Close factor credential expiry and recovery acceptance for P05
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a092fe-13b1-7f12-ac74-7d258af4d79c
This commit is contained in:
codex 2026-09-13 22:20:14 +02:00
parent a704a72b6e
commit 817c122d07
2 changed files with 34 additions and 2 deletions

View file

@ -53,3 +53,17 @@ were true: wrong-SA rejection, issuer-password denial, sibling-secret denial,
mounted-token/custody equality, KeyCape per-user lookup, provider administration
denial, renewed projection acceptance, and explicit reader-session revocation.
KeyCape remained Ready 1/1 at deployment generation 46. CCR validation passed.
## P05 acceptance closure — 2026-09-13
RPF-WP-0040-T04 is complete. Actual installed-provider isolated fixture
`provider-p05-contract-01` verifies expiry, fresh-session recovery, expired
predecessor denial and policy permission withdrawal/recovery. Native proof
`keycape-factor-proof-91ea82cd` repeated all eight checks successfully, including
mounted rotation after renewal Job `keycape-factor-rotate-91ea82cd` and explicit
proof-session revocation. CronJob retains failed Jobs (limit 3), and ESO reports
Ready/SecretSynced. Provider and credential failure/recovery are covered by
KeyCape's Go adapter suite. See user-engine's P05 evidence for exact boundaries.
The preceding "remaining T04" statements are historical and superseded here.
Existing NK-WP-0033 and KEY-WP-0035 retain resolver/policy residual ownership.