Skip to content

security(attestation): bind immutable artifact size in scientific-validation receipt #2314

Description

@seonghobae

Finding

Issue #2299 requires the scientific-validation owner contract to bind same-run immutable GitHub artifact ID, name, size, and digest metadata before signer authority exists. Current PR #2300 binds artifact ID/name/digest into both the unsigned predicate and versioned receipt manifest, but omits GitHub REST size_in_bytes entirely.

That omission leaves the future signer handoff unable to prove that its receipt refers to the exact live artifact metadata tuple required by #2299. GitHub's Actions artifact API exposes id, name, size_in_bytes, digest, and workflow-run identity as independent artifact metadata; size must therefore be carried as an authenticated control value rather than inferred from the extracted JSON member or ZIP payload bytes.

RED / acceptance

Add owner-level contracts proving that:

  • one positive-decimal evidence_artifact_size_in_bytes control is required;
  • the generated scientific-validation predicate commits the exact artifact size alongside artifact ID/name/digest;
  • the versioned completion manifest commits the same size and validate_receipt_manifest rejects a syntactically valid size that conflicts with the committed predicate;
  • zero, signed, fractional, or non-decimal sizes fail closed;
  • size is treated as GitHub artifact metadata and is not recomputed from the extracted evidence JSON byte length;
  • current strict schema, no-clobber publication, predicate-byte commitment, execution-artifact ordering, and scientific does_not_prove boundary remain unchanged.

Because no scientific-validation owner contract has been released or immutable-pinned yet, repair the still-unreleased v1 predicate/manifest before first release instead of creating compatibility debt solely to preserve an unpublished omission.

Do not claim signer/OIDC authority from this repair. #2164 and #2299 remain the authentication/signing path; TEPP #637 must continue to wait for released/pinned authenticated owner authority.

Refs #2299 #2300 #2164 ContextualWisdomLab/TEPP#637.

Activity

  1. seonghobae commented on Sep 21, 2026

    @seonghobae
    ContributorAuthor

    Implemented the #2314 owner repair on the canonical #2300 branch.

    Lineage:

    • source-level RED: 2a8d86c4895419d24389dd36da051bed9fd0bae8 adds explicit artifact-size binding/refusal/conflict/non-inference contracts;
    • quality inclusion: 47ac935c2e92196971048322de84b4b23b1af288 puts that RED under the 100% owned-branch quality lane;
    • existing fixture migrations: 29f1b323467adeff8f762f81f37c7f48c2531c5a, a4ec7265cfa5564799a11fc054b5d3c76abd4ecb, c3628052a301623f8f945f86098b2d4950404b4e;
    • causal production repair: a0c75c0eeb4bae31fd1dbeece902d90354901b3c;
    • CHANGELOG currentness: 949ff3649dc235566e8e1008bfb645c25e52dcad.

    The repair requires positive-decimal --evidence-artifact-size-in-bytes, commits it as predicate artifact_size_in_bytes and manifest evidence_artifact_size_in_bytes, and cross-binds the two in validate_receipt_manifest. It deliberately does not compare this value with the extracted evidence JSON length; it remains independent GitHub artifact metadata supplied by the future live-metadata boundary.

    This remains unsigned local verifier authority. No signer/OIDC/attestation authority is claimed; #2164/#2299 remain prerequisites. Keep this issue open until the final exact head has hosted quality/security settlement and qualifying review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions