1
0
Fork 0

fix(security): harden 5 adversarial-review findings (M1/M2/M3 + m4/m6) via TDD

Pre-release hardening from an independent adversarial review; each fixed
test-first (failing test -> fix -> green). 214 tests pass.

- entropy (M1): decode-and-rescan now runs BEFORE false-positive suppression,
  so an SRI/media-prefixed injection blob is still decoded and lexicon-rescanned.
  Suppression gates only the entropy finding, never the decode.
- output/disposition (M3): the invisible-carrier invariant now holds on the
  persist gate. scan_output flags zero-width/BIDI presence and disposition
  treats those + lexicon:unicode-tags-present as any-tier carriers, so a carrier
  in model output fails secure even under a trusted policy.
- contract (M2): assert_credential_allowlist catches a bare <PROVIDER>_KEY
  (e.g. STRIPE_KEY) that the old regex silently missed (fail-open). Deliberately
  broad: also flags PARTITION_KEY/SORT_KEY as loud, allowlistable FPs -- fail-loud
  beats fail-silent for an isolation control.
- disposition (m6): guard runs decide inside its guarded block -> total
  fail-closed even on a malformed report.
- output (m4): egress placeholder suppression anchors word markers (example,
  todo, ...) to a word boundary, closing a fail-open where a real secret merely
  containing such a word was suppressed.

Docs: CHANGELOG Security subsection; README honest-limit for lexicon dedup (m5,
documented tradeoff, not fixed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HyRCQMocjZ6SmSQ6JidJ2k
This commit is contained in:
Kjell Tore Guttormsen 2026-07-05 10:45:05 +02:00
commit 5397ba15a1
10 changed files with 233 additions and 18 deletions

View file

@ -78,10 +78,15 @@ def assert_tool_less(request: Mapping[str, object]) -> None:
# --- (b) per-stage credential allowlist ------------------------------------
# Credential-shaped env-var names, matched on the underscore-delimited word
# boundary so ``SECRETARY_NAME`` does not false-positive. Ported verbatim from
# the reference pipeline's proven ``CREDENTIAL_NAME_RE``.
# boundary so ``SECRETARY_NAME`` does not false-positive. Extends the reference
# pipeline's ``CREDENTIAL_NAME_RE`` with a bare ``KEY`` alternative so a
# provider key like ``STRIPE_KEY`` is caught rather than silently missed. This
# is deliberately broad: it also flags non-secret keys (``PARTITION_KEY``,
# ``SORT_KEY``), but that is a LOUD false positive (raises; fixed with a
# one-line allowlist entry), chosen over a silent fail-open on a new provider's
# ``<X>_KEY`` — for an isolation control, fail-loud beats fail-silent (§4.7).
CREDENTIAL_NAME_RE = re.compile(
r"(^|_)(API_?KEY|APIKEY|TOKEN|SECRET|PASSWORD|PASSWD|CREDENTIALS?)(_|$)"
r"(^|_)(API_?KEY|APIKEY|KEY|TOKEN|SECRET|PASSWORD|PASSWD|CREDENTIALS?)(_|$)"
)