Skip to content

feat: bound exact-candidate packets, security, and review (TAB-24–29) - #51

Merged
hudsonaikins merged 3 commits into
codex/tab-23-evidence-statusfrom
codex/tab-24-25-safe-packets
Sep 12, 2026
Merged

hudsonaikins merged 3 commits into
codex/tab-23-evidence-statusfrom
codex/tab-24-25-safe-packets

Conversation

@hudsonaikins

@hudsonaikins hudsonaikins commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

TAB-24 through TAB-29: review packets identify the exact current candidate, include only bounded source metadata, omit raw payloads, and enforce a 65,536-byte limit including formatted JSON and newline. The native schema accepts generated packets and rejects malformed envelopes. Integrated child PRs add separately bound security receipts, safe CLI/GitHub review publication, and 11 failure/recovery demo cases with fresh-store replay.

Candidate 8370782056c2efd097972d5e25362cf0f05a7b36: required local validation, hosted product validation, and hosted Quality passed. Author review found no remaining code findings; the Plane bot reference is informational. PRs #52–55 are merged into this branch.

Stacked on #50. Source fixture and blocked-result demonstrations satisfy the stated rebuild acceptance; complete live-provider provenance is not claimed. Foundation Buildkite still blocks main integration. Release and deployment remain separate decisions.

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88
@makeplane

makeplane Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Linked to Plane Work Item(s)

References

This comment was auto-generated by Plane

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88
* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
@hudsonaikins hudsonaikins changed the title TAB-24–25: bound complete review packets and verify exact candidates feat: bound exact-candidate packets, security, and review (TAB-24–29) Sep 12, 2026
@hudsonaikins
hudsonaikins marked this pull request as ready for review September 12, 2026 23:24
@hudsonaikins
hudsonaikins merged commit 06e68f9 into codex/tab-23-evidence-status Sep 12, 2026
4 checks passed
@hudsonaikins
hudsonaikins deleted the codex/tab-24-25-safe-packets branch September 12, 2026 23:24
hudsonaikins added a commit that referenced this pull request Sep 12, 2026
* feat: preserve safe source failure reasons in review packets

Plane-Work-Item: TAB-23
Entire-Checkpoint: 95aae876ef91

* feat: exact-candidate packets, security, and review (TAB-24–29) (#51)

* fix: enforce complete review packet bounds and candidate acceptance

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88

* test: validate review packets with the native schema checker

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88

* feat: exact security evidence, review, and recovery (TAB-26–29) (#52)

* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
hudsonaikins added a commit that referenced this pull request Sep 12, 2026
#49)

* feat: rebuild provenance from pinned source snapshots

Plane-Work-Item: TAB-22
Entire-Checkpoint: 95aae876ef91

* feat: explicit provenance verdicts and safe review (TAB-23–29) (#50)

* feat: preserve safe source failure reasons in review packets

Plane-Work-Item: TAB-23
Entire-Checkpoint: 95aae876ef91

* feat: exact-candidate packets, security, and review (TAB-24–29) (#51)

* fix: enforce complete review packet bounds and candidate acceptance

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88

* test: validate review packets with the native schema checker

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88

* feat: exact security evidence, review, and recovery (TAB-26–29) (#52)

* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8370782056

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

const result = { schemaVersion: "tabellio-security-review/v0.1", candidate: packet.candidate, packetDigest: packet.digest, policyDigest, observedAt: now, status, checks: results };
// Reuse timestamp validation and ensure the review remains bounded.
normalizeRecord({ entityType: "security", entityKey: packet.digest, source: "tabellio", sourceId: packet.digest, observedAt: now, sensitivity: "private" });
requireFact(Buffer.byteLength(JSON.stringify(result)) <= 65536);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Enforce the limit on the serialized security receipt

The size check measures compact JSON before the digest is added, but tabellio-provenance security emits the completed receipt through writeJsonOutput, which uses two-space formatting and a final newline. A valid result with two categories containing 64 findings and roughly 275-character paths passes this check at about 56 KB, then produces about 68 KB of CLI output, violating the intended 65,536-byte bound. Measure the completed, formatted envelope as it will be written, as buildReviewPacket already does.

Useful? React with 👍 / 👎.

Comment on lines +50 to +52
for (const expected of intent.statuses) {
await assertCurrent(repo, intent, base, head);
published.push(checkedResponse(await publisher.publish(expected), expected));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Recheck approval expiry before each status publication

The approval is checked only once before the repository and ledger work begins, while each GitHub request can take up to the publisher timeout. If an approval expires after that initial check—especially between the two status requests—the loop still performs the remaining external mutation after authorization has expired. Revalidate the approval against a fresh clock immediately before each publisher.publish call, as the release workflow does for each publication phase.

Useful? React with 👍 / 👎.

Comment on lines +76 to +79
if (prior.value !== null) {
contract.equals(prior.value.intentDigest, intent.integrity.digest, "used approval intent");
if (prior.value.status !== "pending") return prior.value;
return { ...prior.value, status: "blocked", reason: "An earlier attempt is unresolved. Inspect GitHub before authorizing another attempt." };

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate stored receipts before accepting them

When an entry already exists, any JSON object with the matching intentDigest and a status other than pending is returned as the authoritative publication receipt without validating its schema, approval ID, candidate ID, status enum, or published responses. A malformed or modified ledger entry such as {intentDigest, status: "published"} therefore makes the command skip GitHub and falsely report publication. Validate the complete stored receipt and its binding before replaying it, failing closed on malformed state.

Useful? React with 👍 / 👎.

Comment on lines +85 to +86
const completed = { ...receipt, ...await sendStatuses({ repo, intent, base, head, publisher }) };
await ledger.write(path, completed, { expectedVersion: attempt.version });

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve receipts across unrelated concurrent publications

The completion write requires the ledger ref to remain exactly at the version created by this approval's reservation. If another approval writes to the same refs/tabellio/provenance-statuses ref while this request is publishing, the GitHub mutations can succeed but this final CAS fails; the first approval remains permanently stored as pending, and every retry reports it as unresolved. Complete the entry against the latest ref after verifying that this approval's reserved value is unchanged, rather than treating unrelated ledger updates as publication uncertainty.

Useful? React with 👍 / 👎.

Comment on lines +132 to +134
"path": {
"$ref": "#/$defs/text"
},

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Constrain finding paths in the security schema

The runtime rejects absolute paths, backslashes, empty components, . and .., but the published findings schema applies only the generic text definition. Consequently values such as /etc/passwd, ../private, or src/../secret pass schemas/provenance-security-review.schema.json even though the producer and importer consider them malformed. Consumers relying on the advertised schema can therefore accept security evidence that the native implementation rejects; encode the same safe-relative-path constraints in this property.

Useful? React with 👍 / 👎.

hudsonaikins added a commit that referenced this pull request Sep 12, 2026
…48)

* feat: normalize candidate-bound provenance source snapshots

Plane-Work-Item: TAB-21
Entire-Checkpoint: 95aae876ef91

* fix: select comparison base for manual quality checks

Plane-Work-Item: TAB-21
Entire-Checkpoint: 95aae876ef91

* feat: replay source evidence with safe review and recovery (TAB-22–29) (#49)

* feat: rebuild provenance from pinned source snapshots

Plane-Work-Item: TAB-22
Entire-Checkpoint: 95aae876ef91

* feat: explicit provenance verdicts and safe review (TAB-23–29) (#50)

* feat: preserve safe source failure reasons in review packets

Plane-Work-Item: TAB-23
Entire-Checkpoint: 95aae876ef91

* feat: exact-candidate packets, security, and review (TAB-24–29) (#51)

* fix: enforce complete review packet bounds and candidate acceptance

Plane-Work-Item: TAB-25

Validates TAB-24 candidate movement and unrelated-history rejection.

Entire-Checkpoint: 7098fc8f9b88

* test: validate review packets with the native schema checker

Plane-Work-Item: TAB-25
Entire-Checkpoint: 7098fc8f9b88

* feat: exact security evidence, review, and recovery (TAB-26–29) (#52)

* feat: bind separate security checks to immutable review candidates

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* ci: require pinned provenance security scanners

Plane-Work-Item: TAB-26
Entire-Checkpoint: 3a4c8131eec1

* feat: exact review results, safe publication, and recovery (TAB-27–29) (#53)

* feat: show actionable provenance review and GitHub statuses

Plane-Work-Item: TAB-27
Entire-Checkpoint: 3a4c8131eec1

* test: demonstrate failure recovery and secured review (TAB-28/TAB-29) (#54)

* test: demonstrate provenance failure and clean-store recovery (TAB-28)

Entire-Checkpoint: 3a4c8131eec1

* fix: review the secured lineage in the release demo (TAB-29) (#55)

* test: generate unsafe token fixture at runtime (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

* fix: demonstrate review of the secured provenance lineage (TAB-29)

Entire-Checkpoint: 3a4c8131eec1

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>

---------

Co-authored-by: hudsonaikins-crown <hudson.aikins@blanoire.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant