Wire keychain status to local keychain ops

This commit is contained in:
Eric Wendland 2026-05-16 16:34:20 +02:00
commit 99f6dee26f
12 changed files with 191 additions and 20 deletions

View file

@ -138,11 +138,16 @@ resource-scoped capability decisions.
- JSON is not used as the signed representation.
- Tests verify equivalent operations hash/sign identically across runs.
- `[ ]` SSH-admin-rooted keychain initialization.
- `[~]` SSH-admin-rooted keychain initialization.
Acceptance criteria:
- `geth keychain init` records a signed `KeychainInit`.
- OpenSSH signature namespaces are explicit.
- Missing `ssh-keygen` or unavailable hardware keys produce clear errors.
- `[x]` `geth keychain init` records a local `KeychainInit`.
- `[x]` `geth keychain init --admin-key <path>` records an admin SSH public
key fingerprint.
- `[x]` `geth keychain status` reports the reduced local keychain view.
- `[ ]` Future completion records signed `KeychainInit` operations.
- `[ ]` OpenSSH signature namespaces are explicit in the signing flow.
- `[ ]` Missing `ssh-keygen` or unavailable hardware keys produce clear
errors during signing.
- `[x]` Keychain operation reducer.
Acceptance criteria: