Skip to content

Close proof, contract, release, and onboarding audit gaps - #78

Open
iperev wants to merge 1 commit into
mainfrom
fix/audit-remediation
Open

Close proof, contract, release, and onboarding audit gaps#78
iperev wants to merge 1 commit into
mainfrom
fix/audit-remediation

Conversation

@iperev

@iperev iperev commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Summary

Closes the confirmed July 2026 architecture, proof, security, release, package, documentation, onboarding, browser-UX, and test-oracle findings with owner-bound contracts and executable falsifiers.

  • Design: docs/implementation/audit-remediation-design.md
  • Implementation plan: docs/implementation/audit-remediation-plan.md
  • Those tracked documents own the correction ledger, rejected alternatives, invariants, decomposition inventory, rollback conditions, and non-claims.

Exact object

  • Base and single parent: 0df4c28bac9737f476f7dc66030363b8b40d5417
  • Candidate: b95e51cdc4341d47dd6f4912b8e05628e509a53e
  • Tree: 4752d14de2fd817404dc3ac32c77cf32d7393d23
  • Diff: 150 files, 39,197 insertions, 2,176 deletions
  • Binary diff SHA-256: beb2f8a662e894e66cb4173e6485d1f736a55896ded2cb2333aae29774fec91a

Principal repairs

  • immutable admission of caller-owned input before policy, routing, persistence, or reporting decisions;
  • closed CLI JSON, exit-code, package, workflow, and release contracts;
  • non-vacuous selector, condition, source, scanner, and provider-boundary oracles;
  • installed npm and Python onboarding chains with explicit invocation profiles;
  • state-complete browser UX, accessibility, concurrency, and retained-failure diagnostics;
  • exact release-change, migration, SBOM, artifact, and evidence-class closure;
  • measured large-file and reverse-decomposition review with retirement conditions for temporary audit documents;
  • Playwright 1.62 browser-proof toolchain synchronized across manifest, lock, package verifier, and verifier fixture without changing production or browser-test semantics;
  • C-117 test-oracle correction that proves setgid mutation materialization under both normal and foreign-group TMPDIR environments while leaving the production writer unchanged.

Local verification

The exact candidate passed the frozen full npm run check under the previously failing foreign-group TMPDIR, including:

  • browser static checks: 21/21;
  • browser runtime: 75/75 (25 Chromium, 25 Firefox, 25 WebKit);
  • all Go tests, format, vet, staticcheck, actionlint, and govulncheck (No vulnerabilities found);
  • npm tarball and Python wheel build/verification, self-hosting receipts, coverage, SBOM, manifest, and release closeout.

The Playwright 1.62 immutable epoch passed 30/30 separate Firefox processes and 750/750 tests with one worker, zero retries/skips/unexpected/flaky results, input digest sha256:a59f21235ca787068784ef4d2b8b382acb407bfdc32fbe74f2a3341673b08f53, historical test-ID digest sha256:f7b80cd6ea950cad6693a7b11020f746581d6eba4f2b7314700e4161448a554c, and records SHA-256 f1c8edba65b0ed82958660483784b74ec18439db5afbb56b886b7a25889ae24f. Two post-epoch full browser proofs passed 75/75, the composite gate passed 21+75, and the final frozen full-check watchdog exited with code zero and no signal or process-group errors.

C-117 passed the complete output-writer falsifier 100/100 under both default and retained foreign-group temp roots. Independent design, plan, causal-forensics, and regression reviews returned APPROVE with no unresolved confirmed P0-P3 finding. The final gpt-5.6-sol maximum-reasoning audit returned APPROVE, P0/P1/P2/P3 = 0/0/0/0, and 100/100 within the declared audit scope for this exact candidate.

Fresh provider attempt 1 for this literal SHA is fully green (CI 30302474547, CodeQL 30302474632, OSV 30302474558, semantic diff 30302474603); source, browser runtime, macOS, required aggregate, CodeQL, OSV, and semantic diff succeeded, while provider-upload jobs were policy-valid skips. The pull request remains unmerged and requires separate user authorization to merge.

Dependency pull requests admitted before this candidate

Non-claims

This pull request does not prove or perform registry publication, provider attestation, branch-protection configuration, rollout, deployment, production readiness, complete WCAG conformance, or branded Safari parity. Local stress and package evidence remains advisory and does not substitute for provider evidence. The pull request remains open and will not be merged without separate authorization.

@iperev
iperev force-pushed the fix/audit-remediation branch from bd3b429 to 1a681c4 Compare July 27, 2026 08:23
@iperev iperev changed the title Close audit remediation gaps across proof, release, and onboarding Close proof, contract, release, and onboarding audit gaps Jul 27, 2026
@iperev
iperev force-pushed the fix/audit-remediation branch 6 times, most recently from 26e44b7 to 7e29a8e Compare July 27, 2026 20:02
@iperev
iperev force-pushed the fix/audit-remediation branch from 7e29a8e to b95e51c Compare July 27, 2026 20:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant