Skip to content

fix(reliability): fail closed on unknown runtime image configuration keys #220

Description

@seonghobae

Current authoritative state

This defect is repaired on canonical single-writer Draft PR #216 / fix/image-config-runtime-validation-215. Protected shipped truth and the frozen v0.6.0 candidate remain main@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is 85aac6e55b4839b456b6ed464dbab78fd9d402c6. Fresh ancestry resolves protected main as merge base, 15 commits ahead / 0 behind, with only the three intended extension-configuration files changed.

The active implementation inspects own keys/descriptors before reads and accepts only the documented enumerable data-property keys for build/image configuration. Unknown string keys, symbol keys, accessors, non-enumerable properties, malformed containers and hostile reflection failures fail closed with stable payload-redacted configuration errors. Valid defaults and known fields retain their established semantics, including non-negative safe-integer image ceilings and finite [0,1] quality.

Test-first lineage and exact-head proof

Unknown-key RED f18fd401775a34ea1fa679df6d71cc9945ce52db established that misspelled/symbol configuration was silently accepted. Current synchronized exact head 85aac6e55b4839b456b6ed464dbab78fd9d402c6 has repository CI 32101702170, Security Scan 32101702155, and SAST Semgrep 32101702154 completed / success. Formal submitted reviews are 0; repository technical success is not qualifying independent approval and does not replace separately applicable central workflows.

Integration boundary

The defect is repaired on active Draft #216 but is not protected-main shipped behavior. Keep #216 Draft/unmerged while #118 owns exact v0.6.0 publication/provenance/digest acceptance and while qualifying independent latest-push approval plus every applicable central required workflow remain unsatisfied. Any head/base/ruleset movement requires fresh exact evidence; do not create a competing kit.ts writer, self-approve, weaken gates, transfer predecessor evidence, move protected main, or fabricate release identity.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: authAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions