Skip to content

hardening: share-guard byte-value and key matching; shared vectors v3 - #13

Merged
SaulBuilds merged 1 commit into
mainfrom
fix/pba-r2-sdk-guard-shapes
Sep 26, 2026
Merged

SaulBuilds merged 1 commit into
mainfrom
fix/pba-r2-sdk-guard-shapes

Conversation

@SaulBuilds

Copy link
Copy Markdown
Contributor

Summary

Hardening follow-up to #11 for the metadata key-share guard. Version stays at 0.6.3 (unpublished).

  • Byte values: _is_byte_int now accepts whole-number floats and signed values in -128..255, matching _share_x. This also applies inside JSON strings (171.0, 1.71e2).
  • Buffer shape: {"type": "Buffer", "data": [...]} is matched whatever other keys are present.
  • Key case: both x/X and y/Y are checked. A benign value under one case no longer masks the other.
  • Shared vectors are now v3 (64 entries). The file is byte-identical with citrate-sdk-js and its sha256 (674d35d7…) is pinned in both repos.
  • README and CHANGELOG: one sentence stating that the guard is a safety net against accidental inclusion and that deploy_model never places key shares in metadata itself.

Evidence

  • Red first: 6 new tests failed before the fix.
  • Revert check: reverting crypto.py fails 12 tests.
  • Hand mutants: 6 of 6 killed (float bytes, signed range, Buffer exact keys, uppercase X, uppercase Y, float integrality).
  • Local CI (Python 3.11, uv sync --frozen --all-extras): ruff ok; mypy clean (84 files); uv lock --check ok; pip-audit found no known vulnerabilities; slugs ok; tests 753 passed / 43 skipped (non-economics); wheel tripwire passed for 0.6.3.

Details are in the private audit record.

🤖 Generated with Claude Code

https://claude.ai/code/session_012cD3fDq5vhh2YWZPU2SV6H

…uard; shared vectors v3

- Byte values may be whole-number floats and signed values (-128..255), including inside JSON strings.
- The Buffer JSON shape matches on type == "Buffer" plus a data list, whatever other keys are present.
- x/X and y/Y are all checked.
- The shared vectors file is v3 (sha256 pinned), byte-identical in citrate-sdk-js.
- README and CHANGELOG say that the guard is a safety net against accidental inclusion and that the SDK never places key shares in metadata itself.
Hand mutants: all 6 killed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@SaulBuilds
SaulBuilds merged commit b2856f7 into main Sep 26, 2026
10 checks passed
@SaulBuilds
SaulBuilds deleted the fix/pba-r2-sdk-guard-shapes branch September 26, 2026 04:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants