Skip to content

fix(reliability): validate runtime image configuration before extension setup #215

Description

@seonghobae

Current authoritative state

This defect is repaired on canonical single-writer Draft PR #216 / fix/image-config-runtime-validation-215. Protected shipped truth and the frozen v0.6.0 candidate remain main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is 85aac6e55b4839b456b6ed464dbab78fd9d402c6. Fresh ancestry resolves protected main as merge base, 15 commits ahead / 0 behind, with only src/extensions/buildExtensionsRuntimeBoundary.test.ts, src/extensions/imageConfigRuntime.test.ts, and src/extensions/kit.ts changed.

The active implementation fail-closes malformed top-level build options and nested ImageConfig, uses bounded own-key/descriptor reflection before value reads, validates maxSizeBytes / maxDimension as non-negative safe integers with zero preserving documented disable semantics, validates quality as finite [0,1], and preserves valid/default extension, image, paste/drop/upload, package and host-composition behavior. Transport, persistence, authorization, tenancy, credentials, network/model/provider policy, deployment, migration, retention and durable audit remain host-owned.

Test-first lineage and exact-head proof

RED lineage includes malformed-container/value head 3995d336c4a8aa06b4632732fadc48816683165a. Current synchronized exact head 85aac6e55b4839b456b6ed464dbab78fd9d402c6 has repository CI 32101702170, Security Scan 32101702155, and SAST Semgrep 32101702154 completed / success. Formal submitted reviews are 0; repository technical success is not qualifying independent approval and does not replace separately applicable central workflows.

Integration boundary

The defect is repaired on active Draft #216 but is not protected-main shipped behavior. Keep #216 Draft/unmerged while #118 owns exact v0.6.0 publication/provenance/digest acceptance and while qualifying independent latest-push approval plus every applicable central required workflow remain unsatisfied. Any head/base/ruleset movement requires fresh exact evidence; do not create a competing kit.ts writer, self-approve, weaken gates, transfer predecessor evidence, move protected main, or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions