Skip to content

Enforce source and browser artifact provenance - #7

Merged
deku2026 merged 2 commits into
mainfrom
codex/wp00-03-provenance
Sep 19, 2026
Merged

deku2026 merged 2 commits into
mainfrom
codex/wp00-03-provenance

Conversation

@deku2026

@deku2026 deku2026 commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

Change

The existing static browser candidate lacked provenance for bundler/style helpers and embedded upstream code, and the production-only npm SBOM omitted emitted React-family packages. Bind the actual 303-module input graph, 136 emitted module identities and 18 generated/copied browser resources to immutable reviewed source/package evidence and an independent two-build output oracle. Preserve complete existing notices and add the required Vite, Rolldown companions, Tailwind, turbo-stream/devalue and original protobuf terms.

Add the closed reuse policy, complete source inventory, ten-field records, trusted-history immutability and deterministic source notice. Package exact active records, the profile and a source-bound closed-member receipt, and reject changed code/legal material, substituted provenance, altered SBOM edges and extra resources even after resealing. The build SBOM covers the full lock; the browser SBOM covers actual emitted origins. CI and hooks enforce these gates; documentation distinguishes browser viewports from native desktop/Android tests.

Scope: WP00.03 only, under Design 5322d698a1b650a52a5a139d986dd85b00b48581. The AGPL checker/test port is recorded from merged Cloud 3165c97cccd3ea1e0b230d66e22ab9c775ca19d8; no sibling-source dependency. Published Contracts remains 1.0.0-ci.25.1. No package upgrades, browser behavior or native client changes.

Validation

  • Windows and native Linux worktrees: pinned restore, formatting, lint, TypeScript, 22 existing unit/component/wire tests and 53 source/candidate/regression scenarios passed.
  • Actual candidate: all 18 Chromium/Firefox/WebKit tests passed; candidate verified afterward.
  • Source naming: 109 files, zero findings. IDE declarations, actionlint and npm audit passed; zero known vulnerabilities.
  • Full 15-commit secret scan passed. Four actual scanner probes prove the narrow public-checksum false-positive rules do not exempt other paths, changed digests or extra keys.
  • Full local change reviewed, including original licence scope and exact source-port adaptations. The initial CodeQL regex-backtracking finding is fixed with linear validation and bounded regression tests; used R1 records remain unchanged. 13 historical records (12 active) cover 14 reused source/legal files and the actual browser artifact.

Deployment

Required PR CI and separate CodeQL scanning remain pending. After all applicable checks are green, merge and verify main's actual Cloudflare deployment, public release/candidate byte equality, public legal resources and real browser delivery. No deployment configuration or secret changes. Branches and worktrees are retained.

Signed-off-by: sammiller <dekueon@gmail.com>
Comment thread tooling/provenance.ts Fixed
Signed-off-by: sammiller <dekueon@gmail.com>

@deku2026 deku2026 left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the complete final diff at 5a22b396cfd8166bbe830a692afd265ca3e35b05: every one of the 44 remote changed blobs matches the reviewed local head. Source/file and packaging provenance, exact original legal terms, upstream scope, independent browser byte oracle, actual graph, SBOM edges, trusted history, Git isolation, candidate failures and CI/deployment integration were checked.

Fixed the initial CodeQL js/redos finding by replacing the nested legal-name regex with delimiter splitting and linear segment checks. New regression tests include 50,000-character delimiter inputs under a subprocess deadline. Used R1 records are unchanged; R2 records the exact reviewed fix. Windows and Linux each passed 22 existing tests plus 53 provenance/regression cases. The actual candidate passed all 18 Windows browser scenarios and subsequent verification. No unresolved review finding.

All applicable latest-head CI, including the separate CodeQL scanning result, remains a merge prerequisite. Main publication, exact public artifact comparison and fresh real Cloudflare/browser-to-NativeAOT verification remain post-merge gates.

@deku2026
deku2026 merged commit 84939ca into main Sep 19, 2026
10 checks passed
@deku2026

Copy link
Copy Markdown
Contributor Author

Post-merge verification completed for 84939ca1fde0f0653d2cb4d8b8f9e5dd1057abb5. All applicable main CI checks passed, including the real Cloudflare deployment and live gate.

Downloaded the actual public web-0.1.0-ci.22.1 release: all 50 archive files match the CI candidate byte-for-byte, and public deployment.json matches retained CI evidence. Archive SHA-256: ad36fbf27582f9571e92b22772172bbb14dfab9eeecce102adcc28de3d6d3d6f. Consumed those exact published bytes in a clean worktree, without rebuilding a substitute; verify:candidate passed.

Fresh public HTTPS checks validated every served candidate resource, CSP/security/cache headers and genuine 404 responses. 15 live browser scenarios passed, followed by 3 additional real Chromium/Firefox/WebKit click scenarios through the Worker to Native AOT Cloud revision 3165c97cccd3ea1e0b230d66e22ab9c775ca19d8, each with zero automatic API requests, one binary gRPC-Web request after the click, no cookie/authorization, and the genuine Hello, ArcForges! response. No mocks or request interception. These are Web browser checks, not native client tests.

Primary checkout pulled to the merged commit; branches and worktrees retained. Local evidence: artifacts/evidence/post-merge-closure.json in the retained wp00-03-postmerge-verify worktree.

@deku2026
deku2026 deleted the codex/wp00-03-provenance branch September 19, 2026 13:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants