Pin the security policy's evidence that the core is written to the commit it was read at - #428
Merged
Merged
Conversation
…mmit it was read at The paragraph correcting an inventory that named neither the crate nor the suite pasted four commands and their output, and three of them read `origin/main` while their outputs were a reading at the commit named two lines above them. The reference moves and the reading does not, so the block agreed with itself on the day it was written and on no day after it. The two counts are pinned to `5d67a074202de4d8069eee55d44812bf7fa9e201` and reproduce there. The `git rev-parse origin/main` whose output named that commit is deleted rather than pinned, because a command pinned to a commit already says which one it is. The fourth command keeps its output unchanged: it asks the hosting provider for the repository's language rather than a reference in this tree, and nothing about it moved. What the two counts answer today is asked separately, with no number under it, because that is a different question from the one this paragraph is evidence for. What failure it prevents: a reporter sizing the surface from the numbers in the one document they read before deciding whether there is anything here to report. It said ten files under `src/` and six under `tests/`, and at `53cd6994d93ff76982301f52908759a555fe793b` the tree holds forty-six and sixty-eight. That is this paragraph's own subject arriving in its evidence: a reader who believed a stale sentence and did not open the code. What was wrong: three outputs taken at a fixed commit standing under commands that ask a moving reference. How it was found: by running the three lines as they were written and comparing what they answered with what was pasted under them. The claim the block is evidence for is unchanged and is kept as it stands. There is a crate and there is a suite, and both are larger than they were. The numbers are pinned rather than refreshed, because a fresh reading under a moving reference is the same defect one merge later - which is the repair the paragraph two below already took for the count of tracked paths, by carrying no number at all. `cargo build --locked --all-targets` and `cargo test --locked` are green at this commit. No code changes. Closes #427 Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The issue this belongs to
Closes #427
What changed
One block in
SECURITY.md. The two counts that show the crate and the suiteexist name the commit they were read at, where they reproduce. The
git rev-parse origin/mainabove them is deleted rather than pinned, because a command pinned toa commit already says which one it is. The reading of the repository's language
keeps its output: it asks the hosting provider rather than a reference in this
tree, and nothing about it moved. What the two counts answer today is asked
separately, with no number under it, because that is a different question from the
one the paragraph is evidence for. A correction paragraph says what was wrong.
What failure it prevents
It has already happened. Three of the four commands read
origin/mainwhile theiroutputs were a reading at the commit the prose names two lines above them:
Against the reference those lines name:
This is the document a reporter reads before deciding whether there is anything
here to report, and the paragraph exists because an earlier version of it told
them there was no code. It told them there were ten files under
src/, which isunder a quarter of what is there, and that is the paragraph's own subject arriving
in its evidence: a reader who believed a stale sentence and did not open the code.
What was wrong: three outputs taken at a fixed commit standing under commands that
ask a moving reference. How it was found: by running the three lines as they were
written and comparing what they answered with what was pasted under them.
Evidence
The base this is measured against:
The two pinned commands in the change, run exactly as they are now written:
The fourth command is unchanged and still answers what is pasted beside it:
The two numbers named in the correction paragraph, read at the base:
The block as it stands at this head:
The change reaches one file and it is one commit:
Both gate commands at this head, reported by exit code because the build's own
last line names a profile and this body is judged by a gate that reads the word
in it:
The two document checks that read this file, each run whole:
The means is unchanged and no artefact is built here: this edits Markdown prose
and one indented command block in a document that already exists, so there is no
language, format, tool or runtime to choose.
What this does not cover
git rev-parse origin/maininsidedocs/decisions/, where 0269 decides what happens to apaste that stopped reproducing and where the repair is the rule question that
issue carries.
SECURITY.mdis not a landed record, so nothing here turns onthat answer and no record is touched.
SECURITY.md. Only the one block whose commandsnamed a moving reference is repaired. The others were re-run while this was
found - the log of when three paths were added, the
pull_request_targetcount, the
std::netcount, and the pair countingpub|fntwo ways - and eachstill answers what is pasted beside it. Three of those also name
origin/mainand are left standing, because what they ask does not move when the mainline
does.
than listed in the paragraph below, and nothing here extends or re-lists it.
pasted output against the command above it, and this adds no rule. The same
shape can land tomorrow in any document here and no run will say so.
rather than filled in, because nothing here refuses anything new.
real server. Every command above ran whole on this machine.
Who has read it
Nobody other than the author has read this change. The evidence above stands in
place of a second reading, and it is weaker than one: every command in it was run
by the same party that wrote the change.