Refs CUST-WP-0068 Assistant: claude-code Assistant-Model: opus Assistant-Process: 2583210@bnt-lap001 Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
34 lines
1 KiB
Markdown
34 lines
1 KiB
Markdown
---
|
|
id: ADHOC-2026-08-21
|
|
type: workplan
|
|
title: "OpenBao dev-test and safe-path robustness"
|
|
domain: infotech
|
|
repo: secrets-engine
|
|
status: finished
|
|
owner: codex
|
|
topic_slug: custodian
|
|
created: "2026-08-21"
|
|
updated: "2026-08-21"
|
|
state_hub_workstream_id: "643a3710-9778-54d2-8bd5-cdc23a4139a6"
|
|
---
|
|
|
|
# ADHOC-2026-08-21 - OpenBao dev-test and safe-path robustness
|
|
|
|
## Keep verification safe in sandboxed environments
|
|
|
|
```task
|
|
id: ADHOC-2026-08-21-T01
|
|
status: done
|
|
priority: low
|
|
state_hub_task_id: "2d309354-7a5f-59f2-9817-15545f0fda5e"
|
|
```
|
|
|
|
While verifying SECRETS-WP-0006, the suite exposed two environment-sensitive
|
|
test failures. OpenBao 2.5.5 dev mode attempted to persist its root token under
|
|
the read-only home directory, and an empty `/tmp/.git` sandbox marker was
|
|
treated as a real Git worktree.
|
|
|
|
The dev fixture now uses `-dev-no-store-token`. Secret provisioning and AppRole
|
|
handoff still reject real worktrees (`.git` file or `.git/HEAD`) but ignore an
|
|
empty directory that is not a valid Git marker. Unit coverage preserves both
|
|
the rejection and false-positive cases.
|