Skip to content

P2 hardening: close seven G01 evidence-packet review gaps #79

Description

@jjangg96

Context

Codex exact-head review of PR #78 at b6dbf021801ef5d920d1a9e7659f8bd97be11695 reported seven P2 findings in the reusable G01 evidence packet. Under the maintainer review policy, these are tracked separately and do not block the current candidate solely by severity.

Source review comment: #78 (comment)

Follow-up findings

  • Path filesystem readers beyond read_text/read_bytes can bypass the reviewed-path boundary: packet lines
  • Environment values from loops/comprehensions are not tainted before sinks: packet lines
  • Launcher aliases obtained through iterable targets can bypass command checks: packet lines
  • Shell export/set forms can dump inherited variables: packet lines
  • Git child environments can forward unrelated credentials: packet lines
  • Exact-head parity does not reject intent-bit or raw-byte divergence: packet lines
  • Git configuration includes are not rejected before read-only commands: packet lines

Acceptance

  • Reproduce each finding with a focused negative test.
  • Add the smallest fail-closed correction for the affected scanner/verification boundary.
  • Preserve safe positive cases and current evidence reuse semantics.
  • Record exact red/green commands, review URLs, and rollback evidence.
  • Re-review only the changed boundary and batch the fixes into one candidate.

This issue is intentionally separate from PR #78 to keep the current delivery moving. Promote it to a blocking gate only if a maintainer explicitly classifies a finding as release, security, data-loss, or live-safety critical.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:P2Future optional scoperisk:highIndependent gpt-luna-max review on risky boundariestype:implementationBounded implementation goal with TDD evidence

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions