Files
felhom.eu/documentation/audits/offsite-lock-build-2026-10-03/partB/red-proofs-hub.txt
T
admin f417cdede1
gates / gates (push) Successful in 29s
hub v0.127.0: off-site key registrar (box never gets the storage password), password sealed at rest, daily key check, clean-up window (shipped off) — decisions 68-69, R-820/R-821/R-822
Part A evidence (migration spike, sftp-written repo through the pinned rclone key) and the hub
red-proofs under documentation/audits/offsite-lock-build-2026-10-03/. Manifest bump follows after
the image is built and Secret/offsite-secret-key exists.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-03 16:57:04 +02:00

23 lines
1.2 KiB
Plaintext

## RP1: SaveOneTimeSecret without sealing (the pre-v0.127.0 behaviour)
=== RUN TestOffsiteSecret_RawRowHoldsNoPassword
offsite_secret_seal_test.go:39: raw row is not sealed: "Sup3rSecretPw%"
--- FAIL: TestOffsiteSecret_RawRowHoldsNoPassword (0.02s)
## RP2: consume handler serving the password again (the pre-v0.127.0 handler)
=== RUN TestConsumePassword_RetiredReturnsNoPassword
offsite_test.go:43: consume → 200, want 410 (retired)
--- FAIL: TestConsumePassword_RetiredReturnsNoPassword (0.02s)
## RP3: audit that ignores the pin (every line counted as pinned)
=== RUN TestInstall_MigratesUnpinnedKeyAndAuditGoesClean
offsitekeys_test.go:98: before: {Lines:2 Pinned:2 Findings:[]} <nil> — want 2 unpinned findings (the decoy must be seen)
--- FAIL: TestInstall_MigratesUnpinnedKeyAndAuditGoesClean (0.00s)
=== RUN TestWindow_PrependAuditClose
offsitekeys_test.go:171: a window line with no open window must alarm: {Lines:2 Pinned:2 Findings:[]}
--- FAIL: TestWindow_PrependAuditClose (0.00s)
## restored — all green:
ok gitea.dooplex.hu/admin/felhom-hub/internal/store 2.888s
ok gitea.dooplex.hu/admin/felhom-hub/internal/api 4.047s
ok gitea.dooplex.hu/admin/felhom-hub/internal/offsitekeys 0.009s