R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed, authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820, R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions. Register 326 -> 327. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -26,6 +26,17 @@
|
||||
|
||||
---
|
||||
|
||||
## 2026-10-03 — off-site append-only, measured on the provider (R-436, R-430)
|
||||
|
||||
> Spike, no product change. Evidence and design: `audits/offsite-append-only-2026-10-03/`.
|
||||
|
||||
| Row | What | Closed | Evidence |
|
||||
|---|---|---|---|
|
||||
| **R-436** | **Hetzner's `--append-only` forced command holds for the key it is pinned to.** On `u629488-sub4` (tester-1's, operator-ruled venue; scratch repo `spike-r436`, removed): pinned key `command="rclone serve restic --stdio --append-only spike-r436",restrict` — `init`, two `backup`s, `snapshots`, `restore` (bytes identical), `check` OK; `forget d807418c --prune`, `forget --keep-last 1`, `prune` → `blob not removed, server response: 403 Forbidden (403)`, rc=1, count unchanged; control with an unpinned key: `1 / 1 files deleted`. The client's path and flags are ignored; no shell, sftp, scp, rsync or port forward (`administratively prohibited`). **Reasoning kept: the pin protects a repository only if no other route can rewrite `authorized_keys` — and the password can (R-820).** | CLOSED 2026-10-03 — MEASURED; the due-check (2026-10-06) is cleared by this measurement | `live/E1-E3-init-backup.txt`, `live/E4-E6-deletes-and-C1.txt`, `live/B2-forced-key-misuse.txt`, `live/TEARDOWN.txt` (authorized_keys restored, sha256 identical) |
|
||||
| **R-430** | **`restic unlock` prints `successfully removed locks` after removing nothing — by design; and `unlock --remove-all` DOES work through the append-only key.** Measured live and in the lab: a crash lock (not yet stale: under 30 min, new hostname) survives plain `unlock`, which still prints success; `--remove-all` removes it because the rclone append-only server allows lock deletion. A crash lock blocks `check`, not `backup`. So `resticStep`'s self-heal stays valid under R-436's transport; the earlier sticky-directory model does not describe it. | CLOSED 2026-10-03 — ANSWERED; not a precondition for the rclone transport | `live/C2-A5-locks.txt`, `lab/A5-locks.txt` |
|
||||
|
||||
---
|
||||
|
||||
## 2026-10-03 — the triage: finished rows moved out of the open register
|
||||
|
||||
> Every row below sat in `OPEN-ITEMS.md` with a finished LEADING verdict (or was verified finished against
|
||||
|
||||
File diff suppressed because one or more lines are too long
Reference in New Issue
Block a user