docs: record the answers received and the questions routed
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s

Six inbound messages attended, three of them carrying real asks.

flex-auth FLEX-DEC-2026-004 answers WARDEN-WP-0034-T05's decision-lifetime
question: a decision lifetime shorter than the certificate TTL is meaningful,
but only as authority to ISSUE, never to USE an already-issued certificate.
The question had mistaken a decision lifetime for a credential lifetime. They
declined to move the §9.7.2 revocation residue to their side; that refusal is
right and the stance map is unchanged. T05 still waits on ops-mason and
railiance-infra.

WARDEN-WP-0039-T03 routed to flex-auth: is there an admitted contract for a
delegated credential read where caller and resource owner differ? Three
outcomes named as equally acceptable, including that there should be no such
contract and the interim proxy transport is itself the defect -- which would
shorten WP-0033 rather than block it. Two easy fixes ruled out in writing:
broadening the caller binding, and relabelling resource.system as ops-warden
so the binding matches. The second would make the audit trail assert we own
credentials we deliberately do not, by editing a field instead of making an
argument.

WARDEN-WP-0037: npm path routed to railiance-platform, catalog unchanged
pending their answer. secrets-engine refused to resolve it from a
coordination message and was right; asserting our own pointer is
authoritative because it is ours would route around that. The ask names a
location only, and flags that a `bao kv get` answer would be the 2026-07-16
disclosure vector on a risk: high lane.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013EPuTc18FjU5WFqoSEKH3C

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1276224@bnt-lap001
Assistant-Session: 426ec497-e1c4-4dd3-b417-dfce1ca1dbc3
This commit is contained in:
tegwick 2026-09-09 16:40:46 +02:00
parent 1e3eb8df2a
commit 3aedd8f844
3 changed files with 88 additions and 0 deletions

View file

@ -74,3 +74,31 @@ authorized by this workplan alone. HFACT-WP-0001-T03 consumes this return.
Validation: 429 tests passed (4 integration tests deselected by the repository default); Ruff passed for changed Python files. Full tests used the declared phase-memory source and an isolated temporary memory store. The focused policy/proxy suite passed 69 tests. The existing authenticated SSH policy probe still returns HTTP 200/ALLOW, decision:f3f7c88f9585582a; the credential-owner request returns 403. No CA issue or credential read was performed by these probes.
Installed verification: source guard present after refreshed owner installation (`19bb75c`). `warden access forgejo-admin-api-token --exec --field API_TOKEN -- true` exits 4 with explicit HTTP 403 before credential transport or child execution. The previous fail-open warning is absent. The probe requested no output value; no credential was fetched. T01/T02 are complete; T03 owns the remaining exact policy-binding admission.
**T03 routed 2026-09-09.** Asked `flex-auth` whether an admitted contract exists
for a delegated credential read where the caller (ops-warden) and the resource
owner differ, since that is exactly the shape drawing the live 403. Three outcomes
were named as equally acceptable answers, with no preference stated between the
first two: an existing contract to conform to; no contract yet, making this a
design question they should raise rather than one ops-warden invents a shape for;
or that there should be **no** such contract — the interim proxy transport is
itself the defect and the answer is to finish the native handoff
(`WARDEN-WP-0033` / `SECRETS-WP-0006`).
The third is a real possibility and was not argued against. Eleven catalog lanes
are ops-warden proxies with a named intended owner precisely because no owner
front door exists; if delegated reads should not be made policy-admissible, that
shortens WP-0033 rather than blocking it.
Two fixes were explicitly ruled out in the message rather than left unmentioned:
broadening the ops-warden caller binding so it may read other systems' resources,
and relabelling `resource.system` as ops-warden so the existing binding matches.
The second is worse — it would make the audit trail assert ops-warden owns
credentials it deliberately does not, which is the claim `ADR-0002` exists to
prevent, achieved by editing a field instead of making an argument.
The refusal stays in place until an answer yields positive evidence plus
wrong-caller, wrong-owner and wrong-tenant negatives. No grant was requested.
`secrets-engine` was told this bears on SECRETS-WP-0007-T04 and on how many lanes
stay proxied; `gate-house` was told it may reach how the signing lane's
approval-consume is built (GH-DEC-2026-005).