ops-warden/workplans/WARDEN-WP-0036-attended-login-openbao-output.md

69 lines
2.8 KiB
Markdown
Raw Normal View History

---
id: WARDEN-WP-0036
type: workplan
title: "Accept contained OpenBao login output only after helper persistence"
domain: infotech
repo: ops-warden
status: finished
owner: codex
topic_slug: attended-login-openbao-output
created: "2026-09-01"
updated: "2026-09-28"
state_hub_workstream_id: "d844c96e-152d-53fa-bff6-e072125ef66c"
---
## Repair attended-login handoff
```task
id: WARDEN-WP-0036-T01
status: done
priority: high
state_hub_task_id: "7eb8b9c9-1285-5ada-a17b-1d5bfbb8ba59"
```
Allow a successful OpenBao login to proceed when its output is fully contained
and the private mode-0600 token helper is populated. Continue failing closed on
non-zero login, missing persistence, child output, revocation failure, or cleanup
failure.
## Verify live contained operation
```task
id: WARDEN-WP-0036-T02
status: done
priority: high
state_hub_task_id: "d22bab05-c38b-561f-95de-6c146ce7c6cf"
```
Run the proxy regression suite, reinstall the CLI, and complete one governed
OpenBao platform-admin operation with deterministic self-revocation.
Completed 2026-09-01. The installed CLI completed the governed Policy Nexus
Forgejo source bootstrap with all child output contained, then revoked and
removed its isolated helper session.
### 2026-09-28 contained-result correction (existing T01/T02)
Addressed the September 21 attended-login failure/audit report under the existing
handoff repair and verification tasks. Failed envelopes now use distinct
non-zero codes 10–14 for login, child failure, child output, unconfirmed revocation
and cleanup failure. Both audit files retain the actual Warden exit code and
phase outcome. Any child bytes, including whitespace, fail closed; the access
advisory now states the silent-child requirement and the playbook documents codes,
retry limits and the WSL tunnel/browser requirements.
The pre-change checkout already raised exit 5 on ProxyError, so the reported
historical exit-zero failure was not reproduced here. The actual reproduced defect
was unconditional success auditing; the new CLI regression covers failed login
with returncode zero but missing persistence as well as non-zero login, start
failures, child output/failure, revocation and cleanup. Revocation still checks
revoke-self's exit status; it does not misinterpret an arbitrary failed lookup as
proof. The September 23 platform return confirms revoke-self is already granted.
Validation: focused proxy suite 48 passed; full suite 483 passed, 4 integration
tests deselected by repository default; changed Python files pass Ruff. No live
OIDC, credential read or production operation was used. The earlier September 1
live operation remains historical evidence, not a live validation of this change.
Automated endpoint/browser preflight and OIDC URL presentation remain optional
inbox suggestions, outside these completed handoff acceptance criteria.