Skip to content

Track accepted E1 post-release security hardening (F1–F7) #49

Description

@eamirian

E1 passed for the exact v0.3.0 artifact set after an independent Claude Fable 5 review and release-owner countersignature. This issue tracks the accepted low/informational residuals; it does not reopen the E1 release gate unless a containment condition fails.

Evidence:

Follow-up checklist

  • F1 (completed in merged Core main 7013de62ae7320c51c3de9e9a03b049e768e4d84): add an in-transaction generation guard or real-database concurrency test; reconcile proposal state from receipts.
  • F2 (2026-11-05): add direct observability for failed selection/use receipt persistence.
  • F3 (re-dated to 2026-11-05 by the 0.6 release-owner disposition below): add trusted registration ceilings and explicit partial-registration rollback/reporting.
  • F4 (next security bundle): embed the executed restart e2e receipt or immutable CI run identity in the bundle.
  • F5 (completed in merged Core main 7013de62ae7320c51c3de9e9a03b049e768e4d84): pin the legacy optimizer query to self_optimizer_proposal.
  • F6 (2026-11-05): retain strict owner-credential isolation and evaluate per-reviewer/step-up identity.
  • F7 (before production traffic): enforce or operationally verify at least 32 bytes of JWT signing entropy.

Containment

The v169 activation-generation unique index, task-projected receipts, trusted-extension-only boundary, retained CI/deployment receipts, credential isolation, and setup-generated high-entropy JWT secret remain the accepted containment controls. Any release artifact change requires a fresh registry-to-matrix comparison.

F3 0.6 disposition — 2026-08-11

F3 is explicitly re-dated to 2026-11-05; it is not waived or resolved. ACE 0.6 does not expand the supported extension surface. Until the bounded atomic-registration packet lands, containment remains: trusted installed packages only, the ACE_DISABLE_EXTENSIONS=1 kill switch, the compatibility matrix, and operator disablement if unexpected partial registration is observed. The follow-up must stage every mutable registration surface, enforce ceilings, publish or roll back atomically, and emit a bounded failure report.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions