Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6ef-4273-7fc2-8741-dc96b3e5fe0d
68 lines
2.8 KiB
Markdown
68 lines
2.8 KiB
Markdown
---
|
||
id: WARDEN-WP-0036
|
||
type: workplan
|
||
title: "Accept contained OpenBao login output only after helper persistence"
|
||
domain: infotech
|
||
repo: ops-warden
|
||
status: finished
|
||
owner: codex
|
||
topic_slug: attended-login-openbao-output
|
||
created: "2026-09-01"
|
||
updated: "2026-09-28"
|
||
state_hub_workstream_id: "d844c96e-152d-53fa-bff6-e072125ef66c"
|
||
---
|
||
|
||
## Repair attended-login handoff
|
||
|
||
```task
|
||
id: WARDEN-WP-0036-T01
|
||
status: done
|
||
priority: high
|
||
state_hub_task_id: "7eb8b9c9-1285-5ada-a17b-1d5bfbb8ba59"
|
||
```
|
||
|
||
Allow a successful OpenBao login to proceed when its output is fully contained
|
||
and the private mode-0600 token helper is populated. Continue failing closed on
|
||
non-zero login, missing persistence, child output, revocation failure, or cleanup
|
||
failure.
|
||
|
||
## Verify live contained operation
|
||
|
||
```task
|
||
id: WARDEN-WP-0036-T02
|
||
status: done
|
||
priority: high
|
||
state_hub_task_id: "d22bab05-c38b-561f-95de-6c146ce7c6cf"
|
||
```
|
||
|
||
Run the proxy regression suite, reinstall the CLI, and complete one governed
|
||
OpenBao platform-admin operation with deterministic self-revocation.
|
||
|
||
Completed 2026-09-01. The installed CLI completed the governed Policy Nexus
|
||
Forgejo source bootstrap with all child output contained, then revoked and
|
||
removed its isolated helper session.
|
||
|
||
### 2026-09-28 contained-result correction (existing T01/T02)
|
||
|
||
Addressed the September 21 attended-login failure/audit report under the existing
|
||
handoff repair and verification tasks. Failed envelopes now use distinct
|
||
non-zero codes 10–14 for login, child failure, child output, unconfirmed revocation
|
||
and cleanup failure. Both audit files retain the actual Warden exit code and
|
||
phase outcome. Any child bytes, including whitespace, fail closed; the access
|
||
advisory now states the silent-child requirement and the playbook documents codes,
|
||
retry limits and the WSL tunnel/browser requirements.
|
||
|
||
The pre-change checkout already raised exit 5 on ProxyError, so the reported
|
||
historical exit-zero failure was not reproduced here. The actual reproduced defect
|
||
was unconditional success auditing; the new CLI regression covers failed login
|
||
with returncode zero but missing persistence as well as non-zero login, start
|
||
failures, child output/failure, revocation and cleanup. Revocation still checks
|
||
revoke-self's exit status; it does not misinterpret an arbitrary failed lookup as
|
||
proof. The September 23 platform return confirms revoke-self is already granted.
|
||
|
||
Validation: focused proxy suite 48 passed; full suite 483 passed, 4 integration
|
||
tests deselected by repository default; changed Python files pass Ruff. No live
|
||
OIDC, credential read or production operation was used. The earlier September 1
|
||
live operation remains historical evidence, not a live validation of this change.
|
||
Automated endpoint/browser preflight and OIDC URL presentation remain optional
|
||
inbox suggestions, outside these completed handoff acceptance criteria.
|