Skip to content

docs: Record security audit verdict - #23

Draft
BenWestgate wants to merge 4 commits into
fix-hrp-83-limitfrom
20-security-audit-docs
Draft

BenWestgate wants to merge 4 commits into
fix-hrp-83-limitfrom
20-security-audit-docs

Conversation

@BenWestgate

@BenWestgate BenWestgate commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

What

Record the finished 2026-09-22 python-codex32 security-audit verdict in docs/audits/ while keeping local planning and unfinished review material out of the repository.

The audit records confirmed findings, the falsified candidate, protocol/application hazards, and the release recovery boundary. It explicitly separates:

The no-record path is documented as a last-resort waiver/visual authorization, not independent authentication.

Review stack

Base: #33 (fix-hrp-83-limit). Current head: d07024a.

This refresh replayed the four previously reviewed human-authored commits onto the settled runtime/foundation stack. All four stable patch IDs are unchanged. The GitHub diff remains one audit file and all prior review threads are resolved.

Validation

On the stacked candidate through #52:

  • 950 tests passed normally;
  • 950 tests passed under python -O;
  • Ruff check and format check passed;
  • strict mypy passed for 21 source files;
  • workflow YAML parsed successfully;
  • git diff --check passed.

Refs #20.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 00470b1f2b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .gitignore Outdated
Comment thread docs/planning/usability-appraisal.md Outdated
Comment thread docs/planning/build_alignment_report.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3bc520a5d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/security/audit-2026-09-22.md Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 30e54cab79

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/security/invariants.md Outdated
Comment thread docs/planning/resume_alignment_benchmarks.py Outdated
Comment thread docs/planning/resume_alignment_benchmarks.py Outdated

@baslabofhd777-lab baslabofhd777-lab left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c5ec185f0a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/planning/build_alignment_report.py Outdated
Comment thread docs/planning/gui-plan.md Outdated
@BenWestgate

Copy link
Copy Markdown
Owner Author

Put planning back in .gitignore. this is a nightmare to review documents the world is not meant to see. Create a separate folder for audit results instead which are at least finished documents not subject to endless nit picking..

@BenWestgate
BenWestgate force-pushed the 20-security-audit-docs branch from c5ec185 to dc0d70a Compare September 23, 2026 12:11
@BenWestgate BenWestgate changed the title docs: Restore audit planning and verdict docs: Record security audit verdict Sep 23, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: dc0d70a46d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/audits/security-2026-09-22.md
Comment thread docs/audits/security-2026-09-22.md Outdated
@BenWestgate BenWestgate added gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review. area: security Security invariants, hardening, and security-sensitive boundaries. documentation Improvements or additions to documentation labels Sep 24, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f7b86cd9b7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/audits/security-2026-09-22.md

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated review (Claude), posted at the maintainer's request.

ACK f7b86cd, with one cross-PR conflict.

  • The accident-safety vs tampering split (#28/#57 vs #55) reads accurately, and the 32-bit grind point is stated without overclaiming.
  • #21 and #22 closed today. A one-line "Status: fixed in " under each would stop readers treating them as open. Same for #32 once #33 lands.
  • Nit: no trailing newline at EOF.

Comment thread docs/audits/security-2026-09-22.md Outdated

Copy link
Copy Markdown
Owner Author

Follow-up on the ACK nits: I’m not baking transient PR state into this historical verdict yet. The report intentionally records what was true at audited parent c118a83; #21/#22 are already fixed on reviewability-v1, #32 remains pending #33, and the restore finding remains pending #57/#28 integration. When those release-gate fixes land, add a compact “Status after audit” section (rather than rewriting each finding as if it were true at c118a83) and fix the EOF newline in that same doc-only touch. No security conclusion is blocked on those editorial nits.

Copy link
Copy Markdown
Owner Author

Release-gate follow-up: the cross-PR conflict noted in the f7b86cd ACK is resolved by current #57 head dcc0d41, which restores the no-record codex32/Bails/Bails-alpha identifier evidence and has been independently re-verified for verify-before-mutate. The published-audit sequencing condition is also satisfied because the cache-bound and secret-rendering fixes are already on reviewability-v1. The remaining review notes are editorial/historical-status nits; #32 should only be marked fixed in the audit after #33 actually lands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 64bc3e4be3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/audits/security-2026-09-22.md Outdated
@BenWestgate BenWestgate added the area: packaging/release Packaging, artifacts, compatibility, and release qualification. label Sep 30, 2026 — with ChatGPT Codex Connector

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-generated release-gate review, posted at the maintainer's request.

ACK 9c5fd5a.

The current one-file audit accurately records the historical findings while separating the release-gate accident-safety control (#28/#57) from the stronger malicious-tampering design work in #55. The no-record fallback is correctly described as an explicit operator waiver/authorization, not independent authentication, and the required recovery invariant matches that distinction. All prior inline findings are resolved and exact-head Python-package run 417 is green.

Nit only: the Markdown file still lacks a final newline. That is non-blocking and can be folded into the final human integration/handoff rather than creating review churn.

Copy link
Copy Markdown
Owner Author

Agent release-gate review at exact head 9c5fd5a: the audit record now accurately separates validated implementation findings from protocol/application hazards, explicitly marks the opaque-HRP candidate as falsified, and distinguishes the release-gate fingerprint/no-record accident-safety control from #55's stronger malicious-tampering design. Its required restore invariant matches the current #57/#28 direction. Exact-head Python-package run 36532244956 succeeded. No documentation blocker found; the missing final newline is non-functional and not worth another churn commit. Review after the underlying #33/#57 behavior is settled so the recorded status remains true.

Keep local planning state ignored and publish only the finished audit result in a dedicated audit directory. This narrows the review surface to stable findings and their tracking references.

Refs #20.
@BenWestgate
BenWestgate force-pushed the 20-security-audit-docs branch from 9c5fd5a to d07024a Compare October 2, 2026 01:06
@BenWestgate
BenWestgate changed the base branch from reviewability-v1 to fix-hrp-83-limit October 2, 2026 01:06

@BenWestgate BenWestgate left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Codex current-head audit-verdict re-review: ACK d07024a for content.

The one-file verdict accurately separates the four confirmed implementation findings (#21, #22, #32, #26/#30), the two application-level BIP93 hazards, the falsified opaque-HRP candidate, and the stronger malicious-substitution work deferred to #55. Its recovery invariant matches the live restore stack: independent record evidence first, explicit no-record waiver only when independent evidence is absent. All prior inline findings are resolved.

This draft head has no GitHub workflow run attached, so this review is a content/traceability ACK rather than a fresh CI claim. The missing final newline is still a non-blocking editorial nit. No material audit-tracking blocker found.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging/release Packaging, artifacts, compatibility, and release qualification. area: security Security invariants, hardening, and security-sensitive boundaries. documentation Improvements or additions to documentation gate: adversarial review Resolve, merge, or explicitly defer before the next full adversarial review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants