Skip to content

security: seal normalized integer policy values before runtime retention #122

Description

@seonghobae

Buyer-visible immutable-policy value gap

EgressWeave's shared scalar-normalization boundary must retain reviewed built-in values rather than arbitrary int subclasses that can carry polymorphic behavior into authority/resource policy. This is trusted configuration integrity, not a Python-sandbox claim.

Current canonical candidate

Historical #123/#153/#159 are evidence only. The current candidate is Ready PR #178security: reconstruct scalar integer sealing on current main.

Fresh exact identities:

The candidate requires exact built-in integers at shared allowed-port, DNS-count, positive-count and positive-byte-count normalization while preserving reviewed ASCII decimal-string configuration and existing range/default/authority behavior. The current branch was reconciled onto the protected tree without transferring predecessor evidence.

Exact-current-head evidence

On unchanged aca7d0f7b99cdc7f10be711cddc9f686c459088f:

  • local Python 3.14 acceptance recorded by the current PR: 944 passed;
  • exact owned-production coverage: 100% (1704/1704 statements, 576/576 branches);
  • Ruff, hourly product guard and compileall: passed locally;
  • hosted CI 31555659130: terminal success;
  • hosted SAST Semgrep 31555659129: terminal success;
  • hosted Security Scan 31555659142: terminal aggregate success;
  • dependency-review job 93987430043: wrapper success, but its actual immutable-pinned Dependency review step 4 is skipped. This is not accepted dependency-review evidence;
  • OpenCode/GHAS scanner checks visible on this exact head are machine/check evidence only and do not substitute for current semantic review or the missing dependency-review action.

The old exact-head Strix result recorded for predecessor 65485ee... is historical and is no longer used as current-head acceptance. Obtain/revalidate current-head review evidence on aca7d0f... without churning the clean source head.

Read-only central prerequisite

The organization-owned fail-closed dependency-review repair remains ContextualWisdomLab/.github#897 until a fresh protected-central successor is proven and integrated. .github is read-only from this loop. EgressWeave must not substitute another scanner for Dependency Review or add a local fail-open workaround.

Acceptance criteria

  • Preserve test-first RED evidence for representative non-exact integer values.
  • Require exact built-in int at shared integer-form normalization boundaries while preserving reviewed decimal-string forms.
  • Preserve authority/local-development/method/range/DNS/TLS/proxy/request/response/public-builder/dependency/credential/release semantics.
  • Preserve actionable startup diagnostics, beginner-readable guidance, [Unreleased] parity and the explicit no-Python-sandbox boundary.
  • Maintain exact 100% owned-production statement/branch coverage and Python 3.14 validation on the current candidate.
  • Pass current exact-head CI and SAST.
  • Obtain/revalidate current exact-head automated/source review with zero valid unresolved findings; predecessor/status/check/model evidence does not transfer.
  • Integrate the separately governed central dependency-review repair and obtain a fresh Security Scan in which the actual pinned Dependency review action executes and succeeds.
  • Revalidate exact head/live base/rulesets/checks/findings immediately before merge; satisfy every live requirement and keep zero valid unresolved findings.
  • Merge only the accepted unchanged tree and verify the scalar-value boundary from protected main before closure.

Successor / writer discipline

Draft #184 is the distinct HTTP method-string successor and currently diverges from the live #178 tip after its predecessor moved; it remains Draft until #178 reaches an accepted stable identity or protected integration. Issues #131/#132/#133 remain distinct future host/port, DNS-timeout and authority-pair boundaries. Do not create a parallel scalar branch and do not churn a clean head merely to retrigger external behavior.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions