From 8c40f23bc75496c25c2e5fd6b8e1c5752edcdc44 Mon Sep 17 00:00:00 2001 From: Nils Lehnen <30603423+iderex@users.noreply.github.com> Date: Thu, 17 Sep 2026 23:43:21 +0200 Subject: [PATCH] Pin the security policy's evidence that the core is written to the commit it was read at The paragraph correcting an inventory that named neither the crate nor the suite pasted four commands and their output, and three of them read `origin/main` while their outputs were a reading at the commit named two lines above them. The reference moves and the reading does not, so the block agreed with itself on the day it was written and on no day after it. The two counts are pinned to `5d67a074202de4d8069eee55d44812bf7fa9e201` and reproduce there. The `git rev-parse origin/main` whose output named that commit is deleted rather than pinned, because a command pinned to a commit already says which one it is. The fourth command keeps its output unchanged: it asks the hosting provider for the repository's language rather than a reference in this tree, and nothing about it moved. What the two counts answer today is asked separately, with no number under it, because that is a different question from the one this paragraph is evidence for. What failure it prevents: a reporter sizing the surface from the numbers in the one document they read before deciding whether there is anything here to report. It said ten files under `src/` and six under `tests/`, and at `53cd6994d93ff76982301f52908759a555fe793b` the tree holds forty-six and sixty-eight. That is this paragraph's own subject arriving in its evidence: a reader who believed a stale sentence and did not open the code. What was wrong: three outputs taken at a fixed commit standing under commands that ask a moving reference. How it was found: by running the three lines as they were written and comparing what they answered with what was pasted under them. The claim the block is evidence for is unchanged and is kept as it stands. There is a crate and there is a suite, and both are larger than they were. The numbers are pinned rather than refreshed, because a fresh reading under a moving reference is the same defect one merge later - which is the repair the paragraph two below already took for the count of tracked paths, by carrying no number at all. `cargo build --locked --all-targets` and `cargo test --locked` are green at this commit. No code changes. Closes #427 Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com> --- SECURITY.md | 30 +++++++++++++++++++++++++----- 1 file changed, 25 insertions(+), 5 deletions(-) diff --git a/SECURITY.md b/SECURITY.md index b5b0150..3634f00 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -72,17 +72,37 @@ THIS PARAGRAPH NAMED NEITHER THE CRATE NOR THE SUITE, AND THE ONE AFTER IT SAID THE CORE WAS NOT WRITTEN. Both were true when they were written and had stopped being true. A reporter who believed either would not have opened the code, because the file told them there was none. Read at -`5d67a074202de4d8069eee55d44812bf7fa9e201`: +`5d67a074202de4d8069eee55d44812bf7fa9e201`, and each command names that commit so +that running it returns what is beside it: - git rev-parse origin/main - 5d67a074202de4d8069eee55d44812bf7fa9e201 - git ls-tree -r --name-only origin/main | grep -c '^src/' + git ls-tree -r --name-only 5d67a074202de4d8069eee55d44812bf7fa9e201 | grep -c '^src/' 10 - git ls-tree -r --name-only origin/main | grep -c '^tests/' + git ls-tree -r --name-only 5d67a074202de4d8069eee55d44812bf7fa9e201 | grep -c '^tests/' 6 gh api repos/Flowfin/core --jq .language Rust +What the two counts answer today is a different question from what this +paragraph is evidence for, and it is asked without a number beside it: + + git ls-tree -r --name-only origin/main | grep -c '^src/' + git ls-tree -r --name-only origin/main | grep -c '^tests/' + +THE THREE COMMANDS THAT READ THE TREE ASKED `origin/main` UNTIL THIS EDIT, AND +THE OUTPUTS UNDER THEM WERE A READING AT THE COMMIT NAMED ABOVE THEM. The +reference moves and the reading does not, so the block agreed with itself on the +day it was written and on no day after it: at +`53cd6994d93ff76982301f52908759a555fe793b` the two counts answer forty-six and +sixty-eight, against the ten and the six pasted here. A reporter sizing the +surface from those numbers was reading a fraction of it, which is this +paragraph's own subject - a reader who believed a stale sentence and did not open +the code. The fourth command is unmoved and keeps its output: it asks the hosting +provider rather than a reference in this tree. The numbers are pinned rather than +refreshed, because a fresh reading under a moving reference is this same defect +one merge later, and a `git rev-parse origin/main` whose output named the commit +is gone rather than pinned, since a command pinned to a commit already says which +one it is. It was found by running the three lines as they were written. + The inventory above is a list, and a list drifts, which is what happened. The count beside it always said to derive it and still does: