-
Notifications
You must be signed in to change notification settings - Fork 0
fix(reliability): redact hostile Hangul option access failures #366
Copy link
Copy link
Open
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineageDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Description
Activity
Metadata
Metadata
Assignees
Labels
area: authAuthentication, authorization, identity, or tenant isolationAuthentication, authorization, identity, or tenant isolationarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineageDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingSomething isn't workingpriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmentOpen issue has an organization taxonomy assignmenttype: bugDefect or incorrect behaviorDefect or incorrect behavior
Current authoritative state
This hostile-option-access defect is repaired on the existing canonical single-writer Draft PR #320 / branch
feat/hwp-hwpx-authoring. Protected shipped truth remainsmain@3b38ead2d00f44eb578d0689087b9293b3dabe1e; current exact Draft head is5ee6e4d0c3b2a804f39a8d186a8bdd7c2a38a782.Current
src/hangul/index.tsuses module-ownedreadHangulOption()for the host-suppliedengine, importmaxSourceBytes, exportmaxOutputBytes, and exportformatreads before those values cross into engine/resource authority. If an accessor or Proxy trap throws, Inkspan catches the unknown thrown value without reading, stringifying, coercing, enumerating, or prototype-inspecting it and raises the stable payload-redactedHangulDocumentError('INVALID_CONFIGURATION', 'Hangul options are invalid.').Numeric byte-limit validation and its existing messages remain authoritative after a successful read; omitted/default HWPX selection and explicit HWP/HWPX semantics are unchanged. Cleanup containment (#365), finite structural-metadata ceilings (#367), supported-content behavior, standalone/no-network operation, and host-owned engine authority remain preserved.
This is Inkspan-owned local argument/error-containment scope. Hosts still own the actual HWP/HWPX engine, filesystem/network/WASM initialization, credentials, persistence, publication, and telemetry.
Test-first lineage
907b088a77a6c0324b2907cba13235da8d508e58proved hostile getters formaxSourceBytes,maxOutputBytes, andformatcould leak private thrown values before engine authority.0786240d8e30e66effd8326fad3d5d67af427f4dadded module-ownedreadHangulOption()containment with stableINVALID_CONFIGURATIONsemantics.5ee6e4d0c3b2a804f39a8d186a8bdd7c2a38a782carries that repair together with later feat(hangul): import, edit, and export HWP/HWPX #320 engine-boundary and documentation hardening; predecessor workflow/review evidence does not transfer after head movement.Exact-current-head evidence
For unchanged exact head
5ee6e4d0c3b2a804f39a8d186a8bdd7c2a38a782against protectedmain@3b38ead2d00f44eb578d0689087b9293b3dabe1eat the latest fresh refetch:32395091285: completed / success; build/test96510085342checked out the exact head and completed 161 files / 898 tests at 100% statement/branch/function/line coverage, with package/build verification;32395091192: completed / success;32395091052: completed / success;All observed repository-owned exact-head workflows are terminal success. The absent qualifying approval remains non-passing; repository technical success does not replace separately applicable central or review governance.
Integration boundary
The behavioral defect is repaired on active Draft #320 but is not protected-main shipped behavior. Keep this issue open until #320 integrates under live governance. Keep #320 Draft/unmerged while #118 owns the frozen
v0.6.0publication/provenance boundary. Any #320 head/base/ruleset movement invalidates corresponding exact-head evidence and requires fresh revalidation. Do not create a competing Hangul writer, transfer predecessor evidence, self-approve, weaken gates, move protected main, or fabricate release identity.