Skip to content

[Governance] Enforce Security Notes for doctoring documents with external references #1203

Description

@seonghobae

Finding

docs/doctoring/sidebar-disabled-tooltips.md lost its reviewed Security Notes trust-boundary statement repeatedly through later regeneration/update commits while the cited MDN/W3C/Base UI references and runtime trust/network semantics remained unchanged. Tooltip #1193 preserves the product evidence, but branch-local .jules guidance is advisory and was itself deleted with the doctoring text.

The original repository gate only scanned docs/plans/*.md, so quickcheck could report Security Notes check passed after this doctoring security boundary disappeared.

Canonical repair

Draft #1204 is the repository-policy owner. Current exact head is b217087f7697dbc255cd31688ad5868fd489ee15 on protected develop@314ddeae7b775a4957594b599358c8255617eb2e.

The repair keeps the plan six-subsection contract unchanged and adds an explicit opt-in doctoring registry. Registered evidence must contain rendered ## Security Notes → ### Trust boundary substantive prose. Focused RED→GREEN coverage now rejects narrative text outside the section, missing/empty/short trust-boundary bodies, fenced code, indented code, and valid-looking evidence hidden inside multiline HTML comments. Unregistered doctoring citations remain outside the policy.

The latest hidden-comment bypass was encoded in RED b160bb354748dab4ef03308f64772d73aa71e930 and repaired in GREEN b217087f7697dbc255cd31688ad5868fd489ee15. Fresh exact-head CodeRabbit review found no actionable issue; this is review evidence, not formal approval.

Hosted evidence and prerequisite

Hosted ci run 34570305066, job 103171867553 executed exact b217087f.... Documentation, all 5 focused Security Notes tests, the production Security Notes gate, security-pattern, supply-chain, GitHub-bootstrap, Python docstring, and repository-pinned Ruff 0.15.5 lint all PASS.

The first causal CI failure is outside #1204 ownership: Ruff format reports only services/analysis-engine/tests/test_supply_chain_policy.py. That protected-base formatter debt is canonical #1176. #1204 therefore does not copy or rewrite the foreign file; #1176 must reach protected ancestry, then #1204 must be ordinarily reconciled and revalidated. SBOM on b217087f... is already SUCCESS; queued/pending workflows are not passing evidence.

Ownership boundary

This is repository governance/checking, not Tooltip product semantics. Keep #1193 limited to its five-file UI/doctoring ownership. Do not solve this by adding another Tooltip-local guard, copying #1176, weakening references, adding synthetic statuses, or bypassing review/protection.

Keep this issue open until #1176 prerequisite and #1204 machine-enforced repository gate reach protected develop with fresh terminal checks and qualifying acceptance. #1193 restoration alone remains evidence preservation, not root-fix completion.

Activity

  1. seonghobae commented on Sep 11, 2026

    @seonghobae
    CollaboratorAuthor

    Canonical repair is now Draft #1204, exact head 47595c4c7bae985068878ba2a816e9e978da6a73, based directly on protected develop@314ddeae7b775a4957594b599358c8255617eb2e. It owns only verify_security_notes.py, its focused regression suite, and one additive quickcheck invocation. The current policy requires an explicit level-two ## Security Notes section plus an in-section trust-boundary statement for registered doctoring evidence; narrative mentions outside that section fail closed. Keep #1203 open until this control reaches protected develop; #1193 restoration alone is still not root-fix completion.

  2. seonghobae commented on Sep 11, 2026

    @seonghobae
    CollaboratorAuthor

    #1204 has advanced by ordinary descendants to exact 58d76aab5dd614375758af3c143a79e8c78712e8 after repairing the predecessor review findings. Current machine contract is structural: registered doctoring evidence must contain ## Security Notes → ### Trust boundary with substantive statement body; narrative/heading-only/token-only/short-fragment fixtures are RED. The protected-base docs/plans extractor semantics are preserved. #1203 remains open until #1204 reaches protected develop.

  3. seonghobae commented on Sep 11, 2026

    @seonghobae
    CollaboratorAuthor

    Canonical root repair #1204 is now exact 21d8856f95e93baf93511d4162438760f2238981. The latest valid P1 is also repaired: doctoring evidence extraction removes fenced Markdown and 4-space/tab indented code before matching ## Security Notes / ### Trust boundary, with focused RED fixtures for both code-block bypasses. Keep #1203 open until this control reaches protected develop; #1193 document restoration remains dependent product evidence, not root-fix completion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions