs(governance): 對齊 P1-001 最新正式 deploy marker [skip ci]` | +| 最新觀察到的 `gitea/main` | `a516d3f8 docs(security): 補 S4.9 owner response intake form [skip ci]` | | 最新 P2-D0 繁中文案基準 | code `cd2275a2`、deploy marker `1920bd08`、code-review `2565`、CD `2564` | | 最新 P2-D1 本地掃描基準 | `VISIBLE_LITERAL_TARGET_SCAN_OK files=221`;全站 TS / TSX 中文 literal 盤點 `35` 檔 / `752` 行;註解語氣 backlog `32` 筆 | | 最新 P2-D1 正式部署基準 | code `f9bf8a28`、deploy marker `879b0a36`、CD `2578`、code-review `2579` | @@ -21,6 +21,7 @@ | 最新 AI Agent automation P1-001 基準 | code `de3007b7`、stability fix `fd33591c`、deploy marker `8caba233`、LOGBOOK / marker 對齊 `37c0e171`;runtime surface `22`、Secret surface `4`、live gaps `6`、backlog `74%`、done `17/23`、下一步 `P1-002` | | 最新 S4.9 canonical owner response envelope 基準 | `docs/security/S4-9-CANONICAL-OWNER-RESPONSE-ENVELOPE.md`;六欄信封、欄位 alias、五題投影、quarantine-first 與 reviewer checklist 已固定;owner response gate 仍 `0%` | | 最新 S4.9 owner response intake form 基準 | `docs/security/S4-9-OWNER-RESPONSE-INTAKE-FORM.md`;五題可填表、六欄填寫規則、reviewer 收件欄與 outcome lanes 已固定;owner response gate 仍 `0%` | +| 最新 S4.9 reviewer validation checklist 基準 | `docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md`;Reviewer 分工、V0-V8 gates、outcome 決策表、count transition 與 cross-packet consistency 已固定;owner response gate 仍 `0%` | | 目前平行 Session | AwoooP thread `019e9154-7d5e-7b72-85be-c9d97e43ecc9` 正在推 `P1-002 Gitea 工作流程與 runner 健康合約盤點`;本視窗避免修改同一批 workflow / runner snapshot / API / UI 檔 | | 前一個正式 IwoooS 候選基準 | code `7b8fc093`、deploy marker `45c63488`、LOGBOOK `02cadee6` | | 最新導航 IA 基準 | code `973fc7a4`、LOGBOOK `2555c811`、deploy marker `0260ec89` | @@ -55,6 +56,7 @@ | P0-2c | S4.9 current gap audit | 100% | 已新增 `S4-9-OWNER-RESPONSE-GATE-CURRENT-GAP-AUDIT.md`,列出已符合、仍不符合、需新增、需調整、五題回覆與 0 / false 邊界;owner response gate 仍 0% | owner response guard、progress guard、diff check | | P0-2d | S4.9 canonical owner response envelope | 100% | 已新增 `S4-9-CANONICAL-OWNER-RESPONSE-ENVELOPE.md`,固定六欄信封、source template alias mapping、五題投影、quarantine-first 與 reviewer checklist;owner response gate 仍 0% | owner response guard、progress guard、diff check | | P0-2e | S4.9 owner response intake form | 100% | 已新增 `S4-9-OWNER-RESPONSE-INTAKE-FORM.md`,固定五題可填表、六欄填寫規則、reviewer 收件欄與 outcome lanes;owner response gate 仍 0% | owner response guard、progress guard、diff check | +| P0-2f | S4.9 reviewer validation checklist | 100% | 已新增 `S4-9-REVIEWER-VALIDATION-CHECKLIST.md`,固定 reviewer 分工、V0-V8 gates、outcome 決策表、count transition 與 cross-packet consistency;owner response gate 仍 0% | owner response guard、progress guard、diff check | | P0-3 | AwoooP 同步封包 | 100% | 已送至 AwoooP 平行工作 thread `019e9154-7d5e-7b72-85be-c9d97e43ecc9`;後續仍需每次推版前重新 fetch / fast-forward | 本文件、thread send readback、mirror checklist readback | | P0-4 | production live sanity 節點 | 100% | desktop / mobile / 展開區塊 / overflow / action href 檢查已完成 | Playwright production sanity 通過 | | P0-5 | LOGBOOK 與完成度更新 | 100% | D2 comments-only、D2 AIOps sample、D2 Code Review 候選分類與 D2 AwoooP Runs fallback 皆已回填;可見 / bundle 變更皆已補 local / production desktop + mobile smoke | `docs/LOGBOOK.md` readback | @@ -131,6 +133,18 @@ S4.9 是目前 IwoooS 64% 能往前的第一優先 gate。驗收前所有 count | Reviewer 收件欄 | 100% | 五題完整性、decision、scope、redacted refs、sensitive payload、執行要求、補證與 reviewer validation 已列檢查欄 | 不代表 accepted | | Outcome lanes | 100% | waiting、request_more_evidence、quarantine、reject_execution_request、ready_for_reviewer_validation 已固定 | 不得開 action button 或 runtime gate | +### 3.7 2026-06-05 Reviewer Validation Checklist + +本輪把 S4.9 從「owner 可直接照表填五題」再推到「reviewer 可逐關判定補件、隔離、拒收或可進下一階段」。這是 reviewer validation 準備度,不是 request dispatch、不代表 owner response received,也不代表 accepted;所有 count 與授權 flag 仍不變。 + +| 項目 | 完成度 | 目前狀態 | 不可誤讀 | +|------|--------|----------|----------| +| Reviewer 分工 | 100% | intake、redaction、scope、consistency、final recorder 已拆責 | 不代表 reviewer 可代 owner 填 decision | +| V0-V8 validation gates | 100% | 基線同步、五題完整、六欄完整、decision allowlist、sensitive payload、execution request、evidence refs、cross-packet consistency、gate boundary 已固定 | 不代表通過任一 gate 就 accepted | +| Outcome 決策表 | 100% | waiting、補件、隔離、拒收、ready for security acceptance record 已定義 | 不得自動開 runtime gate | +| Count transition | 100% | request sent、received、accepted、rejected、redacted payload、runtime execution、GitHub primary switch 的變更前提已拆開 | 不得因表單或 reviewer note 連動調高 | +| Cross-packet consistency | 100% | S4.5 / S4.10 / S4.11 / S4.12 / rollback ADR / runtime gate 的交叉檢查已列入 | 不得用單一表單覆蓋其他缺口 | + ## 4. 驗證節點規則 | 階段類型 | 必跑驗證 | 是否需要實際開頁 | @@ -218,6 +232,7 @@ P1 只讀重盤階段整體完成度:`70%`。它代表 freshness / inventory / | 需要調整規範 | AwoooP 同步封包 | P1 要同步 refreshed counts、blocked gates、no-run 狀態,避免另一 Session 以舊 `117` heads / `141` items 繼續推進 | 本總帳與 LOGBOOK 會作為同步封包來源 | | 需要調整規範 | S4.9 欄位同義詞混用 | `affected_repos`、`affected_sources`、`canonical_namespace`、`evidence_refs`、`review_owner` 等欄位容易和使用者要求的六欄封套混用 | 已新增 canonical owner response envelope 規範;source template 可保留細分欄位,但收件 / 顯示 / LOGBOOK 必須映射回六欄 | | 需要新增規範 | S4.9 owner 可填表單 | 既有 request draft 與 response package 有欄位與規則,但缺一份 owner 可直接逐題填寫、reviewer 可直接分類的六欄 intake form | 已新增 `S4-9-OWNER-RESPONSE-INTAKE-FORM.md`;表單可用但 request sent / received / accepted 仍全部 0 | +| 需要新增規範 | S4.9 reviewer validation checklist | Intake form 已能填寫,但缺一份 reviewer 收件後逐關判定補件、隔離、拒收、可進下一階段與 count transition 的 checklist | 已新增 `S4-9-REVIEWER-VALIDATION-CHECKLIST.md`;reviewer validation 可操作化但 accepted 仍全部 0 | | 需要新增規範 | 111 / 168 開發主機 scope handoff | 原本只有 observe-only mapping,缺 owner 可審的 scope boundary、credential refusal、rollback owner、validation metrics 與維護窗口欄位 | 已新增 P1-8 handoff、snapshot 與 schema;host execution 仍 `0%` | | 需要調整規範 | 111 Ollama fallback wording | 111 是 ADR-110 local fallback evidence 範圍,不可被誤讀成可直接改 route、重啟 Ollama 或停止模型 | 已在 P1-8 固定 `fallback_route_change_authorized=false` 與 route truth observe-only | | 需要調整規範 | 168 dev origin / repo hygiene wording | repo hygiene 與 local service exposure 容易被誤讀成可掃個人資料、讀未授權目錄或改 CORS / firewall | 已在 P1-8 固定未授權目錄、個人資料、secret derivative、CORS / firewall / service change 全部拒收 / 禁止 | @@ -318,6 +333,7 @@ P1 只讀重盤階段整體完成度:`70%`。它代表 freshness / inventory / | P2-D2 AwoooP Runs fallback 文案 | code `7f6028c3`、deploy marker `bf016e91`;`/zh-TW/awooop/runs`、Callback Evidence、Source Flow 與 status-chain fallback 可見文案已清理;i18n mirror `9020` leaves;目標殘留詞掃描命中 `0`;typecheck、build、owner response guard、security mirror progress guard、diff check 通過;Gitea code-review `2591` 成功、CD `2590` 成功;local / production desktop + mobile 均 `horizontalOverflow=0`;截圖 `/tmp/awoooi-runs-callback-i18n-prod-desktop-bf016e91.png`、`/tmp/awoooi-runs-callback-i18n-prod-mobile-bf016e91.png` | | S4.9 canonical owner response envelope | 新增 `docs/security/S4-9-CANONICAL-OWNER-RESPONSE-ENVELOPE.md`;六欄信封、alias mapping、五題投影、quarantine-first、reviewer checklist 與驗收前 `0 / false` 邊界已固定;本段純文件,不改前端、不改 API、不新增 deploy;owner response gate 仍 `0%` | | S4.9 owner response intake form | 新增 `docs/security/S4-9-OWNER-RESPONSE-INTAKE-FORM.md`;五題可填表、六欄填寫規則、reviewer 收件欄、outcome lanes 與驗收前 `0 / false` 邊界已固定;本段純文件,不改前端、不改 API、不新增 deploy;owner response gate 仍 `0%` | +| S4.9 reviewer validation checklist | 新增 `docs/security/S4-9-REVIEWER-VALIDATION-CHECKLIST.md`;reviewer 分工、V0-V8 gates、outcome 決策表、count transition、cross-packet consistency 與驗收前 `0 / false` 邊界已固定;本段純文件,不改前端、不改 API、不新增 deploy;owner response gate 仍 `0%` | 本輪驗證後仍維持: