Skip to content

Fix cross-session chain break attribution - #48

Merged
404SecNotFound merged 1 commit into
mainfrom
codex/fix-cross-session-chain-attribution
Sep 8, 2026
Merged

404SecNotFound merged 1 commit into
mainfrom
codex/fix-cross-session-chain-attribution

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

A modified record in one session could inherit coverage from a later signature when the shared collector stream crossed into another session. The earlier session was then reported as verified_complete even though the next record exposed a broken chain.

This change attributes an ambiguous broken boundary to both adjacent sessions and records it once per session. Both sessions become inadmissible, and sequence_verified rejects the altered position. It adds an end-to-end regression for the sparse signed, multiplexed-stream case and refreshes generated repository counts.

Validation:

  • New regression reproduced the false-verification result before the fix and passes afterward.
  • Independent F05 review probe passes.
  • All 16 repository verification gates pass locally.

@404SecNotFound
404SecNotFound merged commit d6a68c5 into main Sep 8, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant