Commit Graph

91 Commits

Author SHA1 Message Date
michael
3b519578c5 feat(gui): WatchdogState pure-logic helper for first-run modal
Convert gui/src/firstrun.rs to a module dir with watchdog.rs, the
pure-logic WatchdogState helper that the GTK widget code in Task 2
will poll. Three unit tests cover fresh/expired/poke transitions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 11:19:46 -07:00
michael
712c1e9c1d Merge branch 'feature/prep-shell-and-pending' 2026-04-27 10:56:14 -07:00
michael
2ed95d21da style(daemon): rustfmt collapse get_pending_status match arm
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:55:51 -07:00
michael
b8e8368a25 feat(gui): bus::Daemon::{get_pending_status,clear_pending_flag} client wrappers
clear_pending_flag is added alongside get_pending_status because Phase 10
needs both — its first-login modal checks status on startup and clears
the flag on successful enrollment. Bundling here keeps the Phase 10 lane
free of bus.rs edits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:52:14 -07:00
michael
1976971bb5 feat(daemon): GetPendingStatus D-Bus method + 2 integration tests
Drops the #[allow(dead_code)] on AppState::get_pending_status — it's now
called from the D-Bus dispatch. Two new p2p tests cover the absent and
the round-trip cases.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:51:25 -07:00
michael
86e3ffe8d5 feat(daemon): AppState::get_pending_status returns wire-friendly bool+flag
has_pending stays #[cfg(test)] because production GUI reads via the new
get_pending_status (one round-trip carries both presence and flag);
production PAM module reads the file directly. Method gated with
#[allow(dead_code)] until Task 5 wires D-Bus.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:49:53 -07:00
michael
e1542d6d1f feat(common): PendingStatus wire type + Default impl on PendingFlag
PendingStatus carries an explicit 'present' bool next to a PendingFlag
because zvariant doesn't support Option<T>. Two new serde tests.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:47:01 -07:00
michael
8d19be3e58 feat(gui): --first-run flag + firstrun::run stub for Phase 10
argv is read manually before adw::Application sees it (GTK's option parser
rejects unknown long flags), then the filtered list is passed to
app.run_with_args. Stub exits cleanly with a stderr breadcrumb so a
developer who passes --first-run before Phase 10 lands doesn't get a
stuck process.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:45:52 -07:00
michael
a927d96630 refactor(gui): extract AppContext for shared page handles
KeysPage::new now takes a single AppContext that owns parent_window,
toast_overlay, and the shared daemon Rc<RefCell<Option<Daemon>>>. Phases
9, 10, 11, and 12 GUI tab will all consume this struct.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:42:11 -07:00
michael
d20643cde5 docs(plan): coordinator + 3 step-level plans for parallel Phase 9/10/11 fan-out
Ships four documents:
  * 2026-04-27-parallel-fanout-9-10-11.md — coordinator. File-conflict map,
    prep-lane scope rationale, post-prep parallel-safety guarantee, merge
    order rule, and risks.
  * 2026-04-27-prep-shell-and-pending.md — small ~1hr prep lane: extract
    AppContext, add --first-run flag scaffold (with stub firstrun::run),
    add daemon GetPendingStatus D-Bus method + GUI client wrapper, new
    PendingStatus wire type. 6 tasks, single agent.
  * 2026-04-27-phase-10-firstrun.md — first-login flow. Fullscreen modal,
    60s idle watchdog (TDD'd as pure WatchdogState), enrollment via Phase
    8 enroll_dialog, ClearPendingFlag on success, gnome-session-quit on
    idle, autostart .desktop entry, debian install. 6 tasks.
  * 2026-04-27-phase-11-totp.md — TOTP support behind default-on Cargo
    feature. Daemon-side: 160-bit secret + base32 + otpauth URI + atomic
    0600 writes in pam_google_authenticator format. PAM profile renderer
    extension. D-Bus surface. CLI subcommand. GUI tab with QR modal.
    Deviation flagged: TOTP recovery codes reuse the Phase 12 recovery
    flow rather than introducing a parallel hashed-recovery file format.
    9 tasks.

Execution model: prep lane first (single agent ~1hr), then dispatch three
subagents in parallel worktrees for the three follow-on lanes. Per the
conflict map, the lanes are file-disjoint after prep merges; merge order
is any-order.

If all four lanes land cleanly, the roadmap jumps from 13/19 to 17/19
phases code-complete in a single session, leaving Phase 13 (deb finalization),
14 (PPA + smoke), 17 (integration tests), 18 (user docs), and the v1.0
release tag.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:28:23 -07:00
michael
b624f005b2 docs(roadmap): refresh post Phase 8 + Phase 12 backend merges
* Phase 9/10/11 status rows: dependencies satisfied, mark "open now" with
  pointers to step-level plans where they exist.
* Phase 12 row: GUI tab is folded into the Phase 9 lane plan (not its own).
* ASCII dependency diagram: collapse the just-landed Phase-8/Phase-12-backend
  layer; show the three open lanes (9+12-GUI, 11 TOTP, 10 first-login)
  fanning into Phase 13.
* "Parallel-safe right now" heading bumped to post-Phase-8+12-backend.
  Table swaps the now-stale Recovery and post-Phase-8 GUI rows for the
  three actually-open lanes, with file footprints + plan links.
* Sequential tail paragraph names the six Code-complete phases (1, 3, 4,
  6, 8, 12) whose deferred gates Phase 14 must clear.
* Phase 12 closeout intro names the merge commit and corrects the now-stale
  "waiting on Phase 8" wording.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 10:09:22 -07:00
michael
4ec69119f6 Merge branch 'feature/phase-12-recovery-backend'
# Conflicts:
#	docs/plans/2026-04-26-authforge-implementation.md
2026-04-27 10:05:59 -07:00
michael
91731150d5 docs: phase 12 backend closeout notes
Flips Phase 12 status to  Code complete; bumps progress to 12/19 (63%).
Closeout block summarizes the 8 implementation tasks, lists all new
artifacts, calls out the 80-test count (was 60), and flags the Phase 14
deferred verifications (libargon2-dev compile + pamtester smoke).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:53:09 -07:00
michael
982b9403d0 feat(cli): authforgectl recovery list and revoke
* RecoveryCmd::List no longer takes a user — lists all active codes
  across users, matching the daemon's ListRecoveryCodes signature.
* RecoveryCmd::Revoke <user> calls RevokeRecoveryCode; exits 1 with
  a stderr message when the user has no active code.
* bus.rs gains list_recovery_codes() / revoke_recovery_code(user).
* Two new clap-parser tests cover the new subcommand shapes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:51:52 -07:00
michael
56ba4dd924 feat(pam): recovery-code mode with Argon2id verify and pending re-enroll handoff
C-side:
* New mode=recovery argv branch in pam_sm_authenticate. Reads the two-line
  /var/lib/authforge/recovery/<user> file, argon2_verify against PAM_AUTHTOK,
  on match unlinks the file (one-shot) and writes pending(re_enroll=true).
  Always returns PAM_IGNORE on failure paths so a missing/wrong code never
  blocks normal auth.
* Makefile links -largon2 alongside -lpam.

Daemon-side:
* policy_apply::render_profile renders the recovery line first in the auth
  stack with [success=done default=ignore] — successful recovery short-
  circuits the rest, missing/wrong code falls through.
* New policy_apply test asserts the recovery line precedes the default
  backstop.

Doc:
* pam/TESTING.md adds libargon2-dev to the build prereqs and a new
  Smoke test 4 walking through the manual recovery-code flow.

C compile gate (make -C pam) requires libargon2-dev — flagged as a
deferred verification step until a host with the dev package is available.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:49:44 -07:00
michael
a420aa5f75 feat(daemon): real GenerateRecoveryCode + ListRecoveryCodes + RevokeRecoveryCode
Replace the random-number stub at dbus.rs:132 with state.issue_recovery,
add ListRecoveryCodes (returns Vec<RecoveryCodeSummary>) and RevokeRecoveryCode.
New polkit actions list-recovery / revoke-recovery (auth_admin_keep). Adds
4 D-Bus integration tests; the previously-stub generate-code test now
exercises the real Argon2id-backed write path.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:39:16 -07:00
michael
42482f2a44 docs: mark Phase 8 done in roadmap + closeout notes 2026-04-27 09:37:22 -07:00
michael
e9efde9077 feat(daemon): wire RecoveryStore into AppState with AUTHFORGE_RECOVERY_DIR override
StorageConfig gains a recovery_dir field; from_env_or_defaults reads
AUTHFORGE_RECOVERY_DIR (default /var/lib/authforge/recovery). AppState
exposes issue/list/revoke methods that Task 6 wires through D-Bus. Test
fixtures in state.rs and dbus.rs updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:35:06 -07:00
michael
517b015996 feat(daemon): RecoveryStore with atomic 0600 writes and one-shot verify-and-consume
Two-line file format (expires_unix\nargon2id-PHC) keeps the C PAM module
parser trivial — no json-c link needed. Atomic temp+rename means a
concurrent reader never sees a half-written file.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:32:40 -07:00
michael
943d9b01ae Merge branch 'feature/phase-8-gui-keys'
Phase 8: GUI Keys tab. Lists current user's enrolled FIDO2 credentials,
enrolls a new key with a touch-prompt modal driven by the daemon's
EnrollmentFailed signal (success comes from the call return), removes
credentials per row, degrades gracefully to a Retry banner when the
daemon is unreachable, and surfaces transient errors via adw::Toast.

8 tasks, 4 unit tests (error classifier).
2026-04-27 09:32:37 -07:00
michael
27dec5ab4a docs(gui): smoke-test recipe and CI gate 2026-04-27 09:26:17 -07:00
michael
14b473a48a feat(gui): wire adw::ToastOverlay for error surfacing 2026-04-27 09:25:50 -07:00
michael
45ac398730 feat(daemon): recovery code generation and Argon2id hashing
Pure-logic module: generate 8-digit codes, Argon2id PHC hash with OS RNG salt,
verify via constant-time PasswordVerifier. Dead-code allow until Task 4 wires
the store on top.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:25:30 -07:00
michael
3fbd872a9c feat(gui): TouchDialog modal racing EnrollOwn against EnrollmentFailed signal
Adds enroll_dialog::present which opens an adw::AlertDialog with a spinner
and races the EnrollOwn call against the EnrollmentFailed signal stream:
- Call returns Ok(_cred) -> close dialog, fire on_success refresh callback.
- Call returns Err -> swap dialog body to the user-message form.
- Signal arrives first -> swap to the signal payload (faster than waiting
  for the call's typed Err to traverse the bus).

KeysPage::start_enroll wires the activated row to present(), passing the
parent window for modal anchoring and a refresh closure as on_success.

Plan deviation: AlertDialog is libadwaita v1_5-gated, so gui/Cargo.toml
enables that feature. Targets Ubuntu 24.04+ (libadwaita 1.5).
2026-04-27 09:24:50 -07:00
michael
402addca27 chore(daemon): add argon2 0.5 for recovery code hashing
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:23:20 -07:00
michael
eb208579e3 refactor(daemon): centralize username path-segment sanitizer
Extract the inline path-traversal check from PendingStore into a shared
storage::safe_user::join_user_segment helper. RecoveryStore (next) reuses it.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:22:23 -07:00
michael
f11047fbcb feat(gui): list enrolled credentials with per-row remove + enroll button 2026-04-27 09:21:45 -07:00
michael
5d6b7ceeb0 feat(gui): KeysPage scaffold + tokio runtime in main, gtk::Box layout
KeysPage::new spawns the connect-and-render flow on glib::MainContext::
spawn_local. On success it shows a placeholder PreferencesPage (Task 5
fills in the list); on failure it shows StatusPage with a Retry button
that re-runs the connect attempt.

main.rs installs the multi-thread tokio runtime guard before app.run()
so zbus's tokio futures execute correctly when polled by glib.

Layout deviation from plan: ToolbarView is libadwaita v1_4-gated; the
project sticks with gtk::Box vertical for portability (commit c6a5e94
established this pattern).
2026-04-27 09:20:31 -07:00
michael
de369ef390 docs(plan): step-level plans for Phase 12 backend and Phase 9 + Phase 12 GUI
Phase 12 backend lane is unblocked by Phase 6+7 and runs independently of
Phase 8. Phase 9 + Phase 12 GUI lane gates on Phase 8 landing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 09:14:57 -07:00
michael
d07d3469fe feat(gui): D-Bus client wrapper around AuthForge interface 2026-04-27 09:13:14 -07:00
michael
d7e6d562dd feat(gui): error helper to classify zbus errors and produce user messages 2026-04-27 09:11:06 -07:00
michael
8d6b80276e chore(gui): add zbus + tokio + futures-util deps for D-Bus client 2026-04-27 09:08:02 -07:00
michael
a17f70c4ac docs(plan): fix Phase 8 zbus runtime path (no glib feature exists)
zbus 4.4 does not expose a glib feature; my earlier draft was wrong about
that. Switch the plan to use the workspace tokio config and install a
multi-thread tokio runtime in main.rs, with the runtime guard kept alive for
the lifetime of app.run(). glib::MainContext::spawn_local still drives the
widget-touching closures; tokio's reactor wakes them.

Also: hoist futures-util into the Task 1 dep bundle so Task 6 doesn't need
a separate Cargo.toml edit.
2026-04-27 09:05:58 -07:00
michael
5294ef61ce docs: add Phase 8 GUI Keys tab implementation plan
Single-lane, sequential plan to land the authforge GUI Keys tab — empty-state
banner with Retry, list of enrolled credentials with per-row remove, modal
TouchDialog driving EnrollOwn against the Phase 3 EnrollmentSucceeded /
EnrollmentFailed signals. zbus uses the glib runtime feature (not the
workspace tokio config), so all async runs on the GTK main thread via
glib::MainContext::spawn_local — no tokio dep in the GUI process.

Eight tasks, ~1 day of work. TDD applies to error.rs (pure logic, 4 tests);
widget code ships with the manual smoke recipe at gui/TESTING.md as the
acceptance gate.
2026-04-27 08:55:04 -07:00
michael
481f7f8543 docs: consolidate roadmap with status legend and per-phase closeout notes
Cleans up scattered status markers into a single legend (Done / Code complete
/ Spec'd / Bundled), backfills v0.1.0-phase1 tag reference for Phase 1, marks
the table consistently for what's actually shipping vs. what needs the Phase
14 VM smoke. Updates the lane diagram to show what's done vs. in flight, and
adds a 'lessons learned from this session's parallelism' section capturing
when subagents-in-worktrees actually work and when they slip on sandbox-blocked
verification commands.

Adds closeout notes for Phases 3, 4+5, 6, 7, 15, 16 alongside the existing
Phase 1 and Phase 2 sections — what shipped, plan deviations, and any wire-
breaking signature changes (SetPolicy gained a force flag in Phase 4+5).
2026-04-27 08:48:34 -07:00
michael
5668ba1f69 docs: mark Phases 4, 5, 15, 16 done in roadmap 2026-04-27 08:42:19 -07:00
michael
7eae081dd7 Merge branch 'gnome-integration-lane' 2026-04-27 08:41:15 -07:00
michael
61f89abae0 Merge branch 'ansible-lane' 2026-04-27 08:41:10 -07:00
michael
5c94319bf0 feat(daemon): policy apply via pam-auth-update + lockout simulator (Phase 4+5)
Lands Lane 1 of the Phase 4+5+8+15+16 parallel cycle. Phase 4 + Phase 5 must
land together because both modify the SetPolicy code path.

- daemon/src/lockout.rs — pure simulate(new_policy, registry) -> Vec<Violation>.
  Iterates Required stacks, flags users with no enrolled credential of any
  required method. 5 unit tests cover: optional-mode skipped, required-with-
  unenrolled flagged, any-method-satisfies, empty registry, multi-stack.
- daemon/src/policy_apply.rs — PolicyApplier renders the pam-configs profile
  (Default: yes when any stack requires fido2; pam_u2f.so + pam_authforge_pending
  when fido2 required, only pam_authforge_pending otherwise) and runs
  pam-auth-update --package. Stash-and-restore on failure: prior profile
  contents are restored and pam-auth-update re-run, so a failed apply leaves
  the system in its previous PAM state. 4 unit tests including a real-process
  rollback test against a failing /bin/sh shim.
- daemon/src/state.rs — AppState::set_policy(p, force) returns
  PolicyApplyResult. Always runs the simulator first; if violations and !force,
  returns { applied: false, violations } without writing. Otherwise persists
  via PolicyStore::save and invokes PolicyApplier::apply. StorageConfig grows
  pam_profile_path + pam_auth_update fields (env-var driven, tests inject a
  no-op /bin/sh shim into a tempdir).
- daemon/src/dbus.rs — SetPolicy signature is now (Policy, bool) -> Result.
  Wire-breaking pre-alpha; CLI updated in this commit.
- cli/src/{bus,commands}.rs — set_policy takes force flag. policy set runs
  with force=false and surfaces violations as a non-zero exit + stderr list
  pointing the user at policy apply --force-i-know-what-im-doing. policy
  apply now actually invokes pam-auth-update via the daemon.

Test count: 42 daemon (was 33; adds 5 lockout + 4 policy_apply). 13 common.
5 cli. cargo clippy --workspace --all-targets -D warnings clean.

Plan deviation: PolicyApplier::from_env() became PolicyApplier::new(profile_path,
pam_auth_update) with the env defaults moved into StorageConfig::from_env_or_defaults.
Cleaner: state owns one source of truth for env-driven path config.
2026-04-27 08:41:00 -07:00
michael
407e71072d ansible: document role variables and ship example playbook
README walks through what the role does, every default, and how to
invoke it from a parent playbook. examples/playbook.yml is a runnable
copy that targets a `workstations` group with a sudo=required+fido2
stack and one pending user.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 08:36:29 -07:00
michael
6e47dbd3df packaging: ship authforge-gnome-integration binary package
Declares the new arch-all binary package in debian/control (depending on
authforge-gui + gnome-control-center) and wires its single data file
(gnome-integration/io.dangerousthings.AuthForge.UsersPanel.desktop) into
debian/rules' override_dh_auto_install so it lands in
/usr/share/applications/. The metapackage already Suggests:
authforge-gnome-integration, so no change there.
2026-04-27 08:35:33 -07:00
michael
457db3ced2 ansible: implement install + policy + pending tasks
Adds the apt_repository / apt steps that pull authforge-daemon, -pam,
and -cli (with -gui gated behind authforge_install_gui), the template
step that renders /etc/authforge/policy.d/90-fleet.conf and notifies the
restart handler, and a loop that calls `authforgectl pending set` for
each entry in authforge_pending_users.

The template emits TOML that round-trips through tomllib for both the
empty-stacks default and a populated multi-stack config.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 08:35:28 -07:00
michael
e638a2defd gnome-integration: add Users-panel .desktop overlay and README
Adds the data file shipped by the optional authforge-gnome-integration
package: a /usr/share/applications/.desktop overlay tagged with
X-GNOME-Settings-Panel=user-accounts so gnome-control-center surfaces a
"Configure security…" launcher inside each user's detail view. The
README documents why a .desktop overlay was picked over a JS extension
(cross-version stability, packaging simplicity) and how to verify the
integration works in GNOME 46/47.
2026-04-27 08:34:50 -07:00
michael
792dca976d ansible: scaffold dangerousthings.authforge role skeleton
Adds meta/main.yml (Galaxy metadata for Ubuntu 22.04/24.04 under the
Apache-2.0 license), defaults/main.yml covering the policy/storage/
firstrun/pending knobs the tasks layer will consume, and a single
restart-daemon handler. Tasks and template land in the next commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 08:34:26 -07:00
michael
865e37b6aa docs: mark Phases 3, 6, 7 done in roadmap 2026-04-27 08:30:09 -07:00
michael
22938f657a feat(daemon-fido): Authenticator trait + Mock + Ctap impl + signals (Lane A)
Bundles plan tasks A2 (PamU2fCred encoder), A3 (Authenticator trait), A4
(MockAuthenticator), A5 (CtapAuthenticator wrapping ctap-hid-fido2 3.5.9),
A6 (wire enrollment through AppState::enroll), A7 (DeviceFound /
TouchRequired / EnrollmentSucceeded / EnrollmentFailed D-Bus signals).

- daemon/src/fido/format.rs — PamU2fCred -> 'kh,pk,es256,+presence' with
  hex::encode for the binary blobs and CoseType matching COSE alg -7/-8.
- daemon/src/fido/authenticator.rs — Authenticator trait with discover() and
  make_credential(rp_id, user, pin); AuthnError covers NoDevice / Cancelled /
  PinRequired / Backend.
- daemon/src/fido/mock.rs — MockAuthenticator::with_one_yubikey produces
  deterministic-but-distinct PamU2fCreds (counter-bumped per call).
- daemon/src/fido/ctap.rs — CtapAuthenticator. discover via
  ctap_hid_fido2::get_fidokey_devices(); make_credential via
  FidoKeyHidFactory::create + fk.make_credential. Heuristic error mapping
  to AuthnError variants. Real-hardware path; compile-clean gate only.
- daemon/src/state.rs — AppState::open now takes Arc<dyn Authenticator>.
  New enroll(user, nickname) replaces the Phase 2 add_credential stub: calls
  authn.make_credential, writes pam_u2f line via CredentialsStore::add,
  records enrollment in userdb, returns Credential with hex(keyHandle) as id.
- daemon/src/dbus.rs — enroll_own / enroll_other now emit TouchRequired
  before the call and EnrollmentSucceeded / EnrollmentFailed after. Removed
  the unused stub-credential builder + import baggage.
- daemon/src/main.rs — picks CtapAuthenticator for prod; tests inject Mock.

Test count: 33 daemon tests pass (was 26). Adds 2 fido::format tests, 3
fido::mock tests, 1 state::enroll_writes_real_pam_u2f_line, 1 dbus::
enrollment_succeeded_signal_fires_on_enroll_own. cargo clippy --workspace
--all-targets -D warnings clean. cargo fmt clean.

Plan deviations:
- HidInfo doesn't have a serial_number field in 3.5.9; switched to using
  product_string and HidParam::Path/VidPid for the device path label.
- FidoKeyHidFactory and LibCfg are at the crate root, not under fidokey::.
- fido/mod.rs has #![allow(dead_code)] for now: discover() and DiscoveredDevice
  fields are wired via the trait but only called from tests until Phase 8
  GUI consumes the DeviceFound signal.
2026-04-27 08:29:42 -07:00
michael
01df2109d8 chore: add ctap-hid-fido2 + hex deps for Phase 3 (Task A1) 2026-04-27 08:20:15 -07:00
michael
1c6c361d4a docs(pam): smoke-test recipe + test PAM stack file (Task B2) 2026-04-27 08:19:18 -07:00
michael
209167df22 feat(pam): real pending-flag check with path-traversal guard (Task B1)
Replaces the Phase 0 stub. Reads PAM_USER, rejects usernames containing /,
\0, .., or that are . / .. / empty. stat()s /var/lib/authforge/pending/<user>:
present -> emits the design-doc user-facing message + PAM_AUTH_ERR; ENOENT
-> PAM_IGNORE (lets the rest of the stack decide); other errno -> logs and
fails closed (PAM_AUTH_ERR).

Builds clean against libpam0g-dev with -Wall -Wextra -Werror -fPIC -O2.
Resulting .so is a 16KB stripped-with-buildid x86-64 ELF; passes file(1) sanity.
pamtester smoke recipe lands in Task B2 alongside the test PAM stack file.
2026-04-27 08:18:57 -07:00
michael
0697ba1c65 feat(cli): D-Bus client wrapper + full subcommand dispatcher
Lands plan tasks C2 (Daemon proxy wrapping all 9 D-Bus methods via
Proxy::new_owned), C3 (status/list/policy-show), C4 (enroll/remove/policy-
set/apply/validate), and C5 (pending/recovery). Bundled because dispatch
needs the bus wrapper to compile cleanly under -D warnings.

Phase 4/5/12 placeholders in the dispatcher: policy apply re-saves to trigger
PolicyChanged; policy validate is a TOML round-trip; pending list and
recovery list are no-op messages until the corresponding D-Bus methods land.

5 clap-parser tests pass (was 5; same — parser shape unchanged in this
commit). Workspace clippy clean.
2026-04-27 08:18:17 -07:00