fix: reject unsafe evidence documentation claims
This commit is contained in:
@@ -247,14 +247,18 @@ contract_path = base / "docs/contracts/workspace-evidence-v3.md"
|
||||
local_path = base / "docs/install/local-workspace-registry.md"
|
||||
server_path = base / "docs/install/server-workspace-registry.md"
|
||||
bindings_path = base / "docs/install/examples/workspace-bindings.env.example"
|
||||
paths = [contract_path, local_path, server_path, bindings_path]
|
||||
descriptor_paths = [
|
||||
base / "deploy/workspaces/example.yaml",
|
||||
base / "deploy/workspaces/psd.yaml.example",
|
||||
]
|
||||
paths = [contract_path, local_path, server_path, bindings_path, *descriptor_paths]
|
||||
for path in paths:
|
||||
if not path.is_file():
|
||||
raise SystemExit(f"missing workspace Evidence contract input: {path.relative_to(base)}")
|
||||
|
||||
# Generic descriptors must publish an explicit, ID-derived canonical filesystem contract.
|
||||
for relative in ("deploy/workspaces/example.yaml", "deploy/workspaces/psd.yaml.example"):
|
||||
path = base / relative
|
||||
for path in descriptor_paths:
|
||||
relative = path.relative_to(base).as_posix()
|
||||
document = yaml.safe_load(path.read_text())
|
||||
workspace_id = document["workspace"]["id"]
|
||||
evidence = document.get("evidence")
|
||||
@@ -402,7 +406,25 @@ if not all(token in p1 for token in ("lexical URI", "Git tree", "same commit", "
|
||||
if not all(token in p6 for token in ("commit-addressed materialization", "realpath", "recursive containment", "nested-symlink", "race")):
|
||||
raise SystemExit("missing P6 materialization ownership")
|
||||
no_scope = "P1 performs no acquisition, extraction, preprocessing/indexing, embeddings, Qdrant writes, `ACTIVE` publication, retention, or GC."
|
||||
if no_scope not in contract or re.search(r"P1\s+(?:materializes|extracts|indexes)", contract, re.IGNORECASE):
|
||||
positive_p1_operation = re.compile(
|
||||
r"""\bP1\b(?:\s+(?:also|then|now|directly|itself))*\s+(?:
|
||||
(?:will\s+|must\s+|may\s+|can\s+)?(?:
|
||||
acquires?|materializes?|extracts?|preprocesses?|indexes?|retains?|
|
||||
(?:creates?|generates?)\s+embeddings?|
|
||||
writes?\s+(?:embeddings?\s+)?to\s+Qdrant|
|
||||
publishes?\s+`?ACTIVE\b`?|
|
||||
garbage[- ]collects?|
|
||||
(?:runs?|performs?)\s+(?:retention|GC|garbage[ -]collection)
|
||||
)|
|
||||
(?:owns?|handles?|performs?|is\s+responsible\s+for)\s+(?:Evidence\s+)?(?:
|
||||
acquisition|materialization|extraction|preprocessing|embeddings?|
|
||||
Qdrant\s+writes?|indexing|`?ACTIVE`?\s+publication|retention|GC|
|
||||
garbage[ -]collection
|
||||
)
|
||||
)\b""",
|
||||
re.IGNORECASE | re.VERBOSE,
|
||||
)
|
||||
if no_scope not in contract or positive_p1_operation.search(contract):
|
||||
raise SystemExit("P1 scope violation")
|
||||
|
||||
installation_rows = {row[0]: row[1:] for row in table_for("Installation files")}
|
||||
@@ -454,6 +476,15 @@ for guide in (local_path, server_path):
|
||||
if any(position < 0 for position in positions) or positions != sorted(positions):
|
||||
raise SystemExit(f"{guide.name}: curator flow out of order")
|
||||
|
||||
# Public prose, YAML, and examples may name credential variables and describe forbidden shapes,
|
||||
# but they must never contain a high-confidence access-key literal. Identifier-aware boundaries
|
||||
# avoid treating a legitimate variable name as a credential value.
|
||||
aws_access_key = re.compile(
|
||||
r"(?<![A-Za-z0-9_])(?:AKIA|ASIA)[A-Z0-9]{16}(?![A-Za-z0-9_])"
|
||||
)
|
||||
if aws_access_key.search(all_public):
|
||||
raise SystemExit("credential literal forbidden")
|
||||
|
||||
# Parse dotenv assignments in the core example and fenced public guide blocks. Public examples may
|
||||
# contain paths and query-free identities, but never credential values or unsafe placeholders.
|
||||
def dotenv_lines(path):
|
||||
|
||||
Reference in New Issue
Block a user