Skip to content

fix(validation): bind executed conformance to run output provenance - #1093

Merged
seonghobae merged 9 commits into
feat/cross-engine-conformance-provenance-1077from
fix/conformance-execution-provenance-1092
Aug 21, 2026
Merged

seonghobae merged 9 commits into
feat/cross-engine-conformance-provenance-1077from
fix/conformance-execution-provenance-1092

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Fixes #1092. Advances #1077. Stacks directly on #1085.

RED → GREEN

  • RED 3b24452acd916304f4ce83676391dbc3ed5b5655 adds public regressions proving that executed passed, failed, and indeterminate evidence was accepted without run provenance, and that executed inventories could omit raw or normalized output hashes.
  • GREEN 8de61b4a275775c8bc723dcc86855c8440b5ece3 centralizes executed-status identity and makes ConformanceInventory fail closed unless an executed evidence set has a revalidated ConformanceRunProvenance with both raw-output and normalized-output SHA-256 identities.
  • Compatibility ef04b7a034623cc64cfcc1144603e195e31a2e97 updates existing executed fixtures to carry complete provenance while preserving optional output hashes for genuinely nonexecuted plans.
  • Release record 5c5edf601778c72c5ce4c6b480c796a299a41461 adds the governed changelog fragment.

Integrity boundary

The consistency check runs only after capability and nested provenance records are reconstructed through the existing exact-record admission path. Post-construction mutation therefore cannot bypass the new executed-run gate before validation.

Ownership boundary

Python validation/provenance only. No likelihood, estimator, scoring, alignment, discrepancy, bias/MAE/RMSE, Monte Carlo, uncertainty, or other psychometric/statistical arithmetic changes. External engines remain isolated validation instruments and production numerical ownership remains Rust-first.

Stack / acceptance

Base is the exact current #1085 branch. Keep Draft until the predecessor stack is integrated and this exact head has terminal CI/security/package/coverage and independent review evidence. Predecessor-head checks/reviews are historical only.

@coderabbitai

coderabbitai Bot commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: a56242fc-8187-406f-9e92-e5e043800c89

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head review and fix record: executed conformance evidence now requires an exact run-level provenance record plus both raw and normalized output SHA-256 identities; nested provenance is revalidated before the execution gate, and no raw output or external engine is introduced. During review, the parent mutation fixture failed because it omitted the new required provenance. Added a current-contract-only fixture correction (no future enum fields). Exact new HEAD 3185ced9 passes all cross-engine provenance/replay suites (56 passed), Ruff, production interrogate 100%, compileall, and git diff --check. Review this exact stacked HEAD only; merge normally after its base, without bypass.

@seonghobae
seonghobae marked this pull request as ready for review August 21, 2026 01:59
@seonghobae
seonghobae enabled auto-merge (squash) August 21, 2026 01:59

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Open in Devin Review

* test(conformance): require runtime and redistribution provenance

* feat(conformance): bind runtime and redistribution provenance

* test(conformance): align inventory fixtures with runtime provenance

* test(conformance): carry runtime identities in provenance replay fixture

* test(conformance): carry runtime identities in execution fixture

* docs(changelog): record runtime provenance contract

* test(conformance): cover malformed runtime provenance controls

* test(conformance): provide provenance for executed mutation fixture

* feat(validation): strictly replay persisted conformance manifests (#1097)

* test(conformance): require strict persisted manifest replay

* feat(conformance): strictly replay persisted manifests

* docs(changelog): record strict conformance manifest replay

* test(conformance): cover nested manifest replay boundaries

* test(conformance): require stable JSON resource failures

* fix(conformance): stabilize bounded JSON replay failures

* fix(conformance): bound parsed manifest nesting

* test(conformance): provide provenance for executed mutation fixture
@seonghobae
seonghobae merged commit b297a2d into feat/cross-engine-conformance-provenance-1077 Aug 21, 2026
9 of 10 checks passed
@seonghobae
seonghobae deleted the fix/conformance-execution-provenance-1092 branch August 21, 2026 10:06
seonghobae added a commit that referenced this pull request Aug 21, 2026
* feat(validation): add conformance run provenance

* fix(changelog): restore fragment headings

* test(validation): reproduce run provenance replay bypass

* fix(validation): replay run provenance before serialization

* docs(validation): record provenance replay integrity

* fix(validation): bind executed conformance to run output provenance (#1093)

* test(conformance): require output provenance for executed evidence

* fix(conformance): bind executed evidence to run outputs

* test(conformance): align fixtures with executed provenance contract

* docs(changelog): record executed conformance provenance gate

* test(conformance): seal mutated output provenance before execution gate

* test(conformance): provide provenance for executed mutation fixture

* Revert "test(conformance): provide provenance for executed mutation fixture"

This reverts commit b94cf2e.

* test(conformance): provide legacy provenance fixture

* feat(validation): complete conformance runtime provenance (#1095)

* test(conformance): require runtime and redistribution provenance

* feat(conformance): bind runtime and redistribution provenance

* test(conformance): align inventory fixtures with runtime provenance

* test(conformance): carry runtime identities in provenance replay fixture

* test(conformance): carry runtime identities in execution fixture

* docs(changelog): record runtime provenance contract

* test(conformance): cover malformed runtime provenance controls

* test(conformance): provide provenance for executed mutation fixture

* feat(validation): strictly replay persisted conformance manifests (#1097)

* test(conformance): require strict persisted manifest replay

* feat(conformance): strictly replay persisted manifests

* docs(changelog): record strict conformance manifest replay

* test(conformance): cover nested manifest replay boundaries

* test(conformance): require stable JSON resource failures

* fix(conformance): stabilize bounded JSON replay failures

* fix(conformance): bound parsed manifest nesting

* test(conformance): provide provenance for executed mutation fixture

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

Open in Devin Review

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: New executed-evidence gate ordering preserves prior validation errors

The new fail-closed gate at cross_engine_conformance.py runs after package_version, source_commit, _capability_values, and _schema_version validation. I verified this ordering does not regress the untouched edge tests in tests/test_cross_engine_conformance_edges.py: constructions expecting errors (duplicate capabilities, bad schema 2.0, container-type errors) all trip earlier validation before the executed gate, so they still raise the expected messages. The gate also correctly uses the revalidated local capabilities/provenance variables rather than raw attributes, so post-construction mutation cannot bypass it.

(Refers to this code)

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +906 to +919
def _validate_manifest_nesting(value: object) -> None:
"""Reject parsed JSON containers deeper than the replay contract allows."""
stack: list[tuple[object, int]] = [(value, 0)]
while stack:
current, depth = stack.pop()
if type(current) is dict:
children = dict.values(current)
elif type(current) is list:
children = current
else:
continue
if depth >= MAX_MANIFEST_NESTING:
raise ValueError("manifest JSON nesting is too deep")
stack.extend((child, depth + 1) for child in children)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Deep JSON nesting has two independent guards

from_json guards stack exhaustion twice: it catches RecursionError from json.loads, and it runs the iterative depth check _validate_manifest_nesting (cross_engine_conformance.py). Both raise the same 'too deep' error, so nesting rejection is stable across interpreter recursion limits. from_manifest reads a fixed schema depth, so a directly-passed dict cannot trigger unbounded recursion.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

seonghobae added a commit that referenced this pull request Aug 24, 2026
)

* test(validation): define cross-engine conformance inventory contract

* feat(validation): add cross-engine conformance inventory

* docs(changelog): record cross-engine conformance inventory

* test(validation): cover conformance contract fail-closed edges

* fix(validation): seal conformance package records

* test(validation): seal conformance record subclasses

* fix(validation): complete conformance commit provenance boundary

* fix(validation): require executed conformance evidence

* test(validation): reproduce unsupported conformance coverage claim

* test(validation): pin execution-backed coverage invariant

* test(validation): reproduce Unicode conformance identity drift

* fix(validation): normalize conformance text before hashing

* test(validation): make schema-version regex literal

* test(conformance): expose post-init mutation replay gap

* fix(conformance): revalidate records on manifest replay

* docs(conformance): record replay integrity hardening

* test(conformance): document replay fixtures

* fix(changelog): restore authoritative fragment format

* feat(validation): add conformance run provenance (#1085)

* feat(validation): add conformance run provenance

* fix(changelog): restore fragment headings

* test(validation): reproduce run provenance replay bypass

* fix(validation): replay run provenance before serialization

* docs(validation): record provenance replay integrity

* fix(validation): bind executed conformance to run output provenance (#1093)

* test(conformance): require output provenance for executed evidence

* fix(conformance): bind executed evidence to run outputs

* test(conformance): align fixtures with executed provenance contract

* docs(changelog): record executed conformance provenance gate

* test(conformance): seal mutated output provenance before execution gate

* test(conformance): provide provenance for executed mutation fixture

* Revert "test(conformance): provide provenance for executed mutation fixture"

This reverts commit b94cf2e.

* test(conformance): provide legacy provenance fixture

* feat(validation): complete conformance runtime provenance (#1095)

* test(conformance): require runtime and redistribution provenance

* feat(conformance): bind runtime and redistribution provenance

* test(conformance): align inventory fixtures with runtime provenance

* test(conformance): carry runtime identities in provenance replay fixture

* test(conformance): carry runtime identities in execution fixture

* docs(changelog): record runtime provenance contract

* test(conformance): cover malformed runtime provenance controls

* test(conformance): provide provenance for executed mutation fixture

* feat(validation): strictly replay persisted conformance manifests (#1097)

* test(conformance): require strict persisted manifest replay

* feat(conformance): strictly replay persisted manifests

* docs(changelog): record strict conformance manifest replay

* test(conformance): cover nested manifest replay boundaries

* test(conformance): require stable JSON resource failures

* fix(conformance): stabilize bounded JSON replay failures

* fix(conformance): bound parsed manifest nesting

* test(conformance): provide provenance for executed mutation fixture

* feat(validation): render accessible cross-engine conformance evidence (#1164)

* test(validation): require accessible conformance evidence report

* feat(validation): render accessible conformance evidence

* docs(changelog): record conformance evidence report

* test(validation): require downloadable long-form conformance rows

* feat(validation): export long-form conformance evidence rows

* docs(changelog): record long-form conformance export

* fix(report): stop over-escaping the CSP meta-tag content in cross-engine report

Strix flagged this exact pattern on this PR (CWE-693, CVSS 6.5):
escape(_CSP, quote=True) converts the CSP's literal 'none' source
expression to 'none', which browsers do not parse as valid CSP
syntax, silently disabling the meta-delivered policy. _CSP is a fixed
module constant with no user-controlled content, so interpolating it
directly is safe. This mirrors the same fix already applied to every
other report generator on main in #1230.

Added a regression assertion that the CSP is embedded unescaped.
Verified: pytest tests/test_cross_engine_conformance_report.py -- 8 passed.

* Revert "fix(report): stop over-escaping the CSP meta-tag content in cross-engine report"

This reverts commit 051bc1b.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant