BREAKING feat/sec-kn-4c-land #2 / 2
aaronrene · 41 days ago · Aug 1, 2026 · Diff

security(icp): SEC-KN-4c-b land identity migration hook (T4)

Bring forward the identity Migration.migration on StableStorage + flipped verify-canister-migration contracts from feat/sec-kn-4c-identity-migration onto current main (fresh feat/sec-kn-4c-land per freeze §4). Flip the SEC-KN-4 unit assertion off TODO(SEC-KN-4c) (4C-R6) and add the seven-tier suite test/sec-kn-4c-migration-hook-restore.test.mjs (4C-R7): 11/11 green, SEC-KN-4 31/31, canister:verify-migration exit 0, dfx build --check hub exit 0. Live module hash re-read this session: 0x039360a0985c79e2ec993e0d 0b81dc6e6b85e4d924c1123f5d1af26cdfd69bae matches frozen expected — NO redeploy (4C-R8). Freeze artifact carried onto branch. No posture/env flips; F7 parked; P6 UNVERIFIED. BV review pending before DONE.

sha256:ec1e80b32f4a7ba9ebbde63edb62395a9e83d79db0d29e754c8b791d87cb8326 sha
+34 symbols
sha256:961dd9a9a0aab86c4a1727843d965b686f28aafa9464bbdcae811f31ea416da8 snapshot
+34
symbols added
0
dead code introduced
Semantic Changes 34 symbols
+ SEC-KN-4c — frozen spec: restore migration hook to identity (T4 land) section SEC-KN-4c — frozen spec: restore migration hook to identity (T4 land) L1–298
+ Plain-language summary section 1. Plain-language summary L78–88
+ Technical summary section 2. Technical summary L88–119
+ 1 Verified state (this Thinking session — 2026-08-01) section 2.1 Verified state (this Thinking session — 2026-08-01) L98–119
+ table section table L100–112
+ Frozen requirements (4C-R1 … 4C-R9) section 3. Frozen requirements (4C-R1 … 4C-R9) L119–223
+ 4C-R1 — Actor hook is identity on StableStorage section 4C-R1 — Actor hook is identity on StableStorage L121–137
+ code[motoko] variable variable code[motoko] L125–130
+ 4C-R2 — Remove the one-shot TODO marker section 4C-R2 — Remove the one-shot TODO marker L137–143
+ 4C-R3 — Keep historical helpers section 4C-R3 — Keep historical helpers L143–154
+ 4C-R4 — Module header documents the post-T1 invariant section 4C-R4 — Module header documents the post-T1 invariant L154–162
+ 4C-R5 — Verify script contracts flip section 4C-R5 — Verify script contracts flip L162–175
+ 4C-R6 — SEC-KN-4 unit assertion flips section 4C-R6 — SEC-KN-4 unit assertion flips L175–187
+ 4C-R7 — Seven-tier matrix (land-focused) section 4C-R7 — Seven-tier matrix (land-focused) L187–202
+ table section table L189–198
+ 4C-R8 — No canister redeploy by default section 4C-R8 — No canister redeploy by default L202–211
+ 4C-R9 — Hard stops (out of scope) section 4C-R9 — Hard stops (out of scope) L211–223
+ Auto land procedure (SEC-KN-4c-b) — mechanical section 4. Auto land procedure (SEC-KN-4c-b) — mechanical L223–249
+ 4C-R0 — Citation readiness section 4C-R0 — Citation readiness L71–78
+ Definition of Done section 5. Definition of Done L249–263
+ table section table L251–260
+ Ground-truth edge section 6. Ground-truth edge L263–272
+ Residual / also open (not blockers for 4c-b) section 7. Residual / also open (not blockers for 4c-b) L272–282
+ table section table L274–279
+ Paste-ready Auto prompt (after freeze pass) section 8. Paste-ready Auto prompt (after freeze pass) L282–298
+ code[text] variable variable code[text] L284–298
+ Freeze-contract declaration section Freeze-contract declaration L13–55
+ code[yaml] variable variable code[yaml] L15–54
+ Review record section Review record L55–71
+ Round 1 findings (cited — file+line) section Round 1 findings (cited — file+line) L63–71
+ table section table L65–68
+ table section table L57–62
+ migrationSource function function migrationSource L31–33
+ publicMigrationHookSource function function publicMigrationHookSource L39–43

0 comments

No comments yet. Be the first to start the discussion.

To add a comment, use the Muse CLI: muse hub commit comment sha256:ec1e80b32f4a7ba9ebbde63edb62395a9e83d79db0d29e754c8b791d87cb8326 --body "your comment"