fix(evidence): harden source acquisition
This commit is contained in:
@@ -34,3 +34,23 @@ configuration with legacy compatibility, and factory construction.
|
||||
The approved `SourceObject` namespace grammar does not permit raw quoted ETags such as
|
||||
`etag:"abc"`. The adapter therefore uses `etag:<sha256-of-opaque-etag>`: it preserves ETag-based
|
||||
change identity without weakening the canonical contract or exposing validator contents.
|
||||
|
||||
## Review hardening follow-up
|
||||
|
||||
Four review findings were closed in a separate follow-up commit:
|
||||
|
||||
- Filesystem access now anchors a persistent descriptor at the canonical root and walks each
|
||||
component with `openat` semantics (`dir_fd`, `O_NOFOLLOW`, and `O_DIRECTORY`). The regular-file
|
||||
check, bounded read, metadata, and hash all use the opened descriptor. Acquisition reopens by
|
||||
the same path-safe mechanism and rejects a changed fingerprint. Deterministic tests swap both a
|
||||
leaf and an ancestor to symlinks at open time.
|
||||
- HTTP network policy defaults to public hosts only. Initial URLs and every redirect reject
|
||||
userinfo, mixed public/private IPv4/IPv6 answers fail closed, and the connected peer must be a
|
||||
public member of the previously validated DNS answer set before any body bytes are consumed.
|
||||
Explicit `allow_private_hosts: true` is required for trusted private deployments and local tests.
|
||||
- Every HTTP response is closed in a `finally` block, including redirects, status failures,
|
||||
policy failures, oversized bodies, and mid-stream exceptions.
|
||||
- ETag and Last-Modified values remain adapter-internal. Repeated discovery and acquisition send
|
||||
conditional headers; a 304 reuses only previously verified cached bytes and identity. The LRU
|
||||
content cache has an explicit byte bound (`max_cache_bytes`). Validators are not forwarded
|
||||
across redirect origins.
|
||||
|
||||
Reference in New Issue
Block a user