risk-nexus/docs/verifications/2026-09-05-open-findings-source-review.md
tegwick bbbede5f47 Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 07:56:58 +02:00

104 lines
5.6 KiB
Markdown

---
id: RISK-V-0003
type: verification
title: "Owner-source progress and outstanding runtime evidence"
date: "2026-09-05"
owner: risk-nexus
workplan: RISK-WP-0007
findings: [RISK-F-0011, RISK-F-0010, RISK-F-0008]
---
# Owner-source review — 2026-09-05
This is a checkout and inbox review, not a runtime probe. No credentials were
used or reproduced, no system was changed and no legal determination was renewed.
Files can include uncommitted owner work; repository HEAD is context, not proof
that every inspected change is in that commit.
## Qonto deny-stream completeness
Read State Hub notice `c6442eef-34fc-46a7-9639-10f2cd6120fc` (2026-09-04),
QONTO-WP-0005, `specs/audit-emission-cadence.yaml`, `src/qonto_assistant/audit.py`,
the application lifespan/reconciliation endpoint, and KG-WP-0005.
The source now declares process instance/sequence semantics, a 24-hour default
active-process heartbeat, startup and best-effort shutdown, and reconciliation
counts. AuditLogger serializes emission and exposes source counters; the app
wires the heartbeat lifecycle and identity-checked snapshot route. Qonto records
88 passing tests on its latest review; that suite was not rerun by risk-nexus.
King's Guard records local source-path validation and explicitly leaves
KG-WP-0005-T03 waiting for authorized deployed evidence.
**Conclusion:** the old statement that no source cadence/reconciliation exists
is obsolete. Runtime completeness remains unestablished. F-0011 stays open,
medium and public, with QONTO-WP-0005 and KG-WP-0005-T03 as tracking.
**Closure evidence owed:** qonto's runtime owner supplies a bounded capture from
one deployed instance, naming the deployed revision, configured heartbeat
interval and observation window. It covers startup, a request transition,
periodic heartbeat timing, sequence/instance continuity and a same-instance
reconciliation snapshot. King's Guard compares received counts and source counts,
records any gaps and the acceptance decision. Evidence may support only the
observed instance/window, never an unbounded all-time completeness claim.
The original 2026-09-16 default remains; a completed source plan does not close
the runtime finding. This narrows the existing evidence request; no new request
or message was sent in this sitting.
## Backup credential
Read RPF-WP-0029 and inspected `tools/cmd/forgejo-backup` in memory for the
named shell fallback without outputting credential-bearing lines. No nonempty
literal fallback for `RAILIANCE_BACKUP_NC_TOKEN` remains in that script.
The owner records fail-closed input tests as complete under T01. T02 is `wait`:
provider-side invalidation and encrypted upload/restore receipts are absent.
**Conclusion:** source removal is established in the checkout; predecessor
invalidation is not. F-0010 stays open, low and embargoed. RPF-WP-0029-T02 names
the remaining provider/recovery work. The 2026-09-15 embargo review/default
stands. No inference is made about whether the predecessor is still valid.
Only non-secret invalidation, governed ciphertext upload and restore receipts
can complete the remaining evidence; source removal alone cannot lift the hold.
## Accepted retention obligation
Read the existing acceptance and determination references in F-0008 and
`audit-core/docs/erasure-and-audit.md`. Audit Core still documents the
cleartext-hash confirmation problem and says keyed commitments are not built.
No new answer to the co-residency horizon or keyed-commitment wait was present
in the fetched risk-nexus inbox. This is not proof that no answer exists elsewhere.
F-0008 already has a named accepter, an ending condition, a real determination
and a next check. The reporting problem is classifying that accepted obligation
as an untracked fix. The report should expose its existing acceptance terms
without inventing engineering work or treating acceptance as closure. Its
substantive review remains due: this sitting does not establish that the
real-person/counterparty trigger has not fired and does not renew the legal basis.
## External intake and scheduled reviews
Searched policy-nexus publication configuration, workplans and deployment files
for a security contact/security.txt or delivered external-report route. None
was found in those inspected sources. The existing intake proposal remains the
available evidence; current public endpoints and estate-wide contact availability
were not verified. Publishing a new contact requires its actual receiving owner.
Searched activity-core's local definitions and evidence for the two risk register
activities. No matching execution receipt was found in those paths. The two
definitions in risk-nexus remain source instructions. Their live registration,
execution and completed-session chain are unverified; this search is not proof
that the activities do not run. No deployment or synchronization was attempted.
## Source provenance
| Inspected source | SHA-256 of the non-secret document |
| --- | --- |
| qonto-assistant QONTO-WP-0005 | `f3b21ed7d046e7a4e5e8eee1397dcdcf1a17211f75786da3a0a2258b44802c3a` |
| qonto-assistant cadence declaration | `69db6068b2e262f6b9108903cf7c5a7764efba5c981344c50df496018bc98ed9` |
| qonto-assistant audit.py | `573e669914ae2ae77dfbf0a0929ef080cfbcb7dd4e0ba79e9408dd401fd74437` |
| railiance-platform RPF-WP-0029 | `396d2e167b8bd1141671fadd864660a1e8bc6efb1ea3a09be3465e841ce33144` |
| audit-core erasure-and-audit.md | `40d0f86ad401c3fb413fb21346a77210b6840d52f05093b31143a11b8a3a878b` |
Observed HEADs: qonto `e5611147fd72a23e58618b87b0c3b96c807d0043`,
railiance-platform `f637989a6911a7a13812cba223ffc007d78d6302`,
audit-core `95dcb78e17d46889c17b55e3ba1aadbcceec6a99`,
policy-nexus `c1b60f322e3bcddff3cece618ece2bd3686169e1`.