ops-warden/workplans/WARDEN-WP-0039-explicit-policy-refusal.md
repo-manager 589d9067da
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
repo.work.assign_missing_identifiers
source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-5.6-luna
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
2026-09-08 17:04:02 +02:00

76 lines
3.7 KiB
Markdown

---
id: WARDEN-WP-0039
type: workplan
title: "Preserve explicit policy caller refusals before credential and CA effects"
domain: infotech
repo: ops-warden
status: blocked
owner: codex
topic_slug: custodian
created: "2026-09-08"
updated: "2026-09-08"
origin: residual
origin_ref: HFACT-WP-0001
state_hub_workstream_id: "ae44a935-6fca-514c-a385-4550dd2b1fe8"
---
The factory critical-path review reproduced a live HTTP 403 from the reachable
PDP for the configured ops-warden caller and a railiance-platform secret read.
`check_fetch_policy` treated it as evaluator unavailability and used unknown-zone
fail-open. Caller-auth rejection is an explicit refusal, not a transport outage.
## Preserve explicit authentication and binding refusals
```task
id: WARDEN-WP-0039-T01
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "eaad08d9-ae47-5f50-8278-ea402a0e2869"
```
HTTP 401 and 403 stop signing and credential fetch irrespective of the outage
profile. Do not expose response bodies or alter system identity to bypass the
refusal. Preserve configured behavior for genuine evaluator failures. Prove
both permissive and closed outage profiles and refusal before child execution.
## Verify and publish the correction
```task
id: WARDEN-WP-0039-T02
status: done
priority: high
assignee: the-custodian
state_hub_task_id: "ac85cf00-391c-5c63-b8f4-ed5bd57684e5"
```
Run the policy and proxy suites, retain a value-free live refusal receipt,
publish the reviewed source, and verify the installed CLI refuses before any
credential transport. A refusal is not a successful credential-read admission.
The owner installer initially reused a cached wheel despite `--force`, leaving
the pre-fix policy code installed. Both Makefile installation targets now use
`--reinstall-package ops-warden` to refresh this package from the reviewed source.
Verify the installed module as well as the checkout before the live refusal test.
## Resolve the credential proxy's admitted policy binding
```task
id: WARDEN-WP-0039-T03
status: wait
priority: high
assignee: the-custodian
blocking_reason: "The configured ops-warden caller represents ops-warden; credential requests name their owner as resource.system. Need the flex-auth/credential-owner contract for that exact delegated read, without broadening caller bindings or relabelling resource ownership."
state_hub_task_id: "8ca28b63-2e04-5333-b635-011b124c1806"
```
Consume the existing native-lane handoff (WARDEN-WP-0033 / SECRETS-WP-0006)
and flex-auth caller contract. Establish whether this interim transport needs an
admitted dedicated policy route or must finish its native handoff. Retain the
refusal until that contract yields positive and wrong-caller/owner/tenant
negative evidence. No credential read, secret generation, or policy grant is
authorized by this workplan alone. HFACT-WP-0001-T03 consumes this return.
Validation: 429 tests passed (4 integration tests deselected by the repository default); Ruff passed for changed Python files. Full tests used the declared phase-memory source and an isolated temporary memory store. The focused policy/proxy suite passed 69 tests. The existing authenticated SSH policy probe still returns HTTP 200/ALLOW, decision:f3f7c88f9585582a; the credential-owner request returns 403. No CA issue or credential read was performed by these probes.
Installed verification: source guard present after refreshed owner installation (`19bb75c`). `warden access forgejo-admin-api-token --exec --field API_TOKEN -- true` exits 4 with explicit HTTP 403 before credential transport or child execution. The previous fail-open warning is absent. The probe requested no output value; no credential was fetched. T01/T02 are complete; T03 owns the remaining exact policy-binding admission.