Source default removed, governed upload and restore have receipts, and the predecessor share is invalidated by owner attestation (no probe, by design). Fixed, embargo lifted, publication handover pending. Age-key taint referred to railiance-platform as a possible separate finding. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2.6 KiB
Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure
Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence
default, which does not apply: railiance-platform answered (message
2caae2ef, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit
6dfb751).
Evidence against the closure condition
| Leg | Evidence (railiance-platform) | Class |
|---|---|---|
| Literal source default removed | tools/cmd/forgejo-backup names the variable only in a comment; lib/railiance-backup-common.sh returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. |
Observed source |
| Governed ciphertext upload | docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json: upload 201, download 200, matching ciphertext hash, decrypted |
Receipt |
| Restore | docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json: isolated restore, database import, application health, 2040 package blobs verified, cleanup |
Receipt |
| Predecessor invalidated | docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json: the operator attests the personal file-drop share was unshared; no HTTP probe |
Owner attestation |
Decision
Fixed, low retained for the record, embargo lifted, no escalation.
The invalidation leg rests on attestation rather than a receipt. This register accepts that: the only independent probe would mean reconstructing the predecessor credential, which every record here forbids, and the attesting party is the provider owner with authority over the share. An unshared file-drop token cannot authorize a write, so the embargo condition ("revoked or invalidated and the literal source default is removed") is met. The evidence class is stated in the finding. If the share is ever found live, the finding reopens at its original grade.
Kept outside this finding
- Age recovery-key taint. RPF-WP-0029 says the age-key exposure is still open and that rotating the upload token cannot clear it. RISK-F-0010 covered only the WebDAV credential, and its report found the age key separate from the script. Any age-key exposure is a separate matter. I asked railiance-platform whether it should be filed as its own finding; it is not folded in here.
- Secondary-lane quota (10 GiB, about two archives). This is a retention and capacity question for RPF, not an exposure.
- Discoverability. RPF asked why its tracking was not found. RISK-WP-0007
had already reconciled
fix_tracking: RPF-WP-0029-T02. The 2026-09-01 gap came before that task was linked.