Files
felhom.eu/documentation/audits/offsite-append-only-2026-10-03/lab/B-rclone-server-surface.txt
T
admin 9268d9933b
gates / gates (push) Successful in 29s
R-436 measured on the provider: append-only forced key HOLDS (403 on every delete), but the sub-account password defeats it (R-820); design proposal + ep0 options
Spike, no product change. Venue u629488-sub4 (tester-1, operator ruling); scratch repo removed,
authorized_keys restored byte-identical. Closed R-436 (due-check cleared), R-430. Opened R-820,
R-821, R-822. R-95 and R-342 updated. 07 §D [FACT] block. STATUS: two operator decisions.
Register 326 -> 327.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 13:40:35 +02:00

33 lines
1019 B
Plaintext

rclone: rclone v1.75.1 (lab; the provider runs its own version)
T1 DELETE snapshots/<existing> -> 403 Forbidden
T2 POST over existing snapshots/<id> -> 403 Forbidden
T3 POST over existing config -> 403 Forbidden
T4 DELETE data/<existing pack> -> 403 Forbidden
T5 POST ../.ssh/authorized_keys -> 400 Bad Request
T6 POST %2e%2e/.ssh/authorized_keys -> 400 Bad Request
T7 POST data/..%2f..%2f.ssh/x -> 400 Bad Request
T8 POST a NEW keys/aaaa -> 200
T9 POST arbitrary top-level foo -> 200
T10 DELETE the new keys/aaaa -> 403 Forbidden
T11 POST a NEW locks/bbbb then DELETE -> 200 / 200
after: snapshot present: yes; config unchanged: yes; authorized_keys unchanged: yes; stray files:
/home/sub:
spike-repo
/home/sub/.ssh:
authorized_keys
/home/sub/spike-repo:
config
data
foo
index
keys
locks
snapshots
/home/sub/spike-repo/keys:
aaaa
f651e7eec6b06d2594a748cb05cfaca39f7488092af5c4da5c332a7c3a7a8e5e
/home/sub/spike-repo/locks: