feat: preserve explicit provenance verdicts and safe review (TAB-23–29) - #50
Conversation
Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91
|
Linked to Plane Work Item(s) References This comment was auto-generated by Plane |
* fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
#49) * feat: rebuild provenance from pinned source snapshots Plane-Work-Item: TAB-22 Entire-Checkpoint: 95aae876ef91 * feat: explicit provenance verdicts and safe review (TAB-23–29) (#50) * feat: preserve safe source failure reasons in review packets Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91 * feat: exact-candidate packets, security, and review (TAB-24–29) (#51) * fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
…48) * feat: normalize candidate-bound provenance source snapshots Plane-Work-Item: TAB-21 Entire-Checkpoint: 95aae876ef91 * fix: select comparison base for manual quality checks Plane-Work-Item: TAB-21 Entire-Checkpoint: 95aae876ef91 * feat: replay source evidence with safe review and recovery (TAB-22–29) (#49) * feat: rebuild provenance from pinned source snapshots Plane-Work-Item: TAB-22 Entire-Checkpoint: 95aae876ef91 * feat: explicit provenance verdicts and safe review (TAB-23–29) (#50) * feat: preserve safe source failure reasons in review packets Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91 * feat: exact-candidate packets, security, and review (TAB-24–29) (#51) * fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 06e68f9c69
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| const match = /^(100644|100755) blob ([a-f0-9]{40,64})\t(.+)$/s.exec(row); | ||
| if (!match) throw new Error("Unsupported candidate file mode."); |
There was a problem hiding this comment.
Skip non-regular entries instead of aborting the security scan
When the candidate tree contains any symlink (120000) or submodule (160000), git ls-tree -r returns an entry that cannot match this regular-file-only expression, causing snapshot() to throw before any scanner runs. Consequently, repositories using either common Git feature cannot produce a security receipt at all, even though the declared policy scope is tracked regular files; non-regular entries should be skipped or handled separately rather than blocking analysis of the regular files.
Useful? React with 👍 / 👎.
| function execute(command, args, { cwd, signal, binary = false } = {}) { | ||
| return new Promise((resolvePromise, reject) => { | ||
| execFile(command, args, { | ||
| cwd, signal, encoding: binary ? "buffer" : "utf8", timeout: 240000, maxBuffer: 4 * 1024 * 1024, |
There was a problem hiding this comment.
Allow blobs up to the snapshot's declared size bound
For any tracked file larger than 4 MiB, git cat-file blob exceeds this execFile buffer and rejects before snapshot() can apply its explicit 32 MiB aggregate candidate limit. Such candidates therefore cannot produce a security receipt even when their total tree size is within the accepted bound; blob reads should be streamed or use a buffer consistent with the snapshot limit.
Useful? React with 👍 / 👎.
| const id = candidate.repositoryId.replace(/^github\.com\//, ""); | ||
| return parseGitHubRepositoryRemote(`https://github.com/${id}`); |
There was a problem hiding this comment.
Normalize the GitHub host prefix case-insensitively
When candidate.repositoryId uses an equivalent mixed-case host such as GitHub.com/Example/Tabellio, which candidateIdentity() accepts and GitHub treats case-insensitively, this replacement leaves the host in place and constructs a three-segment path that parseGitHubRepositoryRemote() rejects. The review then silently returns no GitHub statuses and review-intent fails with a missing-repository-identity error, so the host prefix should be normalized case-insensitively.
Useful? React with 👍 / 👎.
| } | ||
|
|
||
| function section(kind, reasons, evidence) { | ||
| const status = reasons.some((item) => item.state === "failed") ? "failed" : reasons.length ? "blocked" : "passed"; |
There was a problem hiding this comment.
Let candidate staleness override prior failure verdicts
When the current candidate has moved and the old lineage also contains a failed review, validation, or security observation, this precedence selects failed rather than blocked despite the candidate-staleness reason. The generated GitHub payload consequently targets the new head commit with a failure inherited from the old candidate, and publish-review can publish that unrelated failure; a candidate mismatch must force both sections to the stale/error state before considering old observation verdicts.
Useful? React with 👍 / 👎.
| const target = join(directory, path); | ||
| await mkdir(dirname(target), { recursive: true }); | ||
| await writeFile(target, blob.stdout, { mode: 0o600 }); |
There was a problem hiding this comment.
Detect snapshot path collisions before writing scanner inputs
On the supported macOS environment, whose default filesystem is case-insensitive, a candidate containing distinct Git paths such as src/Auth.mjs and src/auth.mjs maps both entries to the same temporary path and the later writeFile silently overwrites the earlier blob. Gitleaks and the syntax scanners then inspect only one of the committed files and can return a false pass when the overwritten file contains a secret or unsafe construct; snapshot creation should reject filesystem-normalized collisions or scan each blob without materializing a colliding tree.
Useful? React with 👍 / 👎.
TAB-23 through TAB-29: lineage evaluation distinguishes missing, stale, conflicting, inferred, failed, and blocked evidence; candidate movement invalidates readiness. Validation, review, and security observations must explicitly pass. Integrated child PRs add bounded packets, security receipts, scoped publication, and failure/recovery demonstrations.
Candidate
06e68f9c694298d7f4df51617602784ac9cee991: required local validation, hosted product validation, and hosted Quality passed. Author review found no remaining code findings; the Plane bot reference is informational. PRs #51–55 are merged into this branch.Stacked on #49. The documented fixture and blocked-result demonstrations satisfy rebuild acceptance without claiming complete live-provider provenance. Foundation Buildkite still blocks main integration; release and deployment require separate decisions.