risk-nexus/docs/rulings/2026-09-22-f0010-closure.md
tegwick 81e31b379c Close RISK-F-0010 on RPF-WP-0029 evidence (RISK-RULING-2026-09-22-A)
Source default removed, governed upload and restore have receipts, and the
predecessor share is invalidated by owner attestation (no probe, by design).
Fixed, embargo lifted, publication handover pending. Age-key taint referred
to railiance-platform as a possible separate finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 08:01:39 +02:00

2.6 KiB

Ruling RISK-RULING-2026-09-22-A — RISK-F-0010 closure

Date: 2026-09-22. Graded by risk-nexus. Supersedes the 2026-09-15 silence default, which does not apply: railiance-platform answered (message 2caae2ef, 2026-09-09) and closed RPF-WP-0029-T02 on 2026-09-15 (commit 6dfb751).

Evidence against the closure condition

Leg Evidence (railiance-platform) Class
Literal source default removed tools/cmd/forgejo-backup names the variable only in a comment; lib/railiance-backup-common.sh returns 1 when the governed token is absent, before the URL template is built. Re-read 2026-09-22 without displaying any value. Observed source
Governed ciphertext upload docs/evidence/RPF-WP-0029-secondary-transfer-2026-09-06.json: upload 201, download 200, matching ciphertext hash, decrypted Receipt
Restore docs/evidence/RPF-WP-0029-secondary-restore-2026-09-06.json: isolated restore, database import, application health, 2040 package blobs verified, cleanup Receipt
Predecessor invalidated docs/evidence/2026-09-15-rpf-wp-0029-predecessor-share-invalidated.json: the operator attests the personal file-drop share was unshared; no HTTP probe Owner attestation

Decision

Fixed, low retained for the record, embargo lifted, no escalation.

The invalidation leg rests on attestation rather than a receipt. This register accepts that: the only independent probe would mean reconstructing the predecessor credential, which every record here forbids, and the attesting party is the provider owner with authority over the share. An unshared file-drop token cannot authorize a write, so the embargo condition ("revoked or invalidated and the literal source default is removed") is met. The evidence class is stated in the finding. If the share is ever found live, the finding reopens at its original grade.

Kept outside this finding

  • Age recovery-key taint. RPF-WP-0029 says the age-key exposure is still open and that rotating the upload token cannot clear it. RISK-F-0010 covered only the WebDAV credential, and its report found the age key separate from the script. Any age-key exposure is a separate matter. I asked railiance-platform whether it should be filed as its own finding; it is not folded in here.
  • Secondary-lane quota (10 GiB, about two archives). This is a retention and capacity question for RPF, not an exposure.
  • Discoverability. RPF asked why its tracking was not found. RISK-WP-0007 had already reconciled fix_tracking: RPF-WP-0029-T02. The 2026-09-01 gap came before that task was linked.