Check the OpenBao half of the read-boundary; route RISK-F-0004
agent-high-risk-boundary denies 5 data paths, covering 6 of ops-warden's 17 high-risk lanes. Eight high-risk lanes with concrete KV paths are not denied, four of which were already graded high before the 2026-08-19 regrade — the divergence is pre-existing and the regrade only made the lists comparable. This is the layer that matters most: warden access exits 7 for all 17, but that protects only the ops-warden path. The policy protects a direct bao kv get, which is the 2026-07-16 vector. Routed to risk-nexus as RISK-F-0004 with fix_owner railiance-platform, since the policy is theirs. Live confirmation outstanding — ops-warden's OpenBao token is expired, so this is a static file-vs-catalog comparison and the finding says so rather than implying it was verified against the server. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
9fc5a735c6
commit
50e185ed7b
2 changed files with 25 additions and 4 deletions
|
|
@ -120,4 +120,4 @@
|
|||
| task | WARDEN-WP-0032-T03 | wait | — | workplans/WARDEN-WP-0032-security-zones.md |
|
||||
| task | WARDEN-WP-0032-T04 | wait | — | workplans/WARDEN-WP-0032-security-zones.md |
|
||||
| task | WARDEN-WP-0032-T05 | done | — | workplans/WARDEN-WP-0032-security-zones.md |
|
||||
| task | WARDEN-WP-0032-T06 | wait | — | workplans/WARDEN-WP-0032-security-zones.md |
|
||||
| task | WARDEN-WP-0032-T06 | progress | — | workplans/WARDEN-WP-0032-security-zones.md |
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue