Close RISK-F-0010 on RPF-WP-0029 evidence (RISK-RULING-2026-09-22-A)

Source default removed, governed upload and restore have receipts, and the
predecessor share is invalidated by owner attestation (no probe, by design).
Fixed, embargo lifted, publication handover pending. Age-key taint referred
to railiance-platform as a possible separate finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
tegwick 2026-09-22 08:01:39 +02:00
parent 93e142f2b5
commit 81e31b379c
4 changed files with 77 additions and 34 deletions

View file

@ -0,0 +1,42 @@
# Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure
Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence
default, which does not apply: railiance-platform answered (message
`2caae2ef`, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit
`6dfb751`).
## Evidence against the closure condition
| Leg | Evidence (railiance-platform) | Class |
|-----|-------------------------------|-------|
| Literal source default removed | `tools/cmd/forgejo-backup` names the variable only in a comment; `lib/railiance-backup-common.sh` returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. | Observed source |
| Governed ciphertext upload | `docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json`: upload 201, download 200, matching ciphertext hash, decrypted | Receipt |
| Restore | `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`: isolated restore, database import, application health, 2040 package blobs verified, cleanup | Receipt |
| Predecessor invalidated | `docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`: the operator attests the personal file-drop share was unshared; no HTTP probe | Owner attestation |
## Decision
**Fixed, `low` retained for the record, embargo lifted, no escalation.**
The invalidation leg rests on attestation rather than a receipt. This register
accepts that: the only independent probe would mean reconstructing the
predecessor credential, which every record here forbids, and the attesting
party is the provider owner with authority over the share. An unshared
file-drop token cannot authorize a write, so the embargo condition
("revoked or invalidated and the literal source default is removed") is met.
The evidence class is stated in the finding. If the share is ever found live,
the finding reopens at its original grade.
## Kept outside this finding
- **Age recovery-key taint.** RPF-WP-0029 says the age-key exposure is still
open and that rotating the upload token cannot clear it. RISK-F-0010 covered
only the WebDAV credential, and its report found the age key separate from
the script. Any age-key exposure is a separate matter. I asked
railiance-platform whether it should be filed as its own finding; it is not
folded in here.
- **Secondary-lane quota (10 GiB, about two archives).** This is a retention
and capacity question for RPF, not an exposure.
- **Discoverability.** RPF asked why its tracking was not found. RISK-WP-0007
had already reconciled `fix_tracking: RPF-WP-0029-T02`. The 2026-09-01 gap
came before that task was linked.