fix(calibration): grade active content on URL shape, not construct type
v0.3.0 made the untrusted upload path unusable: measured on both doors, an ordinary remote image fail_secure'd and an ordinary link/autolink/refdef quarantined, so only documents without external references persisted. Two independent defects compounded; neither fix works alone: 1. `markdown-image: HIGH` fired on any external image. The exfil primitive is a URL that moves bytes outward, not an image. `is_ordinary_url` now grades on shape - http(s)/protocol-relative, no query, no userinfo, no percent-escape, no opaque host label or path segment -> LOW; anything data-carrying keeps the carrier's severity. raw-html and data: URIs stay HIGH unconditionally. Opacity reuses entropy's primitives; floors calibrated against real doc URLs (worst legit token H=4.08, exfil segments 4.36-4.54) and frozen in calibration. 2. The quarantine_default floor fired on ANY finding, a premise that broke when every ordinary link became a finding. It now fires at MEDIUM+ - a no-op for every detector that shipped before 0.3.0 (no LOW/INFO exists), which is what makes this a patch rather than a minor. The corpus blind spot that let this pass 522 green tests is closed: the FP corpus carries realistic markdown and is asserted on the OUTPUT gate under PRESET_USER_UPLOAD, with a counter-corpus of exfil-shaped URLs that must still block. Beaconing and short opaque segments are conceded in LIMITATIONS and asserted by the coverage matrix rather than papered over. No new public API; no new preset (0.4.0 work); allow_reserved default unchanged.
This commit is contained in:
parent
da7421e6c8
commit
6e9b8168e3
13 changed files with 533 additions and 46 deletions
|
|
@ -197,12 +197,28 @@ def test_guard_disposes_findings_like_decide():
|
|||
|
||||
# --- Presets --------------------------------------------------------------
|
||||
|
||||
def test_user_upload_preset_quarantines_any_finding():
|
||||
# a single LOW finding that would WARN under a plain policy -> QUARANTINE here.
|
||||
report = _report(_finding(severity=Severity.LOW, label="lexicon:soft"))
|
||||
def test_user_upload_preset_holds_medium_for_review():
|
||||
report = _report(_finding(severity=Severity.MEDIUM, label="lexicon:config"))
|
||||
assert decide(report, PRESET_USER_UPLOAD).disposition is Disposition.QUARANTINE_REVIEW
|
||||
|
||||
|
||||
def test_user_upload_floor_does_not_fire_on_a_lone_low_finding():
|
||||
# 0.3.1: the floor fires at MEDIUM+, not on ANY finding. "Any finding ->
|
||||
# review" rested on the premise that findings are the exception; that premise
|
||||
# broke the moment every ordinary markdown link became a (LOW) finding, and
|
||||
# the floor then quarantined documents whose only sin was having a link.
|
||||
report = _report(_finding(severity=Severity.LOW, label="active:markdown-link"))
|
||||
assert decide(report, PRESET_USER_UPLOAD).disposition is Disposition.WARN
|
||||
|
||||
|
||||
def test_quarantine_floor_still_lifts_a_semi_trusted_policy():
|
||||
# The floor is not dead weight: a caller-defined TRUSTED policy that opts into
|
||||
# quarantine_default still lifts a MEDIUM finding that trust alone would WARN.
|
||||
semi_trusted = Policy(trust=Trust.TRUSTED, quarantine_default=True)
|
||||
report = _report(_finding(severity=Severity.MEDIUM, label="lexicon:config"))
|
||||
assert decide(report, semi_trusted).disposition is Disposition.QUARANTINE_REVIEW
|
||||
|
||||
|
||||
def test_user_upload_preset_hard_fails_on_critical():
|
||||
report = _report(_finding(severity=Severity.CRITICAL, label="lexicon:override"))
|
||||
assert decide(report, PRESET_USER_UPLOAD).disposition is Disposition.FAIL_SECURE
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue