RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading
Severity (impact x likelihood, fidelity modifier for controls that lie, headline-vs-constraint, build-mode double grade, the floor), disclosure (publish/embargoed/restricted, and the build-mode deferral re-taken and narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers settled plus an ordering-hazard trigger the RISK-F-0002 case forced; proposed, awaiting the custodian), review (intervals, what a review is, what missing one produces, the production re-score). Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002 medium with a high constraint on RISK-F-0001's remediation, filed as a peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no escalation. No unset field remains. REGISTER.md is generated; make check reports overdue, stalled, ungraded and unanswered escalations without changing anything. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
e268259f94
commit
d5a3953f2e
15 changed files with 1334 additions and 14 deletions
|
|
@ -12,10 +12,27 @@ environment: production
|
|||
fix_owner: ops-warden
|
||||
fix_tracking: WARDEN-WP-0007 (gate shipped, disabled) / FLEX-WP-0007 (runtime deploy)
|
||||
related: [RISK-F-0001]
|
||||
# risk-nexus's to set, not the reporter's (INTENT, "What it does not own").
|
||||
severity: unset
|
||||
disclosure: unset
|
||||
escalation: unset
|
||||
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-first-grading.md
|
||||
severity: medium
|
||||
severity_at_production: medium
|
||||
impact: I3
|
||||
likelihood: L2
|
||||
fidelity_modifier: false
|
||||
production_rescore: false
|
||||
constraint_on: RISK-F-0001
|
||||
constraint_severity: high
|
||||
constraint: "policy.enabled must not be turned on while flex-auth /v1/check answers unauthenticated callers — the gate would sign a false attestation"
|
||||
disclosure: embargoed
|
||||
embargo_condition: "FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production"
|
||||
embargo_since: "2026-08-19"
|
||||
embargo_review: "2026-11-17"
|
||||
escalation: required
|
||||
escalation_trigger: 6
|
||||
escalation_status: pending-operator
|
||||
last_reviewed: "2026-08-19"
|
||||
review_by: "2026-11-17"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-08-19
|
||||
---
|
||||
|
||||
# RISK-F-0002 — the SSH signing gate is off, and turning it on is now the more dangerous move
|
||||
|
|
@ -120,3 +137,59 @@ the risk of a decision we had already made and filed away as merely blocked.
|
|||
The estate's habit of recording a blocker once and not revisiting it is the
|
||||
thing to watch. A blocker is a claim about the world at a date. `RISK-F-0001`
|
||||
invalidated this one in a day, and nothing would have re-checked it.
|
||||
|
||||
## Register ruling — 2026-08-19
|
||||
|
||||
All three questions this finding put are answered.
|
||||
|
||||
**1. Severity — `medium` today, with a `high` constraint.** The headline
|
||||
scores the state of the world now: the gate is off, a missing control honestly
|
||||
represented. `I3` (SSH certificates into production hosts cross a trust
|
||||
boundary) × `L2` (scoped `VAULT_TOKEN`, actor in `inventory.yaml`, TTLs, every
|
||||
issuance logged — thin, but not nothing).
|
||||
|
||||
The argument that the two states are not equally bad is **accepted in full**,
|
||||
and it is now written into the scale as the fidelity modifier: a control that
|
||||
lies is one impact band worse than the same control absent
|
||||
(`docs/method/severity.md`). It is recorded as a constraint rather than the
|
||||
headline because the register describes the estate as it is, and the dangerous
|
||||
state does not exist yet:
|
||||
|
||||
> **Constraint, severity `high`.** Enabling `policy.enabled` while `/v1/check`
|
||||
> answers unauthenticated callers converts an absent control into a false
|
||||
> attestation — a genuine `allow` obtained by anyone with ClusterIP reach, and
|
||||
> a `policy_decision_id` in the signature log asserting the issuance was
|
||||
> authorized. `I3 + fidelity → I4`, `L2` → `high`.
|
||||
|
||||
The constraint is attached to `RISK-F-0001`'s remediation and recorded on both
|
||||
findings. A reader must not take away `medium` and miss it.
|
||||
|
||||
**2. Peer, not consequence.** Filed as `ops-warden` filed it. The fix owner
|
||||
differs and the "off" state has standing regardless of how `RISK-F-0001`
|
||||
resolves — if that finding were withdrawn tomorrow, production signing would
|
||||
still carry no per-request judgement. What is not independent is the ordering,
|
||||
and that travels as a constraint rather than by collapsing the two records.
|
||||
|
||||
**3. Escalation — the register disagrees, narrowly.** On triggers 1-5 it
|
||||
agrees with `ops-warden`: no real tenant data, no obligation, no spend, no
|
||||
ownership dispute, no stall. But "it is written down in both repos" is the one
|
||||
argument the register cannot accept here, because this finding is itself the
|
||||
evidence against it: its own blocker was written down, filed, and invalidated
|
||||
in a day with nothing re-checking it.
|
||||
|
||||
So trigger 6 — ordering hazard producing a false attestation — fires **once**.
|
||||
One acknowledgement that the operator holds the ordering, then the register
|
||||
carries it. Not a standing supervision request. That trigger exists in
|
||||
`docs/method/escalation.md` because of this finding.
|
||||
|
||||
**The general point is adopted.** "A blocker is a claim about the world at a
|
||||
date" is now question 2 of every review in `docs/method/review.md`, and this
|
||||
finding is cited there as the case that bought it.
|
||||
|
||||
Reasoning: `docs/rulings/2026-08-19-first-grading.md`.
|
||||
|
||||
## Reviews
|
||||
|
||||
- **2026-08-19** — graded. Next review 2026-11-17 (`medium` → 90 days).
|
||||
Open at review: has `FLEX-WP-0007` or `WARDEN-WP-0007` moved; is the stated
|
||||
blocker still true; does the ordering constraint still hold.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue