fix: anchor P1 manual extraction and scans

This commit is contained in:
2026-08-09 22:43:44 +02:00
parent bd1f4083e9
commit a3129b8b81
3 changed files with 310 additions and 39 deletions
+12 -7
View File
@@ -7,8 +7,9 @@ result. Automation never creates `VERDICT.md`, never records PASS, and never con
## Prerequisites
From a clean repository checkout, Task 8 must already be implemented. Install Node/npm and Git,
`curl`, `unzip`/`zipinfo`, `lsof`, and the harness development environment so `harness/.venv/bin/tht` is executable.
From a clean repository checkout, Task 8 must already be implemented. Install Node/npm, `python3`,
and Git, `curl`, `unzip`/`zipinfo`, `lsof`, and the harness development environment so
`harness/.venv/bin/tht` is executable.
Ports `127.0.0.1:8791` and `127.0.0.1:8792` must be free. The helper builds and serves only the
production backend; it does not start Docker or the frontend.
@@ -55,11 +56,15 @@ its commit-addressed owned snapshot path, the saved publish commit, and the inst
calling the acceptance-only production renderer. The renderer imports the built `ThtRunner`, resolves
bindings from environment paths, copies one lease atomically with mode `0600`, and releases it in
`finally`. For each exported ZIP, invoke the generated extractor with the exact expected workspace ID
(`p1-filesystem`, `p1-http`, or `p1-s3`); it stages one immutable owned copy, confines extraction,
and binds both the manifest and parsed descriptor identity to that expected ID. The generated secret
scan checks bounded bytes from every Git object, including unreachable blobs and dangling commits.
Do not inspect or print raw secret-file contents; only inspect ownership/mode/path metadata and canary
absence outside `fixture-secrets`.
(`p1-filesystem`, `p1-http`, or `p1-s3`); its `python3` helper opens the source once, stages and
revalidates its SHA-256, anchors every extraction and cleanup operation to an opened no-follow
`exports/extracted` directory descriptor, and binds both the manifest and parsed descriptor identity
to that expected ID. It verifies exactly four regular entries and publishes only their exact checked
bytes. The generated secret scan reads every bounded filesystem file outside the direct
`fixture-secrets` directory, including Git metadata and arbitrary `.git`-named directories, then
enumerates every reachable or unreachable Git object and scans the bounded raw blob, commit, tree,
and tag bytes. Findings redact canary values. Do not inspect or print raw secret-file contents; only
inspect ownership/mode/path metadata and canary absence outside `fixture-secrets`.
## Failures and verdict