docs: accept native factory audit sender delivery
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Has been cancelled

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-11 10:31:15 +02:00
parent 47223007ba
commit 1ec5b587db
5 changed files with 179 additions and 11 deletions

View file

@ -120,6 +120,23 @@ verification:
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
- 'Status applied: native ESO delivery, scope verification, receiver reload and
producer acceptance remain.'
- at: '2026-09-11T08:30:43+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_native_delivery
result: passed
details:
- Fresh attended retry completed in 28 seconds; wrapper exit 0 and session self-revocation
confirmed. Both exact projections are ESO-owned and match independent version-1
custody.
- Native readers denied sibling, registry, metadata and listing access. Wrong
service account and namespace login failed; disallowed store namespace created
no Secret. Coding-agent deny boundary prevailed. Temporary readers revoked and
namespace deletion verified.
- 'Registry version 8 was delivered exactly before Audit Core reload. Receiver
c82e0442 is Ready and operational/durable. Receipt: docs/evidence/2026-09-11-factory-audit-delivery-live.json.'
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
and bearer-revocation evidence. Reader-session revocation does not revoke audit
bearer credentials.
lifecycle:
deactivate: Stop the exact producer; remove only its admitted token from the registry
using CAS and reload/verify receiver refusal. Then detach its reader policy and

View file

@ -121,6 +121,23 @@ verification:
docs/evidence/2026-09-11-factory-audit-sender-seed.json.'
- 'Status applied: native ESO delivery, scope verification, receiver reload and
producer acceptance remain.'
- at: '2026-09-11T08:30:43+00:00'
actor: codex via attended user platform-admin
kind: factory_audit_native_delivery
result: passed
details:
- Fresh attended retry completed in 28 seconds; wrapper exit 0 and session self-revocation
confirmed. Both exact projections are ESO-owned and match independent version-1
custody.
- Native readers denied sibling, registry, metadata and listing access. Wrong
service account and namespace login failed; disallowed store namespace created
no Secret. Coding-agent deny boundary prevailed. Temporary readers revoked and
namespace deletion verified.
- 'Registry version 8 was delivered exactly before Audit Core reload. Receiver
c82e0442 is Ready and operational/durable. Receipt: docs/evidence/2026-09-11-factory-audit-delivery-live.json.'
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
and bearer-revocation evidence. Reader-session revocation does not revoke audit
bearer credentials.
lifecycle:
deactivate: Stop the exact producer; remove only its admitted token from the registry
using CAS and reload/verify receiver refusal. Then detach its reader policy and