Cancel withdrawn approval operator reader without inventing auth
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-10 08:10:33 +02:00
parent 07b6b63fe6
commit 3109f950f9
7 changed files with 152 additions and 26 deletions

View file

@ -7,7 +7,7 @@ repo: railiance-platform
status: blocked
owner: codex
created: "2026-09-05"
updated: "2026-09-09"
updated: "2026-09-10"
related:
- RPF-WP-0032
- RPF-WP-0033
@ -253,6 +253,29 @@ intervention_note: ""
state_hub_task_id: "68bff751-e48b-548b-8fb4-dfb3b16210c2"
```
**Current return, 2026-09-10:** CCR-2026-0020 is cancelled on the requesting
Approval Engine owner's explicit withdrawal, source
`849c75bb094613ff6ac1a1d4cda56a745520c5a1:docs/keycape-service-registrations.md`.
No presenter exists and no reader is wanted. The validator now accepts terminal
cancellation of an incomplete request only with owner/source/reason evidence,
retained declared omissions and a disabled, non-resolvable front door. Apply
remains refused. No live identity, policy, role, custody or verifier was changed.
Human approval follows existing INFD-WP-0001-T07/T08; future service requesters
need a separate narrow registration, not this withdrawn bundle.
**Remaining unblock:** CCR-2026-0019 needs the exact authorized operator group
from NetKingdom/KeyCape, then reviewed attended file delivery and its scoped
positive/negative proof. Completed CCR-2026-0017/0018 remain closed. T06 stays
`wait`; its historical two-reader notes below are superseded for reader 2.
Separate retained owner decision: KeyCape's 2026-09-10 return
`21427688-725f-4dea-aab4-7c78fd4328d2` identifies the already-live, unpresented
CCR-2026-0018 registration. Approval Engine, KeyCape and Platform must explicitly
decide retention/expiry or coordinated disablement. Reader cancellation neither
disables that live registration nor accepts indefinite retention. Keep this
disposition in T06; it is separate from the wanted CCR-2026-0019 factory reader.
No unilateral issuer/config/Secret change is authorized by this closeout.
Residual handoff from RPF-WP-0035-T05; consumes the completed verifier custody
without extending CCR-2026-0017/0018. Owner: railiance-platform with the named
secrets-engine and approval-engine operator consumers.
@ -313,7 +336,8 @@ own accepted native delivery return. Client-side admission is not ready for a
new human decision until exact requests and contained execution/rollback checks
are reviewable; the completed verifier reviews must not recur in that queue.
**Done when:** both separate consumer admissions are approved and implemented;
**Done when:** each retained consumer admission is approved and implemented, or
its requesting owner explicitly cancels it (CCR-2026-0020 now satisfies that branch);
actual consumer authentication/delivery succeeds; sibling/listing/wrong-reader
and scope refusals plus reader expiry/revocation/cleanup are evidenced; version-1
custody and verifier availability remain intact. Return the source and metadata