Skip to content

feat: preserve explicit provenance verdicts and safe review (TAB-23–29) - #50

Merged
hudsonaikins merged 2 commits into
codex/tab-22-source-replayfrom
codex/tab-23-evidence-status
Sep 12, 2026
Merged

hudsonaikins merged 2 commits into
codex/tab-22-source-replayfrom
codex/tab-23-evidence-status

Conversation

@hudsonaikins

@hudsonaikins hudsonaikins commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

TAB-23 through TAB-29: lineage evaluation distinguishes missing, stale, conflicting, inferred, failed, and blocked evidence; candidate movement invalidates readiness. Validation, review, and security observations must explicitly pass. Integrated child PRs add bounded packets, security receipts, scoped publication, and failure/recovery demonstrations.

Candidate 06e68f9c694298d7f4df51617602784ac9cee991: required local validation, hosted product validation, and hosted Quality passed. Author review found no remaining code findings; the Plane bot reference is informational. PRs #51–55 are merged into this branch.

Stacked on #49. The documented fixture and blocked-result demonstrations satisfy rebuild acceptance without claiming complete live-provider provenance. Foundation Buildkite still blocks main integration; release and deployment require separate decisions.

Plane-Work-Item: TAB-23
Entire-Checkpoint: 95aae876ef91
@makeplane

makeplane Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Linked to Plane Work Item(s)

References

This comment was auto-generated by Plane

* fix: enforce complete review packet bounds and candidate acceptance

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88

* test: validate review packets with the native schema checker

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88

* feat: exact security evidence, review, and recovery (TAB-26–29) (#52)

* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
@hudsonaikins hudsonaikins changed the title TAB-23: explain missing and conflicting source evidence safely feat: preserve explicit provenance verdicts and safe review (TAB-23–29) Sep 12, 2026
@hudsonaikins
hudsonaikins marked this pull request as ready for review September 12, 2026 23:26
@hudsonaikins
hudsonaikins merged commit 520cb39 into codex/tab-22-source-replay Sep 12, 2026
4 checks passed
@hudsonaikins
hudsonaikins deleted the codex/tab-23-evidence-status branch September 12, 2026 23:27
hudsonaikins added a commit that referenced this pull request Sep 12, 2026
#49)

* feat: rebuild provenance from pinned source snapshots

Plane-Work-Item: TAB-22
Entire-Checkpoint: 95aae876ef91

* feat: explicit provenance verdicts and safe review (TAB-23–29) (#50)

* feat: preserve safe source failure reasons in review packets

Plane-Work-Item: TAB-23
Entire-Checkpoint: 95aae876ef91

* feat: exact-candidate packets, security, and review (TAB-24–29) (#51)

* fix: enforce complete review packet bounds and candidate acceptance

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88

* test: validate review packets with the native schema checker

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88

* feat: exact security evidence, review, and recovery (TAB-26–29) (#52)

* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
hudsonaikins added a commit that referenced this pull request Sep 12, 2026
…48)

* feat: normalize candidate-bound provenance source snapshots

Plane-Work-Item: TAB-21
Entire-Checkpoint: 95aae876ef91

* fix: select comparison base for manual quality checks

Plane-Work-Item: TAB-21
Entire-Checkpoint: 95aae876ef91

* feat: replay source evidence with safe review and recovery (TAB-22–29) (#49)

* feat: rebuild provenance from pinned source snapshots

Plane-Work-Item: TAB-22
Entire-Checkpoint: 95aae876ef91

* feat: explicit provenance verdicts and safe review (TAB-23–29) (#50)

* feat: preserve safe source failure reasons in review packets

Plane-Work-Item: TAB-23
Entire-Checkpoint: 95aae876ef91

* feat: exact-candidate packets, security, and review (TAB-24–29) (#51)

* fix: enforce complete review packet bounds and candidate acceptance

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88

* test: validate review packets with the native schema checker

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88

* feat: exact security evidence, review, and recovery (TAB-26–29) (#52)

* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 06e68f9c69

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines +45 to +46
const match = /^(100644|100755) blob ([a-f0-9]{40,64})\t(.+)$/s.exec(row);
if (!match) throw new Error("Unsupported candidate file mode.");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Skip non-regular entries instead of aborting the security scan

When the candidate tree contains any symlink (120000) or submodule (160000), git ls-tree -r returns an entry that cannot match this regular-file-only expression, causing snapshot() to throw before any scanner runs. Consequently, repositories using either common Git feature cannot produce a security receipt at all, even though the declared policy scope is tracked regular files; non-regular entries should be skipped or handled separately rather than blocking analysis of the regular files.

Useful? React with 👍 / 👎.

function execute(command, args, { cwd, signal, binary = false } = {}) {
return new Promise((resolvePromise, reject) => {
execFile(command, args, {
cwd, signal, encoding: binary ? "buffer" : "utf8", timeout: 240000, maxBuffer: 4 * 1024 * 1024,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Allow blobs up to the snapshot's declared size bound

For any tracked file larger than 4 MiB, git cat-file blob exceeds this execFile buffer and rejects before snapshot() can apply its explicit 32 MiB aggregate candidate limit. Such candidates therefore cannot produce a security receipt even when their total tree size is within the accepted bound; blob reads should be streamed or use a buffer consistent with the snapshot limit.

Useful? React with 👍 / 👎.

Comment on lines +14 to +15
const id = candidate.repositoryId.replace(/^github\.com\//, "");
return parseGitHubRepositoryRemote(`https://github.com/${id}`);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Normalize the GitHub host prefix case-insensitively

When candidate.repositoryId uses an equivalent mixed-case host such as GitHub.com/Example/Tabellio, which candidateIdentity() accepts and GitHub treats case-insensitively, this replacement leaves the host in place and constructs a three-segment path that parseGitHubRepositoryRemote() rejects. The review then silently returns no GitHub statuses and review-intent fails with a missing-repository-identity error, so the host prefix should be normalized case-insensitively.

Useful? React with 👍 / 👎.

}

function section(kind, reasons, evidence) {
const status = reasons.some((item) => item.state === "failed") ? "failed" : reasons.length ? "blocked" : "passed";

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Let candidate staleness override prior failure verdicts

When the current candidate has moved and the old lineage also contains a failed review, validation, or security observation, this precedence selects failed rather than blocked despite the candidate-staleness reason. The generated GitHub payload consequently targets the new head commit with a failure inherited from the old candidate, and publish-review can publish that unrelated failure; a candidate mismatch must force both sections to the stale/error state before considering old observation verdicts.

Useful? React with 👍 / 👎.

Comment on lines +53 to +55
const target = join(directory, path);
await mkdir(dirname(target), { recursive: true });
await writeFile(target, blob.stdout, { mode: 0o600 });

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Detect snapshot path collisions before writing scanner inputs

On the supported macOS environment, whose default filesystem is case-insensitive, a candidate containing distinct Git paths such as src/Auth.mjs and src/auth.mjs maps both entries to the same temporary path and the later writeFile silently overwrites the earlier blob. Gitleaks and the syntax scanners then inspect only one of the committed files and can return a false pass when the overwritten file contains a secret or unsafe construct; snapshot creation should reject filesystem-normalized collisions or scan each blob without materializing a colliding tree.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant