Skip to content
Draft
Show file tree
Hide file tree
Changes from 21 commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
513302a
test(strix): bind evidence helper to trusted source root
seonghobae Sep 19, 2026
c08b13d
fix(strix): resolve evidence binder from trusted source
seonghobae Sep 19, 2026
ca7e1e7
test(strix): materialize trusted binder fixtures
seonghobae Sep 19, 2026
db1fd61
fix(strix): restore complete verified fixture tree
seonghobae Sep 19, 2026
fb9c0e2
test(strix): require consumer-free trusted binder fixture
seonghobae Sep 19, 2026
78b33a8
repair(strix): restore executable harness after binary blob corruption
seonghobae Sep 19, 2026
191bd63
test(strix): require binder-free consumer fixture
seonghobae Sep 19, 2026
ef1a866
test(strix): separate trusted gate from consumer root
seonghobae Sep 19, 2026
abc9a7d
docs(strix): bind consumer isolation evidence to exact commits
seonghobae Sep 19, 2026
00082e8
docs(strix): describe separated trusted runtime fixture
seonghobae Sep 19, 2026
782d67b
test(strix): retain canonical gate source under scan
seonghobae Sep 20, 2026
a8d6261
test(strix): red specialized fixture owner boundary
seonghobae Sep 20, 2026
bbe225d
test(strix): materialize specialized fixtures' trusted runtime outsid…
Sep 21, 2026
1794626
test(strix): pin trusted evidence-binder path
seonghobae Sep 21, 2026
361a9eb
merge: adopt current CI owner and repair CodeQL URL oracle
seonghobae Sep 26, 2026
1fd22f4
test(strix): require Job Analysis authority context
seonghobae Sep 26, 2026
808a8a7
fix(strix): include Job Analysis authority context
seonghobae Sep 26, 2026
b90d873
docs(strix): record Job Analysis authority context
seonghobae Sep 26, 2026
5ee6c87
fix(strix): fail closed on missing Job Analysis context
seonghobae Sep 27, 2026
20f4556
docs: record required Strix context evidence
seonghobae Sep 27, 2026
c7b5e75
docs: qualify Orgmetra evidence references
seonghobae Sep 27, 2026
f42aa2d
merge: adopt current main Strix owner and keep Job Analysis context
seonghobae Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions CHANGELOG.d/20260920-strix-trusted-binder-runtime-fixture.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
### Strix keeps trusted evidence binding outside consumer workspaces

- The Strix gate resolves its evidence binder beside the trusted gate source.
The executable core harness now materializes that trusted runtime under a
separate source directory, passes a binder-free consumer workspace through
`STRIX_REPO_ROOT`, and invokes the trusted gate by its absolute path.
- OpenCode coverage assertions follow the consolidated
`validate-pr-metadata` owner instead of the removed
`coverage-source-tree` job and failure-report step.
- The commercial-readiness receipt contract now compares the complete parsed
harden-runner endpoint set instead of treating an expected hostname as a URL
substring. This closes the exact CodeQL
`py/incomplete-url-substring-sanitization` finding without suppressing it or
widening egress.
- The branch adopts the current central dependency owner, including the
explicit AnyIO 4.14.2 source-to-hash pin required by the Python security
gate.
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
### Strix supplies bounded Job Analysis authority context from the trusted base

- ContextualWisdomLab/orgmetra#63 changes `packages/hris-kernel/src/orgmetra_hris_kernel/job_analysis.py`, but the Strix scan workspace previously omitted the unchanged authorization, HTTP, snapshot, and persistence collaborators that establish its resource-ownership boundary. That incomplete context produced a false HIGH IDOR finding even though the product reconstructs owner scope and authorizes resource fields before port access. A source-first executable fixture now requires the changed PR-head module, exactly five unchanged Job Analysis authority files from the authenticated trusted base, and exclusion of an unrelated administration file. RED `1fd22f4e` failed because `auth.py` was absent; the gate now recognizes only the normalized Job Analysis trigger and adds the five fixed context paths through the existing trusted-base materialization boundary. Follow-up `5ee6c876da508e45d284517a3812d52e053e3728` closes a fail-open edge in that contract: if any of the five required trusted-base files is absent while the Job Analysis trigger changed, the gate exits before invoking Strix. The same commit pins pytest-asyncio's fixture loop scope to `function`, eliminating the suite's configuration deprecation without changing any async fixture behavior. No consumer source, provider/model policy, severity gate, timeout, or write authority changes.

### OpenCode coverage image materializes every Dockerfile lock input

- Required OpenCode run `35370902053` for `.github#2266@12621f75e` failed before executing PR code because its trusted Dockerfile copied `requirements-noema-document-ci-hashes.txt` while the isolated build context contained only the OpenCode lockfile. The coverage owner now validates both lockfiles as regular non-symlink files and copies both into the trusted build context before the networked image build. `tests/test_opencode_agent_contract.py` pins the complete input boundary. Hosted exact-head acceptance remains Proposed until the new run reaches the image-build and coverage steps.
Expand Down
84 changes: 84 additions & 0 deletions docs/product-technical-gap-baseline.md
Original file line number Diff line number Diff line change
Expand Up @@ -3430,3 +3430,87 @@ alone -- it is a documented multi-PR hot-file collision zone. Contract:
**Action.** Exact `57477289ebec5631b0c48f0bc419f336dbe19deb` adds a dependency-free synthetic-302 transport to `tests/test_github_api_url_boundary.py`. For both actual production openers, the case drives a canonical bearer request through the real HTTPS open/response chain, requires the typed HTTP-302 failure mapping, and proves transport receives exactly one original request; lookalike HTTPS, HTTP, `file:`, and same-authority redirect targets never receive a second request or bearer. Exact `e0b0b4d4fff5b6ea88236a1e91dcd7dbb3be09b5` repairs the doctoring claim so direct-handler coverage is not mislabeled as production-chain proof.

**Evidence / remaining condition.** The standalone fixture mechanism was executed locally against Python stdlib and produced one canonical request followed by terminal HTTP 302 for every hostile target. This is mechanism evidence, not repository acceptance. Final authority requires focused/full exact-tree GREEN, fresh exact-head Security/SAST/Python Security/CodeQL/runtime-quality checks, no unresolved actionable review, ordinary protected-main integration, and downstream consumer validation. No scanner suppression, redirect allowlist widening, provider fallback, workflow gate weakening, or credential-boundary change is included.

## 2026-09-20 Strix trusted-binder consumer-isolation gap

**Status:** Proposed on `ContextualWisdomLab/.github#2291`; exact-head hosted
checks, independent review, and protected-main integration remain required.

**Context Map / owner.** The central `.github` CI bounded context owns
`strix_quick_gate.sh`, its evidence binder, and the executable gate harness.
Consumer repositories supply only the scan workspace through
`STRIX_REPO_ROOT`; they do not copy or own the binder.

**Gap / root cause.** The production gate incorrectly resolved the trusted
binder from the consumer root. The first repair correctly moved that lookup to
`SCRIPT_DIR`, but its test harness copied only the gate and model helper into
the isolated fixture. The current PR head therefore still reproduced the same
missing-binder exit in the `success` scenario. Three assertions in that harness
also described the removed standalone `coverage-source-tree` job after its
responsibility moved into `validate-pr-metadata`.

**Action / evidence.** The production gate resolves
`strix_evidence_binding.py` beside its trusted source. RED `191bd630`
requires the generic executable consumer fixture to contain no binder. GREEN
`ef1a8667` materializes the gate, model helper, and binder under a separate
`trusted-source/scripts/ci` directory, passes only the binder-free consumer
workspace through `STRIX_REPO_ROOT`, and invokes the trusted gate by its
absolute path. This makes the core executable fixture reproduce the production
owner boundary instead of proving a co-located copy. The full exact-tree Strix
harness and hosted checks remain the release authority; no provider, model,
timeout, severity, or consumer ownership boundary changes.

**2026-09-26 exact-head RCA / owner integration.** Exact Python-security job
`107750961662` on head `1794626af3473ef23b9c2e678c3f06fd6c11636f`
found AnyIO 4.14.0's CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349 in
`requirements-strix-ci-hashes.txt`; this branch had not adopted the central
source-to-hash AnyIO 4.14.2 repair from `ContextualWisdomLab/.github#2385`.
Exact CodeQL dispatch run `36204821293`, Python job `108319933572`, separately
produced one Medium+ SARIF result:
`py/incomplete-url-substring-sanitization` at
`tests/test_organization_commercial_readiness_loop_receipt_contract.py:60`.
The receipt test parsed the complete YAML endpoint block but then expressed the
expected receiver hostname through a subset/membership-style assertion that
CodeQL correctly rejects on URL-security surfaces. The ordinary two-parent
owner integration adopts #2385's AnyIO contract; the test now compares the
complete seven-entry endpoint set exactly. This strengthens the egress oracle:
an unexpected endpoint fails rather than being tolerated. No CodeQL query,
severity, SARIF gate, dependency audit, or endpoint allowlist is suppressed or
widened. Fresh exact-head hosted Python Security and CodeQL remain mandatory.

**2026-09-27 Job Analysis bounded-context repair.** ContextualWisdomLab/orgmetra#63 exact head
`d88800a5ca3ca15df332e8def5e25064c46e4005` changes the HRIS-kernel Job
Analysis aggregate module, while the trusted scan workspace previously omitted
the unchanged product-owned authority context that explains its ownership
checks. Strix consequently reported a HIGH IDOR finding against an incomplete
workspace even though the Job Analysis API reconstructs the canonical owner and
authorizes resource fields before snapshot or PostgreSQL port access. Source-
first RED `1fd22f4e1e86d0ebfe5dab932697e95593c9ad10` adds an executable
pull-request-target fixture whose fake scanner refuses to run unless the changed
PR-head `job_analysis.py` is accompanied by exactly the five fixed trusted-base
collaborators (`auth.py`, `authorization.py`, `http.py`, `postgres.py`, and
`snapshot.py`); it also proves an unrelated administration module is excluded.
The minimal GREEN recognizes only that normalized trigger and emits those five
paths through the existing trusted-base context materializer. This is a bounded
CI-context repair, not a transfer of product domain truth: no Orgmetra source,
authorization order, persistence boundary, model/provider policy, severity,
timeout, or write capability changes. Exact-head hosted Strix acceptance,
independent review, ordinary protected-main integration, and a fresh
ContextualWisdomLab/orgmetra#63 consumer run remain mandatory before the
false-positive gap is complete.

**2026-09-27 required-context fail-closed follow-up.** Review of PR #2291 at
head `b90d873e67860944308d5cef919a1f95243ef98f` found that the five paths above
were selected but not required: the shared trusted-context copier treated a
missing base path as an optional success. A Job Analysis scan could therefore
reach Strix without the authority evidence the mapping promises. RED removed
`auth.py` from the authenticated base, changed only the Job Analysis kernel,
and observed exit 1 after one fake-Strix invocation. Exact source commit
`5ee6c876da508e45d284517a3812d52e053e3728` makes those five paths mandatory
only when that kernel trigger is in the authenticated changed-file inventory;
missing context now exits 2 before Strix, while unrelated mapping families keep
their prior optional-file behavior. The full Strix shell harness passes, and
the full Python suite passes with DeprecationWarning promoted to an error
(`3388 passed, 28 skipped, 40 subtests`). Hosted exact-head checks, qualifying
independent review, ordinary protected-main integration, and a fresh
ContextualWisdomLab/orgmetra#63 consumer run remain mandatory.
1 change: 1 addition & 0 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ dev = [

[tool.pytest.ini_options]
pythonpath = ["."]
asyncio_default_fixture_loop_scope = "function"

[tool.coverage.run]
branch = true
Expand Down
36 changes: 35 additions & 1 deletion scripts/ci/strix_quick_gate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -243,7 +243,7 @@ PY
sanitize_remediation_evidence_claims() {
local log_file="$1"
local report_root="$2"
local binder="$REPO_ROOT/scripts/ci/strix_evidence_binding.py"
local binder="$SCRIPT_DIR/strix_evidence_binding.py"
local report_file

if [ ! -f "$binder" ] || [ -L "$binder" ]; then
Expand Down Expand Up @@ -1384,6 +1384,7 @@ pull_request_scope_context_files() {
local needs_backend_app_python=0
local needs_contextual_orchestrator_python=0
local needs_frontend_email_api_context=0
local needs_orgmetra_job_analysis_authority_context=0
local needs_deployment_context=0
local changed_file normalized_changed_file
for changed_file in "$@"; do
Expand All @@ -1400,6 +1401,9 @@ pull_request_scope_context_files() {
contextual_orchestrator/*.py)
needs_contextual_orchestrator_python=1
;;
packages/hris-kernel/src/orgmetra_hris_kernel/job_analysis.py)
needs_orgmetra_job_analysis_authority_context=1
;;
# The app shell, email components, threading URL builder, and API client can
# shape frontend email retrieval flows; include backend auth context with them.
frontend/src/components/EmailDetail.tsx | frontend/src/components/EmailList.tsx | frontend/src/app/page.tsx | frontend/src/lib/api-client.ts | frontend/src/lib/email-threading.ts)
Expand Down Expand Up @@ -1549,6 +1553,16 @@ backend/services/threading_service.py
EOF
fi

if [ "$needs_orgmetra_job_analysis_authority_context" -eq 1 ]; then
cat <<'EOF'
services/job-analysis-api/src/orgmetra_job_analysis_api/auth.py
services/job-analysis-api/src/orgmetra_job_analysis_api/authorization.py
services/job-analysis-api/src/orgmetra_job_analysis_api/http.py
services/job-analysis-api/src/orgmetra_job_analysis_api/postgres.py
services/job-analysis-api/src/orgmetra_job_analysis_api/snapshot.py
EOF
fi

if [ "$needs_deployment_context" -eq 1 ]; then
cat <<'EOF'
Dockerfile
Expand Down Expand Up @@ -1688,6 +1702,26 @@ PY
esac
local src_path="$REPO_ROOT/$relative_path"
if [ ! -e "$src_path" ]; then
case "$relative_path" in
services/job-analysis-api/src/orgmetra_job_analysis_api/auth.py | \
services/job-analysis-api/src/orgmetra_job_analysis_api/authorization.py | \
services/job-analysis-api/src/orgmetra_job_analysis_api/http.py | \
services/job-analysis-api/src/orgmetra_job_analysis_api/postgres.py | \
services/job-analysis-api/src/orgmetra_job_analysis_api/snapshot.py)
local job_analysis_change_rc=0
changed_file_list_contains \
"packages/hris-kernel/src/orgmetra_hris_kernel/job_analysis.py" || job_analysis_change_rc=$?
case "$job_analysis_change_rc" in
0)
echo "ERROR: required Job Analysis trusted context file is unavailable: $context_file" >&2
return 2
;;
2)
return 2
;;
esac
;;
esac
return 0
fi
if [ ! -f "$src_path" ] || [ -L "$src_path" ]; then
Expand Down
Loading
Loading