v0.4.3
Release v0.4.3 – Cross-Platform Absolute Path Evasion Defense & Validation Taxonomy Reconciliation
Release v0.4.3 delivers critical defensive security hardening against cross-platform absolute path evasion, patches a multi-line YAML frontmatter smuggling bypass in Markdown concept bodies, clarifies and reconciles the CLI validation taxonomy and summary counters, and broadens automated audit remediation discovery.
1. Cross-Platform Absolute Path Evasion Defense (#37)
- Cross-Platform
IsAbsPathEngine: Introducedpkg/okf/path.goproviding runtime OS-agnostic absolute path detection. Standardfilepath.IsAbsis host-dependent and fails to detect Windows drive letters (e.g.C:\,D:/) on POSIX systems or leading POSIX slashes on Windows. - Boundary Enforcement Across Subsystems: Applied
IsAbsPathchecks across all entry points:ensureWithinRoot(pkg/okf/bundle.go): Confinement checks reject foreign absolute path specifications before path resolution.resolveInBundle(pkg/okf/mutate.go): Concept mutations reject absolute paths upfront.ValidateConceptID(pkg/okf/mutate.go): Prohibits absolute concept IDs across platforms.resolveBundleDir(cmd/okf/mcp.go): Confinement checks prevent escaping the MCP server root via Windows drive paths.Validate(pkg/okf/validator.go): Enforces thatcode_refsmust be relative paths.
- Test Coverage: Added comprehensive unit tests in
pkg/okf/path_test.go, mutation test suites inpkg/okf/mutate_security_test.go, and cross-platform traversal vectors incmd/okf/mcp_test.go.
2. Multi-Line YAML Frontmatter Smuggling Defense (#36)
- Delimiter State Persistence: Fixed an edge case in
pkg/okf/mutate.go:sanitizeConceptMetadatawhere theinDelimitertoggle state was prematurely cleared upon evaluating non-matching lines within nested---blocks. - Anti-Spoofing Assertion: Smuggled frontmatter blocks containing reserved keys (
verified:,governance:,generated:,type:,status:) are now deterministically detected and rejected even if preceded by unreserved metadata lines inside body blocks. - Negative Unit Testing: Added
smuggled multi-line frontmatter block in bodytest case topkg/okf/mutate_security_test.go.
3. Validation Findings Taxonomy & Count Reconciliation (#35)
- Taxonomy Separation: Refactored
cmd/okf/main.govalidate reporting to cleanly distinguish and format:- Structural errors (
res.Errors) - Quality and connectivity warnings (
res.Warnings) - Epistemic gate findings (
res.GateFindings)
- Structural errors (
- Summary Counter Alignment: Reconciled summary reporting so displayed error, warning, and gate finding totals match the printed findings deterministically across both standard and
--strictvalidation runs. - Verification Suites: Added
cmd/okf/validate_output_test.gocovering clean runs, pure warnings, pure gate findings, mixed outputs, and strict promotion behavior.
4. Automated Security Workflow Expansion
- Discovery Pattern Expansion: Updated
scripts/jules-flow.shandknowledge/convention/security-audit.mdto discover remediation branches matchingfix-abs-path-*,security-harden-*,fix-cwe22-*, andfix-mcp-*alongsidesecurity-audit-*andjules-*.
Community & Special Thanks
- Matt (@mattgdrums-cloud) — Detailed bug report, root-cause diagnosis, and taxonomy reconciliation proposal for CLI validate warning and gate counts (#35).
Pre-Built Binaries
Pre-compiled standalone binaries for macOS, Linux, and Windows are available in the release assets on GitHub:
- macOS (
darwin/arm64,darwin/amd64) - Linux (
linux/amd64,linux/arm64) - Windows (
windows/amd64,windows/arm64)
Full Changelog
See commits between v0.4.2...v0.4.3 on GitHub.