Fix attended login result auditing and reconcile blocked workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6ef-4273-7fc2-8741-dc96b3e5fe0d
This commit is contained in:
parent
940e164c9b
commit
4c3a0f4d3a
11 changed files with 260 additions and 32 deletions
|
|
@ -4,14 +4,14 @@ type: workplan
|
|||
title: "Tamper-resistant credential governance + mass rotation/lockdown (Strand B)"
|
||||
domain: infotech
|
||||
repo: ops-warden
|
||||
status: active
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
owner: codex
|
||||
topic_slug: custodian
|
||||
planning_priority: medium
|
||||
planning_order: 27
|
||||
created: "2026-07-16"
|
||||
updated: "2026-08-23"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "21528e8d-a049-523d-9ae1-da7a27cb8bbf"
|
||||
---
|
||||
|
||||
|
|
@ -28,7 +28,7 @@ Strand A makes accidental disclosure structurally hard and gives every lane
|
|||
layer: turning that advisory guidance into one-command action and hardening policy
|
||||
governance against silent drift or malicious change.
|
||||
|
||||
## Status: active, narrowly on T02
|
||||
## Status: blocked on T02 (reviewed 2026-09-28)
|
||||
|
||||
Activated by the operator on 2026-08-22 after the second activation gate became
|
||||
concrete. `RAILIANCE-WP-0024-T03` now requires an approved recovery window,
|
||||
|
|
@ -40,7 +40,7 @@ heavyweight machinery.
|
|||
Activation is deliberately narrow. No mass-disclosure incident triggers T01,
|
||||
and no fleet policy currently mandates T03's signed policy-manifest reconcile.
|
||||
Those tasks remain `cancel`; cancellation here continues to mean deferred, not
|
||||
abandoned. T02 alone is `progress`.
|
||||
abandoned. T02 alone was activated; it now waits on a fresh attended drill.
|
||||
|
||||
## Activation gate (promote to `ready` only when ≥1 holds)
|
||||
|
||||
|
|
@ -89,7 +89,7 @@ each verified capabilities-safe, taint cleared only on success.
|
|||
|
||||
```task
|
||||
id: WARDEN-WP-0027-T02
|
||||
status: progress
|
||||
status: wait
|
||||
priority: medium
|
||||
state_hub_task_id: "cae498ee-6307-5d32-9f1b-a471cfcc2536"
|
||||
```
|
||||
|
|
@ -287,3 +287,12 @@ manifest, and an attended reconcile can restore it.
|
|||
approved ops-bridge unattended-signing design may still re-evaluate it
|
||||
cert_command cutover
|
||||
- `secrets-engine` `SECRETS-WP-0004` — the parked AppRole apply/handoff
|
||||
|
||||
### 2026-09-28 loose-end review
|
||||
|
||||
T02 now waits and the workplan is blocked. Source containment acceptance is
|
||||
already complete in railiance-platform's archived RPF-WP-0017; it is not a live
|
||||
drill receipt. The terminal August scenario remains consumed. Completion still
|
||||
requires a fresh platform-driven attended emergency seal/unseal scenario, fresh
|
||||
platform/infra/master receipts and a new founder GO. The cancelled T01/T03 stay
|
||||
cancelled. No ceremony, rotation or production mutation was performed.
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Layer model v0.7 conformance — state the deadline, bind the agent boundary, steward the estate's newest rule"
|
||||
domain: infotech
|
||||
repo: ops-warden
|
||||
status: active
|
||||
status: blocked
|
||||
flavor: implementation
|
||||
depends_on:
|
||||
- WARDEN-WP-0030
|
||||
|
|
@ -14,7 +14,7 @@ planning_priority: P1
|
|||
depends_on_workplans:
|
||||
- WARDEN-WP-0030
|
||||
created: "2026-08-29"
|
||||
updated: "2026-09-21"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "ae3ff76f-883d-5e2f-b6aa-144d61e8fdef"
|
||||
---
|
||||
|
||||
|
|
@ -336,3 +336,12 @@ layer-conformance script, and the declaration-route CLI smoke check pass.
|
|||
- `security-layer-model_v0.7.md` §3.4, §6.4, §9.6, §9.7, §11, §13.1
|
||||
- `net-kingdom/SECURITY-COMPANION.md` v0.2
|
||||
- `ADR-0002`, `ADR-0003`, `ADR-0004`, `ADR-0005`, `ADR-0009`, `ADR-0010`
|
||||
|
||||
### 2026-09-28 loose-end review
|
||||
|
||||
T05 remains wait; the workplan is blocked on the two outstanding owner answers.
|
||||
The local ops-mason checkout still has no published stance map, and the available
|
||||
railiance-infra workplans/docs contain no KRL-versus-TTL acceptance or refusal.
|
||||
The flex-auth decision-lifetime answer remains accepted. Warden's declaration,
|
||||
TTL-bound tests and fresh-check behavior are complete; inventing an owner answer
|
||||
would not satisfy T05. No certificate lifetime or revocation policy was changed.
|
||||
|
|
|
|||
|
|
@ -8,7 +8,7 @@ status: finished
|
|||
owner: codex
|
||||
topic_slug: attended-login-openbao-output
|
||||
created: "2026-09-01"
|
||||
updated: "2026-09-01"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "d844c96e-152d-53fa-bff6-e072125ef66c"
|
||||
---
|
||||
|
||||
|
|
@ -41,3 +41,28 @@ OpenBao platform-admin operation with deterministic self-revocation.
|
|||
Completed 2026-09-01. The installed CLI completed the governed Policy Nexus
|
||||
Forgejo source bootstrap with all child output contained, then revoked and
|
||||
removed its isolated helper session.
|
||||
|
||||
### 2026-09-28 contained-result correction (existing T01/T02)
|
||||
|
||||
Addressed the September 21 attended-login failure/audit report under the existing
|
||||
handoff repair and verification tasks. Failed envelopes now use distinct
|
||||
non-zero codes 10–14 for login, child failure, child output, unconfirmed revocation
|
||||
and cleanup failure. Both audit files retain the actual Warden exit code and
|
||||
phase outcome. Any child bytes, including whitespace, fail closed; the access
|
||||
advisory now states the silent-child requirement and the playbook documents codes,
|
||||
retry limits and the WSL tunnel/browser requirements.
|
||||
|
||||
The pre-change checkout already raised exit 5 on ProxyError, so the reported
|
||||
historical exit-zero failure was not reproduced here. The actual reproduced defect
|
||||
was unconditional success auditing; the new CLI regression covers failed login
|
||||
with returncode zero but missing persistence as well as non-zero login, start
|
||||
failures, child output/failure, revocation and cleanup. Revocation still checks
|
||||
revoke-self's exit status; it does not misinterpret an arbitrary failed lookup as
|
||||
proof. The September 23 platform return confirms revoke-self is already granted.
|
||||
|
||||
Validation: focused proxy suite 48 passed; full suite 483 passed, 4 integration
|
||||
tests deselected by repository default; changed Python files pass Ruff. No live
|
||||
OIDC, credential read or production operation was used. The earlier September 1
|
||||
live operation remains historical evidence, not a live validation of this change.
|
||||
Automated endpoint/browser preflight and OIDC URL presentation remain optional
|
||||
inbox suggestions, outside these completed handoff acceptance criteria.
|
||||
|
|
|
|||
|
|
@ -4,12 +4,12 @@ type: workplan
|
|||
title: "Repoint the whynot-design npm lane to Forgejo"
|
||||
domain: infotech
|
||||
repo: ops-warden
|
||||
status: active
|
||||
status: blocked
|
||||
flavor: planning
|
||||
owner: codex
|
||||
topic_slug: whynot-design-forgejo-npm-lane
|
||||
created: "2026-09-04"
|
||||
updated: "2026-09-27"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "42a097db-1c24-558e-a724-030bb2b4443e"
|
||||
---
|
||||
|
||||
|
|
@ -174,3 +174,12 @@ T03 remains wait and the founder's no-rotation hold remains effective.
|
|||
Resume only on the SECRETS-WP-0006-T06 migration receipt, then rotate through
|
||||
the dedicated package lane and prove a fresh publish plus exact npm view.
|
||||
Do not treat the September 16 OpenRouter key-check receipt as npm acceptance.
|
||||
|
||||
### 2026-09-28 loose-end review
|
||||
|
||||
Workplan state corrected to blocked to match T03's wait and the September 27
|
||||
owner return. The governed catalog field and path are already correct. The
|
||||
founder's no-rotation hold remains binding until SECRETS-WP-0006-T06 supplies
|
||||
native governed-consumer migration evidence; a dedicated token rotation and a
|
||||
fresh package publish/exact-version lookup then remain. No credential fetch,
|
||||
rotation or publication was attempted.
|
||||
|
|
|
|||
|
|
@ -9,7 +9,7 @@ flavor: residual
|
|||
owner: codex
|
||||
topic_slug: custodian
|
||||
created: "2026-09-08"
|
||||
updated: "2026-09-08"
|
||||
updated: "2026-09-28"
|
||||
origin: residual
|
||||
origin_ref: HFACT-WP-0001
|
||||
state_hub_workstream_id: "ae44a935-6fca-514c-a385-4550dd2b1fe8"
|
||||
|
|
@ -106,3 +106,13 @@ wrong-caller, wrong-owner and wrong-tenant negatives. No grant was requested.
|
|||
`secrets-engine` was told this bears on SECRETS-WP-0007-T04 and on how many lanes
|
||||
stay proxied; `gate-house` was told it may reach how the signing lane's
|
||||
approval-consume is built (GH-DEC-2026-005).
|
||||
|
||||
### 2026-09-28 loose-end review
|
||||
|
||||
T03 remains wait and the workplan remains blocked. Re-read the owner's finished
|
||||
FLEX-WP-0026: no admitted delegated-read binding exists, and its native OpenRouter
|
||||
contract explicitly does not close WARDEN-WP-0039-T03. FLEX-DEC-2026-015 also
|
||||
confirms resource.system is runtime policy vocabulary, not a repository rename.
|
||||
Retain the explicit refusal. A native owner route's success does not grant this
|
||||
interim proxy general delegated-read authority; exact positive and caller/owner/
|
||||
tenant negative evidence is still required for the route that replaces it.
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ type: workplan
|
|||
title: "Adopt unknown -> fail_closed behind signing-target classification coverage"
|
||||
domain: infotech
|
||||
repo: ops-warden
|
||||
status: proposed
|
||||
status: blocked
|
||||
flavor: planning
|
||||
depends_on:
|
||||
- WARDEN-WP-0032
|
||||
|
|
@ -16,7 +16,7 @@ depends_on_workplans:
|
|||
- WARDEN-WP-0032
|
||||
- WARDEN-WP-0034
|
||||
created: "2026-09-09"
|
||||
updated: "2026-09-09"
|
||||
updated: "2026-09-28"
|
||||
state_hub_workstream_id: "c8ee441e-1be1-5219-910c-e79ff23cc9ec"
|
||||
---
|
||||
|
||||
|
|
@ -43,7 +43,7 @@ So: coverage first, then the cell. That ordering is the whole holding of
|
|||
|
||||
```task
|
||||
id: WARDEN-WP-0040-T01
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "611f0901-9fb5-5954-8dd0-a860c5f0cbec"
|
||||
```
|
||||
|
|
@ -65,7 +65,7 @@ outcome this workplan exists to prevent.
|
|||
|
||||
```task
|
||||
id: WARDEN-WP-0040-T02
|
||||
status: todo
|
||||
status: wait
|
||||
priority: high
|
||||
state_hub_task_id: "54ad4864-7bcf-592e-a187-9239a81a0b11"
|
||||
```
|
||||
|
|
@ -114,7 +114,7 @@ or the test fails — which is the property that makes the map worth publishing.
|
|||
|
||||
```task
|
||||
id: WARDEN-WP-0040-T04
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
state_hub_task_id: "222a8c5d-0c0f-5a1d-98d8-02be7dca3358"
|
||||
```
|
||||
|
|
@ -154,3 +154,30 @@ adopted.
|
|||
T01–T03 are unchanged and still gate the conversion. Coverage is now measured
|
||||
rather than asserted (`scripts/report_coverage.py`), so T02's reporting obligation
|
||||
has a tool behind it and the published figure cannot drift from the register's.
|
||||
|
||||
### 2026-09-28 loose-end review
|
||||
|
||||
T04 is done: GH-DEC-2026-011 already answered both transition asks on September 9;
|
||||
the accepted coverage column and declared-gap disposition are recorded above.
|
||||
No additional response is required to meet that task's acceptance criterion.
|
||||
|
||||
T01/T02 now wait; the workplan is blocked. Re-ran both coverage reports:
|
||||
signing targets = 0 resolved / 3 unknown / 1 not-applicable; routing lanes =
|
||||
3 resolved / 20 unknown / 15 not-applicable. Refreshed pep-stance.yaml's measured
|
||||
date. These figures describe the checked-in registry and local owner declarations,
|
||||
not a live PDP query. No zone membership was inferred or changed.
|
||||
|
||||
The exact missing workload resolutions are `ops-bridge-tunnel` for
|
||||
`agt-state-hub-bridge`, `codex-interhub-bootstrap` for
|
||||
`agt-codex-interhub-bootstrap`, and `backup-daily` for `atm-backup-daily`.
|
||||
The seed inventory's `adm-example` is not an admitted repair actor.
|
||||
Warden's own workload declaration cannot classify those target workloads.
|
||||
T01 needs an owner-declared continuity actor/target and its authoritative
|
||||
z2-continuity resolution; T02 retains the owner-routing/declaration follow-up
|
||||
(ops-bridge, the Inter-Hub execution owner and the backup execution owner).
|
||||
Without it, changing unknown to fail_closed would deny their issuance during a
|
||||
PDP outage. Coverage reporting is complete, but owner coordination is not.
|
||||
|
||||
T03 also remains gated on standard acceptance: the local authoritative
|
||||
net-kingdom/canon/standards/security-layer-model_v0.8.md still says proposed.
|
||||
No superseding ADR or runtime stance change is warranted before these gates.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue