Fix attended login result auditing and reconcile blocked workplans
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e6ef-4273-7fc2-8741-dc96b3e5fe0d
This commit is contained in:
tegwick 2026-09-28 09:44:49 +02:00
parent 940e164c9b
commit 4c3a0f4d3a
11 changed files with 260 additions and 32 deletions

View file

@ -33,8 +33,10 @@ workload KV-read lane and it does not provision a secret value.
and remain silent. Warden self-revokes the session and removes the helper on
every success or failure path.
Safety does not rely on `-no-print`. Any client or child output, helper
persistence defect, non-zero exit, or revocation/cleanup defect fails closed.
Safety does not rely on `-no-print`. Login output stays contained and is
accepted only after successful helper persistence. Any child output (including
whitespace), persistence defect, non-zero exit, or revocation/cleanup defect
fails closed.
Captured bytes are never returned, logged, excerpted, hashed, or fingerprinted.
Do not paste a token into chat, State Hub, a shell argument, or a handoff file.
Root is offline break-glass authority, not a fallback for failure.
@ -53,6 +55,34 @@ mount, `platform-admin` role, and allowed callback with `railiance-platform` and
`key-cape`. Do not retry with a workload-specific OIDC role: it is intentionally
incapable of OpenBao control-plane administration.
## Exit status and audit
After argument/configuration validation, the contained envelope returns:
| Exit | Audit outcome | Meaning |
| --- | --- | --- |
| 0 | `ok` | Login, silent child, self-revocation and cleanup succeeded. |
| 10 | `login_failed` | Login or private-home preflight failed; child did not run. |
| 11 | `child_failed` | Child could not start or exited non-zero. |
| 12 | `child_output` | Child emitted stdout/stderr, even whitespace; takes precedence over child exit failure. |
| 13 | `revoke_unconfirmed` | Child succeeded silently, but self-revocation was not confirmed. |
| 14 | `cleanup_failed` | Private storage cleanup failed; overrides the prior phase. |
Both `access-audit.log` and `audit.jsonl` record the Warden exit code and phase
outcome, never captured bytes. Revocation warnings accompany child failures too.
Codes 11–14 do not establish that the child made no changes: check its permitted
metadata receipt before retrying. A zero exit from `bao token revoke -self` is
Warden's revocation confirmation; no post-revoke lookup is used. An arbitrary
lookup failure would not prove revocation.
On the WSL workstation, use the ops-bridge `openbao-ui-railiance01` tunnel at
`http://127.0.0.1:18200` for `BAO_ADDR` and `VAULT_ADDR`, with the founder's TTY
and a working browser opener (`xdg-open`, or the configured OpenBao browser).
`bao.coulomb.social` serves a public notice, not OpenBao. The captured OIDC output
is not a browser fallback. Check the opener before starting an attended login.
The reviewed child must redirect both streams if its tools normally print success
messages; it should write only approved, value-free evidence to its own receipt.
## Authority
- OpenBao policy and role owner: `railiance-platform/docs/openbao.md`