fix: reject runtime directives in declared binary artifacts - #2386
Conversation
|
Warning Review limit reachedNext included review available in 33 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Exact-head repair evidence — 2026-09-26Current head: The source repair introduced a third admission invariant for declared artifacts with unrecognized suffixes: no patch, invalid UTF-8, and no prohibited runtime pattern in replacement-decoded text. The module contract and policy document previously still described the old two-condition rule. This ordinary child synchronizes those authoritative docs, CHANGELOG, and Topology and scope:
Fresh exact-tree verification:
Fresh exact-head hosted evidence:
There is no current-head independent approval. Therefore this is repair evidence, not merge evidence; no self-approval, manual rerun, protection bypass, auto-merge, Force Push, or stale-evidence promotion was performed. |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for 6a32843cc698a301f968dc4a3edec2e2d380dc0f (COMMENT, not approval).
The source repair closes the reported admission path at the production boundary. A declared artifact prefix is still loaded only from the base ref; _is_binary_documentation_asset still rejects runtime-shaped paths before binary evidence is considered; and unrecognized-format bytes now require all three conditions before admission: no GitHub patch, invalid UTF-8, and no CONTENT_RULES match in bounded replacement-decoded content. When readable Nginx content is present, evidence confirmation returns false and the normal UTF-8 loader fails closed. The parametrized .sh/.dat/.txt regression exercises evaluate_pull_request, the base declaration fetch, final-head content fetch, and the rejection path rather than only testing the helper.
The policy document, module contract, changelog, and CONTROL-PINGORA-DECLARED-BINARY-RUNTIME-01 record the same boundary. I found no additional source-backed defect in the five-file delta. Protected main@e6334e22… comparison is ahead 2 / behind 0 and review threads are zero.
Current exact-head Runtime Quality 36236245589, CodeQL 36236245614, SAST 36236245579, Security 36236245656, and Python Security 36236245577 are all queued, and no qualifying independent APPROVED review exists. This review does not transfer local author evidence, claim GREEN, or authorize merge/auto-merge/bypass/rerun.
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for 6a32843cc698a301f968dc4a3edec2e2d380dc0f (COMMENT, not approval).
I traced the five-path delta through the production admission boundary. The base-ref-only declaration remains unchanged; runtime-named paths still bypass binary admission; recognized PNG/HWPX/PDF evidence keeps its existing structural path; and an unrecognized declared artifact now needs all three conditions before admission: no GitHub patch, invalid UTF-8, and no CONTENT_RULES match in replacement-decoded bytes. A matching readable runtime directive falls through to the existing strict decode and fails closed. The production-bound regression exercises .sh, .dat, and .txt names. I found no additional source-backed defect in this exact delta.
Protected main@e6334e229581a918e2f22de18733b76fa65d7e71 is 2 commits behind this head with 0 commits in the other direction; the PR is mergeable and has no unresolved review thread. Runtime Quality 36236245589, CodeQL 36236245614, SAST 36236245579, Security 36236245656, and Python Security 36236245577 are still queued, and no qualifying independent APPROVED review exists. This review is exact-head review evidence only, not merge authority.
|
Current-head gate record for
Do not merge until the required current-head checks finish successfully and protected merge eligibility is rechecked. Next status check: 11:45Z or the first terminal check event, whichever comes first. The downstream late-life-anxiety-reanalysis #269 declaration remains blocked until this guard lands. |
|
11:45Z exact-head follow-up: #2386 remains No retry or merge is justified by this state. Next check: 12:30Z or the first terminal job event, whichever comes first. #269 must remain blocked until this PR passes its protected gate and merges. |
|
14:25Z 현재 head 다만 필수 CodeQL compatibility (actions/python), Noema, coverage-evidence, OpenCode, Trivy, Scorecard를 포함한 작업 11개가 아직 QUEUED입니다. Noema job은 14:23Z jobs API에서도 runner 미배정( 독립 비작성자 기술 검수는 이 head에서 차단 결함을 찾지 못했고 정책 회귀 87건을 통과했습니다. GitHub 제출 리뷰는 없고 리뷰 스레드는 0개입니다. 현재 |
|
Current-head combined-policy preflight (2026-09-27 KST): the clean merge tree of #2386 Using the combined tree's policy checker and GitHub evidence (without executing PR code), both current PR heads passed with exit 0: late-life-anxiety-reanalysis#269 head This is local preflight evidence only. The hosted jobs and required reviews remain separate. At this observation #2386 Noema, #2396 admission, and #2157 package jobs were still |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head security repair review for 7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6 (COMMENT, not approval).
RCA is bound to Python Security run 36236245577, job 108402877544: the hash-locked Strix runtime selected AnyIO 4.14.0, and pip-audit identified CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349, each fixed in 4.14.2. The generated lock lacked an explicit source constraint, so the vulnerable transitive selection was reproducible but not owner-governed.
- RED
761be5b0…: #2385's source↔lock contract was integrated before production changes and failed exactly becauserequirements-strix-ci.txtomittedanyio==4.14.2(1 failed, 1 passed). - GREEN
c59ef9ae…→a895dc5a…: adds that one source constraint and adopts #2385's generated lock blobeb83beda177c9d2e4ca9b7e2888a1ccb55a123ac. Against the vulnerable lock, only lines 143–145 differ: version plus the two published artifact hashes. - Exact remote three-file verification: focused contract 2/2 passed. The Gap successor
7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6preserves the previous baseline as an exact prefix, adds one Proposed section (59→60), and records the hosted failure plus RED/GREEN lineage. - Effective diff from reviewed predecessor
6a32843c…: ahead 4 / behind 0, four paths, +28/-3. The original Pingora runtime-guard behavior is untouched.
Fresh exact-head Python Security, SAST, Security Scan, CodeQL, and Runtime Quality are queued/pending. This review claims focused GREEN only, not hosted acceptance or merge authority.
|
Current-head correction to my earlier combined preflight: #2386 has advanced to |
|
2026-09-27 02:20 UTC, 현재 head 현재 head의 독립 비작성자 읽기 전용 기술 검토는 Pingora 선언 경로의 잘못된 UTF-8 검사 가드가 유지됐고, AnyIO 4.14.2 핀·잠금 해시·설치 경로에서 새 차단 결함을 찾지 못했습니다. 정확한 트리의 관련 테스트는 로컬에서 89건 통과했습니다. 이 검토는 GitHub 제출 승인이나 hosted 검사 성공을 뜻하지 않습니다. 현재 리뷰 스레드 0개, 현재 head의 GitHub 리뷰는 작성자 COMMENTED 1개이며 APPROVED는 0개입니다. 현재 head의 검사 16개는 QUEUED이고 |
|
Exact-head blocker re-audit: 현재 다음 실질 blocker가 있어 Draft/Proposed로 교정합니다:
Queued/pending review·Checks 또는 승인 대기만으로 Draft 전환하지 않았습니다. Current head에서 blocker가 해소되면 Ready review admission을 복구합니다. |
|
Exact-head failure repaired by ordinary non-force fast-forward.
The PR remains Draft. The predecessor failure was not rerun because the source change generated fresh exact-head workflows; queued checks are not passing evidence. |
seonghobae
left a comment
There was a problem hiding this comment.
Independent source review at exact head efe6073, compared with base fd2a03e. COMMENT, not formal approval or hosted acceptance.
I inspected the full five-file delta and the current production call path: base-only artifact-prefix declaration → binary path prefilter → authenticated final-head raw content → binary confirmation → strict content scan on rejection. Runtime-shaped paths still cannot enter binary admission. Recognized PNG/HWPX/PDF evidence retains its existing handling. For unrecognized formats, missing patch and invalid UTF-8 are no longer sufficient: replacement-decoded content must contain no CONTENT_RULES match. A matching readable runtime directive falls through to strict decoding and fails closed. The three new .sh/.dat/.txt regressions exercise evaluate_pull_request, declaration fetch, current-head bytes, and final rejection.
The code and regression delta matches the described repair; I found no additional blocking defect within this reviewed scope. The newer base integration reduces the effective delta to five files (+60/-12), while the source/lock security carryover is already in base. This is not a general security certification of binary containers.
Independent execution from the clean current-head owner worktree, without edits:
GITHUB_ACTIONS=true PYTHONDONTWRITEBYTECODE=1 /private/tmp/codex-latelife-runner-admission-20260927/.venv/bin/python -m pytest tests/test_pingora_edge_policy.py -q -p no:cacheprovider
# 99 passed in 0.87s
git diff --check
# exit 0
git status --short
# empty
Current-head hosted checks, final integration state, and downstream late-life PR #269 policy execution remain separate evidence gates. The user has since explicitly authorized necessary bypass integration; this source review does not relabel queued checks as passed or constitute a GitHub APPROVED review.
…nner-base-20260927
|
Integration decision under the user's explicit authorization for necessary central CI fixes and bypass merge. Target: reviewed head efe6073. The independent current-head COMMENT and executable policy suite (99 passed) are recorded above. Prior author receipts include runner/policy contracts; these are separate from hosted acceptance. Current central main eb1bdc9 was fetched into the existing worktree without changing owner files or branch. Bypass scope is integration of this reviewed source fix while current-head hosted checks remain queued and no formal APPROVED review exists. Neither condition is relabeled as passed. Use a match-head guard on merge; a changed head requires renewed review. The separate late-life PR #269 execution must select repaired trusted main and supply actual current-head acceptance evidence. This decision does not authorize manuscript submission, downstream release, or relabeling old wheel evidence. |
seonghobae
left a comment
There was a problem hiding this comment.
Correction and renewed exact-head decision: the earlier efe6073 merge attempt was rejected by GitHub's head-match guard because the owner concurrently advanced to 65d639a. No merge occurred on that attempt.
The new head incorporates already-merged central runner changes (#2435/#2436); the Pingora policy source and regressions are unchanged. Independent current-head execution:
GITHUB_ACTIONS=true PYTHONDONTWRITEBYTECODE=1 /private/tmp/codex-latelife-runner-admission-20260927/.venv/bin/python -m pytest tests/test_pingora_edge_policy.py tests/test_docs_only_pr_runner_admission.py tests/test_required_review_runner_image_contract.py -q -p no:cacheprovider
# 112 passed in 1.02s
git diff --check
# exit 0
git merge-tree --write-tree HEAD origin/main
# exit 0, ba58597c3de6fcfbfb6865f2aff977dddf30ed00
This is the same conflict-free integration tree verified for the predecessor against main eb1bdc9. It retains the newer main sidecar Python repair; a simple two-dot diff from main to the PR head is not the integration delta. The actual integration delta remains the five policy/related evidence files.
Runner group 6 read-back now includes ContextualWisdomLab/.github/.github/workflows/strix.yml@refs/heads/main with restricted_to_workflows=true and all earlier entries retained. No runner setting change was needed in this observation. Actual job allocation remains unverified.
The user's necessary-bypass authorization and the scoped decision above apply to this renewed head. Independent source verification is COMMENT evidence, not formal APPROVED or hosted acceptance. Match-head guard remains required.
Problem
A base-branch artifact-path declaration can cause a changed file with no GitHub diff patch and any non-UTF-8 byte to be admitted as a binary research artifact. With
docs/delivery_interim_20260920/declared, adeploy.shcontainingnginx -c /etc/nginx/nginx.confand one invalid byte was admitted with zero violations. This matters before late-life-anxiety-reanalysis #269 merges its broad documentation prefixes.Change
For declared artifacts without recognized format magic, inspect the readable portions of the fetched bytes for the existing prohibited runtime patterns. A match falls through to the policy's fail-closed invalid-UTF-8 handling. Genuine binary research artifacts without those patterns retain the existing admission path.
Verification
.sh,.dat, and.txtnames, then passed after it.python3 -m pytest tests/test_pingora_edge_policy.py -q: 87 passed.GITHUB_ACTIONS=true python3 -m pytest tests/test_pingora_edge_policy.py -q: 87 passed.git diff --check: clean.Dependency: merge this central policy fix before accepting late-life-anxiety-reanalysis #269's artifact-path declaration. Required checks and independent review remain necessary on the current PR head.
Current exact-head evidence
6a32843cc698a301f968dc4a3edec2e2d380dc0f; tree:2ebae343f83d3333bee9e493e36951dd0595d13b.main@e6334e229581a918e2f22de18733b76fa65d7e71: 2 ahead / 0 behind; mergeable; five effective paths.CONTROL-PINGORA-DECLARED-BINARY-RUNTIME-01now describe the same three-condition admission invariant as production code.GITHUB_ACTIONS=true, Python compile andgit diff --checkall pass.2026-09-27 Python Security repair
108402877544, found AnyIO4.14.0affected byCVE-2026-63374,CVE-2026-64847, andCVE-2026-63349; fixed version is4.14.2.761be5b0f63422505b37e28a367a4c5170f302ba: the carried source↔lock contract failed1 failed, 1 passedbecause the explicit source constraint was absent.c59ef9aed32ab4c5138c2b7770ddcc10d7ee8393→a895dc5aec775076c3819679eadf0b50a563aa2e: source input now pinsanyio==4.14.2; the lock is exact repair(foundation): unblock coverage and CodeQL control plane #2385 generated blobeb83beda177c9d2e4ca9b7e2888a1ccb55a123ac, differing from the vulnerable lock only at version line 143 and hash lines 144–145. Exact remote blobs pass2 passed.7d8a6bc30cc84ac1789baa913dc2a566e7eba4f6appends the Proposed carryover record while preserving the previous baseline as a prefix (59→60 level-two sections).Fresh exact-head Python Security/pip-audit, remaining required Checks, and independent approval remain required before merge.