Skip to content

[Security] Version benchmark evidence identity against Unicode default-ignorable profile #323

Description

@seonghobae

Gap

Active benchmark PR #322 now fails closed on C0/C1 controls, U+2028/U+2029, and the exact Unicode Bidi_Control set for ControlledBenchmarkRunContext. That closes the reviewed line/paragraph and directional-rendering cases, but it is not yet a complete invisible-format profile.

Fresh source inspection of #322 exact a4c8ceaf67a075ef483334802aacfc54cf502068 shows validate_run_context_field admits any scalar that is not char::is_control, U+2028/U+2029, or one of the 12 bidi controls. Other Default_Ignorable_Code_Point values therefore remain admissible, including classes represented by zero-width/default-ignorable formatters and variation selectors. These benchmark-owned strings are later rendered in logs/reports and bound into evidence identity, so a byte-distinct value that is visually absent or presentation-dependent can create review/audit ambiguity.

This is narrower than general Unicode text policy. It applies only to OriginWeave-owned benchmark reproducibility identifiers. Browser-issued protocol addresses such as WebDriver BiDi browser.UserContext remain lossless external protocol identity and must not inherit this grammar.

Standards basis

Use the exact adopted Unicode profile, not a hand-maintained folklore list:

  • Unicode Standard Annex feat(evidence): add purpose-bound sensitive access receipts #31, Unicode Identifiers and Syntax, Unicode 18.0.0, Revision 45, 2026-09-01, §7.3 Default-Ignorable Exclusion Profile: exclude code points with Default_Ignorable_Code_Point from identifier Start/Continue; the annex notes that these characters often have no visible effect and can enable spoofing.
  • Unicode Technical Standard test(mv3): require repeated compatibility evidence #39, Unicode Security Mechanisms, Unicode 18.0.0, Revision 34, 2026-08-27: the General Security Profile classifies Identifier_Type=Default_Ignorable as Restricted. ZWJ/ZWNJ are explicitly Default_Ignorable/Restricted unless a documented tailored context is adopted.

References:

Ownership and compatibility boundary

RED → repair acceptance

  1. Add test-first hostile cases proving the current exact predecessor admits representative default-ignorables outside fix(core): reject bidi controls in benchmark evidence identity #322's existing set. At minimum exercise U+200B ZERO WIDTH SPACE, U+200C ZWNJ, U+200D ZWJ, U+2060 WORD JOINER, U+FEFF ZERO WIDTH NO-BREAK SPACE/BOM, and representative variation-selector behavior such as U+FE0F.
  2. Do not stop at those examples. The production decision must be tied to an exact Unicode-versioned property/profile so later Unicode property changes are reviewable rather than silently changing the accepted grammar.
  3. Decide and document whether the benchmark identifier grammar rejects every Default_Ignorable_Code_Point or uses an explicit tailored exception profile. If any exception is permitted, record the exact scalar/sequence context and security rationale. Emoji/join-control usability guidance in UAX feat(evidence): add purpose-bound sensitive access receipts #31 / UTS test(mv3): require repeated compatibility evidence #39 is not an implicit exception.
  4. Preserve visible Korean/Japanese/Chinese/Vietnamese/Spanish/German/French text and ordinary Arabic/Hebrew text that does not require an excluded formatting scalar. Do not widen this repair into ASCII-only admission.
  5. Keep byte identity semantics. Do not silently add NFC/NFKC/case folding/confusable skeletonization; those are separate compatibility/security decisions with their own migration requirements.
  6. Validation must run for both expected and observed contexts before equality can influence benchmark evidence.
  7. Public diagnostics/rustdoc, doctoring, TRACEABILITY, CHANGELOG, and the product-technical gap baseline must name the exact adopted Unicode version/profile and reversal/migration path.
  8. Owned production docstring/rustdoc, test and edge-case coverage remain complete; function/line/region/branch coverage remains 100%.
  9. Exact-head repository contracts, rustfmt, locked tests, strict Clippy, rustdoc/API docs, security/review workflows, and applicable real benchmark/browser evidence must execute. Skipped, queued-only, predecessor, status-only, or synthetic evidence is non-passing.

Non-goals

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions