Skip to content

fix: reject runtime directives in declared binary artifacts - #2386

Merged
seonghobae merged 10 commits into
mainfrom
codex/pingora-declared-runtime-guard-20260926
Sep 27, 2026
Merged

seonghobae merged 10 commits into
mainfrom
codex/pingora-declared-runtime-guard-20260926

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Problem

A base-branch artifact-path declaration can cause a changed file with no GitHub diff patch and any non-UTF-8 byte to be admitted as a binary research artifact. With docs/delivery_interim_20260920/ declared, a deploy.sh containing nginx -c /etc/nginx/nginx.conf and one invalid byte was admitted with zero violations. This matters before late-life-anxiety-reanalysis #269 merges its broad documentation prefixes.

Change

For declared artifacts without recognized format magic, inspect the readable portions of the fetched bytes for the existing prohibited runtime patterns. A match falls through to the policy's fail-closed invalid-UTF-8 handling. Genuine binary research artifacts without those patterns retain the existing admission path.

Verification

  • The new end-to-end regression failed before the fix for .sh, .dat, and .txt names, then passed after it.
  • python3 -m pytest tests/test_pingora_edge_policy.py -q: 87 passed.
  • GITHUB_ACTIONS=true python3 -m pytest tests/test_pingora_edge_policy.py -q: 87 passed.
  • git diff --check: clean.

Dependency: merge this central policy fix before accepting late-life-anxiety-reanalysis #269's artifact-path declaration. Required checks and independent review remain necessary on the current PR head.

Current exact-head evidence

  • Head: 6a32843cc698a301f968dc4a3edec2e2d380dc0f; tree: 2ebae343f83d3333bee9e493e36951dd0595d13b.
  • Protected main@e6334e229581a918e2f22de18733b76fa65d7e71: 2 ahead / 0 behind; mergeable; five effective paths.
  • Module contract, policy, CHANGELOG, and CONTROL-PINGORA-DECLARED-BINARY-RUNTIME-01 now describe the same three-condition admission invariant as production code.
  • Local exact-tree verification: 87 tests in the normal environment, 87 tests with GITHUB_ACTIONS=true, Python compile and git diff --check all pass.
  • Fresh hosted Runtime Quality, CodeQL PR, Semgrep, Security, and Python Security runs are queued. No current-head independent approval exists; this PR remains unmerged.

2026-09-27 Python Security repair

  • RCA: exact-head Python Security run 36236245577, job 108402877544, found AnyIO 4.14.0 affected by CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349; fixed version is 4.14.2.
  • RED 761be5b0f63422505b37e28a367a4c5170f302ba: the carried source↔lock contract failed 1 failed, 1 passed because the explicit source constraint was absent.
  • GREEN c59ef9aed32ab4c5138c2b7770ddcc10d7ee8393→a895dc5aec775076c3819679eadf0b50a563aa2e: source input now pins anyio==4.14.2; the lock is exact repair(foundation): unblock coverage and CodeQL control plane #2385 generated blob eb83beda177c9d2e4ca9b7e2888a1ccb55a123ac, differing from the vulnerable lock only at version line 143 and hash lines 144–145. Exact remote blobs pass 2 passed.
  • Gap authority: exact 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6 appends the Proposed carryover record while preserving the previous baseline as a prefix (59→60 level-two sections).

Fresh exact-head Python Security/pip-audit, remaining required Checks, and independent approval remain required before merge.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 33 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 56f939da-146b-431c-beb2-f1c3d9df2b93

📥 Commits

Reviewing files that changed from the base of the PR and between 2917179 and 65d639a.

📒 Files selected for processing (5)
  • CHANGELOG.md
  • docs/policies/PINGORA_EDGE_POLICY.md
  • docs/product-technical-gap-baseline.md
  • scripts/ci/pingora_edge_policy.py
  • tests/test_pingora_edge_policy.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Exact-head repair evidence — 2026-09-26

Current head: 6a32843cc698a301f968dc4a3edec2e2d380dc0f
Exact tree: 2ebae343f83d3333bee9e493e36951dd0595d13b
Parent source repair: dea7532eea5ca75eb34119e1532f1512607dda3e

The source repair introduced a third admission invariant for declared artifacts with unrecognized suffixes: no patch, invalid UTF-8, and no prohibited runtime pattern in replacement-decoded text. The module contract and policy document previously still described the old two-condition rule. This ordinary child synchronizes those authoritative docs, CHANGELOG, and CONTROL-PINGORA-DECLARED-BINARY-RUNTIME-01 in the product technical Gap baseline. No additional runtime behavior was introduced.

Topology and scope:

  • protected main@e6334e229581a918e2f22de18733b76fa65d7e71
  • 2 ahead / 0 behind; mergeable
  • exactly 5 effective paths: production guard, regression test, module/policy documentation, CHANGELOG, and Gap baseline
  • unresolved review threads: 0

Fresh exact-tree verification:

  • python3 -m pytest tests/test_pingora_edge_policy.py -q: 87 passed
  • GITHUB_ACTIONS=true python3 -m pytest tests/test_pingora_edge_policy.py -q: 87 passed
  • python3 -m compileall -q scripts/ci/pingora_edge_policy.py: PASS
  • git diff --check: PASS
  • the four child blobs were checked byte-for-byte against the locally verified tree

Fresh exact-head hosted evidence:

There is no current-head independent approval. Therefore this is repair evidence, not merge evidence; no self-approval, manual rerun, protection bypass, auto-merge, Force Push, or stale-evidence promotion was performed.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for 6a32843cc698a301f968dc4a3edec2e2d380dc0f (COMMENT, not approval).

The source repair closes the reported admission path at the production boundary. A declared artifact prefix is still loaded only from the base ref; _is_binary_documentation_asset still rejects runtime-shaped paths before binary evidence is considered; and unrecognized-format bytes now require all three conditions before admission: no GitHub patch, invalid UTF-8, and no CONTENT_RULES match in bounded replacement-decoded content. When readable Nginx content is present, evidence confirmation returns false and the normal UTF-8 loader fails closed. The parametrized .sh/.dat/.txt regression exercises evaluate_pull_request, the base declaration fetch, final-head content fetch, and the rejection path rather than only testing the helper.

The policy document, module contract, changelog, and CONTROL-PINGORA-DECLARED-BINARY-RUNTIME-01 record the same boundary. I found no additional source-backed defect in the five-file delta. Protected main@e6334e22… comparison is ahead 2 / behind 0 and review threads are zero.

Current exact-head Runtime Quality 36236245589, CodeQL 36236245614, SAST 36236245579, Security 36236245656, and Python Security 36236245577 are all queued, and no qualifying independent APPROVED review exists. This review does not transfer local author evidence, claim GREEN, or authorize merge/auto-merge/bypass/rerun.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for 6a32843cc698a301f968dc4a3edec2e2d380dc0f (COMMENT, not approval).

I traced the five-path delta through the production admission boundary. The base-ref-only declaration remains unchanged; runtime-named paths still bypass binary admission; recognized PNG/HWPX/PDF evidence keeps its existing structural path; and an unrecognized declared artifact now needs all three conditions before admission: no GitHub patch, invalid UTF-8, and no CONTENT_RULES match in replacement-decoded bytes. A matching readable runtime directive falls through to the existing strict decode and fails closed. The production-bound regression exercises .sh, .dat, and .txt names. I found no additional source-backed defect in this exact delta.

Protected main@e6334e229581a918e2f22de18733b76fa65d7e71 is 2 commits behind this head with 0 commits in the other direction; the PR is mergeable and has no unresolved review thread. Runtime Quality 36236245589, CodeQL 36236245614, SAST 36236245579, Security 36236245656, and Python Security 36236245577 are still queued, and no qualifying independent APPROVED review exists. This review is exact-head review evidence only, not merge authority.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head gate record for 6a32843cc698a301f968dc4a3edec2e2d380dc0f (base e6334e229581a918e2f22de18733b76fa65d7e71), checked at 11:14Z:

  • Independent nonauthor technical review of this exact 130-line diff found no blocking source issue. The reviewer reproduced rejection of a renamed deploy.sh containing readable Nginx commands plus an invalid UTF-8 byte; the focused policy suite passed 87 tests. The reviewer did not submit a GitHub approval.
  • There are zero review threads and no submitted GitHub reviews. Current branch rules require zero approving reviews, while the independent technical review requirement has been met. The repository collaborator list contains only the author account seonghobae.
  • mergeStateStatus is BLOCKED. Required required-workflow-bootstrap, Detect CodeQL languages, and the current scan-pr-queue are QUEUED; the older scheduler run is CANCELLED. Security and review jobs are also queued. No hosted terminal success exists for this head.

Do not merge until the required current-head checks finish successfully and protected merge eligibility is rechecked. Next status check: 11:45Z or the first terminal check event, whichever comes first. The downstream late-life-anxiety-reanalysis #269 declaration remains blocked until this guard lands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

11:45Z exact-head follow-up: #2386 remains 6a32843cc698a301f968dc4a3edec2e2d380dc0f / OPEN / BLOCKED. The current required scan-pr-queue (run), required-workflow-bootstrap (run), and Detect CodeQL languages (run) remain QUEUED; the earlier scheduler job is CANCELLED. The broader security/review jobs are queued too. No GitHub review has been submitted. The exact-head nonauthor technical review remains nonblocking, but it does not replace hosted checks.

No retry or merge is justified by this state. Next check: 12:30Z or the first terminal job event, whichever comes first. #269 must remain blocked until this PR passes its protected gate and merges.

@seonghobae

Copy link
Copy Markdown
Contributor Author

14:25Z 현재 head 6a32843cc698a301f968dc4a3edec2e2d380dc0f, base e6334e229581a918e2f22de18733b76fa65d7e71의 검사 정정입니다. 앞선 11:45Z 댓글에서 대기 중이던 required-workflow-bootstrap, Detect CodeQL languages, 현재 scan-pr-queue는 모두 SUCCESS로 끝났습니다.

다만 필수 CodeQL compatibility (actions/python), Noema, coverage-evidence, OpenCode, Trivy, Scorecard를 포함한 작업 11개가 아직 QUEUED입니다. Noema job은 14:23Z jobs API에서도 runner 미배정(runner_name 빈 값, 단계 없음) 상태였습니다. 이전에 취소된 두 scheduler 작업은 현재 성공한 대체 작업과 구분합니다.

독립 비작성자 기술 검수는 이 head에서 차단 결함을 찾지 못했고 정책 회귀 87건을 통과했습니다. GitHub 제출 리뷰는 없고 리뷰 스레드는 0개입니다. 현재 mergeStateStatus=BLOCKED이므로 남은 필수 검사가 끝나고 보호 규칙 결과를 다시 확인하기 전에는 병합하지 않습니다. #269의 넓은 경로 선언도 이 가드 수용 전에는 차단 상태를 유지합니다.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head combined-policy preflight (2026-09-27 KST): the clean merge tree of #2386 6a32843cc698a301f968dc4a3edec2e2d380dc0f and #2396 f78bc9df4ab7e2f6eefc78e24bdc11eeb3d6b064 is cfabecfe29e626075b181ea286ca49ef50b77994 (git merge-tree --write-tree, no conflicts; git diff --check clean). An isolated export of that tree passed GITHUB_ACTIONS=true PYTHONDONTWRITEBYTECODE=1 python3 -m pytest tests/test_pingora_edge_policy.py tests/test_pingora_edge_workflow_contract.py -q -p no:cacheprovider: 100 passed.

Using the combined tree's policy checker and GitHub evidence (without executing PR code), both current PR heads passed with exit 0: late-life-anxiety-reanalysis#269 head 78617f3160cfe8fbf7a4dae2ca3f3fdaca44db8e / base bcea8006560e50412b630cf8eb5c12d8a7633e5e, and fast-mlsirm#2157 head 58b7b23f7a154c8391c130ebc3aab2dde50bb84b / base 00f5cb91b417e40102036eb31ab8a4b843c76076.

This is local preflight evidence only. The hosted jobs and required reviews remain separate. At this observation #2386 Noema, #2396 admission, and #2157 package jobs were still queued with no runner or steps; no merge is claimed.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head security repair review for 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6 (COMMENT, not approval).

RCA is bound to Python Security run 36236245577, job 108402877544: the hash-locked Strix runtime selected AnyIO 4.14.0, and pip-audit identified CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349, each fixed in 4.14.2. The generated lock lacked an explicit source constraint, so the vulnerable transitive selection was reproducible but not owner-governed.

  • RED 761be5b0…: #2385's source↔lock contract was integrated before production changes and failed exactly because requirements-strix-ci.txt omitted anyio==4.14.2 (1 failed, 1 passed).
  • GREEN c59ef9ae…→a895dc5a…: adds that one source constraint and adopts #2385's generated lock blob eb83beda177c9d2e4ca9b7e2888a1ccb55a123ac. Against the vulnerable lock, only lines 143–145 differ: version plus the two published artifact hashes.
  • Exact remote three-file verification: focused contract 2/2 passed. The Gap successor 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6 preserves the previous baseline as an exact prefix, adds one Proposed section (59→60), and records the hosted failure plus RED/GREEN lineage.
  • Effective diff from reviewed predecessor 6a32843c…: ahead 4 / behind 0, four paths, +28/-3. The original Pingora runtime-guard behavior is untouched.

Fresh exact-head Python Security, SAST, Security Scan, CodeQL, and Runtime Quality are queued/pending. This review claims focused GREEN only, not hosted acceptance or merge authority.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head correction to my earlier combined preflight: #2386 has advanced to 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6 and #2396 to ac08765ede41475d257030fd81a0ea9542ed89d7. Their automatic merge now conflicts only in the append-only docs/product-technical-gap-baseline.md; the policy code auto-merges. A scratch resolution preserving both new sections passed 102 focused tests and the combined policy checker passed the current #269 and #2157 heads. Exact steps, heads and remaining gates: #2396 (comment) . The earlier conflict-free claim remains valid only for the prior heads.

@seonghobae

Copy link
Copy Markdown
Contributor Author

2026-09-27 02:20 UTC, 현재 head 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6, base e6334e229581a918e2f22de18733b76fa65d7e71 판정입니다. 이전 기록의 6a32843… 뒤에 AnyIO Strix 입력 핀·잠금 파일·회귀 테스트·Gap 기록을 담은 4개 커밋이 추가됐습니다. 따라서 이전 head의 원격 검사와 검토를 현재 head의 결론으로 재사용하지 않습니다.

현재 head의 독립 비작성자 읽기 전용 기술 검토는 Pingora 선언 경로의 잘못된 UTF-8 검사 가드가 유지됐고, AnyIO 4.14.2 핀·잠금 해시·설치 경로에서 새 차단 결함을 찾지 못했습니다. 정확한 트리의 관련 테스트는 로컬에서 89건 통과했습니다. 이 검토는 GitHub 제출 승인이나 hosted 검사 성공을 뜻하지 않습니다. 현재 리뷰 스레드 0개, 현재 head의 GitHub 리뷰는 작성자 COMMENTED 1개이며 APPROVED는 0개입니다.

현재 head의 검사 16개는 QUEUED이고 mergeStateStatus=BLOCKED입니다. 중앙 main 보호 규칙은 승인 리뷰 수 0, 스레드 해결 필수, 필수 검사와 최신 base 일치를 요구합니다. 검사들이 완료된 뒤 head·base·규칙 결과를 다시 확인할 때까지 이 PR과 의존하는 #269의 병합은 진행하지 않습니다.

Copy link
Copy Markdown
Contributor Author

Exact-head blocker re-audit: 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6 (base main@e6334e229581a918e2f22de18733b76fa65d7e71, 6 ahead / 0 behind).

현재 다음 실질 blocker가 있어 Draft/Proposed로 교정합니다:

  • terminal workflow failure: Agent Review Runtime Quality CI=failure#36271373151

Queued/pending review·Checks 또는 승인 대기만으로 Draft 전환하지 않았습니다. Current head에서 blocker가 해소되면 Ready review admission을 복구합니다.

Copy link
Copy Markdown
Contributor Author

Exact-head failure repaired by ordinary non-force fast-forward.

  • predecessor head: 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6
  • failed run/job: Agent Review Runtime Quality CI 36271373151, job 108485866297
  • exact log cause: all 3398 passed, 3 skipped, 40 subtests passed at 100% coverage; the final consolidated contract then failed because docs/product-technical-gap-baseline.md:3438 had a new blank line at EOF
  • repair: remove only that trailing blank line
  • local exact repair evidence: consolidated contract 16 passed, compileall clean, git diff --check clean
  • current head: 3234b5bcc97a403ab2c4e02594a6c2d21aab0e9e
  • fresh current-head Agent Review Runtime Quality CI: 36294302215, queued

The PR remains Draft. The predecessor failure was not rerun because the source change generated fresh exact-head workflows; queued checks are not passing evidence.

@seonghobae
seonghobae marked this pull request as ready for review September 27, 2026 12:32

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent source review at exact head efe6073, compared with base fd2a03e. COMMENT, not formal approval or hosted acceptance.

I inspected the full five-file delta and the current production call path: base-only artifact-prefix declaration → binary path prefilter → authenticated final-head raw content → binary confirmation → strict content scan on rejection. Runtime-shaped paths still cannot enter binary admission. Recognized PNG/HWPX/PDF evidence retains its existing handling. For unrecognized formats, missing patch and invalid UTF-8 are no longer sufficient: replacement-decoded content must contain no CONTENT_RULES match. A matching readable runtime directive falls through to strict decoding and fails closed. The three new .sh/.dat/.txt regressions exercise evaluate_pull_request, declaration fetch, current-head bytes, and final rejection.

The code and regression delta matches the described repair; I found no additional blocking defect within this reviewed scope. The newer base integration reduces the effective delta to five files (+60/-12), while the source/lock security carryover is already in base. This is not a general security certification of binary containers.

Independent execution from the clean current-head owner worktree, without edits:

GITHUB_ACTIONS=true PYTHONDONTWRITEBYTECODE=1 /private/tmp/codex-latelife-runner-admission-20260927/.venv/bin/python -m pytest tests/test_pingora_edge_policy.py -q -p no:cacheprovider
# 99 passed in 0.87s
git diff --check
# exit 0
git status --short
# empty

Current-head hosted checks, final integration state, and downstream late-life PR #269 policy execution remain separate evidence gates. The user has since explicitly authorized necessary bypass integration; this source review does not relabel queued checks as passed or constitute a GitHub APPROVED review.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Integration decision under the user's explicit authorization for necessary central CI fixes and bypass merge.

Target: reviewed head efe6073. The independent current-head COMMENT and executable policy suite (99 passed) are recorded above. Prior author receipts include runner/policy contracts; these are separate from hosted acceptance.

Current central main eb1bdc9 was fetched into the existing worktree without changing owner files or branch. git merge-tree --write-tree HEAD origin/main exits 0 with conflict-free candidate tree ba58597c3de6fcfbfb6865f2aff977dddf30ed00. The resulting policy blob is identical to the reviewed head. Effective integration remains the five-file declared-binary runtime guard, regression, and documentation delta. No security rule is disabled.

Bypass scope is integration of this reviewed source fix while current-head hosted checks remain queued and no formal APPROVED review exists. Neither condition is relabeled as passed. Use a match-head guard on merge; a changed head requires renewed review. The separate late-life PR #269 execution must select repaired trusted main and supply actual current-head acceptance evidence. This decision does not authorize manuscript submission, downstream release, or relabeling old wheel evidence.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correction and renewed exact-head decision: the earlier efe6073 merge attempt was rejected by GitHub's head-match guard because the owner concurrently advanced to 65d639a. No merge occurred on that attempt.

The new head incorporates already-merged central runner changes (#2435/#2436); the Pingora policy source and regressions are unchanged. Independent current-head execution:

GITHUB_ACTIONS=true PYTHONDONTWRITEBYTECODE=1 /private/tmp/codex-latelife-runner-admission-20260927/.venv/bin/python -m pytest tests/test_pingora_edge_policy.py tests/test_docs_only_pr_runner_admission.py tests/test_required_review_runner_image_contract.py -q -p no:cacheprovider
# 112 passed in 1.02s
git diff --check
# exit 0
git merge-tree --write-tree HEAD origin/main
# exit 0, ba58597c3de6fcfbfb6865f2aff977dddf30ed00

This is the same conflict-free integration tree verified for the predecessor against main eb1bdc9. It retains the newer main sidecar Python repair; a simple two-dot diff from main to the PR head is not the integration delta. The actual integration delta remains the five policy/related evidence files.

Runner group 6 read-back now includes ContextualWisdomLab/.github/.github/workflows/strix.yml@refs/heads/main with restricted_to_workflows=true and all earlier entries retained. No runner setting change was needed in this observation. Actual job allocation remains unverified.

The user's necessary-bypass authorization and the scoped decision above apply to this renewed head. Independent source verification is COMMENT evidence, not formal APPROVED or hosted acceptance. Match-head guard remains required.

@seonghobae
seonghobae merged commit 1804df3 into main Sep 27, 2026
5 of 19 checks passed
@seonghobae
seonghobae deleted the codex/pingora-declared-runtime-guard-20260926 branch September 27, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant