# Evidence Task 2 Report ## Status Implemented filesystem and explicit-manifest HTTP Evidence source adapters, typed source configuration with legacy compatibility, and factory construction. ## Delivered behavior - Filesystem discovery is deterministic and rooted at a strict canonical directory. - Symlink/path escapes are rejected before content is exposed. - Discovery hashing and acquisition reads enforce a configurable byte limit. - Filesystem fingerprints are content SHA-256 values; stable IDs derive from relative paths. - HTTP accepts only explicit `http`/`https` manifest entries and keeps transport URLs private. - HTTP provenance strips query strings/fragments, while config and adapter representations hide signed or secret-bearing transport URLs. - HTTP acquisition uses separate connect/read timeouts, streaming byte limits, bounded redirects, private redirect rejection, and safe transient/permanent error classification. - HTTP fingerprints prefer a deterministic ETag digest, then Last-Modified, then content SHA-256. - `build_evidence_sources(cfg)` supports both typed `evidence.sources` entries and the legacy `source_root` plus `evidence_dir` filesystem configuration. ## TDD and verification - RED: focused tests initially failed during collection because the adapter package did not exist. - GREEN: `15 passed` for filesystem, HTTP, and resource-config tests. - Full harness: `548 passed, 5 deselected`. - Changed-file Ruff: clean. - Repository-wide Ruff remains non-clean due to 34 pre-existing findings in unrelated test files; no unrelated lint files were modified. ## Notes The approved `SourceObject` namespace grammar does not permit raw quoted ETags such as `etag:"abc"`. The adapter therefore uses `etag:`: it preserves ETag-based change identity without weakening the canonical contract or exposing validator contents.