Source default removed, governed upload and restore have receipts, and the predecessor share is invalidated by owner attestation (no probe, by design). Fixed, embargo lifted, publication handover pending. Age-key taint referred to railiance-platform as a possible separate finding. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
42 lines
2.6 KiB
Markdown
42 lines
2.6 KiB
Markdown
# Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure
|
|
|
|
Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence
|
|
default, which does not apply: railiance-platform answered (message
|
|
`2caae2ef`, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit
|
|
`6dfb751`).
|
|
|
|
## Evidence against the closure condition
|
|
|
|
| Leg | Evidence (railiance-platform) | Class |
|
|
|-----|-------------------------------|-------|
|
|
| Literal source default removed | `tools/cmd/forgejo-backup` names the variable only in a comment; `lib/railiance-backup-common.sh` returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. | Observed source |
|
|
| Governed ciphertext upload | `docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json`: upload 201, download 200, matching ciphertext hash, decrypted | Receipt |
|
|
| Restore | `docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json`: isolated restore, database import, application health, 2040 package blobs verified, cleanup | Receipt |
|
|
| Predecessor invalidated | `docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json`: the operator attests the personal file-drop share was unshared; no HTTP probe | Owner attestation |
|
|
|
|
## Decision
|
|
|
|
**Fixed, `low` retained for the record, embargo lifted, no escalation.**
|
|
|
|
The invalidation leg rests on attestation rather than a receipt. This register
|
|
accepts that: the only independent probe would mean reconstructing the
|
|
predecessor credential, which every record here forbids, and the attesting
|
|
party is the provider owner with authority over the share. An unshared
|
|
file-drop token cannot authorize a write, so the embargo condition
|
|
("revoked or invalidated and the literal source default is removed") is met.
|
|
The evidence class is stated in the finding. If the share is ever found live,
|
|
the finding reopens at its original grade.
|
|
|
|
## Kept outside this finding
|
|
|
|
- **Age recovery-key taint.** RPF-WP-0029 says the age-key exposure is still
|
|
open and that rotating the upload token cannot clear it. RISK-F-0010 covered
|
|
only the WebDAV credential, and its report found the age key separate from
|
|
the script. Any age-key exposure is a separate matter. I asked
|
|
railiance-platform whether it should be filed as its own finding; it is not
|
|
folded in here.
|
|
- **Secondary-lane quota (10 GiB, about two archives).** This is a retention
|
|
and capacity question for RPF, not an exposure.
|
|
- **Discoverability.** RPF asked why its tracking was not found. RISK-WP-0007
|
|
had already reconciled `fix_tracking: RPF-WP-0029-T02`. The 2026-09-01 gap
|
|
came before that task was linked.
|