Vault CLI and Python reference audit
2026-09-15 — CLI 0.20.2 published
CLI 0.20.2 publishes the reviewed transport fix from isolated source b527b60, based on 0.20.1 and excluding concurrent queue/Notes changes. All eight public native binaries and the manifest match the reviewed hashes. A fresh public macOS ARM64 binary passed all 34 HTTP/PTY import checks. Native latest was guarded at 0.20.1, promoted, and read back as 0.20.2; shared installers were preserved. The exact source tag and GitHub manifest were independently read back.
Patch validation: 1,028 source tests/typecheck, nine compiled transport checks, eight builds and 34-page docs build/generated checks passed. This differs from the earlier main-branch 1,251-test result below because the patch deliberately excludes later features. No Python release was needed.
All eight npm platform tarballs and the wrapper now match the reviewed bytes. A fresh isolated registry installation verified the native binary hash and passed the same 34 HTTP/PTY checks. No uncertain upload was repeated. A concurrent npm latest 0.21.0 was preserved; next advanced from 0.20.1 to 0.20.2. The per-tag check did not stop that next advancement after detecting the competing release; this limitation was reported, and review directed preserving all current channels without a corrective mutation. No latest-channel coherence is claimed. Use an exact version to select this patch:
Publication receipt. This is publication evidence, not hosted private execution or broad checklist completion.
2026-09-15 — Guide correction and bounded acceptance
Tracking: Vault #241 · Master #247.
The credential guide incorrectly described HOTP upload and generation as unsupported. Published CLI 0.20.1 and Python 0.16.1 support selected inactive HOTP import, explicit counter ownership and durable request-file issuance/recovery. The guide now pairs the actual CLI flags with Python activate_otp and otp calls. It also replaces obsolete blanket proposed-status statements for host saving and Prefix KMS with links to their bounded release/acceptance evidence. Historical preview-only notes remain dated history.
| Requirement | Verified evidence | Remaining boundary |
|---|---|---|
| Canonical routing and help | Native 0.20.1 vault import --ssh / --pass-otp, source exclusion and legacy aliases exercised by existing import tests. --pass remains unsupported. | No ordinary pass upload promise. This does not cover every Vault command. |
| Conflicting selectors and prefixes | The same real native subprocess suite checks missing/multiple source flags and prefix placement/conflicts before source reads/network. | Unknown/dotted paths still follow command-specific validation. |
| Explicit selection and consent | Real PTY checklist selection, default cancellation, Ctrl-C, source changes, key selection and partial retry/cancel run against native artifacts. | Synthetic sources and loopback HTTP; no user store read. |
| Uncertain writes | Published native 0.20.1 passed 32/34; two dropped PUT checks exposed hidden transport retries. CLI #83 candidate passes 34/34 and 9 compiled transport checks; removing its fix fails 4 PUT/DELETE checks. | Candidate fix is not publication evidence. Server guards prevent assuming two HTTP submissions mean duplicate stored resources. |
| Python parity | 69 tests passed against the freshly installed public 0.16.1 wheel: selected SSH import, OTP import, real synthetic GPG preview/parser and durable HOTP intent. Tests were copied outside repository conftest/source-path injection; imported module is in the public environment's site-packages. | MockTransport/decryptor and local GPG boundaries, not a new hosted HTTP/Mongo cross-client run. |
| Help and generated references | Public help matches the guide's flag names; CLI candidate docs build 38 indexed pages and generated-reference check passed. No CLI signature changed. | Whole-workspace generated output has unrelated existing drift; this guide edit is not a broad generated-reference completion claim. |
The CLI candidate also passed 1,251 source tests/typecheck with zero skips. The native regression used Bun 1.3.14 and actual compiled code; source-mode Node alone had missed it. Python's source tests separately passed the same 69 cases. No release, runtime deployment, remote password mutation or user credential upload occurred during this audit. The broad help/generated-reference/integration checkbox remains open pending its remaining cross-client and hosted coverage.
HOTP ownership and recovery reference · Native transport audit.