Close RISK-F-0010 on RPF-WP-0029 evidence (RISK-RULING-2026-09-22-A)
Source default removed, governed upload and restore have receipts, and the predecessor share is invalidated by owner attestation (no probe, by design). Fixed, embargo lifted, publication handover pending. Age-key taint referred to railiance-platform as a possible separate finding. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
parent
93e142f2b5
commit
81e31b379c
4 changed files with 77 additions and 34 deletions
42
docs/rulings/2026-09-22-f0010-closure.md
Normal file
42
docs/rulings/2026-09-22-f0010-closure.md
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
# Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure
|
||||
|
||||
Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence
|
||||
default, which does not apply: railiance-platform answered (message
|
||||
`2caae2ef`, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit
|
||||
`6dfb751`).
|
||||
|
||||
## Evidence against the closure condition
|
||||
|
||||
| Leg | Evidence (railiance-platform) | Class |
|
||||
|-----|-------------------------------|-------|
|
||||
| Literal source default removed | `tools/cmd/forgejo-backup` names the variable only in a comment; `lib/railiance-backup-common.sh` returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. | Observed source |
|
||||
| Governed ciphertext upload | `docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json`: upload 201, download 200, matching ciphertext hash, decrypted | Receipt |
|
||||
| Restore | `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`: isolated restore, database import, application health, 2040 package blobs verified, cleanup | Receipt |
|
||||
| Predecessor invalidated | `docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`: the operator attests the personal file-drop share was unshared; no HTTP probe | Owner attestation |
|
||||
|
||||
## Decision
|
||||
|
||||
**Fixed, `low` retained for the record, embargo lifted, no escalation.**
|
||||
|
||||
The invalidation leg rests on attestation rather than a receipt. This register
|
||||
accepts that: the only independent probe would mean reconstructing the
|
||||
predecessor credential, which every record here forbids, and the attesting
|
||||
party is the provider owner with authority over the share. An unshared
|
||||
file-drop token cannot authorize a write, so the embargo condition
|
||||
("revoked or invalidated and the literal source default is removed") is met.
|
||||
The evidence class is stated in the finding. If the share is ever found live,
|
||||
the finding reopens at its original grade.
|
||||
|
||||
## Kept outside this finding
|
||||
|
||||
- **Age recovery-key taint.** RPF-WP-0029 says the age-key exposure is still
|
||||
open and that rotating the upload token cannot clear it. RISK-F-0010 covered
|
||||
only the WebDAV credential, and its report found the age key separate from
|
||||
the script. Any age-key exposure is a separate matter. I asked
|
||||
railiance-platform whether it should be filed as its own finding; it is not
|
||||
folded in here.
|
||||
- **Secondary-lane quota (10 GiB, about two archives).** This is a retention
|
||||
and capacity question for RPF, not an exposure.
|
||||
- **Discoverability.** RPF asked why its tracking was not found. RISK-WP-0007
|
||||
had already reconciled `fix_tracking: RPF-WP-0029-T02`. The 2026-09-01 gap
|
||||
came before that task was linked.
|
||||
Loading…
Add table
Add a link
Reference in a new issue