Fix authenticated CHIRP binary object staging - #654
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
ty-everett
left a comment
There was a problem hiding this comment.
Qualified maintainer review accepted exact head f44d09f10e91c2ca170d9f9a03e10540ba3c0967: 39 terminal successful or governed-skip checks, exact-head zero new Sonar findings/unreviewed hotspots and zero CodeQL alerts; no open review threads. Complete diff reviewed: raw staged-object PUT bytes are bounded and parsed before mutual authentication, then the handler streams the same verified bytes to the existing identity/hash/length/quota-aware store. Compressed and oversized requests reject before expensive authentication. JSON routes and legacy streaming uploads retain their behavior, and HEAD wire bytes remain empty. Validation and stage-outcome response handling preserve all existing statuses and error identities. Canonical Lite runtime sources and Cloud copies are byte-identical. Real HTTP fixtures apply the deployed rate-limit stages and fresh transport connections; the controlled idle-expiration failure is reproduced and corrected without retries or relaxed assertions/limits. Full Node22/24 standalone tests, frozen SDK2.8.9 graphs, builds/lint/audits/signatures and all required root controls pass. No schema, persisted-object or CHIRP artifact migration, issue suppression or policy threshold change. Governed version/ledger/docs/copy inventory is current. Protected signed images and live staging-first acceptance remain separate prerequisites.



Authenticated CHIRP object PUTs reached BRC-103 before their binary body was parsed, so valid requests failed verification and the post-auth handler reread an already consumed stream. Lite and Cloud now parse only staged-object PUTs as bounded identity bytes before authentication and stage those same verified bytes. The default 4 MiB limit, signature/identity/hash checks, JSON routes, legacy streaming
/put, HEAD behavior and persisted data remain intact.Program and scope
f44d09f10e91c2ca170d9f9a03e10540ba3c0967.Impact
Verification
npm ci --ignore-scripts, service builds/lint,npm audit --audit-level=highandnpm audit signaturespassed for both frozen standalone graphs.pnpm health:check,lint,format:check, fullbuild,typecheck,node scripts/test-governance.mjsandpnpm audit:securitypassed. Runtime copies/facts/license/operations checks passed through health.Security and dependencies
The generated locks change only root service versions/SDK floors and the SDK2.8.9 record. The new synchronized Cloud parser remains fully analyzed for issues; its exact path is added only to the existing intentional-copy duplication inventory, as required by the repository contract. No analyzer issue exclusion is added.
Release and operations
After reviewed merge and accepted main checks, protected Infra Release builds Linux/amd64 Cloud0.2.48/Lite0.1.45 images, scans and signs immutable digests with SBOM/provenance. Existing images remain the rollback identity. Operator staging-first acceptance, including live signed4 MiB/GCS integrity, paid closure/renewal, default discovery/download and legacy compatibility, is required before production promotion. No service deployment is claimed by this source PR.
Completion evidence