Bind OpenBao builds to approved inputs and secure credential delivery
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
parent
ee1dc2b651
commit
2b83324c01
8 changed files with 622 additions and 84 deletions
|
|
@ -130,6 +130,18 @@ approved (`test_refusal_never_calls_bao`); role_id/secret_id land as
|
|||
`0600` files and never appear in a log line or exception message; the
|
||||
policy HCL goes over stdin, never argv.
|
||||
|
||||
**Hardening follow-up (2026-09-28).** The existing build executor now binds
|
||||
execution to a reviewed `build_spec` plus `approved_spec_sha256`, reloads the
|
||||
approval before use, validates literal scope/token/binding inputs, and pins
|
||||
existing policy contents. Credential files are exclusively created as 0600
|
||||
inside caller-owned 0700 directories before issuance, with symlinks and
|
||||
existing destinations refused. Command errors suppress sensitive output.
|
||||
Historical build approvals were not rewritten and no live lane was changed.
|
||||
The suite passes 108 tests, including refusal-before-mutation, policy drift,
|
||||
permissive-umask, symlink/hardlink/overwrite and error-output regressions.
|
||||
The source contract and recovery limitations are documented in
|
||||
`docs/construction-plan-format.md`. This is maintenance of T04, not a new task.
|
||||
|
||||
```task
|
||||
id: MASON-WP-0001-T04
|
||||
status: done
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue