Skip to content

test(sentinel): complete bounded external evidence acceptance - #217

Merged
sodejm merged 2 commits into
mainfrom
codex/issue-207-sentinel-evidence
Oct 6, 2026
Merged

sodejm merged 2 commits into
mainfrom
codex/issue-207-sentinel-evidence

Conversation

@sodejm

@sodejm sodejm commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Sentinel's external-evidence pipeline enforced its input and integrity boundaries, but lacked acceptance coverage for exact limits, nested pointers, and specific identity/hash failures. This change proves those cases and documents the provenance and omissions an operator must retain when partitioning or summarizing evidence.

Closes #207.

Acceptance criteria

  • Exact 4 MiB external-evidence and 1 MiB parameter files pass the public loaders, alongside existing over-limit rejection cases.
  • Nested content-addressed SBOM, provenance, secret-scan, and reproducible-build artifacts pass integrity validation.
  • Stale subjects, individual artifact hash mismatches, and missing/mismatched host identities fail closed. Host identity cases mutate a valid 2,160-run cross-host baseline.
  • Operations guidance requires source provenance, disclosed omissions, coverage consequences, and next actions.
  • Synthetic/manual tests retain withheld production assurance. Live Microsoft tenant execution and external attestation remain outside this change.

Evidence

  • Original issue implementation: 14 focused Sentinel tests passed and independent review found no actionable findings. A later integrated local revision additionally passed 16 tests, including the hostname regression follow-up.
  • Full make check passed in the dedicated checkout using the repository virtual environment.
  • git diff --check passed; the committed worktree is clean.
  • Whole-repository Ruff passed after integration with current main.
  • Independent Codex review covered original issue head ee65998f5008f099ad01bd5c45eba00147be46f4. The separately merged head was d99a1deaad1a1ab66910a79a4729cb1fb5691b74; later local review covered integration head 6ef1845386f2615d2af90a25a418ed6f1083342f, which was not part of this PR merge.
  • All 17 hosted checks passed on merged head d99a1deaad1a1ab66910a79a4729cb1fb5691b74. PR merged at 42cb017012934839702ce0b939a5cbc9193271ea. The preservation of the upstream exact-hostname regression is submitted separately in Restore Sentinel authoritative-hostname regression #219 (commit 50a1468).

Impact review

  • Tests: adds acceptance coverage; no validator behavior changed.
  • Documentation: updates the Sentinel operations guide with provenance and omission requirements.
  • Architecture/migrations: no schema, dependency, or migration changes.
  • Security/privacy/abuse: negative fixtures prove identity and content-addressed integrity failures do not grant assurance; synthetic fixtures contain no tenant credentials.
  • Operations/rollback: existing evidence limits remain unchanged. Rollback removes the new tests and guidance only.

Risks and residual uncertainty

This is offline acceptance evidence. No Microsoft service or live tenant execution occurred. Accepted external fixtures remain manually supplied and unattested; production efficacy, cost, latency, false-positive performance, and external authenticity remain unverified.

@sodejm
sodejm marked this pull request as ready for review October 6, 2026 01:56
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-06T01:59:01.358252Z d99a1de Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@sodejm
sodejm merged commit 42cb017 into main Oct 6, 2026
17 checks passed
@sodejm
sodejm deleted the codex/issue-207-sentinel-evidence branch October 6, 2026 01:58
sodejm added a commit that referenced this pull request Oct 8, 2026
Follow up on #207 and merged PR #217 by restoring coverage for deceptive hostname, path, and user-info URLs.

[skip-docs: test-only restoration; the merged hostname behavior and its documentation are unchanged]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Complete Sentinel bounded-input and external-evidence acceptance coverage

1 participant