docs: record native audit sender delivery and reload
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
tegwick 2026-09-11 10:32:20 +02:00
parent a8058ee342
commit a2173c6cc4
4 changed files with 157 additions and 2 deletions

View file

@ -71,7 +71,7 @@ The ingress rule is narrower than `user-engine`'s: namespace **and** pod label
in a single `from` peer, so both are ANDed. A new sender should not inherit an
older rule's breadth. `user-engine`'s sender and its policy are unchanged.
## Still owed by others
## Original owner handoff (current delivery recorded below)
| Input | Owner | Note |
| --- | --- | --- |
@ -115,3 +115,20 @@ omission at all — T04 does. So a consumer waiting on T02 before trusting
approval evidence would be waiting on the wrong control. Until T04 and T06
land, Audit Core cannot detect a suppressed revocation, and no reading of the
chain, attested or not, changes that.
## Native delivery return — 2026-09-11
The token is now independently held in OpenBao and delivered through its exact
ESO projection. Namespace restrictions, sibling/full-registry/metadata/listing
denials, wrong-SA/namespace refusals and the coding-agent boundary passed
natively. Registry version 8 was compared exactly before Audit Core reloaded;
receiver c82e0442 is Ready and operational/durable. The admitted manifests and
sender ingress are applied. See the
[native receipt](evidence/2026-09-11-factory-audit-delivery-live.json).
Remaining admission evidence is actual producer accepted/duplicate delivery,
receiver source/tenant/read refusal, independent readback and audit bearer
revocation. No native producer event or operational heartbeat is claimed by
the custody receipt. Attestation/offsite operation remains a separate evidence
quality bound in AUDIT-WP-0009-T12.