[Phase 0][WP7D] Activate bounded operator-snapshot Chroma detection and atomic report finalization - #25
Merged
Conversation
Implement Phase 0 WP7D for #24 with aggregate-only detection, atomic report finalization, exact activation gates, adversarial tests, CI evidence, and bounded public claims.
Export the inherited WP7C OS-egress marker while the WP7D matrix runs the unchanged private compatibility tests under the same verified network denial.
Owner
Author
Independent security review record — Fable PASS FOR FINAL REVIEWThis PR conversation comment records Fable's independent final security result. It is not a formal GitHub approval, and no approval review is being submitted on behalf of the PR author.
Exact-head workflow evidence remains green:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #24
Security objective
Activate one-shot Chroma detection only from a complete offline/full-filesystem snapshot created separately by the operator. Direct/live Chroma access and monitor new scans remain disabled.
Starting SHA:
d3a5145baaee86c17441cc431b934cc42ac8a076Reviewed head corrected:
3ca740328bef7a9c5a77c95f51ef712098c48aa3Correction commit and corrected immutable head:
18d6ea5d2265eb5dab8e421061416ba1f2e02448Scope
1.5.9to Linux/ext4 Python 3.10–3.12, macOS 15/APFS Python 3.12, and Windows/NTFS Python 3.12.read_chroma()denial, the private WP7C 1.5.0/1.5.9 evidence path, and the existing ten-cell WP7C workflow.chroma-snapshot = ["chromadb==1.5.9"].Fable correction pass
Fable identified two material findings against reviewed head
3ca740328bef7a9c5a77c95f51ef712098c48aa3:filename/filename2, causes, contexts, tracebacks, and nested exception groups. Static public failures are raised only after leaving the original exception handler.No code changes were made for Fable's informational observations 2–6; they remain outside this narrowly scoped correction pass.
Numeric decision
The deterministic synthetic measurements and selected values are recorded in Issue #24 comment 5302549996. Selected ceilings: 1,000 collections; 10,000 records; 100,000 segments; 268,435,456 detector UTF-8 bytes; 65,536 bytes/segment; 4,096 findings/segment; 1,000,000 findings; 64 entity types; 16,384-byte detector response; 1,048,576-byte report; 30-second report finalization; existing 1,200-second worker maximum; zero automatic retries.
Correction validation
Deliberate correction red baseline, with regression tests applied to the reviewed production head: 14 failed, 102 deselected. The failures demonstrated the five retained report exception graphs, retained dependency exception graph, three unsupported-filesystem pre-source violations, and five missing approved-tuple cases.
Green local evidence at corrected head
18d6ea5d2265eb5dab8e421061416ba1f2e02448:pip checkclean; complete suite 649 passed, 43 skipped.chromadbabsent;pip checkclean; complete suite 649 passed, 43 skipped.pyproject.tomlparse successfully.git diff --checkpass.d3d0dc8f0f29d0131ff152a3f07dcb579b391584; SHA-256 isd2ae97dda65d9058d05777f414605f1867324c5a58ac2db4169cfaf99a38b584.Fresh exact-head GitHub evidence is green:
The WP7D matrix covers Linux/ext4 Python 3.10–3.12, macOS 15/APFS Python 3.12, and Windows/NTFS Python 3.12 with ChromaDB 1.5.9. Every successful cell records its resolved environment, dependency consistency, native-filesystem identity, OS-level egress denial, focused evidence, and applicable complete suite. Transitive dependencies and runner images are not claimed to be locked.
Boundaries and residual risks
The operator—not RAGLeakGuard—must create a complete, quiescent/full-filesystem snapshot. The acknowledgement does not prove provenance, quiescence, completeness, or transactional atomicity. Detection is best-effort; absence of findings is not proof of safety or compliance. Python interception is not a general sandbox, native calls may block below cooperative deadlines, transitive dependencies and runner images may regress, crashes can leave cleanup residue requiring investigation, deletion is not certified erasure, and directory durability is unavailable on some platforms/filesystems.
PyPI
0.1.0remains unsafe for Chroma scanning. No corrective release has been published. This PR does not authorize release, publication, direct/live access, monitor activation, later work packages, approval, readiness, or merge.Review
Keep this PR draft. Required next action after all checks pass: fresh independent security re-review of the corrected immutable head by Fable.