fix(reputation): bind business authorization evidence - #176
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh exact-head review found a fail-closed scope gap in the new business-authorization binding. Repair acceptance: add hostile tests proving a bound allow fails closed if either decision |
|
Fresh review on exact The normative #173 design says the allow/deny table is protect-mode behavior and that monitor mode must emit a separate This is Wardnet-owned decision/policy provenance, not EgressWeave transport authority. TDD repair acceptance:
Do not claim RED execution until a current-head test actually runs. Current runner/control-plane queues remain separately tracked in |
|
TDD state for the policy-mode finding: test-only RED source is now exact Fresh exact-head execution has materialized but RED has not executed yet: CI |
Review-derived security defect
wardnet.reputation.v1originally allowedassessment=unknown,action=allow,reason=business_authorizationwithout sufficient authorization identity/revision, exact subject scope, approval/ticket, validity/provenance, policy identity/revision, canonicalization identity/version or protect-mode binding. This Draft child owns only that Wardnet reputation-policy/evidence repair. It does not parse or authorize URLs, resolve DNS, follow redirects, choose proxies, establish TLS, perform transport, or duplicate EgressWeave authority.Retained causal lineage
The branch preserves the executed business-authorization REDs and their minimal fixes, including exact-scope binding, required
policy_mode=protect, the inherited 32-reference decision cap, and the parent's 8 KiBObservableUrlinvariant. Ordinary integration CI later exposed three stale test fixtures that deserialized the already-required v1 schema before reaching their intended security assertions. Those failures were repaired test-only by adding the missingpolicy_modeto the affected shared/canonicalization/policy-scope fixtures; production validation was not weakened.The latest movement from
0a79c8af6943ec7c5263b83be0b2d6a3b2e19b72to current exact5d7166da2034d450f37ab69d37fbbb9d1301e287adds only the remainingbusiness_authorization_policy_scope.rsfixture line. Concurrent parent/child movement is therefore adopted as valid causal repair, not treated as a race.Current exact state — 2026-09-07 KST
PR #176 remains open/Draft and mergeable on exact parent
#175@9de0ea568096a18b5c1fc9bc9fce097e08584d44; exact current head is5d7166da2034d450f37ab69d37fbbb9d1301e287.Current exact-head repository lanes are terminal GREEN:
34125618252— success;34125618251— success.These results prove this Draft child against its current parent only. Root #175 is still non-integrated and has a required delegated-CodeQL failure owned by
.github#1929; Draft guards also mean #176 has not materialized the complete eventual merge-gate set. Keep Draft. After #175 reaches protected truth, non-force adopt fresh protected ancestry and reacquire every then-live repository/security/CodeQL/review/thread/governance gate on one unchanged exact child head.Dependent #178 has already non-force adopted this exact parent and must retain only its decision-freshness delta. Do not duplicate the fixture repairs in the child.
EgressWeave remains canonical for executable URL/address/DNS/peer/redirect/proxy/TLS/resource authorization.
context-graph-contractsandenterprise-architecture-coreremain read-only foreign-owner dependencies. No self/model approval, routine administrator bypass, force push/destructive rebase, gate weakening, mutable foreign dependency, source copy, cross-service SQL or predecessor-evidence transfer.