-
Notifications
You must be signed in to change notification settings - Fork 0
fix(core): protect canonical evidence runtime types #63
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
seonghobae
wants to merge
70
commits into
develop
Choose a base branch
from
fix/job-analysis-temporal-evidence-types
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Changes from 11 commits
Commits
Show all changes
70 commits
Select commit
Hold shift + click to select a range
e10bd56
test(job-analysis): reject temporal evidence subclasses
seonghobae 4297396
fix(job-analysis): protect canonical temporal evidence types
seonghobae e6fe899
test(audit): reject canonical-evidence runtime subclasses
seonghobae 3058ff9
fix(audit): protect canonical identity and chronology types
seonghobae 36fe981
test(job-analysis): reject identity runtime subclasses
seonghobae 4a541a5
fix(job-analysis): protect canonical identity types
seonghobae 58a6c78
fix(core): refresh foundation manifest after audit hardening
seonghobae 943c2dc
test(core): reject forged job-analysis primitive types
seonghobae 05d04db
fix(core): reject forged job-analysis codes and levels
seonghobae 7ae6331
test(core): complete adversarial level ordering
seonghobae 9a1bbd3
fix(core): close canonical evidence runtime gaps
seonghobae 5c52509
fix(job-analysis): reject nested evidence subclasses
seonghobae f222934
chore(core): non-force restack runtime integrity on protected develop
seonghobae 9ff8b4e
test(audit): reject post-construction governance mutation
seonghobae b95ff0a
fix(audit): revalidate captured canonical evidence
seonghobae a36e1b6
chore(manifest): reseal audit runtime-integrity evidence
seonghobae c088d97
fix(audit): preserve detached-time fail-closed canonicalization
seonghobae 08a9cad
chore(manifest): reseal corrected audit canonicalization
seonghobae 24ff2a1
test(audit): reject valid canonical evidence reissuance
seonghobae 970bae7
fix(audit): bind canonical export to creation evidence
seonghobae 7f6a2ab
chore(manifest): seal audit creation identity repair
seonghobae cd25ace
fix(audit): keep issuance seal outside mutable event slots
seonghobae fd18a83
chore(manifest): reseal external audit issuance proof
seonghobae 72ec4ec
test(audit): cover issuance registry failure modes
seonghobae 8cddbf7
merge(core): adopt protected workflow consolidation
seonghobae 6d4dabf
merge(core): preserve #161 changelog delta after restack
seonghobae b929661
fix(ci): reseal shared-kernel manifest after protected restack
seonghobae f1447a8
test(core): reject reintroduced audit timezone before callback
seonghobae 6f26acd
fix(core): validate canonical audit timestamp before snapshot comparison
seonghobae ac31f28
fix(core): reseal audit runtime manifest after callback guard
seonghobae 38c3fde
fix(core): restore unrelated migration manifest digest
seonghobae 5d7eef3
fix(core): restore LICENSE manifest digest after reseal repair
seonghobae 50a7dbe
test(core): prove audit event cannot reseal after issuance
seonghobae d076d1f
fix(core): make audit issuance identity single-use
seonghobae ddc41be
fix(core): use unique marker for audit issuance identity
seonghobae 423cf66
build(core): reseal single-use audit runtime evidence
seonghobae 31fabb5
test(core): cover audit issuance lifetime cleanup
seonghobae 701a179
test(audit): hide issuance authority storage from consumers
seonghobae 7b6cb6f
test(audit): exercise private issuance runtime without mutable globals
seonghobae 70bdd6d
fix(audit): hide issuance authority in closure-private state
seonghobae cd3b2f5
test(audit): use valid isolated creation snapshot for cleanup
seonghobae 03d1b8b
chore(manifest): reseal audit runtime authority source
seonghobae 48bfaf7
test(audit): cover private issuance marker and duplicate guards
seonghobae c17af48
test(audit): reject closure-exported issuance authority
seonghobae 8b20c53
test(audit): require structural immutability instead of mutable issua…
seonghobae 1b80534
test(audit): require immutable timestamp evidence after construction
seonghobae e5d4303
test(audit): enforce structural immutability at canonical boundary
seonghobae e29d180
fix(audit): make canonical evidence structurally immutable
seonghobae 1d24cef
test(core): reject executable audit timezones before callbacks
seonghobae 7216153
fix(core): exact-gate audit timezone providers
seonghobae c9f7de3
test(core): align audit timezone contract with inert providers
seonghobae 0607d00
refactor(core): remove unreachable custom-timezone branches
seonghobae 16dce30
chore(manifest): reseal audit timezone owner artifacts
seonghobae 72070cb
test(core): cover audit structural rejection branches
seonghobae 0fc801d
test(audit): match literal timezone provider names
seonghobae 19d515b
chore(manifest): reseal audit regex fixture
seonghobae 92fe70e
fix(manifest): restore verified foundation seal
seonghobae 42ef99a
fix(manifest): reseal audit regex fixture
seonghobae 74f7f2c
test(job-analysis): reject executable timezone providers
seonghobae b846304
fix(job-analysis): gate timezone providers before callbacks
seonghobae 510b50b
fix(job-analysis): remove unreachable provider branches
seonghobae 3bb641b
test(core): reject mutable exact UUID payloads
seonghobae 03ba635
fix(core): detach validated job-analysis UUIDs
seonghobae 2456639
fix(core): detach validated audit UUIDs
seonghobae 0e5d432
chore(core): defer audit UUID repair to manifest-safe slice
seonghobae 4ab735d
test(core): scope UUID payload regressions to job analysis
seonghobae 4ad9363
test(job-analysis): align custom timezone rejection contract
seonghobae c423de6
test(audit): reject mutable exact UUID payloads
seonghobae afd47f0
fix(audit): detach validated UUID identities
seonghobae d88800a
fix(audit): reseal canonical manifest for detached UUID identities
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
|
seonghobae marked this conversation as resolved.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.