fix: recheck policy decision expiry after audit custody
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 15:56:52 +02:00
parent 72f3513954
commit f11b948e8c
7 changed files with 126 additions and 8 deletions

View file

@ -449,6 +449,27 @@ Validation: `make ci-check` passed **399 ordinary tests** (two opt-in modules
skipped), inventory drift, distribution/isolated-wheel checks and **six disposable
PostgreSQL tests**.
## Decision lifetime continuation — 2026-09-28
Closed an authorization timing gap: policy verification previously discarded the
signed decision lifetime, allowing audit custody to finish after a decision had
expired. `Decision.valid_until` now carries the earliest signed allow expiry,
caller expiry and decision freshness deadline. It is mandatory and finite for
all policy adapters. The shared controller checks it before audit and again
before returning an allow to HTTP/browser/SDK callers. Expiry returns `503` and
marks policy readiness unavailable; the existing authorization receipt remains
an attempt, with no business mutation or committed outcome.
Local regression tests exercise each signed deadline source, invalid adapter
deadlines, already-expired decisions, exact-boundary expiry during custody and
a valid write. The [candidate profile](../docs/access-profile-v1.md) documents
the adapter contract change. T03/T04 remain `progress`; this does not establish
live owner admission or deployment acceptance.
Validation: **411 ordinary tests**, **six disposable PostgreSQL tests** and
**six Audit Core owner-source tests** pass. The full `make ci-check` inventory,
build and isolated installed-wheel gates pass.
## Acceptance checkpoints
- [x] Architecture/source/runtime review captured; new implementation owner is hub-core