Close RISK-F-0010 on RPF-WP-0029 evidence (RISK-RULING-2026-09-22-A)

Source default removed, governed upload and restore have receipts, and the
predecessor share is invalidated by owner attestation (no probe, by design).
Fixed, embargo lifted, publication handover pending. Age-key taint referred
to railiance-platform as a possible separate finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
tegwick 2026-09-22 08:01:39 +02:00
parent 93e142f2b5
commit 81e31b379c
4 changed files with 77 additions and 34 deletions

View file

@ -1,15 +1,15 @@
# Register
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-05.
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22.
3 live of 11 findings; 3 notes below the floor.
2 live of 11 findings; 3 notes below the floor.
## Findings
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** |
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | embargoed | none | railiance-platform | open | instant (0) | **due** |
| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | 2026-09-22 07:01Z |
| [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** |
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 1h (1) | **due** |
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** |
@ -36,17 +36,8 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`.
| Finding | Who | What would change | Default if silent | On |
| --- | --- | --- | --- | --- |
| RISK-F-0011 | qonto-assistant | accepted deployed-instance evidence supports bounded stream completeness and permits closure; source-only evidence keeps the finding open | the medium grade stands; missing deployed acceptance is recorded as a stalled remediation, and observation remains staffed with completeness pending | 2026-09-16 |
| RISK-F-0010 | railiance-platform | the finding becomes fixed and the embargo lifts | the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation | 2026-09-15 |
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
## Embargoes
Held from publication with a stated condition. A hold with no moving condition is a stall.
| Finding | Since | Lifts when | Re-decided |
| --- | --- | --- | --- |
| RISK-F-0010 | 2026-09-01 | the provider credential is revoked or invalidated and the literal source default is removed | 2026-09-15 |
## Notes (below the floor)
Seen, deliberately not findings. Not graded, not reviewed, not published.

View file

@ -45,7 +45,7 @@ WP-0007 then reconciled the owner evidence in RISK-V-0003. Qonto's source
cadence/reconciliation exists; KG-WP-0005-T03 waits for deployed acceptance.
RPF-WP-0029 removed the backup fallback; T02 waits for provider invalidation
and recovery receipts. Both findings were recorded as moved and remain open
at `instant`; F-0010 remains embargoed. F-0008's substantive review remains
at `instant`; F-0010 was closed 2026-09-22 (RISK-RULING-2026-09-22-A), embargo lifted. F-0008's substantive review remains
overdue and its existing acceptance terms are displayed explicitly. Ten tests
pass. WP-0007 and four tasks are registered in State Hub.
@ -54,7 +54,7 @@ pass. WP-0007 and four tasks are registered in State Hub.
| ID | Sev | Status | Disclosure | Cadence | System |
| --- | --- | --- | --- | --- | --- |
| `RISK-F-0011` | medium | open | public | instant | qonto-assistant |
| `RISK-F-0010` | low | open | embargoed | instant | railiance-platform |
| `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform |
| `RISK-F-0009` | high | fixed | public | instant | railiance-platform |
| `RISK-F-0008` | medium | accepted | public | 1h | audit-core |
| `RISK-F-0007` | high | fixed | public | instant | estate |
@ -105,7 +105,7 @@ outcome.
| Who | On | Defaults |
| --- | --- | --- |
| qonto-assistant | deployed-instance capture and King's Guard acceptance under `KG-WP-0005-T03`; source cadence/reconciliation now exist (`F-0011`) | 2026-09-16 |
| railiance-platform | provider invalidation and recovery receipts under `RPF-WP-0029-T02`; source fallback removed (`F-0010`) | 2026-09-15 |
| railiance-platform | whether the age recovery-key taint named in RPF-WP-0029 is a separate exposure to file (raised 2026-09-22 after `F-0010` closed) | — |
| the-custodian | canon kinds packet | 2026-09-17 |
| audit-core | keyed commitment; `platform-pg` co-residency horizon | 2026-11-17 |

View file

@ -0,0 +1,42 @@
# Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure
Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence
default, which does not apply: railiance-platform answered (message
`2caae2ef`, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit
`6dfb751`).
## Evidence against the closure condition
| Leg | Evidence (railiance-platform) | Class |
|-----|-------------------------------|-------|
| Literal source default removed | `tools/cmd/forgejo-backup` names the variable only in a comment; `lib/railiance-backup-common.sh` returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. | Observed source |
| Governed ciphertext upload | `docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json`: upload 201, download 200, matching ciphertext hash, decrypted | Receipt |
| Restore | `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`: isolated restore, database import, application health, 2040 package blobs verified, cleanup | Receipt |
| Predecessor invalidated | `docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`: the operator attests the personal file-drop share was unshared; no HTTP probe | Owner attestation |
## Decision
**Fixed, `low` retained for the record, embargo lifted, no escalation.**
The invalidation leg rests on attestation rather than a receipt. This register
accepts that: the only independent probe would mean reconstructing the
predecessor credential, which every record here forbids, and the attesting
party is the provider owner with authority over the share. An unshared
file-drop token cannot authorize a write, so the embargo condition
("revoked or invalidated and the literal source default is removed") is met.
The evidence class is stated in the finding. If the share is ever found live,
the finding reopens at its original grade.
## Kept outside this finding
- **Age recovery-key taint.** RPF-WP-0029 says the age-key exposure is still
open and that rotating the upload token cannot clear it. RISK-F-0010 covered
only the WebDAV credential, and its report found the age key separate from
the script. Any age-key exposure is a separate matter. I asked
railiance-platform whether it should be filed as its own finding; it is not
folded in here.
- **Secondary-lane quota (10 GiB, about two archives).** This is a retention
and capacity question for RPF, not an exposure.
- **Discoverability.** RPF asked why its tracking was not found. RISK-WP-0007
had already reconciled `fix_tracking: RPF-WP-0029-T02`. The 2026-09-01 gap
came before that task was linked.

View file

@ -2,7 +2,7 @@
id: RISK-F-0010
type: finding
title: "Forgejo backup source embeds a WebDAV credential default"
status: open
status: fixed
owner: risk-nexus
reported_by: railiance-platform
reported_via: railiance-platform
@ -12,7 +12,7 @@ date_filed: "2026-08-23"
system: railiance-platform
environment: production
fix_owner: railiance-platform
fix_tracking: RPF-WP-0029-T02
fix_tracking: RPF-WP-0029-T02 (done 2026-09-15)
closure_condition: "provider invalidation plus governed ciphertext upload and restore receipts; source fallback removal alone does not lift the embargo"
verification: RISK-V-0003
# Graded by risk-nexus 2026-09-01 — docs/rulings/2026-09-01-inbox-sweep.md
@ -22,25 +22,24 @@ impact: I2
likelihood: L2
fidelity_modifier: false
production_rescore: false
disclosure: embargoed
embargo_condition: "the provider credential is revoked or invalidated and the literal source default is removed"
embargo_since: "2026-09-01"
embargo_review: "2026-09-15"
disclosure: public
publication: pending-handover
publication_id: risk-f-0010-embedded-backup-webdav-credential
publication_path: "findings/embedded-backup-webdav-credential/v1/index.html"
publication_subtitle: "A backup script carried a literal file-drop credential default; the default is gone, the share is invalidated, and governed upload and restore are proven."
revision: "fixed-1"
embargo_was_condition: "the provider credential is revoked or invalidated and the literal source default is removed"
embargo_lifted: "2026-09-22 — literal default removed (observed) and predecessor share invalidated (owner attestation, no probe by design)"
embargo_was_since: "2026-09-01"
date_fixed: "2026-09-15"
escalation: none
last_checked: "2026-09-05T00:05:51Z"
next_check: "2026-09-05T00:05:51Z"
cadence: instant
clean_streak: 0
waiting_on:
- who: railiance-platform
what: "complete RPF-WP-0029-T02: revoke or invalidate the provider credential and demonstrate governed ciphertext upload plus restore; source fallback removal is established"
since: "2026-09-01"
would_change: "the finding becomes fixed and the embargo lifts"
default: "the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation"
default_at: "2026-09-15"
last_checked: "2026-09-22T06:01:01Z"
next_check: "2026-09-22T07:01:01Z"
cadence: 1h
clean_streak: 1
graded_by: risk-nexus
ruling: RISK-RULING-2026-09-01-A
checked_by: "codex/risk-nexus"
ruling: RISK-RULING-2026-09-22-A
checked_by: "worsch"
---
# RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default
@ -133,8 +132,19 @@ predecessor. Open, low, embargoed and no escalation remain appropriate on the
available evidence. The 2026-09-15 review/default is unchanged. The historical
source-default statements above describe the earlier assessments.
## Closure ruling — 2026-09-22
Fixed; embargo lifted; no escalation. All four closure legs are evidenced: the
source default is removed, governed ciphertext upload and restore have receipts
(2026-09-06), and the predecessor share was invalidated on 2026-09-15. The
invalidation rests on owner attestation because probing it would mean
reconstructing the credential. Age-key taint is outside this finding and has
been referred to railiance-platform. Reasoning:
`docs/rulings/2026-09-22-f0010-closure.md`.
## Reviews
- **2026-09-01** — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant.
- **2026-09-02** — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z.
- **2026-09-05** — not clean: Confirmed source fallback removal and RPF-WP-0029 tracking; provider invalidation and encrypted upload/restore receipts remain pending. Low grade and embargo retained; see RISK-V-0003. Cadence 1h → instant; checked again immediately.
- **2026-09-22** — clean check: Closed under RISK-RULING-2026-09-22-A: source default absent, upload/restore receipts, predecessor share invalidated by owner attestation; embargo lifted. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:01Z.