Commit Graph

6 Commits

Author SHA1 Message Date
operator 6d2cbabe34 feat(ssh): mint and register def@netvm signing key, authorize fleet keys (dev, pip, 646, opm, def) on front-door VM 2026-10-09 12:56:34 +00:00
operator 26535791e5 feat(auth): provision SSH signing keys for 646 and opm and register in allowed_signers 2026-10-05 15:27:34 +00:00
operator 61cf9d027b feat(signers): register operator-dev and dev public keys in allowed_signers 2026-10-05 01:38:07 +00:00
operator 741e5952d4 feat(signers): register operator-pip and pip public keys in allowed_signers 2026-10-05 01:29:08 +00:00
operator 1a271b1bbd feat(hybrid-gateway): integrate muse-cli with Cloudflare netns isolation, symmetric sidechat routing, and 646-pip sync unblock 2026-10-04 22:54:01 +00:00
operator-main d82bf58e78 DM: signed-DM pipeline (dm-sign.sh) + attribution unification + honest docs
- New bin/dm-sign.sh: produce signed DMs (ssh-keygen -Y sign, namespace
  dm) in the [from:X] [id:Y] wire format that dm.py verify-sig checks.
  dm.py referenced it in usage but it never existed.
- dm.py: rewrite stale docstring/argparse (claimed verification was
  removed / delivery unconfirmed — it does recipient-side read-back with
  3 retries); unify all attribution on [from:X]/[id:Y] (was three
  formats: [from X], [X], [from:X]); fix dm_thread double-attribution;
  --no-verify kept as a documented no-op; raw mode sends verbatim and
  reuses the embedded [id:Y] for the audit log; navigation/send/park
  now all target the recipient browser (fixes cross-operator side-chat
  sends); drop dead --from-sender flag.
- Register dm-signers/operator-main.pub.
- Round-trip verified: sign (operator-main) -> send --raw via opm
  loopback -> read-back SENT+VERIFIED -> verify-sig GOOD.
2026-10-04 02:31:37 +00:00