Skip to content

Fix authenticated CHIRP binary object staging - #654

Merged
ty-everett merged 2 commits into
mainfrom
codex/chirp-authenticated-binary-body-20260927
Sep 27, 2026
Merged

ty-everett merged 2 commits into
mainfrom
codex/chirp-authenticated-binary-body-20260927

Conversation

@ty-everett

@ty-everett ty-everett commented Sep 27, 2026 •

Copy link
Copy Markdown
Collaborator

Authenticated CHIRP object PUTs reached BRC-103 before their binary body was parsed, so valid requests failed verification and the post-auth handler reread an already consumed stream. Lite and Cloud now parse only staged-object PUTs as bounded identity bytes before authentication and stage those same verified bytes. The default 4 MiB limit, signature/identity/hash checks, JSON routes, legacy streaming /put, HEAD behavior and persisted data remain intact.

Program and scope

  • Tracker: UHRP service recovery; SDK prerequisite #653, published and verified release36297773288.
  • Program gates: correct binary authentication pipeline, registry-frozen SDK floor and signed service release inputs.
  • Scope: Cloud Bucket0.2.48 and Lite0.1.45; synchronized parser/copy policy, route tests, generated facts and verified SDK publication reconciliation. CHIRP0.1.3 artifact is unchanged.
  • Out of scope: deployed infrastructure/configuration, schema/object/advertisement migrations and npm package publication.
  • Exact head: f44d09f10e91c2ca170d9f9a03e10540ba3c0967.

Impact

  • Infrastructure source, dependency, image, or deployment configuration changed
  • Security-sensitive boundary changed
  • Documentation or examples changed

Verification

  • Node22.21.1 and24.18.0: Lite100 tests/13 suites and Cloud105 tests/19 suites passed against published SDK2.8.9.
  • Real mutually authenticated loopback cases: exact non-text bytes, complete4 MiB, empty bytes, raw bytes with JSON MIME, changed-after-signing401/no staging, oversized413, gzip/br/deflate415, ordinary JSON compatibility and existing bodyless HEAD regressions.
  • npm ci --ignore-scripts, service builds/lint, npm audit --audit-level=high and npm audit signatures passed for both frozen standalone graphs.
  • pnpm health:check, lint, format:check, full build, typecheck, node scripts/test-governance.mjs and pnpm audit:security passed. Runtime copies/facts/license/operations checks passed through health.
  • Real HTTP fixtures retain both deployed rate-limit stages and use a fresh physical connection per request. A controlled idle-expiration experiment reproduced the original shared-pool handshake connection reset and passed with the corrected transport under the same pause. Both full service suites then passed Node22/24, including concurrent validation. Production connection policy, timeouts, body bounds and test assertions remain unchanged.
  • All exact-head hosted CI, image scans, runtime contracts, conformance, package/doc consumers and analysis checks passed. Sonar reports zero new findings/unreviewed hotspots; both exact-tree CodeQL analyses report zero results. No open review threads.
  • Conformance: no codec, wire, schema or shared vector changed; real HTTP service regressions cover the changed boundary. SDK prerequisite passed6,700 conformance assertions and exact packed/browser consumers before publication.
  • Coverage/performance: no threshold changed. One bounded4 MiB buffer is authenticated and streamed to the existing object validator/store; configured service resources remain unchanged.
  • Complete local diff self-reviewed for correctness, security, compatibility, dependencies, docs and operations
  • All applicable hosted checks terminal and successful on this exact head

Security and dependencies

  • Release necessity, runtime/peer compatibility, deduplicated graph and audits reviewed
  • Negative/boundary tests cover the changed trust boundary
  • Exact-head CodeQL has no new alert
  • Exact-head Sonar has zero new findings and unreviewed hotspots
  • No new override, advisory dismissal, issue suppression or skipped test
  • Lifecycle scripts remain denied

The generated locks change only root service versions/SDK floors and the SDK2.8.9 record. The new synchronized Cloud parser remains fully analyzed for issues; its exact path is added only to the existing intentional-copy duplication inventory, as required by the repository contract. No analyzer issue exclusion is added.

Release and operations

  • No workstation or PR npm publication
  • Intended service patch versions and migration guidance included
  • Image/SBOM/provenance/deployment/rollback impact documented

After reviewed merge and accepted main checks, protected Infra Release builds Linux/amd64 Cloud0.2.48/Lite0.1.45 images, scans and signs immutable digests with SBOM/provenance. Existing images remain the rollback identity. Operator staging-first acceptance, including live signed4 MiB/GCS integrity, paid closure/renewal, default discovery/download and legacy compatibility, is required before production promotion. No service deployment is claimed by this source PR.

Completion evidence

  • Hosted checks, qualified final maintainer review and review-thread resolution complete
  • Documentation, release notes, generated facts and operator compatibility guidance current
  • One qualified maintainer approval is sufficient

@socket-security

socket-security Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​bsv/​sdk@​2.8.9741001009980

View full report

Comment thread infra/uhrp-server-basic/test/chirpUploadAuthentication.test.js Fixed
Comment thread infra/uhrp-server-basic/test/chirpUploadAuthentication.test.js Fixed
@sonarqubecloud

Copy link
Copy Markdown

@ty-everett
ty-everett marked this pull request as ready for review September 27, 2026 06:34

@ty-everett ty-everett left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Qualified maintainer review accepted exact head f44d09f10e91c2ca170d9f9a03e10540ba3c0967: 39 terminal successful or governed-skip checks, exact-head zero new Sonar findings/unreviewed hotspots and zero CodeQL alerts; no open review threads. Complete diff reviewed: raw staged-object PUT bytes are bounded and parsed before mutual authentication, then the handler streams the same verified bytes to the existing identity/hash/length/quota-aware store. Compressed and oversized requests reject before expensive authentication. JSON routes and legacy streaming uploads retain their behavior, and HEAD wire bytes remain empty. Validation and stage-outcome response handling preserve all existing statuses and error identities. Canonical Lite runtime sources and Cloud copies are byte-identical. Real HTTP fixtures apply the deployed rate-limit stages and fresh transport connections; the controlled idle-expiration failure is reproduced and corrected without retries or relaxed assertions/limits. Full Node22/24 standalone tests, frozen SDK2.8.9 graphs, builds/lint/audits/signatures and all required root controls pass. No schema, persisted-object or CHIRP artifact migration, issue suppression or policy threshold change. Governed version/ledger/docs/copy inventory is current. Protected signed images and live staging-first acceptance remain separate prerequisites.

@ty-everett
ty-everett merged commit 753854b into main Sep 27, 2026
39 checks passed
@ty-everett
ty-everett deleted the codex/chirp-authenticated-binary-body-20260927 branch September 27, 2026 06:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants