Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,10 @@ activation custody, and availability.
## 2026-08-02 Reconciliation

XINT-002-01 already registered the one contributor action and removed the six
obsolete upload-session actions. AUTH-04B has an approved corrected contract,
but its implementation/activation has not merged; guide binding/read remain
planned. No ART status may describe that planning merge as runtime activation.
obsolete upload-session actions. AUTH-04B implementation merged in PR #245;
fixed-service guide binding/read are active, and ART-03C completed the verified
guide-pipeline cutover. Submission actions remain governed by the later split
activation order below.

The remaining AUTH order requires one correction before submission work can go
live: split XINT-06 into `06A` (pre-submit materializer only, after hidden
Expand All @@ -25,7 +26,8 @@ from activating while its mandatory fixed materializer still denies.

## Guide Source Sequence

1. Existing guide-source actions remain planned and unavailable.
1. Guide-source ingest and fixed-service binding/read are active through their
merged AUTH chunks; contributor submission actions remain unavailable.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
2. ART-03A implements hidden `artifact.guide_source.ingest` behavior and its
exact resource/guard/surface manifest.
3. AUTH activates only that exact action through a separately reviewed AUTH
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,8 +24,8 @@ they cross multiple L1 boundaries.
|---|---|---:|---|
| `WS-ART-001-PLAN3` | Reconcile the complete remaining v0.1 custody chain and AUTH/REV/CON handoffs. | L1 | Planning only; proposed |
| `WS-ART-001-03C` | Clean-cut legacy guide identity/excerpts and make the verified same-generation pipeline live. | L1 | Merged PR #249 |
| `WS-ART-001-04A1` | Remove legacy multi-step contributor intake reachability and schema without adding the replacement route. | L1 | Implemented; internal review passed; external PR gates pending |
| `WS-ART-001-04A2` | Add bounded one-outer-ZIP intake and archive-safety inspection in private scratch. | L1 | Proposed after 04A1 |
| `WS-ART-001-04A1` | Remove legacy multi-step contributor intake reachability and schema without adding the replacement route. | L1 | Merged PR #264 |
| `WS-ART-001-04A2` | Add bounded one-outer-ZIP intake and archive-safety inspection in private scratch. | L1 | Implemented; internal review passed; external PR gates pending |
| `WS-ART-001-04A3` | Add canonical semantic manifest, executable normalization, and unchanged-work gate. | L1 | Proposed after 04A2 |
| `WS-ART-001-04B` | Run non-bypassable platform and locked-guide prechecks against that exact scratch tree and persist bounded evidence. | L1 | Proposed after 04A3 |
| `WS-ART-001-04C1` | Reauthorize and atomically persist capacity plus durable put intent, then write the checked ZIP once. | L1 | Proposed after XINT-06A |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,9 @@ ART-03A and every split ART-03B chunk through 03B4 are merged. The complete
verified guide binding, materialization, classification, extraction, and hidden
same-generation sufficiency continuation exist on `main`.

AUTH-04B production implementation merged in PR #245 at `6babf81b`. The fixed
guide binding and guide-reader services are live, and
AUTH-04A activated `artifact.guide_source.ingest`. AUTH-04B production
implementation merged in PR #245 at `6babf81b`. The fixed guide binding and
guide-reader services are live, and
`artifact.guide_source.binding.create` plus `artifact.guide_source.read` are
active under `XINT_002_04B`. ART-03C's dependency is satisfied.

Expand Down Expand Up @@ -66,18 +67,19 @@ normalizes regular-file executable intent into the semantic manifest; and it
requires fresh AUTH prepared capabilities at durable put intent and atomic
Submission/binding consumption.

## Current Planning Correction
## Completed Guide Pipeline And Current Submission Work

ART-03A and AUTH `WS-XINT-002-04A` are merged. Before ART-03B implementation,
the guide-content boundary is being corrected explicitly: verified binding,
ART-03A and AUTH `WS-XINT-002-04A` are merged. The guide-content boundary was
implemented explicitly as verified binding,
full-read materialization, format classification, isolated extraction,
canonical extraction provenance, incremental complex-format support, and
same-generation sufficiency continuation are separate PR-sized contracts.
`WS-ART-001-03B4` is merged: its reviewed contract fixes the artifact-owned
material port, all-items-required semantics, deterministic 12 MiB assembly,
normalized report-to-extraction provenance, and the hidden pre-submit
identifier/generation continuation. AUTH binding/read production activation
remains unmerged; ART-03C remains blocked on that implementation.
merged through PR #245, and ART-03C's verified-pipeline cutover subsequently
merged.

After 03B3A merged, the original complex-format chunk was found too broad for
one dependency and parser-security review. It is replaced by 03B3B1 dependency
Expand All @@ -103,12 +105,14 @@ omission facts on the shared OOXML boundary. 03B3B3C merged through PR #235 and
adds bounded PPTX slide/notes extraction. 03B3B3D merged through PR #238 and
adds bounded XLSX cell extraction. 03B3B4 merged through PR #239 and adds only
bounded PNG/JPEG/WebP structural metadata. 03B4 merged through PR #240 and adds
the hidden same-generation sufficiency continuation. AUTH binding/read actions
remain planned.

AUTH `WS-XINT-002-04B` follows the complete hidden split-03B series and
activates only fixed-service binding and guide read. ART-03C then removes the
legacy identity/excerpt path and makes the verified pipeline authoritative.
the hidden same-generation sufficiency continuation. ART-03C and ART-04A1 are
merged. ART-04A1 merged through PR #264. ART-04A2 is implemented on its
bounded branch with internal L1 reviews passed; hosted PR gates and human merge
remain pending.

AUTH `WS-XINT-002-04B` activated only fixed-service binding and guide read.
ART-03C removed the legacy identity/excerpt path and made the verified pipeline
authoritative.

## Gate

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Chunk Contract: WS-ART-001-04A2 — Bounded Outer-ZIP Safety

Parent initiative: `WS-ART-001` | Risk: L1 | Status: Proposed after 04A1
Parent initiative: `WS-ART-001` | Risk: L1 | Status: Implemented; internal review passed

## Goal

Expand All @@ -9,13 +9,57 @@ complete file/directory tree without provider I/O or a public route.

## Allowed Files

ART scratch intake/archive safety capability, bounded configuration use,
adversarial ZIP tests/fuzz fixtures, docs, and scoped coverage evidence.
- `backend/app/modules/artifacts/submission_archive.py`: dedicated contributor
outer-ZIP inspector and closed process-local result/failure types;
- `backend/app/modules/artifacts/zip_safety.py`: neutral bounded ZIP-directory
facts shared by guide and submission consumers;
- `backend/app/modules/artifacts/guide_formats.py`: import the moved neutral
`zip_directory_facts()` probe only, without changing guide classification;
- `backend/app/core/config.py` and
`backend/app/adapters/artifacts/__init__.py`: conservative ZIP-safety settings
and composition only;
- `backend/tests/test_submission_archive.py`, `backend/tests/test_config.py`,
and narrowly necessary
additions to `backend/tests/test_artifact_preparation.py`: adversarial
inspection, fixed configuration, and scratch cleanup proof;
- `backend/scripts/run_test_lanes.py` and
`backend/tests/test_ci_test_lanes.py`: exact semantic-lane custody for the
two new focused modules only;
- this contract, the PLAN3 focused-test mapping, the ART status/chunk map,
artifact-storage specification, and
scoped review/coverage evidence; `AUTH_HANDOFF.md` only for current merged
dependency wording.

## Not Allowed Changes

Semantic manifest/change comparison, project checker, durable admission,
provider I/O, nested archive extraction, larger limits, or AUTH activation.
Do not reuse guide-format archive recursion: contributor backslashes are
rejected before normalization and nested ZIP members remain opaque regular
files. Do not add multipart/request parsing in this hidden chunk.

## Internal Handoff And Limits

04A2 must use the existing `PreparedArtifact.inspect(...)` /
`PreparedArtifactInspector` seam. It returns one immutable, non-durable
`SubmissionArchiveInspectionResult` containing only bounded
`SubmissionArchiveEntry` structural facts (normalized POSIX path, closed entry
type, actual byte count, and bounded archive totals) plus closed redacted
failure codes. It must never expose or retain `ZipInfo`, a reader, scratch path
or handle, raw bytes, provider facts, prepared authorization, semantic hashes,
file hashes, executable normalization, or durable identity.

Neutral bounded EOCD/ZIP64/multi-disk directory probing already present as
`zip_directory_facts()` must be reused or moved to a neutral ART module rather
than copied. The guide detector itself must not be reused because its recursive
nested-archive and backslash-normalization semantics are intentionally
different.

The implementation owns conservative startup-fixed limits for maximum entry
count, normalized path bytes/depth, central-directory bytes, actual bytes per
entry, actual total expanded bytes, compression ratio, and inspection time.
Defaults may not raise the existing 512 MiB source ceiling. Limit configuration
is validated once at startup and is identical for processes sharing scratch.

## Acceptance Criteria

Expand All @@ -24,10 +68,59 @@ symlink/special/encrypted/malformed entries, duplicates/NFC/case-fold
collisions, bombs, and every configured limit breach; nested ZIPs stay opaque;
all outcomes clean scratch and disclose no path/handle.

Path validation also rejects empty, `.` and `..` segments, drive/root forms,
ambiguous trailing dot/space segments, file/directory normalized collisions,
and ancestry conflicts such as a regular file `a` plus `a/b`. Implicit
directories are derived deterministically without becoming duplicate entries.

Every regular-file member is fully bounded-read during inspection. Actual reads,
not central-directory declarations, enforce per-entry/aggregate byte and ratio
limits and verify CRC, truncation, local-header consistency, and malformed data
descriptors. Multi-disk/spanned archives and unsupported ZIP64 structures are
rejected; supported bounded ZIP64 metadata must not weaken any limit. ZIP
metadata is never used to create filesystem entries in this chunk.

Cancellation, timeout, malformed input, and every rejection must close the
archive reader and release the enclosing scratch preparation. Stable internal
failure codes distinguish invalid outer ZIP, unsafe path/type, collision,
encryption, malformed/truncated content, bomb/limit breach, and timeout without
including submitted paths or parser/provider details.
v0.1 accepts stored and raw-DEFLATE members only; other compression methods
fail closed and are not silently delegated to provider or checker code.

## Verification Commands

Focused archive/scratch/fuzz tests, Ruff, stale scans, hosted gates, 90% owned
subsystem and 78% repository coverage.
```bash
(cd backend && .venv/bin/python -m ruff check app tests scripts)
(cd backend && .venv/bin/python -m pytest -q \
tests/test_submission_archive.py tests/test_config.py tests/test_guide_formats.py)
(cd backend && .venv/bin/python -m pytest -q tests/test_ci_test_lanes.py)
(cd backend && .venv/bin/python -m pytest \
tests/test_submission_archive.py \
--cov=app.modules.artifacts.submission_archive --cov-report=term-missing \
--cov-fail-under=90)
(cd backend && .venv/bin/python -m pytest \
tests/test_submission_archive.py tests/test_guide_formats.py \
--cov=app.modules.artifacts.zip_safety --cov-report=term-missing \
--cov-fail-under=90)
python3 scripts/check_stale_artifact_contracts.py
python3 scripts/check_stale_authorization_docs.py
python3 scripts/check_stale_workstream_wording.py
python3 scripts/check_markdown_links.py
git diff --check
```

The exact PR head must pass hosted `Backend / test` at the repository-wide 78
percent floor and `Agent Gates / agent-gates`. Semantic-lane inventory must
collect the new focused module exactly once; no test, coverage, lint, or
documentation gate may be skipped or weakened.

Focused tests explicitly cover CRC/truncation and declared-size mismatch,
local-header/central-directory disagreement, data descriptors, ZIP64 and
multi-disk markers, central-directory abuse, high entry count and compression
ratio, all path/collision classes, Unix special modes, encrypted entries,
nested-ZIP opacity, cancellation/timeout cleanup, result redaction, and proof
that no provider or durable service is reachable.

## Required Reviewers

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ git diff --check
| Chunk | Required focused test module(s) |
|---|---|
| `04A1` | `tests/test_artifact_architecture.py`, `tests/test_alembic.py` |
| `04A2` | `tests/test_submission_archive.py`, `tests/test_artifact_scratch_manager.py` |
| `04A2` | `tests/test_submission_archive.py` (including the canonical `PreparedArtifact.inspect(...)` scratch-custody and cleanup seam) |
| `04A3` | `tests/test_submission_manifest.py`, `tests/test_submission_change_gate.py` |
| `04B` | `tests/test_submission_precheck.py`, `tests/test_checker_materialization.py` |
| `04C1`-`04C2` | `tests/test_submission_bundle_admission.py`, `tests/test_artifact_verification.py`, `tests/test_artifact_recovery.py` |
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# WS-ART-001-04A2 External Review Response

## Comments addressed

- Hosted `shared_foundations` found two guide-OOXML regression failures after
the neutral ZIP probe move. EOCD per-disk versus total entry-count mismatch
was being classified as multi-disk before the existing guide layer could
preserve its stable `ooxml_directory_conflict` and `ooxml_zip64` outcomes.
- The neutral probe now reserves `multi-disk` for non-zero disk identifiers,
preserves the existing guide classification order, and retains submission
exact-record validation separately.
- CodeRabbit's completed correction-head review identified three valid small
fixes: align the ingest activation ledger, enforce inspection deadline below
the preparation deadline, and make NFC/NFD test literals explicit. All were
applied. Its hosted-status wording comment was also reconciled here.

## Comments deferred

- The first-head CodeRabbit attempt was rate-limited. The correction-head
review completed; no comment was deferred.

## Human decisions needed

None. Human approval and merge remain required. The first hosted
`shared_foundations` run completed with the two documented guide failures; the
replacement Backend run and all five shards remain pending on the latest head.

## Commands rerun

```text
ruff check app/modules/artifacts/zip_safety.py tests/test_submission_archive.py tests/test_guide_ooxml.py
pytest -q tests/test_guide_ooxml.py tests/test_submission_archive.py tests/test_guide_formats.py
```

Result: Ruff passed; 119 focused tests passed.

## Remaining risks

The exact correction commit still requires fresh hosted Backend and Agent Gates.
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# WS-ART-001-04A2 Internal Review Evidence

## Evidence gate

Result: PASS.

- Scope remains hidden and process-local: no public route, provider I/O,
durable admission, Submission, checker, semantic manifest, or AUTH activation.
- One outer ZIP is inspected through `PreparedArtifact.inspect(...)` while
canonical scratch custody remains with `ArtifactScratchManager`.
- Exact envelope and record coverage rejects prefixes, suffixes, gaps,
overlaps, central-directory disagreement, local/central disagreement,
descriptor corruption, stored extra bytes, and deflate unused tails.
- Paths, normalized collisions, ancestry conflicts, encryption, special Unix
entries, directory payloads, expansion ratios, actual bytes, and deadlines
fail closed with redacted stable internal codes.
- Nested ZIP members remain opaque regular files. Only stored and raw-DEFLATE
member compression is accepted in v0.1.
- Ruff, focused tests, focused 90-percent subsystem coverage, semantic-lane
inventory, stale scans, Markdown links, and diff checks pass locally.

## Reviewer results

- Architecture: PASS after startup cross-limit validation and a distinct
collision failure token were added.
- Security: PASS WITH LOW RISKS after exact byte-envelope/record coverage,
stored-size equality, and exact deflate consumption were added. Its remaining
aggregate-budget observation was also resolved during each member read.
- QA: PASS WITH LOW RISKS after exact envelope, hidden directory payload, and
complete adversarial seam cleanup proofs were added.
- Product/operations: PASS after local filenames for every entry, including
directories, were bound exactly to the central-directory name.
- Senior engineering: PASS WITH LOW RISKS after the neutral ZIP helper move,
directory payload rejection, and finite deadline validation.
- CI integrity: PASS WITH LOW RISKS; no workflow, threshold, package-script, or
dependency weakening. Hosted Backend and Agent Gates remain required.
- Documentation: PASS.
- Reuse/dedup: PASS after the ZIP directory probe moved to neutral
`zip_safety.py`.
- Test delta: PASS WITH LOW RISKS after all requested adversarial and
configuration-mapping cases were added.

## Findings resolved

- Safe central names cannot hide unsafe local-header names.
- No byte before, between, inside, or after ZIP records escapes accounting.
- Directory entries cannot carry hidden payloads.
- Stored and deflated members cannot hide bytes beyond logical content.
- ZIP64 is bounded while multi-disk/spanned layouts remain rejected.
- Configuration limits are validated at startup and capped at 512 MiB.

## Residual risk

The behavior has no public caller yet. Hosted PR shards, CodeRabbit, and human
review of the exact commit remain required before merge.
Loading
Loading