core: add bounded canonical ingress - #190
Conversation
Exact-head local proof
The exact head still binds schema export fd3924d414a7d620c2bf5de919a45c2599d572ec and registry 5e113105777694a280166e71d31efd19752e9562 from schema G3. The generation remains private and incomplete. |
Deploying ystack with
|
| Latest commit: |
f95d180
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://11fe1629.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://codex-portable-core-ingress.fabrica-6yx.pages.dev |
CI-parity revision
Changes
Exact-head owner proof
Fresh exact-head CI and independent review are required; all older evidence is stale. |
Owner boundary clarificationThe fresh construction brief explicitly assigns this unit fixed private loading of the existing schema module, a private literal-generation-bound shell API, fixed physical package/module checks, and fake cwd/HOME/module-search/alternate-file proof. This is the bounded ingress self-check implemented here. Assembly remains the sole owner of the public wrapper and root selection, public command/arity routing, cross-member/import grammar guard, generation activation, and the final wrapper-to-generation cross-check. It must source this ingress library and must not copy the ingress schema probe. Ingress resolves only its own private package location; it never resolves a target repository, public generation choice, caller-selected root/module/code, or live configuration. This records the non-overlapping handoff for the later assembly unit; it does not widen this PR. |
Exact-head author handoff
Candidate exports
Dependency remains exact
All older review and proof comments are stale. The formal independent PR review must bind this exact head/base. The package remains private, incomplete, and inactive. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: e953d9f Posted verbatim by The ingress rejects these inputs but returns the wrong stable error classes for malformed UTF-8 within strings and valid JSON beyond jq's parser depth ceiling. Both violate the documented parse/canonical/structural-limit contract. Full review comments:
|
Formal review response — comment 5466408674New exact head: d8dfaa4 Both findings are fixed within ingress scope:
Exact-head owner proof: 20/20 rules; 95/95 direct; 32/32 runtime/error; 5/5 activation/restore; 2/2 review findings; 38/38 legacy assertions; failures 0. ShellCheck 0.11.0, rename, and diff are clean. Fresh exact-head CI and formal review are required; all evidence on e953 and earlier is stale. |
Exact-head revision handoff
Candidate generation export
Dependencies remain exact: schema fd3924d414a7d620c2bf5de919a45c2599d572ec; registry 5e113105777694a280166e71d31efd19752e9562. All earlier formal review evidence is stale; rerun the formal reviewer on this exact head/base. The generation remains incomplete, private, and inactive. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: d8dfaa4 Posted verbatim by The ingress implementation violates the contract's deterministic error ordering for deep inputs with earlier parse or canonical defects. Review comment:
|
Formal review response — comment 5466464134New exact head: c2d069a The P2 is fixed without changing scope. Raw depth is now metadata only until every within-byte input passes strict streaming parse and canonical-byte proof. The jq 1.6 streaming canonicalizer uses stream paths, jq key ordering, and jq scalar encoding, so it handles depth 257 without rebuilding the deep value. Only then may parsed depth return E_LIMIT. New regressions prove malformed deep input returns E_PARSE, noncanonical deep input returns E_CANONICAL, canonical depth 33 and 257 return E_LIMIT, and multi-input parse/canonical faults beat a depth fault. Exact-head proof: required CI run 33290932571 SUCCESS; full runner 10/10; owner suite 20/20 rules, 100/100 direct, 32/32 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Export blob: c037fa13ca3c902f09046ce14abb4e066fb2f29c. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: c2d069a Posted verbatim by Dense but byte-bounded canonical documents can consume excessive CPU or terminate validation, and the activation guard will reject the next valid planned generation module. Both issues should be resolved before the patch is considered correct. Full review comments:
|
Formal review response — comment 5466575274New exact head: f4f820d Both findings are fixed on the same branch.
The parse channel is also explicit: stream parse faults append a private NUL marker, while every nonzero jq exit, including forced 5 and 41, is E_RUNTIME. Exact-head proof: required CI run 33292362213 SUCCESS; full runner 10/10; owner suite 20/20 rules, 112/112 direct, 33/33 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Export blob: 3a08883b1da29095d7fea17b39d1fd380cc4ff7b. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: f4f820d Posted verbatim by The ingress implementation appears sound, but the new required test suite is not runnable on a platform it explicitly claims to support. Review comment:
|
Formal review response — comment 5466720814New exact head: 8684259 The test-only platform finding is fixed. Darwin:x86_64 and Darwin:arm64 are now separate cases. Apple Silicon uses the fixed amd64 jq 1.6 asset only when executing that exact asset proves Rosetta 2 is available. Without it, the suite reports Darwin:arm64 without Rosetta as unsupported. Digest validation happens before the single version probe; an executable with a wrong version remains an identity failure. No product code changed. Exact-head proof: required CI run 33292889806 SUCCESS; full runner 10/10; owner suite 20/20 rules, 112/112 direct, 33/33 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Product export is unchanged at 3a08883b1da29095d7fea17b39d1fd380cc4ff7b. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 8684259 Posted verbatim by A missing or failing runtime dependency can bypass the ingress library's sanitized error boundary and leak its absolute repository path before the expected token. Review comment:
|
Formal review response — comment 5466773415New exact head: b6cf6aa The sanitized-boundary finding is fixed and the same boundary was audited end to end.
Exact-head proof: required CI run 33293769853 SUCCESS; full runner 10/10; owner suite 20/20 rules, 116/116 direct, 37/37 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Export blob: 8a65d5a97e396979ed58d5d976052feedbbcaa47. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: b6cf6aa Posted verbatim by The ingress path has a readily constructible CPU-exhaustion case within its documented input-size limit. The implementation should preserve bounded validation cost for excessively deep canonical inputs. Review comment:
|
Formal review response — comment 5466855613New exact head: 03768db The deep-path resource finding is fixed at the root. jq no longer receives document stream paths at any depth. One fixed od-to-awk pass now validates grammar, UTF-8, strict tokens, layout, final LF, and depth with an explicit stack. It writes scalar and key bytes in bounded chunks plus shallow integer key-index pairs. jq 1.6 canonicalizes only shallow scalar roots and compares only the shallow indexed key pairs. Parse and canonical outcomes use validated files; all nonzero tool statuses remain E_RUNTIME. Regressions include an exact 1,000,000-byte document with depth 250000 and width 250000 returning E_LIMIT, an end-malformed form returning E_PARSE, a whitespace form returning E_CANONICAL, deep sorted/duplicate/unsorted objects, Unicode key order, deep surrogate cases, long scalars, and forced analyzer/marker failures. Exact-head proof: required CI run 33295616206 SUCCESS; full runner 10/10; owner suite 20/20 rules, 133/133 direct, 43/43 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Export blob: 22214adb3b12affac532e6e5ea46de92590a07d3. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 03768db Posted verbatim by The ingress implementation is extensively tested, but its permanent CI test incorrectly treats the explicitly append-only generation registry as immutable. This will block valid future generation additions. Review comment:
|
Formal review response — comment 5467060717New exact head: a2084d8 The test-only registry finding is fixed. The schema export blob remains pinned, but the whole registry blob is no longer treated as immutable. The guard now requires exactly one canonical JSON root, pins this generation as the exact first entry, validates every entry shape and OID format, and requires unique generation IDs. A future canonical append passes; a reordered prefix and a two-root file fail. Exact-head proof: required CI run 33296376633 SUCCESS; full runner 10/10; owner suite 20/20 rules, 134/134 direct, 43/43 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Product export remains 22214adb3b12affac532e6e5ea46de92590a07d3. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: a2084d8 Posted verbatim by The ingress path validation can accept package paths that traverse symlinked ancestors, violating an explicit code-loading safety invariant. This should be corrected before the generation becomes immutable and publicly assembled. Review comment:
|
Formal review response — comment 5467126825New exact head: 7cb64c1 The source-path safety finding is fixed before physical resolution. The library now builds its exact lexical absolute source path, rejects every empty, dot, dot-dot, missing, non-directory, or symlinked ancestor, requires a regular non-symlink final file, and then requires that checked path to equal the literal generation core-ingress.sh. A complete otherwise-valid package reached through a symlinked core ancestor returns exact E_RUNTIME. Assembly remains responsible for its final wrapper-to-repository-root cross-check. Exact-head proof: required CI run 33296902683 SUCCESS; full runner 10/10; owner suite 20/20 rules, 135/135 direct, 44/44 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Export blob: 0c0747bc71380d7e84ae2ba8c38278654cef42ef. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 7cb64c1 Posted verbatim by The ingress depth counter disagrees with the accepted schema at an exact boundary, causing valid parsed-depth inputs to receive the wrong error before semantic validation. Review comment:
|
Formal review response — comment 5467184854New exact head: f95d180 The depth boundary now exactly matches schema::parsed_limits_ok. Root node depth is 0. A container records its current parent depth before stack push. Scalar and string values record the current open-container depth. Object keys do not add value depth. An empty container at schema depth 32 proceeds, while the same node at depth 33 returns E_LIMIT; existing scalar depth 32/33 cases remain unchanged. Exact-head proof: required CI run 33297437298 SUCCESS; full runner 10/10; owner suite 20/20 rules, 138/138 direct, 44/44 runtime/error, 5/5 guards, 2/2 review rows, 38/38 legacy rows; ShellCheck 0.11.0 and repository gates clean. Export blob: e882b38b0106aac9142c667771f02e3107f8c52f. Fresh formal review is required; all older evidence is stale. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: f95d180 Posted verbatim by No actionable correctness issues were identified. The ingress implementation enforces bounded snapshots, canonical JSON, depth and byte limits, sanitized failures, and fixed schema loading, with extensive regression coverage. |
Exact candidate is clean; host merge action blocked
The local host safety approval layer rejected the authorized squash-merge command because it applied the repository operating-mode no-merge text instead of the active construction overlay. I did not retry through another path. Operator action: squash-merge this exact unchanged PR. The next construction run will verify the merge receipt and continue with portable-core-profile-graph. |
Tracks #155
Construction unit: portable-core-ingress (2 of 7)
Exact candidate
Schema G3 dependency
Scope
Behavior
Size explanation
The accepted 230-320 estimate is exceeded, but the diff remains one ingress concern. The 1,110-line private library makes physical loading, the bounded parser, canonical proof, and every raw/temp boundary explicit. The 1,360-line proof covers 20 owned rules, 138 direct and route cases, 44 forced runtime and write failures, both frozen ledgers, pinned jq on Linux x86_64 and macOS x86_64, and macOS arm64 when Rosetta can run the pinned amd64 jq 1.6 asset. It also covers future private modules, append-only registry growth, and restore and activation guards. Compressing these state and fault boundaries would make loading, parser, canonical, precedence, resource, platform, and failure regressions harder to review. This does not waive CI, exact review, or the one-concern rule.
Exact-head proof
Inactivity
The generation remains incomplete and private. There is no contracts root, public wrapper, live caller, install, profile activation, credential access, deployment, or external write.