rdmsm4x-changelog-20260902-1929-tyrell-build13-cloudkit-hardening-delta-audit
rdmsm4x changelog — Tyrell Build 13 CloudKit hardening delta audit
Audited only the hardening delta from
e0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c to exact HEAD
02bc5403fb9056b180149e986bf82505dd23ae35, confirming the
prior public injectable/direct-save risks are closed at the external API
boundary.
Scope
- Host:
rdmsm4x - Worktree:
/Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902 - Delta:
e0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c..02bc5403fb9056b180149e986bf82505dd23ae35 - Delta tree:
04f1f8aa7142a1cb9df25b904509089b5043161e - Changed files:
Sources/TyrellCloudProjection/ECSCloudKitSnapshotTransport.swift,Tests/TyrellCloudProjectionTests/ECSCloudKitSnapshotTransportTests.swift - No repo/worktree source edit, merge, publication, signing, deployment, credential, CloudKit, service, or live-network mutation.
Verification
swift test --package-path /Users/richh/dev/_worktrees/tyrell-build13-cloudkit-transport-20260902 --scratch-path /tmp/tyrell-build13-cloudkit-hardening-20260902/swiftpm --skip-build --filter 'TyrellCloudProjectionTests'→ exactTyrellCloudProjectionTests.xctest17/17, zero failures;swift_exit=0,pipeline_status=0.- Focused log:
/Users/richh/dev/_handoff/tyrell-build13-cloudkit-transport-hardening-focused-status-20260902.log - Focused log SHA-256:
80685158aaffbef6087f1aec2189d3388e6806095130551e31c6538a90b962b5 - Updated audit packet:
/Users/richh/dev/_handoff/tyrell-build13-cloudkit-transport-independent-audit-20260902.md - Updated packet SHA-256:
62f8e040148296db5b57b995b6119c0d794030cec4a38c622df47c7662d4980b git diff --check e0d5cf5430e6cc8cad4f56b1413ed0155b1cee6c..02bc540passed.- Worktree status was clean at exact HEAD before and after the audit.
Hardening findings
- Public
TyrellECSCloudKitSnapshotTransportinitializer now accepts only explicit write authorization; it fixes the container toiCloud.com.eastcoastscience.Tyrell, uses the real entitlement probe withassumeEntitledWithoutEmbeddedProfile: false, and uses the realCloudKitSyncDatabasefactory. - Entitlement/database injection aliases and initializer are internal test-only seams, not externally callable production API.
- Direct
saverejects any non-canonical zone, decodes and validates the record, re-encodes it through the canonical codec, compares canonical type/name/fields, and only then constructs the authorized database. - New regression coverage rejects foreign-zone and unsanitized records with zero database factory construction and zero database calls.
- Overall delta verdict: hardening accepted; prior public direct-save/injectable-seam risks closed at the external API boundary.
- Overall production publication remains no-adopt/no-publish pending signed/provisioned artifact, real account/zone/schema evidence, controlled sanitized fixture write, reader confirmation, canary, and rollback gates.
Residual risk and owner action
- The internal test initializer must remain internal; future access-level changes must not reopen the injection seam.
- Canonical comparison intentionally ignores
systemFieldsandmodifiedAt, which are transport metadata for compare-and-swap, while comparing all sanitized user fields, record type, and deterministic record name exactly. - The owner may integrate the hardening source candidate for further review, but must keep runtime publication unwired until the separately authorized production CloudKit gates pass.
Backup and undo
No source or runtime state changed. Audit artifacts remain under
/Users/richh/dev/_handoff; SwiftPM scratch output is under
/tmp/tyrell-build13-cloudkit-hardening-20260902. Removing
only these audit artifacts is the reversible undo.