Enforce source and browser artifact provenance - #7
Conversation
Signed-off-by: sammiller <dekueon@gmail.com>
Signed-off-by: sammiller <dekueon@gmail.com>
deku2026
left a comment
There was a problem hiding this comment.
Reviewed the complete final diff at 5a22b396cfd8166bbe830a692afd265ca3e35b05: every one of the 44 remote changed blobs matches the reviewed local head. Source/file and packaging provenance, exact original legal terms, upstream scope, independent browser byte oracle, actual graph, SBOM edges, trusted history, Git isolation, candidate failures and CI/deployment integration were checked.
Fixed the initial CodeQL js/redos finding by replacing the nested legal-name regex with delimiter splitting and linear segment checks. New regression tests include 50,000-character delimiter inputs under a subprocess deadline. Used R1 records are unchanged; R2 records the exact reviewed fix. Windows and Linux each passed 22 existing tests plus 53 provenance/regression cases. The actual candidate passed all 18 Windows browser scenarios and subsequent verification. No unresolved review finding.
All applicable latest-head CI, including the separate CodeQL scanning result, remains a merge prerequisite. Main publication, exact public artifact comparison and fresh real Cloudflare/browser-to-NativeAOT verification remain post-merge gates.
|
Post-merge verification completed for Downloaded the actual public Fresh public HTTPS checks validated every served candidate resource, CSP/security/cache headers and genuine 404 responses. 15 live browser scenarios passed, followed by 3 additional real Chromium/Firefox/WebKit click scenarios through the Worker to Native AOT Cloud revision Primary checkout pulled to the merged commit; branches and worktrees retained. Local evidence: |
Change
The existing static browser candidate lacked provenance for bundler/style helpers and embedded upstream code, and the production-only npm SBOM omitted emitted React-family packages. Bind the actual 303-module input graph, 136 emitted module identities and 18 generated/copied browser resources to immutable reviewed source/package evidence and an independent two-build output oracle. Preserve complete existing notices and add the required Vite, Rolldown companions, Tailwind, turbo-stream/devalue and original protobuf terms.
Add the closed reuse policy, complete source inventory, ten-field records, trusted-history immutability and deterministic source notice. Package exact active records, the profile and a source-bound closed-member receipt, and reject changed code/legal material, substituted provenance, altered SBOM edges and extra resources even after resealing. The build SBOM covers the full lock; the browser SBOM covers actual emitted origins. CI and hooks enforce these gates; documentation distinguishes browser viewports from native desktop/Android tests.
Scope: WP00.03 only, under Design
5322d698a1b650a52a5a139d986dd85b00b48581. The AGPL checker/test port is recorded from merged Cloud3165c97cccd3ea1e0b230d66e22ab9c775ca19d8; no sibling-source dependency. Published Contracts remains1.0.0-ci.25.1. No package upgrades, browser behavior or native client changes.Validation
Deployment
Required PR CI and separate CodeQL scanning remain pending. After all applicable checks are green, merge and verify main's actual Cloudflare deployment, public release/candidate byte equality, public legal resources and real browser delivery. No deployment configuration or secret changes. Branches and worktrees are retained.