Include platform owner in WP-0024 receipts
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02669-87ee-7a31-b111-edc95a16e0fa
This commit is contained in:
codex 2026-08-22 14:59:59 +02:00
parent d8c0cd38a7
commit abf8855ae1
4 changed files with 51 additions and 12 deletions

View file

@ -20,8 +20,8 @@ python3 scripts/wp0024-owner-review.py verify --owner audit-core
python3 scripts/wp0024-owner-review.py approve --owner audit-core --reviewer audit-core
```
Valid owners are `audit-core`, `rapp-postgres`, `railiance-cluster`, and
`railiance-infra`. `approve` repeats verification and submits the receipt only
Valid owners are `audit-core`, `rapp-postgres`, `railiance-cluster`,
`railiance-infra`, and `railiance-platform`. `approve` repeats verification and submits the receipt only
when artifact hashes and all named read-only checks pass. The checks may read
resource metadata, but they never read Secret data or OpenBao lease payloads.
They cannot revoke a lease, restart a workload, create a snapshot, or reboot a
@ -29,9 +29,9 @@ node. A successful review is still not a live execution window.
The task-to-owner interface is explicit in the contract:
- T02 requires `audit-core` and `rapp-postgres`.
- T02 requires `audit-core`, `rapp-postgres`, and `railiance-platform`.
- T03 requires `audit-core`, `rapp-postgres`, `railiance-cluster`, and
`railiance-infra`.
`railiance-infra`, plus `railiance-platform`.
One owner receipt may approve both tasks when that owner is responsible for
both; its receipt is bound to all artifacts and checks in that owner's review.

View file

@ -12,13 +12,15 @@
"task_owners": {
"RAILIANCE-WP-0024-T02": [
"audit-core",
"rapp-postgres"
"rapp-postgres",
"railiance-platform"
],
"RAILIANCE-WP-0024-T03": [
"audit-core",
"rapp-postgres",
"railiance-cluster",
"railiance-infra"
"railiance-infra",
"railiance-platform"
]
},
"owners": {
@ -106,6 +108,31 @@
"focused-unit-tests",
"node-reboot-preflight"
]
},
"railiance-platform": {
"tasks": [
"RAILIANCE-WP-0024-T02",
"RAILIANCE-WP-0024-T03"
],
"artifacts": [
"docs/audit-core-database-lease-recovery.md",
"docs/railiance01-coordinated-reboot.md",
"scripts/audit-core-recovery-preflight.py",
"scripts/audit-core-database-lease-recovery.py",
"docs/audit-core-database-lease-approval.example.json",
"docs/openbao-reboot-snapshot-receipt.example.json"
],
"assertions": [
"T02 remains gated on a named window, abort operator, exact owner receipts and a revision-pinned synthetic-load driver; repository access alone cannot revoke a lease.",
"T02 revokes only the selected runtime handle, forces only the database ExternalSecret and records no credential values or OpenBao response bodies.",
"T03 remains gated on a verified encrypted off-host OpenBao snapshot receipt, 2-of-3 Shamir quorum, provider-console access, all owner receipts and a final attended go/no-go.",
"The platform owner preserves the mutation freeze and ordered OpenBao/ESO recovery boundary and does not initialize OpenBao, restore in place or restart audit-core as a shortcut."
],
"checks": [
"focused-unit-tests",
"database-lease-preflight",
"node-reboot-preflight"
]
}
},
"artifact_sha256": {

View file

@ -22,9 +22,15 @@ class OwnerReviewTests(unittest.TestCase):
def setUp(self) -> None:
self.contract = module.load_contract()
def test_contract_has_four_owners_and_only_known_checks(self) -> None:
def test_contract_has_required_owners_and_only_known_checks(self) -> None:
self.assertEqual(
{"audit-core", "rapp-postgres", "railiance-cluster", "railiance-infra"},
{
"audit-core",
"rapp-postgres",
"railiance-cluster",
"railiance-infra",
"railiance-platform",
},
set(self.contract["owners"]),
)
checks = {
@ -35,12 +41,17 @@ class OwnerReviewTests(unittest.TestCase):
self.assertLessEqual(checks, module.KNOWN_CHECKS)
self.assertEqual(
{
"RAILIANCE-WP-0024-T02": ["audit-core", "rapp-postgres"],
"RAILIANCE-WP-0024-T02": [
"audit-core",
"rapp-postgres",
"railiance-platform",
],
"RAILIANCE-WP-0024-T03": [
"audit-core",
"rapp-postgres",
"railiance-cluster",
"railiance-infra",
"railiance-platform",
],
},
self.contract["task_owners"],

View file

@ -221,9 +221,10 @@ aggregate `status` operations. Approvals are valid only for the canonical
contract digest and the owner's pinned artifact hashes, so a changed procedure
invalidates the old receipt. The interface runs only closed-set, read-only
checks and cannot perform any T02/T03 live mutation.
The task map requires audit-core plus rapp-postgres for T02, and audit-core,
rapp-postgres, railiance-cluster, plus railiance-infra for T03; aggregate status
is computed independently for each task.
The task map requires audit-core, rapp-postgres, plus railiance-platform for
T02, and audit-core, rapp-postgres, railiance-cluster, railiance-infra, plus
railiance-platform for T03; aggregate status is computed independently for
each task.
## Acceptance