fix(acquisition): require canonical release and data-room authority - #501
Draft
seonghobae wants to merge 100 commits into
Draft
fix(acquisition): require canonical release and data-room authority#501seonghobae wants to merge 100 commits into
seonghobae wants to merge 100 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
24 tasks
* test(exchange): reject non-canonical target repository * fix(exchange): preserve canonical target repository authority * fix(exchange): restore canonical source bytes
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Test-first hardening of Noema acquisition/release evidence authority. This branch preserves fail-closed retained release/SBOM/publication identity, bounded parsing, non-reflective diagnostics, stable filesystem evidence reads, and private acquisition-output path integrity.
Current causal repair
Exact head
87899225ff559ea7241a786faa0c605634766ac8closes a raw-path/inspection-path mismatch inscripts/lib/stable-file-evidence.mjs: ancestor validation used a resolved path while file inspection/open could still consume the raw caller path. A symlink-parent plus dot-segment input could therefore make parent inspection and file opening refer to different traversal semantics.2f6bcfc07f64a875e1dcc4a0b7c39ba1a9c386abadds a real symlink-parent + dot-segment reproduction.8d4c1127ea9e8acc5f44da9cb479b108f4ca3ca0fixes the intended lexical-canonical test contract.87899225ff559ea7241a786faa0c605634766ac8rejects non-normalized raw paths before parent inspection/file open while preserving canonical relative paths. ExistingO_NOFOLLOW, real-parent traversal, single-link regular-file authority, bounded reads, and descriptor/path stable-version checks remain intact.Exact current state
87899225ff559ea7241a786faa0c605634766ac8.main:2c83355529447248c246805d1954f268e027d2ab; this lane was created from the prior protected base and remains downstream of fix(oidc): reject non-canonical workflow source configuration #500.33066532873: terminal-success.33066532748: terminal-failure at the signed reviewer sandbox vulnerability scan after tests, exact 100% line+branch coverage, docstring coverage, dependency installation, Cosign, and Trivy setup passed. The branch still carries the signed Node distroless substrate with fixable OpenSSL/libssl3t64 findings.33066532804: workflow-level terminal-success but non-authoritative while central exact-head scanner authority is not protected truth.patch-validator-image33066532764: terminal-success.The reviewer failure is not repaired by weakening Trivy or duplicating a leaf workaround. The causal non-OpenSSL reviewer substrate (
java-base-debian13+ CodeGraph bundled Node) is already owned by earlier Noema dependency-root PR #500 and must converge into this lane through dependency order.Dependency / foreign-owner boundary
Earlier Noema root #500 is now exact head
26d2066af7500d43b4896c1211b45c1f105d9433, exact descendant of protectedmain@2c833555..., ahead 357 / behind 0, Draft/mergeable. Its current repair binds successful GitHub REST installation/install-token JSON authority to the reviewed JSON media type beforeResponse.json()parsing. Adopted RED8788bd737453d65bd65fab95ebba9b2f81a753f5failed Application33136111362/ job98736346184; production repair8bf2ec89b96008015bbddd6a75361a3c49713437added the fail-closed media-type guard;f780dc077e858a5894b5defbf1edb82c6bd33cc7restored source newline only. Exact CI33136701756then exposed a 99.97% branch-coverage gap in the absent-Content-Type path despite all 2,926 behavior tests passing. Current26d2066...adds a real no-header byte-body regression. Application33136876714, reviewer33136876715, and Security33136876724are terminal-success; dedicated image33136876735remainsin_progress/non-passing. #500 therefore still precedes this lane.Read-only protected central
.github/mainis GitHub-verified17052a7ca3c16db90932a4d6036b43165ddee418..github#1222remains the canonical owner of exact submitted-head/live-base scanner authority. Existing owner PR #897 is aligned to that central base at exact head1f834b4d0f86abb407fa286b1f7b857889d8ec33, open/Ready/mergeable; its exact-head security/scanner workflows are terminal-success but current review history does not establish a qualifying explicit APPROVE on that exact head. Protected central Security Scan still gives OSV immutable base/head materialization while Dependency Review and Trivy use generic checkout and the support probe can convert exact-comparison HTTP 403/404 tosupported=falseplus success. Current Noema Security success therefore does not transfer as merge-authoritative evidence after dependency convergence.Existing central #834 separately owns the Noema stable exchange-envelope consumer correction (
.tokenversus stabledata.token) and remains a foreign-owner historical-base, non-mergeable lane. No producer workaround belongs here.Merge boundary
Keep Draft. Do not merge until #500 resolves in dependency order, this branch converges without losing its stronger acquisition-evidence repair, every applicable exact-head gate is regenerated and terminal-clean, central scanner/consumer repairs reach protected truth with downstream canaries, live base/governance is freshly unchanged, exact 100% owned-production coverage remains proven, and zero valid unresolved findings remain. Technical evidence does not synthesize authentic production/KPI/deployment/revenue/legal-transfer evidence.