Skip to content

fix(security): harden live Coraza authority boundary - #435

Draft
seonghobae wants to merge 98 commits into
mainfrom
codex/coraza-header-enforcement-red-20260917
Draft

seonghobae wants to merge 98 commits into
mainfrom
codex/coraza-header-enforcement-red-20260917

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Refs #434 / parent #86 and exact-request binding #444. This is the bounded Wardnet-owned Coraza/OWASP CRS enforcement lane on protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b. Coraza/CRS remains the proven WAF detection/disruption authority for block-mode requests that Wardnet would otherwise forward; independent Wardnet threat/DNSBL evidence may deny first. This lane does not copy EgressWeave transport policy, quarantine-sandbox-runtime isolation, contextual-orchestrator logic, appguardrail logic, or another owner implementation.

Established RED → GREEN lineage

Hosted exact 3c97011161dbb63fb87797fcb61e8c97cc2c64e7 established the original enforcement RED: a Shellshock-style payload present only in User-Agent traversed a real block route and Wardnet returned 200 OK with clean local evidence. Exact 3e910314fcaf1515f2e378a6ab6c71bf0daf219f then passed the guarded Coraza request-context suite and was ordinarily promoted as ede52a7a25efc2f98e47b64802484009a43a8532.

Post-promotion review found the body-identity boundary: valid UTF-8 containing literal U+FFFD must remain valid, while actual lossy replacement of invalid bytes must fail closed. Test-first c0895b2374f06056efa22f4738bfbbe00052c93d, minimum repair e8d3e02875428911bea4a617c02a1170f3e39027, and docs 4443056d938e1851172c59f2041e0def31ecfa3a preserve that distinction.

A later local-authority transport RED 449d3118cba5a24a8e253f280d87b8829fe02e28 proved that ambient HTTP_PROXY / ALL_PROXY could divert the bounded sidecar envelope away from the validated loopback authority. Minimum repair e7e9d9b87a03c05f802a3d50c0917f75a89f7022 uses a process-reused no-proxy/no-redirect sidecar client while retaining loopback-only authority; generic outbound destination/DNS/peer/redirect/proxy/TLS/resource policy remains EgressWeave ownership.

Exact-request evidence binding — #444

Fresh review then found that response_correlates() accepted only echoed method + URI. A stale/misrouted clean response for one POST /login could therefore authorize a different same-method/same-URI request. Test-only child #445 exact 4c82db44f483aeb9014eba2b4db30bf0c09e0ce9 established hosted semantic RED in CI 35708687049, rust job 106683725479: checkout/toolchain/format completed and the real Test step failed on the unbound/stale-evidence acceptance. Production stayed unchanged in that child.

Minimum causal repair 8400e88d39ac5a13fffa8a0ebafbb9866e2d9b6f adds a bounded request-unique Wardnet correlation id to the sidecar envelope and requires the exact id, method, and URI before either clean or disruptive Coraza evidence can be accepted. The id is evidence correlation, not authentication; loopback/no-proxy/no-redirect authority remains unchanged. tests/coraza_exact_request_binding.rs proves method+URI-only evidence fails closed and a correlation replay from the immediately preceding same-route request fails closed. 1456845cf40f9e49c017b25ea485238299bf569d updates the Coraza contract/security/operations documentation to the same boundary.

Exact-head evidence and central required-workflow handoff

Once hosted runners resumed, CI 35728650113 on exact 1456845cf40f9e49c017b25ea485238299bf569d reached the real Rust job and failed only cargo fmt --check. Rustfmt identified the same correlation-id expression in four Coraza integration fixtures: coraza_loopback_proxy_boundary.rs, coraza_non_disruptive_detection.rs, coraza_non_utf8_body.rs, and coraza_proven_engine_adapter.rs. No semantic production defect was implicated by that failure.

The branch was repaired non-destructively with rustfmt-equivalent formatting only; current exact head is 11e7fabfca76e0051fa883905228a0dbe472f4df. On this unchanged head, repository-owned CI 35751758441, Fuzz 35751758430, Security 35751758443, and SAST 35751758520 are terminal SUCCESS. GitHub dynamic code scanning 35751753384 is also terminal SUCCESS. Required OpenCode review 35751755961, Noema review 35751755933, and merge scheduler 35751755915 are terminal SUCCESS.

Delegated CodeQL PR run 35751758575 is terminal FAILURE, but the exact failure is central settlement ordering rather than Wardnet source/SARIF failure: language detection succeeded; CodeQL compatibility analysis (actions) read the current-head dispatch verdict and failed at Release runner or enforce current-head CodeQL verdict; only afterward did same-generation dispatch job 106949634039 start and complete SUCCESS. This exact unchanged-head specimen is handed to canonical owner .github#1929. No predecessor receipt reuse, leaf wake/no-op commit, synthetic status, central-workflow copy or routine bypass is justified.

Required Strix run 35751756065 / job 106864846606 completed the actual scan with Vulnerabilities 0 (No exploitable vulnerabilities detected) and then failed only because the central required-workflow runtime tried to resolve scripts/ci/strix_evidence_binding.py from Wardnet's trusted target workspace. The exact terminal error is ERROR: Strix evidence binder is missing: /home/runner/work/_temp/trusted-workspace/scripts/ci/strix_evidence_binding.py. That binder is central .github workflow/runtime ownership, not Wardnet application source. The existing central owner defect .github#2292 carries this exact Wardnet reproduction plus RED→GREEN acceptance. Wardnet will not copy the binder locally, weaken the gate, or blind-rerun the unchanged head before the central owner path is repaired.

Dependent gateway mediation PR #441 adopted this complete parent through an ordinary two-parent, non-force restack before continuing its own writer lane. No wake/no-op commit, synthesized status, self/model approval, central-workflow copy, or routine administrator bypass is justified.

Completion boundary

Before ordinary protected integration, one unchanged exact candidate must retain explicit Coraza disruption authority, independent local-deny precedence, byte-exact valid UTF-8 vs actual lossy-byte handling, loopback-only/no-redirect/no-ambient-proxy sidecar transport, exact-request correlation for clean and disruptive evidence, monitor-mode degraded engine_unavailable evidence, and hostile/benign request-context regressions. That same head must obtain terminal-valid fmt/locked workspace tests/strict Clippy/Fuzz/Security/SAST/CodeQL/owned coverage/rustdoc/review/thread/governance evidence. Release readiness remains separate and still requires version/CHANGELOG/tag/package/immutable release/SBOM/provenance/reproducibility/rollback.

No force push, destructive rebase, self/model approval, gate weakening, routine administrator bypass, mutable foreign dependency, source copy, cross-service SQL, predecessor-evidence reuse, or blind rerun.

@coderabbitai

coderabbitai Bot commented Sep 16, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

fix(gateway): enforce bounded HTTP header mediation
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: high High-priority or P1 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant