diff --git a/CHANGELOG.d/999-gap-baseline-0540.md b/CHANGELOG.d/999-gap-baseline-0540.md new file mode 100644 index 00000000..30a5b64c --- /dev/null +++ b/CHANGELOG.d/999-gap-baseline-0540.md @@ -0,0 +1,11 @@ +# Gap baseline snapshot 2026-09-08 + +Records live exact-head evidence for the commercial-readiness loop: #1036 skill-supply-chain repairs; #1173 quoted-shell plus assignment-value command-context RED/GREEN; non-force stack through Draft #1189 `c13142c` with every unique detector/test delta preserved; Draft #1189 quoted/unquoted Deno and CocoaPods publish fail-closed identities plus exact FP/FN boundaries; the canonical fail-closed assurance-state mapping; and the #1131/#1181 dashboard file-picker ownership, source-neutral predecessor, and browser-evidence boundary. This documents Proposed work and exact candidate evidence, not a protected capability, approval, release, or certification claim. + +## Scoped refresh 2026-09-12 + +Preserves the entire preceding baseline as the exact same Git blob `1953b92c6c6fcfbe9a30e2b78094c214c18e6fe6` in `docs/product-technical-gap-baseline-history-6d6d7749.md`. The canonical entry point keeps G-01 through G-08 meanings, the Context Map, assurance mapping and inherited obligations while distinguishing current scoped observations from unrefreshed historical lane states. No valid corpus or prerequisite is retired by this document organization. + +Records #1036 uppercase JSON escape RED `e339880...` (43 failed / 1161 passed), production `79531336...`, final candidate `832d066...` (hosted Python 3.13 1204 passed; Python 3.11 success), CodeRabbit source-thread resolution, and the separate CodeQL run `34682258948` pending-verdict failure linked to canonical `.github#2040`. This is not independent approval, central repair/release completion, protected integration, or a complete security-coverage claim. + +Records #1137 network-secret prefix-collision RED `55f4c02...` (2 failed / 1 passed), exact GREEN `07fcbcd...` (scoped 64/64), and ordinary zero-behind carryover through Draft #1138 `94d3d7f...`, #1139 `87d2571...`, and #1140 `e493ba8...` with scoped 70/70, 77/77, and 84/84 evidence. #1141 and later descendants remain open Draft and still require non-force restack; no hosted evidence, approval, protected merge, release, or Gap completion is claimed. diff --git a/CHANGELOG.md b/CHANGELOG.md index 110a549d..cc099b42 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,25 @@ - 대시보드 검색창 커서 유지 — 검색어 중간에서 텍스트를 수정할 때마다 커서가 검색어의 맨 끝으로 점프하는 불편함을 수정했습니다. 이제 입력창의 커서 위치(`selectionStart`/`selectionEnd`)가 동적 렌더링 이후에도 원래 위치에 정확히 유지되어 자연스러운 타이핑 경험을 제공합니다. ### 보안 +- Claude plugin hosted-deploy detector 계보를 최신 #1173 위로 ordinary two-parent merge했습니다. #1174 exact head `efa3347…`는 17 ahead / 0 behind이며 Vercel/Fly delta와 모든 predecessor 수선을 보존합니다. Restack 전 fixture-contract RED 2건을 수선했고 hosted/Terraform 53/53, 관련 detector 162/162, 전체 Claude-plugin 485/485와 compile·diff check가 통과했습니다. Hosted exact-head workflow와 독립 review가 없어 Draft입니다. +- Claude plugin Terraform/Helm detector 계보를 최신 #1172 위로 ordinary two-parent merge했습니다. #1173 exact head `6ec09ee…`는 current parent보다 42 ahead / 0 behind이며 checksum·GitHub write·credential-store·kubectl/Docker와 Terraform/Helm·dynamic-eval delta를 함께 보존합니다. Targeted deployment/Terraform/Helm/credential/GitHub/checksum 138/138과 전체 Claude-plugin 461/461, compile·diff check가 통과했습니다. Hosted exact-head workflow와 독립 review가 없어 Draft입니다. +- Claude plugin deployment-write detector 계보를 최신 #1171 위로 ordinary two-parent merge했습니다. #1172 exact head `00cdb79…`는 current parent보다 9 ahead / 0 behind이며 checksum·GitHub command-context·credential-store와 kubectl/Docker delta를 함께 보존합니다. Targeted deployment/credential/GitHub/checksum 109/109과 전체 Claude-plugin 432/432, dynamic-eval·compile·diff check가 통과했습니다. Hosted exact-head workflow와 독립 review가 없어 Draft입니다. +- Claude plugin credential-store detector 계보를 최신 #1170 위로 ordinary two-parent merge했습니다. #1171 exact head `c4ad59b…`는 current parent보다 6 ahead / 0 behind이며 checksum·GitHub command-context와 credential-store delta를 함께 보존합니다. Targeted credential/GitHub/checksum 77/77과 전체 Claude-plugin 400/400, compile·diff check가 통과했습니다. Hosted exact-head workflow와 독립 review가 없어 Draft입니다. +- Claude plugin GitHub merge/release detector 계보를 최신 #1169 위로 ordinary two-parent merge했습니다. #1170 exact head `f5c75be…`는 current parent보다 5 ahead / 0 behind이며 checksum nested-path·exact `..` 경계와 GitHub command-context delta를 함께 보존합니다. Targeted GitHub/checksum 60/60과 전체 Claude-plugin 383/383, compile·diff check가 통과했습니다. Hosted exact-head workflow와 독립 review가 없어 Draft입니다. +- Claude plugin successor 계보를 #1169까지 확장했습니다. #1163 command/agent rule reuse, #1164 hide-actions/self-modify/goal-escalation, #1165 setuid/setgid/world-writable mode, #1166 archive decompression/aggregate admission, #1167 scanner release/policy provenance, #1168 deterministic CycloneDX SBOM receipt digest, #1169 first-party checksum admission을 ordinary two-parent merge로 승계해 모두 current parent보다 0 behind로 만들었습니다. #1169는 nested checksum path basename-collapse FN과 정상 `..safe.bin` traversal FP를 RED→GREEN으로 수선했습니다. Exact-tree Claude-plugin 회귀는 265/265에서 352/352까지 누적 통과했으며, hosted exact-head workflow와 독립 review가 없어 모두 Draft입니다. +- Claude plugin successor 계보를 #1161까지 복구했습니다. #1150 browser profile부터 #1156 vendored scope, 기존 #1157 invocation identity, #1158 secret-to-prompt, #1161 secret-to-MCP를 최신 parent 위로 ordinary two-parent merge했고 모든 head가 current parent보다 0 behind입니다. Exact-tree Claude-plugin 회귀는 #1150 153/153에서 #1161 256/256까지 증가하며 통과했습니다. Hosted exact-head workflow와 독립 review가 없어 모두 Draft입니다. +- 대시보드 모바일 overflow 수선 — hosted Chromium RED `1d5adbc…`가 390px viewport에서 document 563px를 측정했습니다. Exact `4dbee0e…`에서 table fixed layout과 cell wrapping으로 root cause를 수선했고 Python 3.11/3.13 1003/1003 및 artifact `10066505328`(198275 bytes, SHA-256 `5b3dd4…`)로 검증했습니다. +- 대시보드 responsive hostile-payload 증거 — #1192 exact `c98c301…`에서 Chromium 기반 1003/1003을 Python 3.11/3.13 모두 통과하고, 1280×800·390×844 list/detail 장면과 exact revision manifest를 artifact `10066280431`(203095 bytes, SHA-256 `ea8f45…`)으로 결속했습니다. 이는 browser artifact Gap만 닫으며 CodeQL handoff·독립 승인을 대체하지 않습니다. +- 대시보드 exact-head 회귀 복구 — #1192의 concurrent `1456e14…`가 `parseInt` 부분 숫자 허용과 Chromium/browser/static corpus 삭제를 재도입한 결함을 확인했습니다. Normal atomic descendant `7e1bb470…`에서 whole-value `Number`·non-negative safe-integer 계약과 #1117 browser prerequisite를 완전히 복구했습니다. `215fa089…`의 hosted Python 3.11/3.13 1003/1003은 predecessor 증거이며 새 exact head로 이전하지 않습니다. +- Exact-head review-control 증거를 갱신했습니다. #1192는 #1117 browser prerequisite를 non-force two-parent merge로 승계했고, 후속 concurrent commit이 삭제한 Chromium workflow·잠금 의존성·browser/static regressions를 복구했습니다. Count는 전체 `Number` 값 중 non-negative safe integer만 허용해 `12px`, 소수, 음수, Infinity와 markup을 0으로 투영하며, hostile list/detail payload, `data-id` round-trip, inherited severity fallback, injected DOM/dialog 부재를 browser oracle로 검증합니다. Predecessor Checks는 이전하지 않습니다. #999 predecessor는 9개 repository workflow가 GREEN이나 Required Noema가 `orchestrator/free` 다중 429/timeout 뒤 HTTP 502로 실패했습니다. Canonical owner contextual-orchestrator #1094의 protected merge·immutable release·consumer bump 전에는 review 실패를 `Clean Scan`이나 승인으로 바꾸지 않습니다. +- Control-plane 대시보드 보안 회귀를 복원했습니다. Concurrent commit이 삭제한 JSON 렌더링 계약을 기존 dashboard security test owner에 통합하고, 숫자 coercion·`data-id` escape·severity own-property 경계와 정확한 innerHTML RCA를 #1192 exact head에 연결했습니다. +- Claude plugin GitHub 실행 경계 보강 — canonical #1170이 structural manifest의 typed `command`/`args`와 bounded nested-shell payload를 공통 parser로 소비합니다. `gh pr merge`와 `gh release create|upload|delete|edit`는 fail-closed하며 description/reporting/assignment/noexec, malformed argv, near verb, non-write verb는 negative로 유지합니다. 수선은 #1171→#1172→#1173에 non-force로 승계됐습니다. +- Claude plugin kubectl/Docker 실행 경계 보강 — canonical #1172가 structural manifest의 typed `command`/`args`와 bounded nested-shell payload를 공통 parser로 소비합니다. `kubectl apply`, `docker push`, `docker image push`는 fail-closed하며 description prose, reporting/no-op command, assignment, noexec, near verb, malformed argv는 negative로 유지합니다. #1173은 해당 prerequisite를 non-force로 통합했습니다. +- Claude plugin 구조화 argv 검출 보강 — JSON manifest의 `command`와 sibling `args`를 하나의 직접 실행 경계로 검증하여 `terraform apply`·`helm install` 우회를 차단합니다. Wrapper/reporting executable, near-verb, 공백 포함 단일 인자, 비배열·혼합형 `args`는 실행으로 추정하지 않으며 기존 shell-string 명령은 그대로 보존합니다. +- Claude plugin nested shell 검출 보강 — 직접 `sh`/`bash`/`dash`/`ksh`/`zsh`의 `-c` option payload와 구조화 shell argv를 bounded하게 재검사합니다. Split·compact·repeated `c`, 공통 no-value option과 Bash 전용 실행 보존 short/long option을 명시적으로 지원합니다. Noexec `n`, Bash `-D`·dump-string, dash/sh의 `-r`, 값 소비 option, missing-`c`, Bash short-before-long 순서는 실행으로 오인하지 않습니다. Reporting·assignment·wrapper·comment prose와 `$0…` 후속 인자는 payload로 합치지 않고 `apply-now`·`install-chart` near-verb도 제외합니다. +- Claude plugin 실행 명령 경계 보강 — quoted CLI 이름(`"deno" publish`, `'pod' trunk push`)을 실제 registry write로 검출하고, quoted near-task suffix는 capability 오탐에서 제외합니다. 공통 parser는 `:`·`true`·`false`의 인자를 실행 명령으로 오인하지 않으며, 뒤따르는 실제 명령은 계속 검출합니다. +- Claude plugin sbt publish 검출 보강 — `sbt "publish"`·`sbt 'publishSigned'`과 `$(...)`/backtick 안의 인용 task도 실제 repository write로 검출합니다. `publishLocal`, assignment·reporting prose, 닫힌 here-document payload는 계속 negative입니다. +- Claude plugin 실행 명령 문맥 정밀화 — 닫힌 literal here-document 본문의 `terraform apply`/`helm install` 같은 문자열은 데이터로 취급해 HIGH 오탐을 제거했습니다. 인용 delimiter와 `<<-` 탭 제거 형식을 지원하며, 닫히지 않거나 모호한 형식은 fail-closed로 유지합니다. 종료 delimiter 뒤의 실제 명령과 인용/주석 opener 유사 문자열 뒤의 실제 명령은 계속 검출합니다. - 리포트 출력 하드닝 — 생성된 markdown 리포트가 HTML로 렌더될 때 악성 finding 내용(예: 외부 엔진이 스캔한 코드의 `