diff --git a/REGISTER.md b/REGISTER.md index 268b19d..f086667 100644 --- a/REGISTER.md +++ b/REGISTER.md @@ -1,15 +1,15 @@ # Register -Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-05. +Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-22. -3 live of 11 findings; 3 notes below the floor. +2 live of 11 findings; 3 notes below the floor. ## Findings | ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** | -| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | embargoed | none | railiance-platform | open | instant (0) | **due** | +| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | public | none | railiance-platform | fixed | 1h (1) | 2026-09-22 07:01Z | | [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** | | [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 1h (1) | **due** | | [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** | @@ -36,17 +36,8 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`. | Finding | Who | What would change | Default if silent | On | | --- | --- | --- | --- | --- | | RISK-F-0011 | qonto-assistant | accepted deployed-instance evidence supports bounded stream completeness and permits closure; source-only evidence keeps the finding open | the medium grade stands; missing deployed acceptance is recorded as a stalled remediation, and observation remains staffed with completeness pending | 2026-09-16 | -| RISK-F-0010 | railiance-platform | the finding becomes fixed and the embargo lifts | the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation | 2026-09-15 | | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | -## Embargoes - -Held from publication with a stated condition. A hold with no moving condition is a stall. - -| Finding | Since | Lifts when | Re-decided | -| --- | --- | --- | --- | -| RISK-F-0010 | 2026-09-01 | the provider credential is revoked or invalidated and the literal source default is removed | 2026-09-15 | - ## Notes (below the floor) Seen, deliberately not findings. Not graded, not reviewed, not published. diff --git a/STATE.md b/STATE.md index 0c6fb84..3478df7 100644 --- a/STATE.md +++ b/STATE.md @@ -45,7 +45,7 @@ WP-0007 then reconciled the owner evidence in RISK-V-0003. Qonto's source cadence/reconciliation exists; KG-WP-0005-T03 waits for deployed acceptance. RPF-WP-0029 removed the backup fallback; T02 waits for provider invalidation and recovery receipts. Both findings were recorded as moved and remain open -at `instant`; F-0010 remains embargoed. F-0008's substantive review remains +at `instant`; F-0010 was closed 2026-09-22 (RISK-RULING-2026-09-22-A), embargo lifted. F-0008's substantive review remains overdue and its existing acceptance terms are displayed explicitly. Ten tests pass. WP-0007 and four tasks are registered in State Hub. @@ -54,7 +54,7 @@ pass. WP-0007 and four tasks are registered in State Hub. | ID | Sev | Status | Disclosure | Cadence | System | | --- | --- | --- | --- | --- | --- | | `RISK-F-0011` | medium | open | public | instant | qonto-assistant | -| `RISK-F-0010` | low | open | embargoed | instant | railiance-platform | +| `RISK-F-0010` | low | fixed | public (handover pending) | 1h | railiance-platform | | `RISK-F-0009` | high | fixed | public | instant | railiance-platform | | `RISK-F-0008` | medium | accepted | public | 1h | audit-core | | `RISK-F-0007` | high | fixed | public | instant | estate | @@ -105,7 +105,7 @@ outcome. | Who | On | Defaults | | --- | --- | --- | | qonto-assistant | deployed-instance capture and King's Guard acceptance under `KG-WP-0005-T03`; source cadence/reconciliation now exist (`F-0011`) | 2026-09-16 | -| railiance-platform | provider invalidation and recovery receipts under `RPF-WP-0029-T02`; source fallback removed (`F-0010`) | 2026-09-15 | +| railiance-platform | whether the age recovery-key taint named in RPF-WP-0029 is a separate exposure to file (raised 2026-09-22 after `F-0010` closed) | — | | the-custodian | canon kinds packet | 2026-09-17 | | audit-core | keyed commitment; `platform-pg` co-residency horizon | 2026-11-17 | diff --git a/docs/rulings/2026-09-22-f0010-closure.md b/docs/rulings/2026-09-22-f0010-closure.md new file mode 100644 index 0000000..3bba193 --- /dev/null +++ b/docs/rulings/2026-09-22-f0010-closure.md @@ -0,0 +1,42 @@ +# Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure + +Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence +default, which does not apply: railiance-platform answered (message +`2caae2ef`, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit +`6dfb751`). + +## Evidence against the closure condition + +| Leg | Evidence (railiance-platform) | Class | +|-----|-------------------------------|-------| +| Literal source default removed | `tools/cmd/forgejo-backup` names the variable only in a comment; `lib/railiance-backup-common.sh` returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. | Observed source | +| Governed ciphertext upload | `docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json`: upload 201, download 200, matching ciphertext hash, decrypted | Receipt | +| Restore | `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`: isolated restore, database import, application health, 2040 package blobs verified, cleanup | Receipt | +| Predecessor invalidated | `docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`: the operator attests the personal file-drop share was unshared; no HTTP probe | Owner attestation | + +## Decision + +**Fixed, `low` retained for the record, embargo lifted, no escalation.** + +The invalidation leg rests on attestation rather than a receipt. This register +accepts that: the only independent probe would mean reconstructing the +predecessor credential, which every record here forbids, and the attesting +party is the provider owner with authority over the share. An unshared +file-drop token cannot authorize a write, so the embargo condition +("revoked or invalidated and the literal source default is removed") is met. +The evidence class is stated in the finding. If the share is ever found live, +the finding reopens at its original grade. + +## Kept outside this finding + +- **Age recovery-key taint.** RPF-WP-0029 says the age-key exposure is still + open and that rotating the upload token cannot clear it. RISK-F-0010 covered + only the WebDAV credential, and its report found the age key separate from + the script. Any age-key exposure is a separate matter. I asked + railiance-platform whether it should be filed as its own finding; it is not + folded in here. +- **Secondary-lane quota (10 GiB, about two archives).** This is a retention + and capacity question for RPF, not an exposure. +- **Discoverability.** RPF asked why its tracking was not found. RISK-WP-0007 + had already reconciled `fix_tracking: RPF-WP-0029-T02`. The 2026-09-01 gap + came before that task was linked. diff --git a/findings/RISK-F-0010-embedded-backup-webdav-credential.md b/findings/RISK-F-0010-embedded-backup-webdav-credential.md index 492013c..5816b1a 100644 --- a/findings/RISK-F-0010-embedded-backup-webdav-credential.md +++ b/findings/RISK-F-0010-embedded-backup-webdav-credential.md @@ -2,7 +2,7 @@ id: RISK-F-0010 type: finding title: "Forgejo backup source embeds a WebDAV credential default" -status: open +status: fixed owner: risk-nexus reported_by: railiance-platform reported_via: railiance-platform @@ -12,7 +12,7 @@ date_filed: "2026-08-23" system: railiance-platform environment: production fix_owner: railiance-platform -fix_tracking: RPF-WP-0029-T02 +fix_tracking: RPF-WP-0029-T02 (done 2026-09-15) closure_condition: "provider invalidation plus governed ciphertext upload and restore receipts; source fallback removal alone does not lift the embargo" verification: RISK-V-0003 # Graded by risk-nexus 2026-09-01 — docs/rulings/2026-09-01-inbox-sweep.md @@ -22,25 +22,24 @@ impact: I2 likelihood: L2 fidelity_modifier: false production_rescore: false -disclosure: embargoed -embargo_condition: "the provider credential is revoked or invalidated and the literal source default is removed" -embargo_since: "2026-09-01" -embargo_review: "2026-09-15" +disclosure: public +publication: pending-handover +publication_id: risk-f-0010-embedded-backup-webdav-credential +publication_path: "findings/embedded-backup-webdav-credential/v1/index.html" +publication_subtitle: "A backup script carried a literal file-drop credential default; the default is gone, the share is invalidated, and governed upload and restore are proven." +revision: "fixed-1" +embargo_was_condition: "the provider credential is revoked or invalidated and the literal source default is removed" +embargo_lifted: "2026-09-22 — literal default removed (observed) and predecessor share invalidated (owner attestation, no probe by design)" +embargo_was_since: "2026-09-01" +date_fixed: "2026-09-15" escalation: none -last_checked: "2026-09-05T00:05:51Z" -next_check: "2026-09-05T00:05:51Z" -cadence: instant -clean_streak: 0 -waiting_on: - - who: railiance-platform - what: "complete RPF-WP-0029-T02: revoke or invalidate the provider credential and demonstrate governed ciphertext upload plus restore; source fallback removal is established" - since: "2026-09-01" - would_change: "the finding becomes fixed and the embargo lifts" - default: "the low grade and embargo stand; absent provider invalidation and recovery evidence is recorded as a stalled remediation" - default_at: "2026-09-15" +last_checked: "2026-09-22T06:01:01Z" +next_check: "2026-09-22T07:01:01Z" +cadence: 1h +clean_streak: 1 graded_by: risk-nexus -ruling: RISK-RULING-2026-09-01-A -checked_by: "codex/risk-nexus" +ruling: RISK-RULING-2026-09-22-A +checked_by: "worsch" --- # RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default @@ -133,8 +132,19 @@ predecessor. Open, low, embargoed and no escalation remain appropriate on the available evidence. The 2026-09-15 review/default is unchanged. The historical source-default statements above describe the earlier assessments. +## Closure ruling — 2026-09-22 + +Fixed; embargo lifted; no escalation. All four closure legs are evidenced: the +source default is removed, governed ciphertext upload and restore have receipts +(2026-09-06), and the predecessor share was invalidated on 2026-09-15. The +invalidation rests on owner attestation because probing it would mean +reconstructing the credential. Age-key taint is outside this finding and has +been referred to railiance-platform. Reasoning: +`docs/rulings/2026-09-22-f0010-closure.md`. + ## Reviews - **2026-09-01** — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant. - **2026-09-02** — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z. - **2026-09-05** — not clean: Confirmed source fallback removal and RPF-WP-0029 tracking; provider invalidation and encrypted upload/restore receipts remain pending. Low grade and embargo retained; see RISK-V-0003. Cadence 1h → instant; checked again immediately. +- **2026-09-22** — clean check: Closed under RISK-RULING-2026-09-22-A: source default absent, upload/restore receipts, predecessor share invalidated by owner attestation; embargo lifted. Cadence instant → 1h (1 clean in a row); next check 2026-09-22 07:01Z.