Bind OpenBao builds to approved inputs and secure credential delivery

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e75a-fc5c-7913-9dba-9846210c766d
This commit is contained in:
tegwick 2026-09-28 11:55:39 +02:00
parent ee1dc2b651
commit 2b83324c01
8 changed files with 622 additions and 84 deletions

View file

@ -130,6 +130,18 @@ approved (`test_refusal_never_calls_bao`); role_id/secret_id land as
`0600` files and never appear in a log line or exception message; the
policy HCL goes over stdin, never argv.
**Hardening follow-up (2026-09-28).** The existing build executor now binds
execution to a reviewed `build_spec` plus `approved_spec_sha256`, reloads the
approval before use, validates literal scope/token/binding inputs, and pins
existing policy contents. Credential files are exclusively created as 0600
inside caller-owned 0700 directories before issuance, with symlinks and
existing destinations refused. Command errors suppress sensitive output.
Historical build approvals were not rewritten and no live lane was changed.
The suite passes 108 tests, including refusal-before-mutation, policy drift,
permissive-umask, symlink/hardlink/overwrite and error-output regressions.
The source contract and recovery limitations are documented in
`docs/construction-plan-format.md`. This is maintenance of T04, not a new task.
```task
id: MASON-WP-0001-T04
status: done