1.8 KiB
1.8 KiB
Evidence Task 2 Report
Status
Implemented filesystem and explicit-manifest HTTP Evidence source adapters, typed source configuration with legacy compatibility, and factory construction.
Delivered behavior
- Filesystem discovery is deterministic and rooted at a strict canonical directory.
- Symlink/path escapes are rejected before content is exposed.
- Discovery hashing and acquisition reads enforce a configurable byte limit.
- Filesystem fingerprints are content SHA-256 values; stable IDs derive from relative paths.
- HTTP accepts only explicit
http/httpsmanifest entries and keeps transport URLs private. - HTTP provenance strips query strings/fragments, while config and adapter representations hide signed or secret-bearing transport URLs.
- HTTP acquisition uses separate connect/read timeouts, streaming byte limits, bounded redirects, private redirect rejection, and safe transient/permanent error classification.
- HTTP fingerprints prefer a deterministic ETag digest, then Last-Modified, then content SHA-256.
build_evidence_sources(cfg)supports both typedevidence.sourcesentries and the legacysource_rootplusevidence_dirfilesystem configuration.
TDD and verification
- RED: focused tests initially failed during collection because the adapter package did not exist.
- GREEN:
15 passedfor filesystem, HTTP, and resource-config tests. - Full harness:
548 passed, 5 deselected. - Changed-file Ruff: clean.
- Repository-wide Ruff remains non-clean due to 34 pre-existing findings in unrelated test files; no unrelated lint files were modified.
Notes
The approved SourceObject namespace grammar does not permit raw quoted ETags such as
etag:"abc". The adapter therefore uses etag:<sha256-of-opaque-etag>: it preserves ETag-based
change identity without weakening the canonical contract or exposing validator contents.