Skip to content

[Security] Enforce one canonical local-audio resource budget before analysis #781

Description

@seonghobae

Canonical implementation authority

Resource Admission & Decode의 단일 source owner는 PR #866입니다. Live source head는 0cb51e4d042a8f4cd5742086156a307bfe1ffac6, protected base는 develop@314ddeae7b775a4957594b599358c8255617eb2e이며 현재 Open / Ready / mergeable입니다. 이 bounded context를 다른 PR로 fan-out하지 않고 dependent/preservation delta는 완전 승계 전까지 닫지 않습니다.

#1116만 docs/product-technical-gap-baseline.md를 쓰고, #970은 durable Project Persistence, #1160은 protected/released Resource Admission + Project Persistence의 Active Player 소비를 소유합니다. #985는 M4A/commercial-decoder evidence를 계속 보존합니다. #1197의 projectId whitespace/dot invariant는 canonical #866에 독립 RED → 최소 fix로 승계됐고, predecessor branch 자체를 merge/cherry-pick하지 않았습니다.

Current exact GREEN

#866은 344b273c49758d46181511940c4ac16eaa04208b까지 owned-production Python statement/branch 100%와 unintended warning 0을 달성했습니다. 이후 preservation #1197의 remaining invariant를 canonical lane에서 직접 재현했습니다.

  • RED f920a4c2acce56b8eaa43cff09c2d74098c45c0b: " .. ", " . ", " project-1 " 거부와 project-1, my..id 보존.
  • GREEN 0cb51e4d042a8f4cd5742086156a307bfe1ffac6: leading/trailing whitespace와 stripped ./..를 canonical validator에서 fail closed 처리.

Exact 0cb51e4d...의 repository ci run 34666905678은 terminal SUCCESS입니다. Canonical quickcheck와 owned-production 100% coverage gate를 포함하며 build-baseline, Security Scan, SBOM, Semgrep 및 protected 14 required context가 current exact head에서 terminal-success evidence를 보유합니다. 이전 Strix in-progress 기록은 historical이며 current merge blocker가 아닙니다.

Fresh formal review inventory에는 exact 0cb51e4d...에 대한 qualifying non-author APPROVED가 없습니다. 과거 CHANGES_REQUESTED는 dismissed predecessor evidence이고 이후 제출은 COMMENTED입니다. Automated check success를 formal approval로 바꾸어 해석하거나 self/admin approval을 사용하지 않습니다.

Central CodeQL prerequisite — refreshed 2026-09-14

BandScope required direct Analyze (javascript-typescript) / Analyze (python)은 GitHub-managed dynamic CodeQL에서 current-head success evidence를 보유합니다. 별도 organization CodeQL PR compatibility/settlement는 central .github owner 경계이며 BandScope가 copied workflow, synthetic status, duplicate scanner 또는 gate weakening으로 우회하지 않습니다.

Protected .github/main은 현재 ebc69a4016f7668beaef5e3b592d378f22ada684입니다. Bootstrap owner .github#2106은 protected-main advance 14 commits를 ordinary reverse PR #2185로 non-force reconciliation하여 exact 4288590362282074d55ef874291ffc2ba884e93d가 되었고, base도 current protected main@ebc69a...입니다. 이전 handler tuple #2106@1ba96e.../828eaa.../34773233399와 그 repository_dispatch run은 ancestry 변경 전 historical evidence입니다.

그 old handler run은 runner가 배정되지 않은 채 queued였고, central repository 전체에도 대규모 Actions queue가 관찰됐습니다. Queue-only delay는 BandScope source defect가 아니므로 consumer lane에서 cancel/rerun/no-op freshness commit을 만들지 않습니다. 새 #2106 exact head가 생성한 fresh checks와 독립 review만 이후 prerequisite evidence가 될 수 있습니다. #2106 bootstrap protected integration 후 #2040 producer/consumer rollout도 ordinary ancestry와 exact-head validation을 거쳐야 합니다.

Repository-wide warning-free/commercial acceptance는 별도 owner가 계속 소유합니다: clean npm ci moderate advisories는 #1206, production JS >500 kB warning은 #1208, GHAS configuration-comparison continuity는 #1209입니다. #866에 unrelated dependency/frontend/control-plane churn을 섞지 않습니다.

Next acceptance

  1. fix(audio): establish canonical local-audio resource policy #866 source 0cb51e4d...를 새 source-backed finding이 없는 한 그대로 보존합니다.
  2. Central #2106의 new exact head 428859...과 이후 #2040 rollout이 정상 protected integration되는지 fresh live metadata로 검증합니다. Queue-only 상태는 lane-local wait이며 BandScope rerun 사유가 아닙니다.
  3. Unchanged fix(audio): establish canonical local-audio resource policy #866 current head에 대한 qualifying independent non-author approval을 확보하고, 그 review에서 valid finding이 나오면 같은 canonical lane에서 RED → minimal fix → exact-head GREEN으로 수리합니다.
  4. Protected 14 required contexts, central settlement/evidence, independent approval, zero unresolved actionable threads를 같은 final fix(audio): establish canonical local-audio resource policy #866 identity에서 만족한 경우에만 normal protected merge합니다.
  5. #1197과 #1194는 successor가 protected merge까지 source/test/contract/evidence를 완전 승계한 뒤에만 preservation close 후보가 됩니다. #985는 M4A/commercial-decoder capability가 별도로 충족되기 전에는 닫지 않습니다.
  6. Protected fix(audio): establish canonical local-audio resource policy #866 이후 fix(project): stage saves before atomic publication #970 crash-safe Project Persistence → feat(player): admit and bind playable stem artifacts #1160 Active Player consumption 순으로 ordinary non-force reconciliation합니다.

Persistence and commercial boundary

Feature-cache manifest-last ordering은 content-generation binding이지 fsync-backed final rehearsal-result crash durability가 아닙니다. Final result cache, project restart/recovery, stale generation rejection은 Project Persistence owner에서 처리합니다.

Windows에는 race-free Job Object containment가 남아 있습니다. Rights-cleared full-length rehearsal audio로 cancellation latency, inherited handle/pipe return, abnormal-child cleanup, decoder/resampler/downstream peak RSS/VRAM, explicit CPU/GPU budgets, recognized MIR reproducibility metrics를 입증해야 합니다.

#866은 Ready이지만 아직 merge-authorized가 아닙니다. UI Delivery Gate: FAIL / Commercial Release Gate: FAIL. #1129, #1180, #1181은 각각 format/licensing, immutable model/update, separation-model commercial-rights owner boundary를 유지합니다.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: apiAPI, protocol, event, or external contractarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: dataDatabase, schema, migration, ETL, or lineagearea: securitySecurity boundary, hardening, or vulnerability preventionenhancementNew feature or requestpriority: mediumNormal-priority or P2 workstatus: triagedOpen issue has an organization taxonomy assignmenttype: featureNew or expanded product capability

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions