Skip to content

security(workforce-validation): prevent public forging of corroborated component resolutions #413

Description

@seonghobae

Finding

FinalWeightComponentEvidenceResolution is an exported proof-bearing success type. The original public constructor accepted caller-created base/specialized projections and therefore allowed callers to manufacture the same success type returned by corroborate_final_weight_component_evidence(...) without the final-weight/binding owner evidence or governed-use checks.

Repair lineage and #415 refinement

Canonical #235 is now exact ab7a968e0109176f0d5862373d0a15d3f1832e92, open · Draft · mergeable=true. The current #415 delta fully carries #413's valid ordinary-constructor objective and strengthens it against the newly verified low-level bypass. #413 is therefore not closed: hosted exact-head acceptance, qualifying independent review, protected integration, and durable consumer adoption are still outstanding.

These commits are source-established evidence only until hosted acceptance completes. No new #407 application-owner family is introduced; the active owner-family set remains twenty-two.

Required contract

  • Ordinary public construction of FinalWeightComponentEvidenceResolution is rejected.
  • Low-level tuple construction is not an alternate proof issuer.
  • Only corroborate_final_weight_component_evidence(...) is the supported production issuer after exact receipt identity, owner scope, semantics, construction/current-use chronology and security(workforce-validation): authorize component-evidence resolution before owner reads #414 purpose-bound authorization pass.
  • Unsealed exact runtime objects fail closed rather than exposing proof-bearing properties.
  • Canonically issued results are immutable through the public mutation surface.
  • Component projections remain public value-minimized adapter values and retain existing canonical reconstruction.
  • No weakening of packaging, docstring, edge, security or review gates.

Completion boundary

Keep open until current exact-head owned test/docstring/edge evidence, installed-wheel/package/PostgreSQL/security gates, qualifying independent review, normal protected integration, and durable #248 (or verified successor) adoption are complete.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions