Complete T03 with native OpenRouter authentication evidence
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a09cbb-87c6-7900-a145-4ce53ba9f1a6
This commit is contained in:
parent
ec7263dc3f
commit
4a8ea4f591
7 changed files with 551 additions and 2 deletions
39
docs/evidence/2026-09-15-t03-native-execution.json
Normal file
39
docs/evidence/2026-09-15-t03-native-execution.json
Normal file
|
|
@ -0,0 +1,39 @@
|
|||
{
|
||||
"status": "failed",
|
||||
"phase": "verify_attempt_started",
|
||||
"observed_at": "2026-09-16T00:04:58.620710+00:00",
|
||||
"actions": [
|
||||
{
|
||||
"action": "apply",
|
||||
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
|
||||
"exit_code": 0,
|
||||
"limits": {
|
||||
"token_ttl": 900,
|
||||
"token_max_ttl": 1800,
|
||||
"secret_id_ttl": 900,
|
||||
"secret_id_num_uses": 1,
|
||||
"token_num_uses": 8
|
||||
}
|
||||
}
|
||||
],
|
||||
"health_before": {
|
||||
"deployment": [
|
||||
{
|
||||
"namespace": "activity-core",
|
||||
"name": "llm-connect",
|
||||
"ready": 1
|
||||
}
|
||||
],
|
||||
"externalsecret": [
|
||||
{
|
||||
"namespace": "activity-core",
|
||||
"name": "llm-connect-provider-secrets",
|
||||
"ready": true
|
||||
}
|
||||
]
|
||||
},
|
||||
"failure_type": "ValueError",
|
||||
"failure_location": "/home/worsch/railiance-platform/scripts/t03-native-execution.py:25",
|
||||
"failure_code": "revoked_token_still_usable",
|
||||
"owner_forwards_closed": true
|
||||
}
|
||||
381
docs/evidence/2026-09-16-t03-completion.json
Normal file
381
docs/evidence/2026-09-16-t03-completion.json
Normal file
|
|
@ -0,0 +1,381 @@
|
|||
{
|
||||
"task": "SECRETS-WP-0010-T03",
|
||||
"status": "passed",
|
||||
"scope": "Exact pinned read-only OpenRouter key-check recipient; no inference",
|
||||
"initial_receipt": "2026-09-15-t03-native-execution.json",
|
||||
"continuation_receipt": "2026-09-16-t03-resume-exec.json",
|
||||
"reconciliation": "Initial supplemental revocation lookup fell back to admin helper after session token cleared; native verify itself passed. Continuation checked exact applied policy/role and consumed apply/verify state, tested the explicit revoked token (403), then consumed only exec.",
|
||||
"native_evidence": [
|
||||
{
|
||||
"action": "apply",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "",
|
||||
"detail": {
|
||||
"approval_status": "pending",
|
||||
"decision_ref": "CCR-2026-0003"
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
|
||||
"result": "attempt",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:08.084607+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "443aeeaf-bae7-479d-a2d1-3d90ccd58594",
|
||||
"related_record_id": "cc68f5e1-2695-4838-b588-082bf204fb21",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:08.202043+00:00"
|
||||
},
|
||||
{
|
||||
"action": "apply",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "decision:dc57b3b9614aa15b",
|
||||
"detail": {
|
||||
"applied": [
|
||||
"policy se-prod-openrouter-llm-connect",
|
||||
"approle se-prod-openrouter-llm-connect -> [se-prod-openrouter-llm-connect]"
|
||||
],
|
||||
"approval_consume_idempotent": false,
|
||||
"approval_consumed": true,
|
||||
"approval_consumed_at": "2026-09-16T00:05:09+00:00",
|
||||
"approval_human_control": true,
|
||||
"approval_id": "9935335c-8e9a-566e-a48e-6a5b5f4882eb",
|
||||
"approval_status": "approved",
|
||||
"auth_provider": "env",
|
||||
"authorization_decision_id": "decision:dc57b3b9614aa15b",
|
||||
"authorization_expires_at": "2026-09-16T00:20:09+00:00",
|
||||
"decision_id": "decision:dc57b3b9614aa15b",
|
||||
"decision_ref": "CCR-2026-0003",
|
||||
"request_digest": "sha256:c5c44adc715385640dffeb3305ff854fc69bd800929f8c31f93a536524089831",
|
||||
"skipped": [
|
||||
"kv-mount platform (externally managed; no mutation)"
|
||||
],
|
||||
"stance_authorized": true,
|
||||
"stance_demo_exception": false,
|
||||
"stance_failure_mode": "fail_closed",
|
||||
"stance_stage": "prod"
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
|
||||
"result": "applied",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:09.827448+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "decision:dc57b3b9614aa15b",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "783c71dc-d848-4511-bb52-a8d2f99f6048",
|
||||
"related_record_id": "fb256f9f-303b-4a7f-a060-71b713e2c085",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:09.941648+00:00"
|
||||
},
|
||||
{
|
||||
"action": "verify",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "",
|
||||
"detail": {
|
||||
"approval_status": "pending",
|
||||
"decision_ref": "CCR-2026-0003",
|
||||
"fields": [
|
||||
"OPENROUTER_API_KEY"
|
||||
],
|
||||
"negative_requested": true,
|
||||
"positive_requested": true
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
|
||||
"result": "attempt",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:10.134582+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "cbca0831-44f3-472a-99c5-e7033f59e450",
|
||||
"related_record_id": "f404f2b5-ae06-4cf8-a41c-52ed8fc42817",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:10.250783+00:00"
|
||||
},
|
||||
{
|
||||
"action": "verify-check",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"detail": {
|
||||
"field": "OPENROUTER_API_KEY",
|
||||
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
|
||||
"reason": "approved consumer can read lane field",
|
||||
"role": "se-prod-openrouter-llm-connect",
|
||||
"session": {
|
||||
"established": true,
|
||||
"revocation_attempted": true,
|
||||
"revocation_succeeded": true,
|
||||
"session_handle": "4c0eb1a18281"
|
||||
}
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
|
||||
"result": "positive:pass",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:12.330802+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "1e8511a0-1b43-4626-a04a-07084c026bd9",
|
||||
"related_record_id": "b97bbbb9-ff29-4591-9f72-486918c1d2ab",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:12.450529+00:00"
|
||||
},
|
||||
{
|
||||
"action": "verify-check",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"detail": {
|
||||
"path": "workloads/activity-core/llm-connect/llm-connect-provider-secrets",
|
||||
"reason": "unrelated token denied read"
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
|
||||
"result": "negative:pass",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:12.456767+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "3d203e9b-b441-4336-b18a-248cea35dde0",
|
||||
"related_record_id": "4c9c8615-2b12-4874-b960-c2ab702009f5",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:12.559760+00:00"
|
||||
},
|
||||
{
|
||||
"action": "verify",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"detail": {
|
||||
"approval_consume_idempotent": false,
|
||||
"approval_consumed": true,
|
||||
"approval_consumed_at": "2026-09-16T00:05:11+00:00",
|
||||
"approval_human_control": true,
|
||||
"approval_id": "273d6882-6253-5dc9-ac54-544f92ef5e56",
|
||||
"approval_status": "approved",
|
||||
"auth_provider": "env",
|
||||
"authorization_decision_id": "decision:b4fca706e4c55b9a",
|
||||
"authorization_expires_at": "2026-09-16T00:20:11+00:00",
|
||||
"check_count": 2,
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"decision_ref": "CCR-2026-0003",
|
||||
"fields": [
|
||||
"OPENROUTER_API_KEY"
|
||||
],
|
||||
"negative_requested": true,
|
||||
"positive_requested": true,
|
||||
"request_digest": "sha256:a735896e9d208032ea08b073bcc819864b12116bdf60852fcdd2e54dad2e62bf",
|
||||
"stance_authorized": true,
|
