Finding
The scientific-validation inert verifier in #2300 validates symlinks for the sealed evidence root and the final output path, but _atomic_json creates/uses path.parent without rejecting symlinked output ancestors. It also permits output_predicate == output_manifest and permits either output path to live inside the sealed evidence root.
Those cases are currently caller-controlled CLI values. A future credentialed #2299 signer is expected to treat the verifier outputs as trusted predicate/receipt material, so the verifier should make the filesystem authority boundary explicit before signer credentials are introduced.
Failure modes
- A symlinked output parent can redirect trusted-looking verifier output outside the intended directory even though the leaf path itself is not a symlink.
- Equal predicate/manifest paths cause the second atomic replace to overwrite the first while verification still returns success.
- An output inside the sealed evidence root mutates the one-member evidence set after its bytes/cardinality were verified, weakening the sealed-artifact invariant for subsequent stages.
This is not a claim that current #2300 authenticates the caller; it is an owner-local filesystem integrity defect in the unsigned verifier boundary.
RED / repair
Add deterministic contracts that reject: (1) symlink ancestry in either output parent, (2) identical predicate and manifest paths, and (3) outputs located within the sealed evidence root. Then validate both output destinations before any publication and keep atomic replacement/temporary cleanup behavior unchanged.
Do not add signer/OIDC credentials here and do not weaken existing strict evidence parsing. Refs #2299 #2300 ContextualWisdomLab/TEPP#637.
Finding
The scientific-validation inert verifier in #2300 validates symlinks for the sealed evidence root and the final output path, but
_atomic_jsoncreates/usespath.parentwithout rejecting symlinked output ancestors. It also permitsoutput_predicate == output_manifestand permits either output path to live inside the sealed evidence root.Those cases are currently caller-controlled CLI values. A future credentialed #2299 signer is expected to treat the verifier outputs as trusted predicate/receipt material, so the verifier should make the filesystem authority boundary explicit before signer credentials are introduced.
Failure modes
This is not a claim that current #2300 authenticates the caller; it is an owner-local filesystem integrity defect in the unsigned verifier boundary.
RED / repair
Add deterministic contracts that reject: (1) symlink ancestry in either output parent, (2) identical predicate and manifest paths, and (3) outputs located within the sealed evidence root. Then validate both output destinations before any publication and keep atomic replacement/temporary cleanup behavior unchanged.
Do not add signer/OIDC credentials here and do not weaken existing strict evidence parsing. Refs #2299 #2300 ContextualWisdomLab/TEPP#637.