feat: bound exact-candidate packets, security, and review (TAB-24–29) - #51
Conversation
Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88
|
Linked to Plane Work Item(s) References This comment was auto-generated by Plane |
Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88
* feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
* feat: preserve safe source failure reasons in review packets Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91 * feat: exact-candidate packets, security, and review (TAB-24–29) (#51) * fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
#49) * feat: rebuild provenance from pinned source snapshots Plane-Work-Item: TAB-22 Entire-Checkpoint: 95aae876ef91 * feat: explicit provenance verdicts and safe review (TAB-23–29) (#50) * feat: preserve safe source failure reasons in review packets Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91 * feat: exact-candidate packets, security, and review (TAB-24–29) (#51) * fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8370782056
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| const result = { schemaVersion: "tabellio-security-review/v0.1", candidate: packet.candidate, packetDigest: packet.digest, policyDigest, observedAt: now, status, checks: results }; | ||
| // Reuse timestamp validation and ensure the review remains bounded. | ||
| normalizeRecord({ entityType: "security", entityKey: packet.digest, source: "tabellio", sourceId: packet.digest, observedAt: now, sensitivity: "private" }); | ||
| requireFact(Buffer.byteLength(JSON.stringify(result)) <= 65536); |
There was a problem hiding this comment.
Enforce the limit on the serialized security receipt
The size check measures compact JSON before the digest is added, but tabellio-provenance security emits the completed receipt through writeJsonOutput, which uses two-space formatting and a final newline. A valid result with two categories containing 64 findings and roughly 275-character paths passes this check at about 56 KB, then produces about 68 KB of CLI output, violating the intended 65,536-byte bound. Measure the completed, formatted envelope as it will be written, as buildReviewPacket already does.
Useful? React with 👍 / 👎.
| for (const expected of intent.statuses) { | ||
| await assertCurrent(repo, intent, base, head); | ||
| published.push(checkedResponse(await publisher.publish(expected), expected)); |
There was a problem hiding this comment.
Recheck approval expiry before each status publication
The approval is checked only once before the repository and ledger work begins, while each GitHub request can take up to the publisher timeout. If an approval expires after that initial check—especially between the two status requests—the loop still performs the remaining external mutation after authorization has expired. Revalidate the approval against a fresh clock immediately before each publisher.publish call, as the release workflow does for each publication phase.
Useful? React with 👍 / 👎.
| if (prior.value !== null) { | ||
| contract.equals(prior.value.intentDigest, intent.integrity.digest, "used approval intent"); | ||
| if (prior.value.status !== "pending") return prior.value; | ||
| return { ...prior.value, status: "blocked", reason: "An earlier attempt is unresolved. Inspect GitHub before authorizing another attempt." }; |
There was a problem hiding this comment.
Validate stored receipts before accepting them
When an entry already exists, any JSON object with the matching intentDigest and a status other than pending is returned as the authoritative publication receipt without validating its schema, approval ID, candidate ID, status enum, or published responses. A malformed or modified ledger entry such as {intentDigest, status: "published"} therefore makes the command skip GitHub and falsely report publication. Validate the complete stored receipt and its binding before replaying it, failing closed on malformed state.
Useful? React with 👍 / 👎.
| const completed = { ...receipt, ...await sendStatuses({ repo, intent, base, head, publisher }) }; | ||
| await ledger.write(path, completed, { expectedVersion: attempt.version }); |
There was a problem hiding this comment.
Preserve receipts across unrelated concurrent publications
The completion write requires the ledger ref to remain exactly at the version created by this approval's reservation. If another approval writes to the same refs/tabellio/provenance-statuses ref while this request is publishing, the GitHub mutations can succeed but this final CAS fails; the first approval remains permanently stored as pending, and every retry reports it as unresolved. Complete the entry against the latest ref after verifying that this approval's reserved value is unchanged, rather than treating unrelated ledger updates as publication uncertainty.
Useful? React with 👍 / 👎.
| "path": { | ||
| "$ref": "#/$defs/text" | ||
| }, |
There was a problem hiding this comment.
Constrain finding paths in the security schema
The runtime rejects absolute paths, backslashes, empty components, . and .., but the published findings schema applies only the generic text definition. Consequently values such as /etc/passwd, ../private, or src/../secret pass schemas/provenance-security-review.schema.json even though the producer and importer consider them malformed. Consumers relying on the advertised schema can therefore accept security evidence that the native implementation rejects; encode the same safe-relative-path constraints in this property.
Useful? React with 👍 / 👎.
…48) * feat: normalize candidate-bound provenance source snapshots Plane-Work-Item: TAB-21 Entire-Checkpoint: 95aae876ef91 * fix: select comparison base for manual quality checks Plane-Work-Item: TAB-21 Entire-Checkpoint: 95aae876ef91 * feat: replay source evidence with safe review and recovery (TAB-22–29) (#49) * feat: rebuild provenance from pinned source snapshots Plane-Work-Item: TAB-22 Entire-Checkpoint: 95aae876ef91 * feat: explicit provenance verdicts and safe review (TAB-23–29) (#50) * feat: preserve safe source failure reasons in review packets Plane-Work-Item: TAB-23 Entire-Checkpoint: 95aae876ef91 * feat: exact-candidate packets, security, and review (TAB-24–29) (#51) * fix: enforce complete review packet bounds and candidate acceptance Plane-Work-Item: TAB-25 Validates TAB-24 candidate movement and unrelated-history rejection. Entire-Checkpoint: 7098fc8f9b88 * test: validate review packets with the native schema checker Plane-Work-Item: TAB-25 Entire-Checkpoint: 7098fc8f9b88 * feat: exact security evidence, review, and recovery (TAB-26–29) (#52) * feat: bind separate security checks to immutable review candidates Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * ci: require pinned provenance security scanners Plane-Work-Item: TAB-26 Entire-Checkpoint: 3a4c8131eec1 * feat: exact review results, safe publication, and recovery (TAB-27–29) (#53) * feat: show actionable provenance review and GitHub statuses Plane-Work-Item: TAB-27 Entire-Checkpoint: 3a4c8131eec1 * test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54) * test: demonstrate provenance failure and clean-store recovery (TAB-28) Entire-Checkpoint: 3a4c8131eec1 * fix: review the secured lineage in the release demo (TAB-29) (#55) * test: generate unsafe token fixture at runtime (TAB-29) Entire-Checkpoint: 3a4c8131eec1 * fix: demonstrate review of the secured provenance lineage (TAB-29) Entire-Checkpoint: 3a4c8131eec1 --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co> --------- Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
TAB-24 through TAB-29: review packets identify the exact current candidate, include only bounded source metadata, omit raw payloads, and enforce a 65,536-byte limit including formatted JSON and newline. The native schema accepts generated packets and rejects malformed envelopes. Integrated child PRs add separately bound security receipts, safe CLI/GitHub review publication, and 11 failure/recovery demo cases with fresh-store replay.
Candidate
8370782056c2efd097972d5e25362cf0f05a7b36: required local validation, hosted product validation, and hosted Quality passed. Author review found no remaining code findings; the Plane bot reference is informational. PRs #52–55 are merged into this branch.Stacked on #50. Source fixture and blocked-result demonstrations satisfy the stated rebuild acceptance; complete live-provider provenance is not claimed. Foundation Buildkite still blocks main integration. Release and deployment remain separate decisions.