docs: Record security audit verdict - #23
BenWestgate wants to merge 4 commits into
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 00470b1f2b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3bc520a5d3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 30e54cab79
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c5ec185f0a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Put planning back in .gitignore. this is a nightmare to review documents the world is not meant to see. Create a separate folder for audit results instead which are at least finished documents not subject to endless nit picking.. |
c5ec185 to
dc0d70a
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dc0d70a46d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f7b86cd9b7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated review (Claude), posted at the maintainer's request.
ACK f7b86cd, with one cross-PR conflict.
- The accident-safety vs tampering split (#28/#57 vs #55) reads accurately, and the 32-bit grind point is stated without overclaiming.
- #21 and #22 closed today. A one-line "Status: fixed in " under each would stop readers treating them as open. Same for #32 once #33 lands.
- Nit: no trailing newline at EOF.
|
Follow-up on the ACK nits: I’m not baking transient PR state into this historical verdict yet. The report intentionally records what was true at audited parent |
|
Release-gate follow-up: the cross-PR conflict noted in the |
f7b86cd to
64bc3e4
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 64bc3e4be3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
BenWestgate
left a comment
There was a problem hiding this comment.
AI-generated release-gate review, posted at the maintainer's request.
ACK 9c5fd5a.
The current one-file audit accurately records the historical findings while separating the release-gate accident-safety control (#28/#57) from the stronger malicious-tampering design work in #55. The no-record fallback is correctly described as an explicit operator waiver/authorization, not independent authentication, and the required recovery invariant matches that distinction. All prior inline findings are resolved and exact-head Python-package run 417 is green.
Nit only: the Markdown file still lacks a final newline. That is non-blocking and can be folded into the final human integration/handoff rather than creating review churn.
|
Agent release-gate review at exact head |
Keep local planning state ignored and publish only the finished audit result in a dedicated audit directory. This narrows the review surface to stable findings and their tracking references. Refs #20.
9c5fd5a to
d07024a
Compare
BenWestgate
left a comment
There was a problem hiding this comment.
Codex current-head audit-verdict re-review: ACK d07024a for content.
The one-file verdict accurately separates the four confirmed implementation findings (#21, #22, #32, #26/#30), the two application-level BIP93 hazards, the falsified opaque-HRP candidate, and the stronger malicious-substitution work deferred to #55. Its recovery invariant matches the live restore stack: independent record evidence first, explicit no-record waiver only when independent evidence is absent. All prior inline findings are resolved.
This draft head has no GitHub workflow run attached, so this review is a content/traceability ACK rather than a fresh CI claim. The missing final newline is still a non-blocking editorial nit. No material audit-tracking blocker found.
What
Record the finished 2026-09-22 python-codex32 security-audit verdict in
docs/audits/while keeping local planning and unfinished review material out of the repository.The audit records confirmed findings, the falsified candidate, protocol/application hazards, and the release recovery boundary. It explicitly separates:
The no-record path is documented as a last-resort waiver/visual authorization, not independent authentication.
Review stack
Base: #33 (
fix-hrp-83-limit). Current head:d07024a.This refresh replayed the four previously reviewed human-authored commits onto the settled runtime/foundation stack. All four stable patch IDs are unchanged. The GitHub diff remains one audit file and all prior review threads are resolved.
Validation
On the stacked candidate through #52:
python -O;git diff --checkpassed.Refs #20.