--- id: SECRETS-WP-ADHOC-2026-08-21 type: workplan title: "OpenBao dev-test and safe-path robustness" domain: infotech repo: secrets-engine status: finished owner: codex topic_slug: custodian created: "2026-08-21" updated: "2026-08-21" state_hub_workstream_id: "5580d785-c80f-5dbd-9ef8-22a630fa607b" --- # SECRETS-WP-ADHOC-2026-08-21 - OpenBao dev-test and safe-path robustness ## Keep verification safe in sandboxed environments ```task id: SECRETS-WP-ADHOC-2026-08-21-T01 status: done priority: low state_hub_task_id: "d50e7dca-ef90-5263-ad40-35ec8a6e5291" ``` While verifying SECRETS-WP-0006, the suite exposed two environment-sensitive test failures. OpenBao 2.5.5 dev mode attempted to persist its root token under the read-only home directory, and an empty `/tmp/.git` sandbox marker was treated as a real Git worktree. The dev fixture now uses `-dev-no-store-token`. Secret provisioning and AppRole handoff still reject real worktrees (`.git` file or `.git/HEAD`) but ignore an empty directory that is not a valid Git marker. Unit coverage preserves both the rejection and false-positive cases.