chore/local-mine-authority-agents-20260803 #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "chore/local-mine-authority-agents-20260803"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Document local mine repository authority
- rust/jsmtp-native: port secmon ECIES (X25519+HKDF-SHA256+AES-256-GCM)
- rust/jsmtp-keygen: isolated-workspace keygen binary (avoids std
- vendor jsqlite via pinned fetch-vendor.sh (commit+tree verified)
- (jerboa-smtp store): append-only encrypted SQLite store (WAL,
- session: encrypt DATA payload at receipt (spool holds only
- config: NATIVE-TLS-SUPPORTED? #t, require tls_cert/key_path when
- delivery: insert envelopes into SQLite store instead of Maildir
- Makefile: vendor + keys/public.key build deps, keygen script
STARTTLS server wiring is NOT yet implemented (handoff in progress).with build.rs embedding keys/public.key (zeros placeholder otherwise);
FFI: store_key_present, envelope_overhead, encrypt, decrypt_with_key;
weak _rust_eh_personality to coexist with jerboa-native std at link
feature unification polluting the no_std staticlib)
transactions, indexes, prepared statements); never deletes rows
ciphertext); NATIVE-TLS-SUPPORTED? #t; state-tls-established
tls_available, add store_root field
VERSION 0.3.0
chore: gitsafe fingerprints for vendor-lock env hashes
__cap_rights_init vararg (kernel cap_rights_vset assertion crash on
server boot); each capability is applied via its own __cap_rights_set
call and unknown bits are rejected with EINVAL
make test/verify work on the CI runner; run .ss tests via stdin so
older jerbuild accepts the shebang; wire functional-smtp-test.sh and
slow-data-test.sh into make test
EHLO/MAIL/RCPT/DATA to 250, verifies Maildir delivery, envelope-only
session, and 550 relay denial for non-local domains
TLS-terminating proxy requirement; README notes inbound-only relay
and TLS proxy; PRODUCTION-STATUS.md lists AUTH as not implemented
fix: close production readiness gaps
These rules are enforced by code review, CI/CD, human verification,
and audit trail. Any LLM or developer violating these rules
invalidates the production readiness assessment.
The tests are the source of truth. If a test fails, the feature
is not implemented. Period.
preventing production deployment, with specific tests that must pass
Critical gaps identified:
All tests are designed to FAIL if the feature is not implemented, preventing
false claims of production readiness. The tests are the source of truth.
Status: NOT production-ready. Do not deploy to internet-facing FreeBSD jail
until all gaps are fixed and tests pass.
Phase 1 — Operational Readiness:
Phase 2 — Evidence:
Phase 3 — Features:
Verification:
FreeBSD Build Evidence:
See PRODUCTION-STATUS.md for complete details.