Files
felhom.eu/documentation/audits/offsite-append-only-2026-10-03/EXIT-TEST.md
T
admin 9268d9933b
gates / gates (push) Successful in 29s
R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed,
authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820,
R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions.
Register 326 -> 327.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 13:40:35 +02:00

34 lines
1.9 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# R-436 exit test — written BEFORE any command ran (2026-10-03 ~11:10 CEST)
The lock HOLDS only if ALL of these are true on the LIVE Storage Box (`u629488`, scratch venue
`u629488-sub4`, a dedicated repo path that is NOT `felhom-repo`):
| # | Through the FORCED key (`command="rclone serve restic --stdio --append-only <path>"`) | Must be |
|---|---|---|
| E1 | `restic init` (scratch repo) | succeeds |
| E2 | `restic backup` of a small tree | succeeds, snapshot count +1 |
| E3 | `restic snapshots`, `restic restore` of one file (bytes compared) | succeeds |
| E4 | `restic forget <id> --prune` | REFUSED — verbatim error quoted; count unchanged |
| E5 | `restic prune` | REFUSED — verbatim; `check` clean |
| E6 | `restic forget --keep-last 1` | REFUSED — verbatim; count unchanged |
| E7 | the same key asking for a shell / `sftp` / `scp` / `rsync` / a port forward | REFUSED |
| E8 | the same key, client asks for a plain `rclone serve restic --stdio` (no flag) | still append-only |
Controls (without them a refusal means nothing):
| # | Control | Must be |
|---|---|---|
| C1 | the same `forget --prune` through a key WITHOUT the forced command | SUCCEEDS (the test can see a delete) |
| C2 | the forced key, client names a DIFFERENT repo path | recorded as observed (expected: the pinned path is served regardless) |
Locks (R-430): kill a backup mid-run through the forced key; record whether the next backup
wedges, and what `unlock` / `unlock --remove-all` report AND what remains on disk.
**Verdict rule:** E1–E8 as stated and C1 succeeding ⇒ the lock holds *for that key*. Part B then asks
whether any OTHER credential reachable from a box defeats it; if one does, the lock alone is not
protection, and that is reported first.
A LOCAL LAB (`lab/`) runs the same matrix against OpenSSH + rclone on DooPlex. It measures rclone's
and restic's behaviour; it CANNOT stand in for the provider's sshd honouring `command=`. Only `live/`
can close R-436.