Buyer-visible immutable-policy value gap
EgressWeave's shared scalar-normalization boundary must retain reviewed built-in values rather than arbitrary int subclasses that can carry polymorphic behavior into authority/resource policy. This is trusted configuration integrity, not a Python-sandbox claim.
Current canonical candidate
Historical #123/#153/#159 are evidence only. The current candidate is Ready PR #178 — security: reconstruct scalar integer sealing on current main.
Fresh exact identities:
The candidate requires exact built-in integers at shared allowed-port, DNS-count, positive-count and positive-byte-count normalization while preserving reviewed ASCII decimal-string configuration and existing range/default/authority behavior. The current branch was reconciled onto the protected tree without transferring predecessor evidence.
Exact-current-head evidence
On unchanged aca7d0f7b99cdc7f10be711cddc9f686c459088f:
- local Python 3.14 acceptance recorded by the current PR: 944 passed;
- exact owned-production coverage: 100% (
1704/1704 statements, 576/576 branches);
- Ruff, hourly product guard and compileall: passed locally;
- hosted CI
31555659130: terminal success;
- hosted SAST Semgrep
31555659129: terminal success;
- hosted Security Scan
31555659142: terminal aggregate success;
- dependency-review job
93987430043: wrapper success, but its actual immutable-pinned Dependency review step 4 is skipped. This is not accepted dependency-review evidence;
- OpenCode/GHAS scanner checks visible on this exact head are machine/check evidence only and do not substitute for current semantic review or the missing dependency-review action.
The old exact-head Strix result recorded for predecessor 65485ee... is historical and is no longer used as current-head acceptance. Obtain/revalidate current-head review evidence on aca7d0f... without churning the clean source head.
Read-only central prerequisite
The organization-owned fail-closed dependency-review repair remains ContextualWisdomLab/.github#897 until a fresh protected-central successor is proven and integrated. .github is read-only from this loop. EgressWeave must not substitute another scanner for Dependency Review or add a local fail-open workaround.
Acceptance criteria
Successor / writer discipline
Draft #184 is the distinct HTTP method-string successor and currently diverges from the live #178 tip after its predecessor moved; it remains Draft until #178 reaches an accepted stable identity or protected integration. Issues #131/#132/#133 remain distinct future host/port, DNS-timeout and authority-pair boundaries. Do not create a parallel scalar branch and do not churn a clean head merely to retrigger external behavior.
Buyer-visible immutable-policy value gap
EgressWeave's shared scalar-normalization boundary must retain reviewed built-in values rather than arbitrary
intsubclasses that can carry polymorphic behavior into authority/resource policy. This is trusted configuration integrity, not a Python-sandbox claim.Current canonical candidate
Historical #123/#153/#159 are evidence only. The current candidate is Ready PR #178 —
security: reconstruct scalar integer sealing on current main.Fresh exact identities:
main:1d2e19049354115776804c66b9366fad2ea5b6c5;1d2e19049354115776804c66b9366fad2ea5b6c5;aca7d0f7b99cdc7f10be711cddc9f686c459088f;The candidate requires exact built-in integers at shared allowed-port, DNS-count, positive-count and positive-byte-count normalization while preserving reviewed ASCII decimal-string configuration and existing range/default/authority behavior. The current branch was reconciled onto the protected tree without transferring predecessor evidence.
Exact-current-head evidence
On unchanged
aca7d0f7b99cdc7f10be711cddc9f686c459088f:1704/1704statements,576/576branches);31555659130: terminal success;31555659129: terminal success;31555659142: terminal aggregate success;93987430043: wrapper success, but its actual immutable-pinnedDependency reviewstep 4 is skipped. This is not accepted dependency-review evidence;The old exact-head Strix result recorded for predecessor
65485ee...is historical and is no longer used as current-head acceptance. Obtain/revalidate current-head review evidence onaca7d0f...without churning the clean source head.Read-only central prerequisite
The organization-owned fail-closed dependency-review repair remains
ContextualWisdomLab/.github#897until a fresh protected-central successor is proven and integrated..githubis read-only from this loop. EgressWeave must not substitute another scanner for Dependency Review or add a local fail-open workaround.Acceptance criteria
intat shared integer-form normalization boundaries while preserving reviewed decimal-string forms.[Unreleased]parity and the explicit no-Python-sandbox boundary.Dependency reviewaction executes and succeeds.Successor / writer discipline
Draft #184 is the distinct HTTP method-string successor and currently diverges from the live #178 tip after its predecessor moved; it remains Draft until #178 reaches an accepted stable identity or protected integration. Issues #131/#132/#133 remain distinct future host/port, DNS-timeout and authority-pair boundaries. Do not create a parallel scalar branch and do not churn a clean head merely to retrigger external behavior.