Prepare scoped factory audit custody and enforce receiver compatibility

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a07ff8-19d0-7820-b4d0-1353833cb7fc
This commit is contained in:
codex 2026-09-11 02:01:57 +02:00
parent d3a502b45c
commit bfe65a5b05
11 changed files with 1053 additions and 1 deletions

View file

@ -0,0 +1,81 @@
{
"schema": "platform.factory-audit-custody-preparation.v1",
"observed_at": "2026-09-11T00:00:15.014528+00:00",
"platform_base_commit": "d3a502b45cebc0a658d0ee7499f1cfcf2a5902a4",
"owner_task": "RPF-WP-0035-T08",
"source_records": [
"CCR-2026-0021",
"CCR-2026-0022",
"AUDIT-WP-0009-T09",
"AUDIT-WP-0009-T11"
],
"status": "proposed_custody_with_receiver_release_prerequisite",
"verification": {
"new_tests_passed": 17,
"existing_credential_change_tests_passed": 53,
"tests_skipped": 0,
"local_openbao_test_cases": 11,
"actual_receiver_source_contract_passed": true,
"all_22_ccrs_valid": true,
"server_dry_run": {
"objects": 4,
"exact_namespace_passed": 3,
"refusal": "approval-engine namespace absent",
"cluster_changes_applied": 0
}
},
"native_receiver": {
"image": "forgejo.coulomb.social/coulomb/audit-core@sha256:c2fe39a0185b99be3fc0cb14d2de69772b8e66e20490097c9d11d90cc39719a6",
"ready_replicas": 1,
"replicas": 1,
"evidence_kind_supported": false,
"probe": "synthetic SenderRegistry contract in exact deployed pod; no environment registry read",
"entry_refusal": "receiver_lacks_sender_contract",
"credential_reads": 0,
"source_contract_commit": "5c0ad522fb36092aa7ec2e8d72f63a5a91853b5b"
},
"recovery_proven": [
"interruption after first token write reuses the same value",
"lost registry write reply reconciles without another write",
"concurrent registry change is preserved by CAS refusal then deliberate resume",
"wrong provenance/scope/duplicate names/token collisions refuse",
"each exact read policy denies sibling data, full registry and metadata",
"all named approvals and exact credential coordinates are enforced"
],
"routing_finding": {
"catalog": "audit-core-senders",
"status": "draft",
"catalog_points_to": "ops-mason bootstrap",
"current_authority": "platform/workloads/audit-core/senders per audit-core operator runbook",
"execution_owner": "railiance-platform attended custody; existing platform helper pattern"
},
"pending_decisions": [
{
"ccr": "CCR-2026-0021",
"status": 201,
"decision_id": "2c9fe9f0-034a-41d7-9d49-b99df488fdc8"
},
{
"ccr": "CCR-2026-0022",
"status": 201,
"decision_id": "ee4ff001-256a-4406-9cb8-51be2cd5d31b"
}
],
"source_sha256": {
"scripts/factory_audit_custody.py": "77b5bd7bd1b27a642d87d73d799b8896ebca1808b7c95fc47dd603ba74d8d30e",
"tests/test_factory_audit_custody.py": "aef55cb98862dd62e2202fe4d2348aa8915f23d059331fd07d5644598452dc9f",
"manifests/factory-audit-senders.yaml": "3d682dfd517b516dcb20c40373aae2557e4d8d2b49b3392d75c2cb36cd80785d",
"openbao/policies/agent-high-risk-boundary.hcl": "9d863886c815740e65458417949c73a616b6e038594979b343ea07d08c585f64",
"openbao/policies/workload-kv-read-approval-engine-audit.hcl": "a527c3bdfe7bf356fcd19f499ebc3ad75a71256a22c19882ad0dfdd09e0f0eb9",
"openbao/policies/workload-kv-read-informed-decision-audit.hcl": "389e952546d32692e87b4f249752a9bee0fafa9fc58bf50ab8904110bf6b3780",
"credential-change-requests/CCR-2026-0021-approval-engine-audit.yaml": "33f3bb5d32f2dbada864e1b89cdb47fcb9742dfe313eb391ca2f342be6bc119a",
"credential-change-requests/CCR-2026-0022-informed-decision-audit.yaml": "7656519a7be847e6cf1b4e3e03200c68f5a36d87db8c81b84a16511b5dfe5d3a",
"docs/credential-lane-designs/factory-audit-senders-review.md": "70e7a3568821672c84e0ce0388f7b8bc7d1b920354b38153995ec45022c53e52"
},
"native_credentials_created": 0,
"native_secret_reads": 0,
"native_policy_writes": 0,
"native_deployments": 0,
"factory_attempts": 0,
"paid_model_calls": 0
}