Skip to content

Record replacement-aware provenance for pilot binaries - #78

Merged
cppla merged 1 commit into
mainfrom
codex/pilot-build-provenance
Oct 9, 2026
Merged

cppla merged 1 commit into
mainfrom
codex/pilot-build-provenance

Conversation

@cppla

@cppla cppla commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Scope

Record the actual compiled dependencies used by future small pilots after the maintained QUIC/uTLS replacements. Production transport behavior, default profiles, dependency pins and historical evidence are unchanged.

Changes

  • Add an offline Go build-info reader that never executes the inspected binaries. It hashes the same bytes it parses, validates the command packages and selected dependencies, follows versioned remote replacements, and emits only allowlisted metadata.
  • Bind the report to both AutoCAR and the standard H3 control binary in the pilot configuration. Reject missing/duplicate fields, incorrect hashes, unsupported sources, local replacements, mismatched targets/compiler and inconsistent official QUIC versions. Derive control version labels from the actual report.
  • Retain the report and include it in the campaign's checksum-frozen effective descriptor. Correct the outdated dependency description in the pilot documentation.
  • Repair an existing dependency-gate false positive: ordinary metadata strings are not Go imports. The existing offline tokenizer now enforces the replacement-path restriction on actual imports, including raw-string carriage-return handling. Pins, native transport separation, escaped-import rejection and the separate application-module source restriction remain intact.

Validation

  • Exact Go 1.27.2, dependency fetching disabled: make check, make stealth-tools-check, and the pilot self-test passed.
  • Collector race tests passed three repetitions; independent review reran the collector race test, Python provenance self-test and all 35 dependency-boundary tests.
  • Parsed real stripped Linux/ARM64 AutoCAR/control binaries with the final published dependency pins. Python validation accepted their actual hashes and effective replacements.
  • Ran the Linux/ARM64 collector in a non-root, read-only local Docker container with no network, all capabilities dropped and bounded resources. Its output matched the macOS collector byte-for-byte.

Boundaries

No remote host was changed, no capture campaign was run or resumed, no historical artifact was rewritten, and no release tag was created. This is provenance/tooling validation, not a real-browser comparison or a source-code attestation. No stronger passive-fingerprint claim is made.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 10:02

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@cppla
cppla merged commit 932e56c into main Oct 9, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants