fix(evidence): close S3 and smoke safety gaps
This commit is contained in:
@@ -43,3 +43,13 @@ acquisition rejects ETag drift.
|
||||
|
||||
Final correction verification: S3/config focused 20 passed; full harness 721 passed, 5 deselected;
|
||||
real Compose smoke and image build passed; scoped Ruff, shell syntax, and diff checks passed.
|
||||
|
||||
## Final security review correction
|
||||
|
||||
Literal non-global IPv4/IPv6 endpoints now require the private-endpoint opt-in without claiming DNS
|
||||
pinning for hostnames. Pagination uses explicit continuation requests and never fetches page
|
||||
`max_pages + 1`. IP-shaped buckets, leading-slash prefixes, empty/overlong/control-character keys,
|
||||
and absent validators fail closed. Acquisition accepts only the exact stored `SourceObject` and
|
||||
compares the response ETag with the stored discovery validator. The real smoke snapshots generation
|
||||
directory counts after every run and has an injected-failure cleanup mode; cleanup fails if Compose
|
||||
down fails or any owned container, volume, or network remains.
|
||||
|
||||
Reference in New Issue
Block a user