Files
felhom.eu/documentation/audits/offsite-append-only-2026-10-03/EXIT-TEST.md
T
admin 9268d9933b
gates / gates (push) Successful in 29s
R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed,
authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820,
R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions.
Register 326 -> 327.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 13:40:35 +02:00

1.9 KiB
Raw Blame History

R-436 exit test — written BEFORE any command ran (2026-10-03 ~11:10 CEST)

The lock HOLDS only if ALL of these are true on the LIVE Storage Box (u629488, scratch venue u629488-sub4, a dedicated repo path that is NOT felhom-repo):

# Through the FORCED key (command="rclone serve restic --stdio --append-only <path>") Must be
E1 restic init (scratch repo) succeeds
E2 restic backup of a small tree succeeds, snapshot count +1
E3 restic snapshots, restic restore of one file (bytes compared) succeeds
E4 restic forget <id> --prune REFUSED — verbatim error quoted; count unchanged
E5 restic prune REFUSED — verbatim; check clean
E6 restic forget --keep-last 1 REFUSED — verbatim; count unchanged
E7 the same key asking for a shell / sftp / scp / rsync / a port forward REFUSED
E8 the same key, client asks for a plain rclone serve restic --stdio (no flag) still append-only

Controls (without them a refusal means nothing):

# Control Must be
C1 the same forget --prune through a key WITHOUT the forced command SUCCEEDS (the test can see a delete)
C2 the forced key, client names a DIFFERENT repo path recorded as observed (expected: the pinned path is served regardless)

Locks (R-430): kill a backup mid-run through the forced key; record whether the next backup wedges, and what unlock / unlock --remove-all report AND what remains on disk.

Verdict rule: E1–E8 as stated and C1 succeeding ⇒ the lock holds for that key. Part B then asks whether any OTHER credential reachable from a box defeats it; if one does, the lock alone is not protection, and that is reported first.

A LOCAL LAB (lab/) runs the same matrix against OpenSSH + rclone on DooPlex. It measures rclone's and restic's behaviour; it CANNOT stand in for the provider's sshd honouring command=. Only live/ can close R-436.