Skip to content

v0.4.3

Choose a tag to compare

@github-actions github-actions released this 23 Sep 19:24
· 9 commits to develop since this release

Release v0.4.3 – Cross-Platform Absolute Path Evasion Defense & Validation Taxonomy Reconciliation

Release v0.4.3 delivers critical defensive security hardening against cross-platform absolute path evasion, patches a multi-line YAML frontmatter smuggling bypass in Markdown concept bodies, clarifies and reconciles the CLI validation taxonomy and summary counters, and broadens automated audit remediation discovery.


1. Cross-Platform Absolute Path Evasion Defense (#37)

  • Cross-Platform IsAbsPath Engine: Introduced pkg/okf/path.go providing runtime OS-agnostic absolute path detection. Standard filepath.IsAbs is host-dependent and fails to detect Windows drive letters (e.g. C:\, D:/) on POSIX systems or leading POSIX slashes on Windows.
  • Boundary Enforcement Across Subsystems: Applied IsAbsPath checks across all entry points:
    • ensureWithinRoot (pkg/okf/bundle.go): Confinement checks reject foreign absolute path specifications before path resolution.
    • resolveInBundle (pkg/okf/mutate.go): Concept mutations reject absolute paths upfront.
    • ValidateConceptID (pkg/okf/mutate.go): Prohibits absolute concept IDs across platforms.
    • resolveBundleDir (cmd/okf/mcp.go): Confinement checks prevent escaping the MCP server root via Windows drive paths.
    • Validate (pkg/okf/validator.go): Enforces that code_refs must be relative paths.
  • Test Coverage: Added comprehensive unit tests in pkg/okf/path_test.go, mutation test suites in pkg/okf/mutate_security_test.go, and cross-platform traversal vectors in cmd/okf/mcp_test.go.

2. Multi-Line YAML Frontmatter Smuggling Defense (#36)

  • Delimiter State Persistence: Fixed an edge case in pkg/okf/mutate.go:sanitizeConceptMetadata where the inDelimiter toggle state was prematurely cleared upon evaluating non-matching lines within nested --- blocks.
  • Anti-Spoofing Assertion: Smuggled frontmatter blocks containing reserved keys (verified:, governance:, generated:, type:, status:) are now deterministically detected and rejected even if preceded by unreserved metadata lines inside body blocks.
  • Negative Unit Testing: Added smuggled multi-line frontmatter block in body test case to pkg/okf/mutate_security_test.go.

3. Validation Findings Taxonomy & Count Reconciliation (#35)

  • Taxonomy Separation: Refactored cmd/okf/main.go validate reporting to cleanly distinguish and format:
    • Structural errors (res.Errors)
    • Quality and connectivity warnings (res.Warnings)
    • Epistemic gate findings (res.GateFindings)
  • Summary Counter Alignment: Reconciled summary reporting so displayed error, warning, and gate finding totals match the printed findings deterministically across both standard and --strict validation runs.
  • Verification Suites: Added cmd/okf/validate_output_test.go covering clean runs, pure warnings, pure gate findings, mixed outputs, and strict promotion behavior.

4. Automated Security Workflow Expansion

  • Discovery Pattern Expansion: Updated scripts/jules-flow.sh and knowledge/convention/security-audit.md to discover remediation branches matching fix-abs-path-*, security-harden-*, fix-cwe22-*, and fix-mcp-* alongside security-audit-* and jules-*.

Community & Special Thanks

  • Matt (@mattgdrums-cloud) — Detailed bug report, root-cause diagnosis, and taxonomy reconciliation proposal for CLI validate warning and gate counts (#35).

Pre-Built Binaries

Pre-compiled standalone binaries for macOS, Linux, and Windows are available in the release assets on GitHub:

  • macOS (darwin/arm64, darwin/amd64)
  • Linux (linux/amd64, linux/arm64)
  • Windows (windows/amd64, windows/arm64)

Full Changelog

See commits between v0.4.2...v0.4.3 on GitHub.