Repository navigation
Enforce explicit egress and scope operator file exports (SPEC-007 4.9) - #744
Open
IanFrelinger wants to merge 11 commits into
Open
IanFrelinger wants to merge 11 commits into
IanFrelinger wants to merge 11 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Explicit egress sites recorded denied decisions but still sent data, wrote exports, or launched working-tree code. This implements SPEC-007 4.9: each site now refuses before the operation or follows its defined graceful-degradation behavior when enforcement is enabled. The default profile switch remains the separate 4.11 phase.
Changes
--no-buildor--no-restore. Docker CLI classification requires recognized network-off/no-pull arguments and a local daemon selection.Testing
All local .NET commands ran through
scripts/test-in-container.shon Linux against committed source.make build-core: passed.make test-prod-style: 131 passed, zero skipped; nonzero-test guard passed.bash scripts/run-cert-gate.sh: 3,174 passed, zero skipped; discovery floor and skip guard passed.bash scripts/ci/run-repo-gates.sh: all 28 passed.make composition-mesh-gate-tier-b: three bridge tests passed, zero skipped; nonzero-test guard passed.e4b7dbff: intended assertion failures, exact source restoration, clean state, and passing reruns. The 21 cases affected by the macOS test transport correction were re-proved against19609af9; the final documentation commit changes no mutation target or test source. Fresh CLI checks passed 63 tests, canonical certification passed 3,174 tests (both zero skips), and all 28 repository gates passed.Testing strategy (blast radius)
The changed API paths have real WebApplicationFactory tests. Docker execution guards use loopback transport twins that assert refusal before any daemon request and verify transport is reached in report mode. On the previous candidate
f9f3f832, Kernel Tier A passed in PR CI (46, 22, and 107 tests; zero skips). Kernel coverage passed: Domain 100%, Infrastructure 84.43%, Core.Application 71.55%. The coverage test runs passed 83, 5,139, and 407 tests respectively; Infrastructure retained eight skips. Canonical certification separately passed all 3,174 tests with zero skips. UAT and all three cross-platform loop checks also passed. Its macOS readiness lane exposed an unavailable multicast route in the discovery test. Commit19609af9uses an internal instance-scoped send boundary and real loopback delivery, retaining zero-send refusal, continued listening, multicast destination, and positive-send assertions. Production multicast behavior is unchanged. Fresh CI is required on that correction.Checklist
Release
Coordinated integration
[coordinated-integration] SPEC-007 4.9 requires an atomic cross-layer change: Abstractions defines the initiator and guard semantics, Infrastructure enforces explicit and process routes, and application CLI/API paths handle refusals and scoped operator exports. These pieces must ship together to avoid leaving routes unenforced or breaking operator exports.