||||
"stance_demo_exception": false,
|
||||
"stance_failure_mode": "fail_closed",
|
||||
"stance_stage": "prod"
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
|
||||
"result": "pass",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:12.565647+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "decision:b4fca706e4c55b9a",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "0ddce2fc-b552-4d62-8c24-6c167ff3826d",
|
||||
"related_record_id": "39f8084d-c3f4-443a-8272-2cda87c46c89",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:05:12.741772+00:00"
|
||||
},
|
||||
{
|
||||
"action": "exec",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "",
|
||||
"detail": {
|
||||
"approval_status": "pending",
|
||||
"command": "/usr/bin/python3.12",
|
||||
"decision_ref": "CCR-2026-0003",
|
||||
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
|
||||
"field": "OPENROUTER_API_KEY",
|
||||
"mode": "exec-env",
|
||||
"session": {}
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
|
||||
"result": "attempt",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:08:28.639246+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "b14a7442-c26b-4368-a4a0-fc39cd902143",
|
||||
"related_record_id": "6c69ca07-4617-4a2b-9802-0811c9204b62",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:08:28.752134+00:00"
|
||||
},
|
||||
{
|
||||
"action": "exec",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"completeness_claimed": false,
|
||||
"decision_id": "decision:82cec64febcf635f",
|
||||
"detail": {
|
||||
"approval_consume_idempotent": false,
|
||||
"approval_consumed": true,
|
||||
"approval_consumed_at": "2026-09-16T00:08:32+00:00",
|
||||
"approval_human_control": true,
|
||||
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
|
||||
"approval_status": "approved",
|
||||
"auth_provider": "env",
|
||||
"authorization_decision_id": "decision:82cec64febcf635f",
|
||||
"authorization_expires_at": "2026-09-16T00:23:31+00:00",
|
||||
"command": "/usr/bin/python3.12",
|
||||
"decision_id": "decision:82cec64febcf635f",
|
||||
"decision_ref": "CCR-2026-0003",
|
||||
"exec_owner_sha256": "22393c7e751e458fa64bb24305ee66a26bbe3993c5aba03ae1fc1a488e777b42",
|
||||
"field": "OPENROUTER_API_KEY",
|
||||
"mode": "exec-env",
|
||||
"request_digest": "sha256:4082d2ccad78097a8be34ff0b0221ed2c4b6407fdbaf36e4a583927ae9acc820",
|
||||
"session": {
|
||||
"established": true,
|
||||
"revocation_attempted": true,
|
||||
"revocation_succeeded": true,
|
||||
"session_handle": "6b9b4927b6ba"
|
||||
},
|
||||
"stance_authorized": true,
|
||||
"stance_demo_exception": false,
|
||||
"stance_failure_mode": "fail_closed",
|
||||
"stance_stage": "prod"
|
||||
},
|
||||
"evidence_kind": "attributive",
|
||||
"evidence_rule": "default-attributive",
|
||||
"hub_delivery_requested": true,
|
||||
"record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
|
||||
"result": "exit-0",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:08:30.937892+00:00"
|
||||
},
|
||||
{
|
||||
"action": "evidence-delivery",
|
||||
"actor": "worsch",
|
||||
"catalog_id": "openrouter-llm-connect",
|
||||
"decision_id": "decision:82cec64febcf635f",
|
||||
"detail": {},
|
||||
"hub_delivery_requested": false,
|
||||
"record_id": "6b1208b7-32fd-4245-b73b-d35968e3a960",
|
||||
"related_record_id": "3823a903-1a13-4d85-aef0-cc2e05c477a0",
|
||||
"result": "delivered",
|
||||
"stage": "prod",
|
||||
"ts": "2026-09-16T00:08:31.048605+00:00"
|
||||
}
|
||||
],
|
||||
"clock_acceptance": {
|
||||
"scope": "production authority acceptance",
|
||||
"host": "railiance01",
|
||||
"client": "Linux/WSL via SSH loopback",
|
||||
"os_clocks_changed": false,
|
||||
"samples": [
|
||||
{
|
||||
"width_ms": 132.40261,
|
||||
"railiance_minus_local_midpoint_ms": 1334.507298,
|
||||
"independent_host_cross_check": true
|
||||
},
|
||||
{
|
||||
"width_ms": 127.548741,
|
||||
"railiance_minus_local_midpoint_ms": 1391.968235,
|
||||
"independent_host_cross_check": true
|
||||
},
|
||||
{
|
||||
"width_ms": 126.412228,
|
||||
"railiance_minus_local_midpoint_ms": 1445.070823,
|
||||
"independent_host_cross_check": true
|
||||
}
|
||||
],
|
||||
"wrong_kid_refused": true,
|
||||
"epoch": "b1164ccb-a4c2-4cc8-adf8-1d5597de697b",
|
||||
"kid": "railiance01-clock-20260915-v1",
|
||||
"public_key_sha256": "bd583446b5ed61d086806b2a0c5aaf33a875b751e45599e75335d1f415be609a",
|
||||
"trust_lifetime_seconds": 900
|
||||
},
|
||||
"residual_handoffs": [
|
||||
"INFD-IN-0005",
|
||||
"SECRETS-WP-0006-T05",
|
||||
"SECRETS-WP-0006-T06",
|
||||
"SECRETS-WP-0007-T04",
|
||||
"SECRETS-WP-0007-T07",
|
||||
"IR-WP-0005",
|
||||
"IR-WP-0006"
|
||||
],
|
||||
"approval_state": "All three native claims inspected as consumed after completion",
|
||||
"inference_performed": false,
|
||||
"provider_key_rotated": false
|
||||
}
|
||||
59
docs/evidence/2026-09-16-t03-resume-exec.json
Normal file
59
docs/evidence/2026-09-16-t03-resume-exec.json
Normal file
|
|
@ -0,0 +1,59 @@
|
|||
{
|
||||
"status": "passed",
|
||||
"phase": "all_actions_completed",
|
||||
"observed_at": "2026-09-16T00:08:21.161761+00:00",
|
||||
"actions": [
|
||||
{
|
||||
"action": "exec",
|
||||
"approval_id": "7ba0c13b-68cd-5b3e-9481-42ba9e385e68",
|
||||
"exit_code": 0,
|
||||
"key_check": {
|
||||
"http_status": 200,
|
||||
"result": "authenticated"
|
||||
}
|
||||
}
|
||||
],
|
||||
"health_before": {
|
||||
"deployment": [
|
||||
{
|
||||
"namespace": "activity-core",
|
||||
"name": "llm-connect",
|
||||
"ready": 1
|
||||
}
|
||||
],
|
||||
"externalsecret": [
|
||||
{
|
||||
"namespace": "activity-core",
|
||||
"name": "llm-connect-provider-secrets",
|
||||
"ready": true
|
||||
}
|
||||
]
|
||||
},
|
||||
"prior_receipt": "2026-09-15-t03-native-execution.json",
|
||||
"completed_actions_not_replayed": [
|
||||
"apply",
|
||||
"verify"
|
||||
],
|
||||
"supplemental_cleanup": {
|
||||
"unrelated_path_denied": true,
|
||||
"session_revocation_verified": true,
|
||||
"revoked_token_lookup_status": 403
|
||||
},
|
||||
"health_after": {
|
||||
"deployment": [
|
||||
{
|
||||
"namespace": "activity-core",
|
||||
"name": "llm-connect",
|
||||
"ready": 1
|
||||
}
|
||||
],
|
||||
"externalsecret": [
|
||||
{
|
||||
"namespace": "activity-core",
|
||||
"name": "llm-connect-provider-secrets",
|
||||
"ready": true
|
||||
}
|
||||
]
|
||||
},
|
||||
"owner_forwards_closed": true
|
||||
}
|
||||
|
|
@ -91,3 +91,15 @@ records the live binding. Attended apply/readback passed; scoped credential
|
|||
delivery verification remains pending. Native requesting
|
||||
identity (`approval:create`) and Informed Decision human review are also needed;
|
||||
do not reuse the withdrawn combined operator client or seed a production approval.
|
||||
|
||||
|
||||
## Native acceptance completed — 2026-09-16
|
||||
|
||||
The sequence above has now passed for the exact pinned key-check recipient.
|
||||
See `docs/evidence/2026-09-16-t03-completion.json` for native positive/negative
|
||||
verification, three distinct consumed human approvals, OpenRouter HTTP 200,
|
||||
revocation HTTP 403, application/ESO health and Railiance Clock admission.
|
||||
The first supplemental revocation probe failed due to admin-helper fallback;
|
||||
the retained continuation fixes that check without replaying apply or verify.
|
||||
Future executions require new approvals. Trials and billing readiness remain
|
||||
owned by IR-WP-0005/0006; general proxy retirement remains SECRETS-WP-0006-T06.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue