Record verified independent factory audit readback
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
parent
005c68eb4c
commit
b75729b799
4 changed files with 249 additions and 0 deletions
|
|
@ -137,6 +137,22 @@ verification:
|
||||||
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
|
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
|
||||||
and bearer-revocation evidence. Reader-session revocation does not revoke audit
|
and bearer-revocation evidence. Reader-session revocation does not revoke audit
|
||||||
bearer credentials.
|
bearer credentials.
|
||||||
|
- at: '2026-09-11T13:11:08+00:00'
|
||||||
|
actor: codex via attended user platform-admin
|
||||||
|
kind: factory_audit_native_producer_and_independent_readback
|
||||||
|
result: passed
|
||||||
|
details:
|
||||||
|
- Native adapters accepted synthetic events (202), retried after process restart
|
||||||
|
as duplicates (200), reconciled count one and refused wrong source/tenant,
|
||||||
|
sibling reconciliation, seven read routes and invalid bearers.
|
||||||
|
- Independent read-only operator found both retained exact source/tenant events;
|
||||||
|
the 36-event chain is intact. Readback wrapper exit 0 confirms this session
|
||||||
|
self-revocation and private-helper cleanup; earlier failed-session uncertainty
|
||||||
|
is not retroactively closed.
|
||||||
|
- 'Receipt: docs/evidence/2026-09-11-factory-native-readback.json.'
|
||||||
|
- Status remains applied pending formerly-valid audit-bearer revocation proof.
|
||||||
|
Invalid-bearer refusal and OpenBao session revocation are distinct checks.
|
||||||
|
|
||||||
lifecycle:
|
lifecycle:
|
||||||
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
||||||
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
||||||
|
|
|
||||||
|
|
@ -138,6 +138,22 @@ verification:
|
||||||
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
|
- Status remains applied pending native producer accepted/duplicate, source/tenant/read-refusal
|
||||||
and bearer-revocation evidence. Reader-session revocation does not revoke audit
|
and bearer-revocation evidence. Reader-session revocation does not revoke audit
|
||||||
bearer credentials.
|
bearer credentials.
|
||||||
|
- at: '2026-09-11T13:11:08+00:00'
|
||||||
|
actor: codex via attended user platform-admin
|
||||||
|
kind: factory_audit_native_producer_and_independent_readback
|
||||||
|
result: passed
|
||||||
|
details:
|
||||||
|
- Native adapters accepted synthetic events (202), retried after process restart
|
||||||
|
as duplicates (200), reconciled count one and refused wrong source/tenant,
|
||||||
|
sibling reconciliation, seven read routes and invalid bearers.
|
||||||
|
- Independent read-only operator found both retained exact source/tenant events;
|
||||||
|
the 36-event chain is intact. Readback wrapper exit 0 confirms this session
|
||||||
|
self-revocation and private-helper cleanup; earlier failed-session uncertainty
|
||||||
|
is not retroactively closed.
|
||||||
|
- 'Receipt: docs/evidence/2026-09-11-factory-native-readback.json.'
|
||||||
|
- Status remains applied pending formerly-valid audit-bearer revocation proof.
|
||||||
|
Invalid-bearer refusal and OpenBao session revocation are distinct checks.
|
||||||
|
|
||||||
lifecycle:
|
lifecycle:
|
||||||
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
deactivate: Stop the exact producer; remove only its admitted token from the registry
|
||||||
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
using CAS and reload/verify receiver refusal. Then detach its reader policy and
|
||||||
|
|
|
||||||
197
docs/evidence/2026-09-11-factory-native-readback.json
Normal file
197
docs/evidence/2026-09-11-factory-native-readback.json
Normal file
|
|
@ -0,0 +1,197 @@
|
||||||
|
{
|
||||||
|
"schema": "platform.factory-native-acceptance-receipt.v1",
|
||||||
|
"status": "native_producer_delivery_verified_pending_bearer_revocation_and_service_admission",
|
||||||
|
"credential_values_emitted": false,
|
||||||
|
"started_at": "2026-09-11T10:42:09.254002+00:00",
|
||||||
|
"run_id": "factory-audit-20260911104152-94aced",
|
||||||
|
"packet_sha256": "5e8a20e29fb309924005a061939c94d8a40815126c44654b6daeb8adf18424c7",
|
||||||
|
"source_commits": {
|
||||||
|
"approval-engine": [
|
||||||
|
"a0a602976eef818f36dde35f76f7f2e589bd051b",
|
||||||
|
"approval_engine"
|
||||||
|
],
|
||||||
|
"informed-decision": [
|
||||||
|
"1a122235741d61b649e39ab86ddfbd317e54ad2f",
|
||||||
|
"informed_decision"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"receiver_before": {
|
||||||
|
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5",
|
||||||
|
"deployment_uid": "b85fe3d0-75c9-4e0d-8c34-c6f1df0881bb",
|
||||||
|
"deployment_resource_version": "59845369",
|
||||||
|
"pod_uid": "4d0ee4e5-5427-43f1-94ca-88e5470c4831",
|
||||||
|
"capabilities": {
|
||||||
|
"load_bearing": true,
|
||||||
|
"redact": true,
|
||||||
|
"write_only": true,
|
||||||
|
"source_exact": true,
|
||||||
|
"tenant_exact": true
|
||||||
|
},
|
||||||
|
"synthetic_probe_only": true,
|
||||||
|
"credential_reads": 0
|
||||||
|
},
|
||||||
|
"phase": "complete",
|
||||||
|
"operator_registry_reads": 0,
|
||||||
|
"created_objects": [
|
||||||
|
{
|
||||||
|
"kind": "ConfigMap",
|
||||||
|
"name": "factory-audit-20260911104152-94aced",
|
||||||
|
"namespace": "approval-engine",
|
||||||
|
"uid": "e847feeb-f847-480a-b4d0-cfc63ddeda94"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "NetworkPolicy",
|
||||||
|
"name": "factory-audit-20260911104152-94aced",
|
||||||
|
"namespace": "approval-engine",
|
||||||
|
"uid": "3cfeab0f-9495-4ac3-916e-4f8ffa7a5b10"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Job",
|
||||||
|
"name": "factory-audit-20260911104152-94aced",
|
||||||
|
"namespace": "approval-engine",
|
||||||
|
"uid": "42a23f42-657b-4077-8935-6b8315711416"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "ConfigMap",
|
||||||
|
"name": "factory-audit-20260911104152-94aced",
|
||||||
|
"namespace": "informed-decision",
|
||||||
|
"uid": "ed443945-66aa-48db-88c6-f176b5c66c70"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "NetworkPolicy",
|
||||||
|
"name": "factory-audit-20260911104152-94aced",
|
||||||
|
"namespace": "informed-decision",
|
||||||
|
"uid": "21bc3c88-5515-4923-b675-f3648f621e4c"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"kind": "Job",
|
||||||
|
"name": "factory-audit-20260911104152-94aced",
|
||||||
|
"namespace": "informed-decision",
|
||||||
|
"uid": "8da3c95a-b194-4acd-aad4-2b0ac1004dbd"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"producers": [
|
||||||
|
{
|
||||||
|
"credential_values_emitted": false,
|
||||||
|
"domain_transaction_atomicity_tested": false,
|
||||||
|
"event_id": "factory-audit-20260911104152-94aced-approval-engine",
|
||||||
|
"http_statuses": [
|
||||||
|
202,
|
||||||
|
200
|
||||||
|
],
|
||||||
|
"human_binding_tested": false,
|
||||||
|
"negatives": {
|
||||||
|
"audit_bearer_revocation_tested": false,
|
||||||
|
"invalid_bearer_denied": 401,
|
||||||
|
"own_reconciliation": true,
|
||||||
|
"probe_count": 1,
|
||||||
|
"read_routes_denied": 7,
|
||||||
|
"sibling_reconciliation_denied": true,
|
||||||
|
"source_denied": 400,
|
||||||
|
"tenant_denied": 400
|
||||||
|
},
|
||||||
|
"phase": "restart-retry",
|
||||||
|
"process_restart_retry": true,
|
||||||
|
"producer_service_deployed": false,
|
||||||
|
"run_id": "factory-audit-20260911104152-94aced",
|
||||||
|
"sender": "approval-engine",
|
||||||
|
"source_zip_sha256": "114215406400f6f5728520bf3d7dc2b7a4ff410784b80201b7a5ae24259f64c0",
|
||||||
|
"status": "passed",
|
||||||
|
"synthetic_outbox_only": true,
|
||||||
|
"pod_uid": "27517b95-091f-405c-9185-2fad1678097f",
|
||||||
|
"image": "forgejo.coulomb.social/coulomb/approval-engine@sha256:251941a5cb2724b57cc32cff6b693b1ab0be695bee4f56f02d51961189c0fa49",
|
||||||
|
"runtime_image_id": "forgejo.coulomb.social/coulomb/approval-engine@sha256:251941a5cb2724b57cc32cff6b693b1ab0be695bee4f56f02d51961189c0fa49",
|
||||||
|
"independent_readback": {
|
||||||
|
"event_id": "factory-audit-20260911104152-94aced-approval-engine",
|
||||||
|
"accepted_at": "2026-09-11T10:42:19+00:00",
|
||||||
|
"source": "approval-engine",
|
||||||
|
"tenant": "tenant:platform",
|
||||||
|
"synthetic": true
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"credential_values_emitted": false,
|
||||||
|
"domain_transaction_atomicity_tested": false,
|
||||||
|
"event_id": "factory-audit-20260911104152-94aced-informed-decision",
|
||||||
|
"http_statuses": [
|
||||||
|
202,
|
||||||
|
200
|
||||||
|
],
|
||||||
|
"human_binding_tested": false,
|
||||||
|
"negatives": {
|
||||||
|
"audit_bearer_revocation_tested": false,
|
||||||
|
"invalid_bearer_denied": 401,
|
||||||
|
"own_reconciliation": true,
|
||||||
|
"probe_count": 1,
|
||||||
|
"read_routes_denied": 7,
|
||||||
|
"sibling_reconciliation_denied": true,
|
||||||
|
"source_denied": 400,
|
||||||
|
"tenant_denied": 400
|
||||||
|
},
|
||||||
|
"phase": "restart-retry",
|
||||||
|
"process_restart_retry": true,
|
||||||
|
"producer_service_deployed": false,
|
||||||
|
"run_id": "factory-audit-20260911104152-94aced",
|
||||||
|
"sender": "informed-decision",
|
||||||
|
"source_zip_sha256": "114215406400f6f5728520bf3d7dc2b7a4ff410784b80201b7a5ae24259f64c0",
|
||||||
|
"status": "passed",
|
||||||
|
"synthetic_outbox_only": true,
|
||||||
|
"pod_uid": "dd2c4175-553a-40af-a656-5cb3db8e45fd",
|
||||||
|
"image": "forgejo.coulomb.social/coulomb/approval-engine@sha256:251941a5cb2724b57cc32cff6b693b1ab0be695bee4f56f02d51961189c0fa49",
|
||||||
|
"runtime_image_id": "forgejo.coulomb.social/coulomb/approval-engine@sha256:251941a5cb2724b57cc32cff6b693b1ab0be695bee4f56f02d51961189c0fa49",
|
||||||
|
"independent_readback": {
|
||||||
|
"event_id": "factory-audit-20260911104152-94aced-informed-decision",
|
||||||
|
"accepted_at": "2026-09-11T10:42:20+00:00",
|
||||||
|
"source": "informed-decision",
|
||||||
|
"tenant": "tenant:platform",
|
||||||
|
"synthetic": true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"cleanup_requested": true,
|
||||||
|
"completed_at": "2026-09-11T13:11:08.775531+00:00",
|
||||||
|
"readback_started_at": "2026-09-11T13:11:05.169589+00:00",
|
||||||
|
"receiver_at_readback": {
|
||||||
|
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c82e0442de0fd181342916ae9cd5d6de41d859e1efda637bd93936c67873afa5",
|
||||||
|
"deployment_uid": "b85fe3d0-75c9-4e0d-8c34-c6f1df0881bb",
|
||||||
|
"deployment_resource_version": "59897385",
|
||||||
|
"pod_uid": "4d0ee4e5-5427-43f1-94ca-88e5470c4831",
|
||||||
|
"capabilities": {
|
||||||
|
"load_bearing": true,
|
||||||
|
"redact": true,
|
||||||
|
"write_only": true,
|
||||||
|
"source_exact": true,
|
||||||
|
"tenant_exact": true
|
||||||
|
},
|
||||||
|
"synthetic_probe_only": true,
|
||||||
|
"credential_reads": 0
|
||||||
|
},
|
||||||
|
"reader_candidates": [
|
||||||
|
{
|
||||||
|
"name": "operator",
|
||||||
|
"may_read": true,
|
||||||
|
"may_write": false,
|
||||||
|
"tenants": [
|
||||||
|
"*"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"registry_version": 8,
|
||||||
|
"reader_name": "operator",
|
||||||
|
"integrity_after": {
|
||||||
|
"intact": true,
|
||||||
|
"events": 36,
|
||||||
|
"head": "ec50d25a1298a83ed1b82ede473ebd792acf6e2b3e78b13d19df958717d3fb83",
|
||||||
|
"head_event_id": "factory-audit-20260911104152-94aced-informed-decision",
|
||||||
|
"head_accepted_at": "2026-09-11T10:42:20+00:00",
|
||||||
|
"first_break": null,
|
||||||
|
"attestation_match": null
|
||||||
|
},
|
||||||
|
"attended_execution": {
|
||||||
|
"wrapper_exit_code": 0,
|
||||||
|
"session_self_revocation_confirmed": true,
|
||||||
|
"private_helper_cleanup_confirmed": true,
|
||||||
|
"earlier_failed_session_revocation_resolved": false
|
||||||
|
},
|
||||||
|
"operator_registry_reads_scope": "Inherited zero count applies to producer Jobs only; the attended independent readback read registry version 8."
|
||||||
|
}
|
||||||
|
|
@ -582,3 +582,23 @@ acceptance; CCR21/22 remain applied. Service/policy/human admission and native
|
||||||
runtime/spend gates remain separate. Factory attempts and paid calls remain 0.
|
runtime/spend gates remain separate. Factory attempts and paid calls remain 0.
|
||||||
|
|
||||||
[Native producer receipt](../docs/evidence/2026-09-11-factory-native-producers.json).
|
[Native producer receipt](../docs/evidence/2026-09-11-factory-native-producers.json).
|
||||||
|
|
||||||
|
|
||||||
|
## Independent audit readback — 2026-09-11 13:11 UTC
|
||||||
|
|
||||||
|
The existing attended readback command completed with exit 0 while the user
|
||||||
|
was present. Independent read-only identity `operator` found both retained
|
||||||
|
`factory-audit-20260911104152-94aced` producer events with exact source and
|
||||||
|
`tenant:platform`; receiver integrity is intact across 36 events. The wrapper
|
||||||
|
confirmed this session's self-revocation and private-helper cleanup. Prior
|
||||||
|
failed sessions' unconfirmed revocation remains historical unresolved evidence.
|
||||||
|
|
||||||
|
This supersedes the earlier readback-login wait. No producer jobs were rerun,
|
||||||
|
no credentials were reseeded and no event was written by the reader. The
|
||||||
|
inherited zero registry-read count belongs to the producer phase; the attended
|
||||||
|
reader did consume registry version 8. CCR21/22 stay applied and owner tasks
|
||||||
|
stay progress pending formerly-valid audit-bearer revocation acceptance.
|
||||||
|
Service/domain-transaction/human and factory runtime/spend admission remain
|
||||||
|
separate; factory attempts and paid model calls remain zero.
|
||||||
|
|
||||||
|
Receipt: [native readback](../docs/evidence/2026-09-11-factory-native-readback.json).
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue