Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are reported rather than aborting; accepted findings and closure evidence are shown; defer requires a valid future date. Adds SCOPE.md, the scope assessment, the open-findings source review and a unittest suite. Stops tracking __pycache__. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
This commit is contained in:
parent
29f50d5143
commit
bbbede5f47
25 changed files with 1007 additions and 43 deletions
104
docs/verifications/2026-09-05-open-findings-source-review.md
Normal file
104
docs/verifications/2026-09-05-open-findings-source-review.md
Normal file
|
|
@ -0,0 +1,104 @@
|
|||
---
|
||||
id: RISK-V-0003
|
||||
type: verification
|
||||
title: "Owner-source progress and outstanding runtime evidence"
|
||||
date: "2026-09-05"
|
||||
owner: risk-nexus
|
||||
workplan: RISK-WP-0007
|
||||
findings: [RISK-F-0011, RISK-F-0010, RISK-F-0008]
|
||||
---
|
||||
|
||||
# Owner-source review — 2026-09-05
|
||||
|
||||
This is a checkout and inbox review, not a runtime probe. No credentials were
|
||||
used or reproduced, no system was changed and no legal determination was renewed.
|
||||
Files can include uncommitted owner work; repository HEAD is context, not proof
|
||||
that every inspected change is in that commit.
|
||||
|
||||
## Qonto deny-stream completeness
|
||||
|
||||
Read State Hub notice `c6442eef-34fc-46a7-9639-10f2cd6120fc` (2026-09-04),
|
||||
QONTO-WP-0005, `specs/audit-emission-cadence.yaml`, `src/qonto_assistant/audit.py`,
|
||||
the application lifespan/reconciliation endpoint, and KG-WP-0005.
|
||||
|
||||
The source now declares process instance/sequence semantics, a 24-hour default
|
||||
active-process heartbeat, startup and best-effort shutdown, and reconciliation
|
||||
counts. AuditLogger serializes emission and exposes source counters; the app
|
||||
wires the heartbeat lifecycle and identity-checked snapshot route. Qonto records
|
||||
88 passing tests on its latest review; that suite was not rerun by risk-nexus.
|
||||
King's Guard records local source-path validation and explicitly leaves
|
||||
KG-WP-0005-T03 waiting for authorized deployed evidence.
|
||||
|
||||
**Conclusion:** the old statement that no source cadence/reconciliation exists
|
||||
is obsolete. Runtime completeness remains unestablished. F-0011 stays open,
|
||||
medium and public, with QONTO-WP-0005 and KG-WP-0005-T03 as tracking.
|
||||
|
||||
**Closure evidence owed:** qonto's runtime owner supplies a bounded capture from
|
||||
one deployed instance, naming the deployed revision, configured heartbeat
|
||||
interval and observation window. It covers startup, a request transition,
|
||||
periodic heartbeat timing, sequence/instance continuity and a same-instance
|
||||
reconciliation snapshot. King's Guard compares received counts and source counts,
|
||||
records any gaps and the acceptance decision. Evidence may support only the
|
||||
observed instance/window, never an unbounded all-time completeness claim.
|
||||
The original 2026-09-16 default remains; a completed source plan does not close
|
||||
the runtime finding. This narrows the existing evidence request; no new request
|
||||
or message was sent in this sitting.
|
||||
|
||||
## Backup credential
|
||||
|
||||
Read RPF-WP-0029 and inspected `tools/cmd/forgejo-backup` in memory for the
|
||||
named shell fallback without outputting credential-bearing lines. No nonempty
|
||||
literal fallback for `RAILIANCE_BACKUP_NC_TOKEN` remains in that script.
|
||||
The owner records fail-closed input tests as complete under T01. T02 is `wait`:
|
||||
provider-side invalidation and encrypted upload/restore receipts are absent.
|
||||
|
||||
**Conclusion:** source removal is established in the checkout; predecessor
|
||||
invalidation is not. F-0010 stays open, low and embargoed. RPF-WP-0029-T02 names
|
||||
the remaining provider/recovery work. The 2026-09-15 embargo review/default
|
||||
stands. No inference is made about whether the predecessor is still valid.
|
||||
Only non-secret invalidation, governed ciphertext upload and restore receipts
|
||||
can complete the remaining evidence; source removal alone cannot lift the hold.
|
||||
|
||||
## Accepted retention obligation
|
||||
|
||||
Read the existing acceptance and determination references in F-0008 and
|
||||
`audit-core/docs/erasure-and-audit.md`. Audit Core still documents the
|
||||
cleartext-hash confirmation problem and says keyed commitments are not built.
|
||||
No new answer to the co-residency horizon or keyed-commitment wait was present
|
||||
in the fetched risk-nexus inbox. This is not proof that no answer exists elsewhere.
|
||||
|
||||
F-0008 already has a named accepter, an ending condition, a real determination
|
||||
and a next check. The reporting problem is classifying that accepted obligation
|
||||
as an untracked fix. The report should expose its existing acceptance terms
|
||||
without inventing engineering work or treating acceptance as closure. Its
|
||||
substantive review remains due: this sitting does not establish that the
|
||||
real-person/counterparty trigger has not fired and does not renew the legal basis.
|
||||
|
||||
## External intake and scheduled reviews
|
||||
|
||||
Searched policy-nexus publication configuration, workplans and deployment files
|
||||
for a security contact/security.txt or delivered external-report route. None
|
||||
was found in those inspected sources. The existing intake proposal remains the
|
||||
available evidence; current public endpoints and estate-wide contact availability
|
||||
were not verified. Publishing a new contact requires its actual receiving owner.
|
||||
|
||||
Searched activity-core's local definitions and evidence for the two risk register
|
||||
activities. No matching execution receipt was found in those paths. The two
|
||||
definitions in risk-nexus remain source instructions. Their live registration,
|
||||
execution and completed-session chain are unverified; this search is not proof
|
||||
that the activities do not run. No deployment or synchronization was attempted.
|
||||
|
||||
## Source provenance
|
||||
|
||||
| Inspected source | SHA-256 of the non-secret document |
|
||||
| --- | --- |
|
||||
| qonto-assistant QONTO-WP-0005 | `f3b21ed7d046e7a4e5e8eee1397dcdcf1a17211f75786da3a0a2258b44802c3a` |
|
||||
| qonto-assistant cadence declaration | `69db6068b2e262f6b9108903cf7c5a7764efba5c981344c50df496018bc98ed9` |
|
||||
| qonto-assistant audit.py | `573e669914ae2ae77dfbf0a0929ef080cfbcb7dd4e0ba79e9408dd401fd74437` |
|
||||
| railiance-platform RPF-WP-0029 | `396d2e167b8bd1141671fadd864660a1e8bc6efb1ea3a09be3465e841ce33144` |
|
||||
| audit-core erasure-and-audit.md | `40d0f86ad401c3fb413fb21346a77210b6840d52f05093b31143a11b8a3a878b` |
|
||||
|
||||
Observed HEADs: qonto `e5611147fd72a23e58618b87b0c3b96c807d0043`,
|
||||
railiance-platform `f637989a6911a7a13812cba223ffc007d78d6302`,
|
||||
audit-core `95dcb78e17d46889c17b55e3ba1aadbcceec6a99`,
|
||||
policy-nexus `c1b60f322e3bcddff3cece618ece2bd3686169e1`.
|
||||
Loading…
Add table
Add a link
Reference in a new issue