Skip to content

research: prepare a GCM-informed MSA probe configuration - #52

Merged
hcoona merged 2 commits into
main-v2from
research/windows-msal-gcm-msa-path
Sep 11, 2026
Merged

hcoona merged 2 commits into
main-v2from
research/windows-msal-gcm-msa-path

Conversation

@hcoona

@hcoona hcoona commented Sep 11, 2026

Copy link
Copy Markdown
Owner

Summary

The attended probe used common with MSA passthrough disabled and returned an unexplained broker error. Prepare one source-informed comparison using organizations, MSA passthrough, and GCM's conditional MSA transfer-tenant rule for silent reuse. Wait for a fresh operator readiness response before any account action.

Authorization and Governing Records

The accepted Delivery Wave architecture and feasibility entry and Issue #35 cover the same designated host, personal account, and single Git discovery target. The existing experiment policy and amended Windows protocol govern execution; this proposal cannot authorize a build before acceptance.

Scope and Non-Goals

Change only the research probe, its cumulative launcher limits, the existing protocol, and pinned source findings. Preserve eleven completed Windows actions. Add one preparation and one interaction, with the existing final silent action conditional on exact-account success and recognized discovery. No product implementation, Profile selection, GCM execution, new endpoint, additional discovery request, dependency upgrade, or failure retry.

Record-System Impact

Update the existing Windows MSAL protocol and V1 public-contract baseline families. Probe code remains the linked research subject. No new family, policy, control, schema, or navigation route.

Evidence and Reasoning

Pinned GCM v2.9.1 source enables MSA passthrough for Azure Repos, selects organizations when its service discovery identifies an MSA-backed organization, and uses the public MSA transfer tenant for selected-account silent acquisition. MSAL 4.83.1 already exposes these APIs. The experiment fixes organizations as a candidate: the designated target's backing directory and installed GCM authority are unknown. This is a paired-configuration comparison, not GCM reproduction or proof of the previous error's cause. Historical observations remain unchanged and no new runtime result is claimed.

Identity and Security Effects

Keep the same Microsoft-owned client, scope, exact account selection/result validation, corporate-session Windows host, WSL initiation, in-memory input transport, and Windows-only token handling. The transfer rule uses only the unique account's home-tenant metadata in memory and exports a Boolean. Normal selected-account WAM/session effects remain permitted; no corporate fallback, PAT, account/tenant administration, cache clearing, or repository writes. Discovery remains capped at three cumulative requests. Sign-in, account choice, MFA, unlock, and consent remain operator-controlled. Logging, deadlines, termination, and retention remain unchanged.

Validation

Local hk commit checks passed, including repository records, links, gitleaks, and all 32 public-build runner conformance groups. GitHub CI remains a required merge gate. Independent research-evidence and record-system review passed for tree b1947fc8579dbc7117ee1bbaaed87195bb3e3017. After merge, the single permitted Windows preparation must restore the retained seven packages, compile, run the existing synthetic self-check, and verify source/artifact/runtime identities. No pre-merge experiment or readiness-test launch is permitted.

Review and Disposition

Review against accepted main-v2 8f2303d3b6d9f279a8fd9a76ddf9daef96ddb62e; final independent review identifies the reviewer and exact tree. Independent triage preceded correction of GCM-1; no material finding remains open. All seven rechecks evaluated: 001/002/006 retain their product-contract dispositions; 003/005 retain the accepted Windows-host research boundary without selecting WSL/Linux support; 004 remains outside the rejected browser path; 007 remains unresolved before any Profile choice. No typed decision/workstream/release trigger or Wave change is introduced. Route any material finding to independent triage before implementation. No new owner risk decision is needed inside the accepted effects envelope.

Upstream Provenance

Configuration and conditional silent-tenant logic derived from git-ecosystem/git-credential-manager v2.9.1, commit 6760f0ef069c994aa2bb1d703fb374986ee82a3e, with exact source links in the baseline. API basis: Microsoft MSAL.NET 4.83.1, commit d5d7de6b103f0d9dd7bca9bf13cbb9f3da37bc9f. No upstream production implementation is imported.

Compare organizations authority and MSA passthrough with the prior attended failure.
Preserve exact-account checks, bounded discovery, cumulative history, and the
explicit readiness handoff; include the conditional MSA silent transfer tenant.

Refs: #35
Resolve independently triaged GCM-1 by stating the amended remaining capacity
and prospective preparation gate while preserving stopped historical outcomes.

Refs: #35
@hcoona

hcoona commented Sep 11, 2026

Copy link
Copy Markdown
Owner Author

Independent finding triage for GCM-1

Originating reviewer: /root/preparation_review. Independent triager: /root/discovery_finding_triage, independent of the author/implementer /root and originating reviewer.

Reviewed tree: 67e189547cb9f54e4cd41b7cdebd98502cc74444; accepted base: 8f2303d3b6d9f279a8fd9a76ddf9daef96ddb62e.

Finding: the protocol current-consumption paragraph outside Execution History still says prepare 6/6, interactive 3/3, and stopped, conflicting with the proposed limits and procedure permitting preparation 12 / interaction 13. Accepted AGENTS stops execution on canonical conflicts; experiment policy requires recoverable remaining capacity.

Disposition: true positive, blocking, confidence 10/10. Smallest action: change only the current-consumption paragraph to 6/7 and 3/4, preserve all eleven completed actions and historical stopped outcomes, and make preparation 12 prospective after acceptance/preflight with fresh readiness required for account actions. No new owner decision is needed. This disposition preceded the corrective edit. The corrected tree requires final independent review.

@hcoona

hcoona commented Sep 11, 2026

Copy link
Copy Markdown
Owner Author

Final independent review

Reviewer: /root/preparation_review, independent of author/implementer /root.
Accepted main-v2 base: 8f2303d3b6d9f279a8fd9a76ddf9daef96ddb62e.
Exact reviewed tree: b1947fc8579dbc7117ee1bbaaed87195bb3e3017.
Carrier: this PR description and four-file change.

  • research-evidence-review: No material findings.
  • record-system-review: No material findings.

GCM-1 was independently triaged by /root/discovery_finding_triage before correction and is resolved in this exact tree. Current capacity now agrees with the advancement, launcher, and procedure; all eleven consumed actions and historical stopped outcomes remain.

The reviewer independently verified pinned GCM/MSAL source/API evidence, the fixed organizations candidate's distinction from GCM discovery and the unknown target backing directory, strict account/result/resource gates, dependency pins, in-memory home-tenant inspection with Boolean output, finite cumulative limits, post-acceptance preparation, and fresh operator readiness. All seven rechecks were considered with no product/Profile/support selection. No experiment or private configuration/account/resource access occurred during review. Mechanical hk/CI results are separate acceptance evidence.

@hcoona
hcoona merged commit e76a8b0 into main-v2 Sep 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant