Record native sender acceptance and retained audit readback gate
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-11 14:23:07 +02:00
parent 9654f9e8cf
commit 005c68eb4c
6 changed files with 1153 additions and 2 deletions

View file

@ -548,3 +548,37 @@ for native producer ingestion/duplicate/scope/read-refusal and bearer
revocation acceptance under AUDIT T09/T11. No credentials were reseeded or
rotated. No producer was deployed and no factory attempt or paid call ran.
[Native delivery receipt](../docs/evidence/2026-09-11-factory-audit-delivery-live.json).
### Native producer return — 2026-09-11 10:42 UTC
Both actual source adapters used their own ESO-delivered credential inside a
bounded native Job. Each synthetic event received 202, retained its durable
outbox after an injected lost receipt, and received duplicate 200 after a fresh
process reopened the outbox. Each source's reconciliation reported exactly one
record for its unique probe class. Wrong source/tenant, seven archive read
routes, sibling reconciliation and invalid-bearer requests were refused.
The first Informed Decision probe exposed a private-store startup defect:
fsGroup volumes add inherited setgid to a newly created 0700 directory.
Informed Decision `1a12223` corrects creation without repairing unsafe existing
data. The regression failed before the fix; the available suite now passes
335 tests with 39 optional checks skipped. Native retry verifies the exact
corrected helper. Six probe tests and eleven rebuilt-container checks pass,
including actual setgid-volume startup, restart/restore and cleanup.
All temporary probe Jobs, Pods, ConfigMaps and NetworkPolicies are verified
absent. Receiver c82e0442 remains operational/durable; tamper_evidence=false.
Producer verification requires no operator registry read or new OpenBao login.
Independent readback is a separate attended command consuming the successful
receipt; it must not rerun the producer jobs. Both attended verification-login
attempts this session ended before handoff (exit 5; remote revocation
unconfirmed), so independent archive readback remains pending.
This proves synthetic outbox delivery/recovery with native sender credentials,
not domain-transaction atomicity, deployed producer services or human binding.
An invalid bearer is not a revoked formerly valid bearer. AUDIT T09/T11 and
RPF T08 remain progress for independent readback and audit bearer-revocation
acceptance; CCR21/22 remain applied. Service/policy/human admission and native
runtime/spend gates remain separate. Factory attempts and paid calls remain 0.
[Native producer receipt](../docs/evidence/2026-09-11-factory-native-producers.json).