D-137 tier 2: live read-only sweep + two probe false-greens it exposed
SEC-021's ON-DISK half REPRODUCED: vr1-dc0-maas-power_ed25519{,.pub} are
genuinely absent from the dc0 jumphost creds folder, not merely undeclared.
Capture: docs/audit/d137-tier2-sweep-20260726.txt (read-only, no sudo,
stat-over-ssh metadata only; jumphost + voffice1 + office1-netbox).

Running it against real hosts exposed two false-greens in the probe:

1. "absent" vs "could not look". /root/maas-secrets and /root/netbox-secrets
   reported "does not exist" -- they exist; SEC-020 is precisely about
   admin.pass living in the first. An unprivileged [ -d ] on a root-owned
   parent is indistinguishable from a missing directory. The probe now tests
   parent traversability and reports UNREADABLE as a FAIL, not a skip.

2. Role-level aggregation manufactured false absences: skipping one location
   let a role's other locations cover it, so credentials in the unprobed
   location reported EXPECTED-BUT-ABSENT. Absence is now asserted only over
   fully-probed roles (14 rows report NOT JUDGED). Refinement: "absent" is a
   conclusive observation and does not gate a role; only unreadable and
   unreachable do.

Harness 33 -> 35 (T33 unreadable location, T34 absent location).
Gauntlet ALL GREEN (80), repo-lint 0-fail.

OUTSTANDING: the two root-owned dirs need a privileged read, so SEC-022's
shadow-store contents and the SEC-020 region secrets stay UNCONFIRMED. That
is a remote-sudo shape and was not run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf
1 parent 492b1d6 commit e37cc504616036a35f52abaca39534b90a1e16e6
@JANeumatrix JANeumatrix authored 11 hours ago
Showing 5 changed files
View
docs/CURRENT-STATE.md
View
docs/audit/d137-tier2-sweep-20260726.txt 0 → 100644
View
docs/changelog-20260726-d137-tier1.md
View
scripts/creds-matrix.py
View
tests/creds-matrix/run-tests.sh