Record privileged action failure evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
tegwick 2026-08-23 12:58:12 +02:00
parent c4504c6de9
commit f579f3761c
8 changed files with 517 additions and 189 deletions

View file

@ -298,9 +298,13 @@ unrelated-identity input is now enforced as a strict mode-0600 out-of-repo token
file; absence fails closed, and throwaway OpenBao integration deliberately adds
an overlapping unrelated read policy and proves the check fails. Production
identity selection/ownership, audit request correlation, queued/replayed State
Hub delivery, and complete privileged failure-path evidence remain outstanding.
Hub delivery, and exact-action authorization remain outstanding. All live
privileged handlers now share one attempt/terminal evidence guard: approval
rejection, backend/input exceptions, interruption, verification failure, and
success are recorded without exception prose. Tests prove decision and backend
failures stop before inappropriate backend work and exclude fake secret text.
The complete repository suite passes with 111 tests after these changes,
The complete repository suite passes with 115 tests after these changes,
including throwaway OpenBao integration coverage.
Make verification and routing truthful for multi-field and high-risk lanes: