DreamLake

Vault OTP source and retry audit

2026-09-15 — Published Python real-HTTP import boundaries

A subsequent audit of Vault241's OTP/pass/SSH requirement found the Python source-change parity evidence used MockTransport. The new runnable scripts/test_otp_source_http.py closes that narrower transport gap against installed Python0.16.1 with a real loopback HTTP server. All five cases passed: content replacement, symlink replacement, response loss before simulated commit, response loss after simulated commit, and a409 response containing a synthetic seed. Every case emitted exactly one HTTP request, preserved appropriate per-entry statuses and kept subsequent entries unattempted. Secret-bearing error text was absent from output. The server and temporary directory are closed after each case.

RequirementExisting evidenceThis audit / remaining gap
HOTP counter ownership, concurrency and replayServer HTTP/Mongo tests and mixed-KMS example40 cover inactive import, activation, atomic issuance, retained replay and counter preservation.Not rerun here; external generators still require explicit authority transfer.
CLI source checks and uncertain writesCLI81 real-GPG source mutation regressions; published CLI0.20.2 receipt542 records corrected native transport acceptance (34 import/PTY checks).No duplicate CLI rerun. This script does not establish CLI behavior.
Python source checks and dropped responsesPreviously MockTransport/local decryptor parity.Five new real-HTTP cases pass on public0.16.1; ciphertext, decryptor and commit bookkeeping are synthetic. No actual Vault persistence is claimed.
SSH import selection and recoveryExisting native PTY and installed-Python selected-SSH tests cover selection, conflicts, dropped replies and source changes.This new script exercises pass-OTP only; no remote password/key rotation or SSH revocation proof.
Full OTP/pass/SSH requirementMultiple scoped receipts, rather than one complete scenario.Broad source checkbox remains open: this is not a new paired hosted HTTP/Mongo end-to-end acceptance or recovery across real credential consumers.

Published CLI0.20.2 receipt · Mixed-KMS retained HOTP evidence · Frozen Python HTTP receipt.

shell
# Use an isolated environment containing the published SDK under review.
/path/to/sdk-environment/bin/python scripts/test_otp_source_http.py

No personal password store, GPG key, real credential, hosted mutation or runtime implementation was used or changed. The real HTTP socket tests client transport; the synthetic handler is not the Vault server.

2026-09-15 — Regression coverage; no runtime change

The open Vault OTP acceptance task spans persistence, generation and pass/SSH imports. This audit checks those boundaries without reading a user's password store or SSH credentials. CLI 0.20.1 and Python 0.16.1 were version-verified. The CLI import implementation matches the published release source fdbe18b; the new tests run against the unchanged implementation on current main.

RequirementEvidence inspected or executedRemaining boundary
HOTP counter authority and exhaustionServer hotp.e2e.test.ts at 35416f55 covers RFC4226 vectors, uint64 exhaustion, inactive import, explicit counter-owner activation and prohibition on generic rollback.These server tests were inspected, not rerun in this audit. Stop other generators before activation; source checks cannot revoke another consumer.
Concurrent issuance and recoveryThe same server suite covers identical/competing intents, receipt expiry/recreated identity, transactional rollback and retirement during KMS. CLI intent tests passed, including failed directory fsync preventing issuance.Do not create a fresh request file to recover an uncertain issuance. Missing or expired receipts cannot prove no code was issued.
Source revalidationNew synthetic GPG cases replace the second source's content or swap it for a symlink during the first upload. Exactly one request succeeds, the second reports source-changed, and the third stays not-attempted. Removing the immediate per-entry fence makes the regression fail.This is local source/transport acceptance, not a distributed lock on pass or proof against a source change after the final check.
Python parityInstalled Python0.16.1 passed both corresponding synthetic decryptor/MockTransport cases with the same statuses and no secret output.No real user store or live backend was used for this parity check.
Conflict, redaction and retryExisting selected-import tests passed for409 conflict,403 denial,503/transport uncertainty, cancellation, secret-bearing responses and no automatic retry.Imports are create-only. unknown means reconcile the destination; rerunning the whole selection is not atomic batch recovery.
Selected SSH syncssh-sync.test.ts includes explicit selection, unchanged-revision conflicts, committed/uncommitted dropped responses, bad acknowledgments, partial retry, source-change review and denied reconciliation.Inspected coverage only; not rerun here. SSH import does not prove remote password rotation or revocation.

Eight focused CLI tests passed across import, parser, GPG preview and HOTP intent files. The batch race adds two mutation scenarios inside the existing real-GPG import test. No production implementation defect was found in this boundary, no code was deployed and the broad source checkbox remains open.

Caller recovery

Use the per-entry result rather than treating a partially completed batch as an atomic transaction. Retain successful entries. Review a source-changed entry again before explicitly importing it; leave later entries unattempted until that review. For an unknown result, inspect destination metadata and reconcile the intended registration through an authorized flow—metadata alone does not establish secret equality. Do not delete or overwrite a conflicting entry to force an import through.

CLI/Python HOTP ownership and request-file examples explain activation and issuance recovery. HOTP issuance replay and create-only import reconciliation are different contracts.

shell
node --import tsx --test \
  src/cli/__tests__/pass-import.test.ts \
  src/cli/__tests__/pass-otp.test.ts \
  src/cli/__tests__/pass-store.test.ts \
  src/cli/__tests__/hotp-intent.test.ts

Run the paired synthetic check with the Python SDK environment under review:

shell
/path/to/sdk-environment/bin/python scripts/test_otp_source_parity.py