fix(evidence): reject provenance locator control injection - #162
Draft
seonghobae wants to merge 14 commits into
Draft
fix(evidence): reject provenance locator control injection#162seonghobae wants to merge 14 commits into
seonghobae wants to merge 14 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Buyer/security gap
ProvenanceRecordretains a channel-specific source locator in credential-safe evidence. Without explicit presentation-safety validation, CR/LF, tab, NUL, ESC, DEL, bidirectional controls, zero-width formatters, soft hyphen, BOM and related invisible formatting characters could cross the evidence boundary and later create ambiguous or forged line-oriented audit/log presentation.Dependency and stack state
This Draft is stacked on exact current PR #157 head
eac07a7125e541c4912b195a7522c319cb2b8792, because #157 owns the adjacent publicEvidenceErrorstandard-error contract. Current exact #162 head isa2855ac3a300626a6ca796850cbb33a3da000d1c.The prerequisite moved from historical
ab90ff5013bf1dfa4002de17816cafe3b86f156ato the protected-main-aligned #157 head. This child was therefore restacked non-destructively with a two-parent commit. Fresh compare reports ahead 14 / behind 0, merge base exactlyeac07a7125e541c4912b195a7522c319cb2b8792, and exactly four intended changed files:CHANGELOG.md,crates/originweave-evidence/src/lib.rs,crates/originweave-evidence/tests/error_contract.rs, andcrates/originweave-evidence/tests/provenance_locator.rs.Keep Draft while #157 remains active. No prerequisite/predecessor check, review, approval, mergeability, synthetic-merge, skipped, cancelled, queued, absent, or status evidence transfers.
TDD and implementation lineage
Exact test-only head
dadc9fe0067a6fd77386f7643cf3b8f67601411eadded hostile CR/LF/tab/NUL/ESC/DEL locator cases while preserving printable channel-specific syntax containing spaces. The production line adds:EvidenceError::InvalidLocatorwith deterministic credential-freeDisplayand source-freestd::error::Errorbehavior;CHANGELOG.mdsecurity entry.Exact-current verification
On unchanged exact head
a2855ac3a300626a6ca796850cbb33a3da000d1cagainst exact baseeac07a7125e541c4912b195a7522c319cb2b8792:31978800285: success;95242235558: repository contracts, canonical formatting, locked workspace/all-target checks, full tests, strict Clippy and rustdoc success;95242235547: exact owned-production function/line/region/branch measurement and enforcement success;Only exact-current-head evidence is represented as current proof. Protected-main-only central/SAST/Security workflows absent for this stacked Draft are absent, not passing.
Scope boundary
This is a bounded evidence-presentation integrity rule, not a locator grammar. Printable spaces and channel-specific CSS/XPath/JSONPath-like syntax remain allowed. No source URL, digest, network redaction, browser observation, persistence, retention, workflow, secret, authorization, model call, or release behavior changes.
Protected-main
AGENTS.mdforbids this scheduled actor from merging or self-approving; passing automation is not integration authority.