Skip to content

Tighten Android prepared RSA parameter validation - #117

Merged
Orazen merged 1 commit into
mainfrom
codex/android-forge-null-backport-20261007
Oct 7, 2026
Merged

Orazen merged 1 commit into
mainfrom
codex/android-forge-null-backport-20261007

Conversation

@Orazen

@Orazen Orazen commented Oct 7, 2026

Copy link
Copy Markdown
Owner

Prepared Android node-forge sources previously accepted a nonempty ASN.1 NULL in RSA DigestInfo. This adds the strict parameter check from upstream PR1157 to Muster’s existing hash-pinned source backport, advances only the recognized prior prepared RSA bytes, and refuses unknown source bytes. Empty or absent NULL, BER compatibility, PSS/NONE, and the real Expo/selfsigned callers retain coverage. The Android manifest, lockfile, SDK baseline, and braces patch are unchanged.

Claim: ROOT-ANDROID-STRICT-NULL/v1. Upstream reference: node-forge PR1157, reviewed at 683ab3344899cc08a581e4d5675a33e87aff7b04.

Validation on Node 24.21.0 / pnpm 10.33.0:

  • Preserved red proof: the prior prepared source accepted all three owned malformed-NULL fixtures (lengths 1, 8, and 32); the new source rejects them.
  • node --test scripts/dependency-security-policy.test.mjs: 14/14 passed, EXIT0.
  • node scripts/verify-toolchain.mjs: 21/21 passed, EXIT0, including real toolchain consumers.
  • Scoped lint: 3 scripts, 0 warnings/errors, EXIT0.
  • Unmodified pnpm test: 524 files, 8,804 passed, 8 skipped, 0 failed, plus 84 auxiliary checks (13 native / 22 broker / 21 updater / 14 lifecycle / 14 packaged), EXIT0.
  • Owned child groups exited naturally, 164 sampled ports closed, and the identity-verified temporary root was removed. The shared checkout and 1,951 nonclaimed base leaves remained unchanged.

Exact candidate: 632435c32b97fba7c74f8118d3218504dae2b8f3; tested/reviewed tree: 735514d32985424dfb241954fbf04a63761bb1c8; source base: 3a4a091eafe2ce91714c381b2ddfb8eda438bc01. Independent author-separated review: ACCEPT, 0 blocking findings. Source review SHA256 bba397cfd404980412e22dd1d939fc3d744c6a8e09b8f9da7d1c66133b3ec5a0; runner review 573ae6ae5d7bb4346e349ac990fcc200a7063a6627a359d511c37a82cac06599; final source/local-evidence review 533d070dc99f26472f07e3556a97a4c7a83f75365a86ca39cdcbcf2bae26f4f0; full raw log SHA256 db7098aa2b9e00b64f1b7be8ab7b9c783b0642d2c96eccb0b0b82de1611e91fc.

Limits: this is a local source mitigation, not an upstream patched-version or advisory-closure claim, a full RSA audit, or proof of keyless signature forgery. The Linux ARM64 Oxlint allocator issue remains unresolved. Copied tool wrappers retain old NODE_PATH fallback metadata; verified entry points and declared dependency probes selected owned bytes, but this is not exhaustive module-load isolation. No new APK/AAB, physical-device, signing, installed-app, or deployment acceptance is claimed. Hosted exact-head checks and current-main integration remain separate gates for Root.

@Orazen

Orazen commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Independent Root review — ACCEPT source/local and current-main composition, hosted gate pending

Candidate 632435c32b97fba7c74f8118d3218504dae2b8f3 has exact tested tree 735514d32985424dfb241954fbf04a63761bb1c8. Only the three claimed Android policy/script/test paths differ from3a4. Current-main76f composition tree 1772e46ea91c9c550bfc17a72af1a6b87b749fa0 preserves all1984 noncandidate leaves/modes, with zero unexpected changes.

Actual verification:14policy+21realtoolchain consumer; full524files/8804passed/8skipped/0failed plus84auxiliary, EXIT0; zero surviving observed children,164sampledportsclosed, proven owned short-temp cleanup. Independent final source/receipt ACCEPT SHA256 533d070dc99f26472f07e3556a97a4c7a83f75365a86ca39cdcbcf2bae26f4f0; current-main source review 2f981a0034301766199a4afbf8389b54bb3c301437e679fe70370fb596f3f2ca; full raw db7098aa2b9e00b64f1b7be8ab7b9c783b0642d2c96eccb0b0b82de1611e91fc.

Copied launcher fallback metadata is explicitly recorded; post-terminal resolution probes are not exhaustive runtime load/OS-isolation evidence. No affected covered consumer was identified; no unjustified repeated full gate. Fresh future gates require reviewed namespace rebind.

This is a fail-closed local supplemental RSA-parameter backport, not an upstream patched release or advisory closure. Published Forge/braces vulnerable dependency paths and LinuxARM64Oxlint allocator failure remain open acceptance findings. No new APK/AAB, installed, physical-device, signing or deployment claim.

Next owner Root: inspect terminal exact-head primary CI/current merge policy, then normal integration only if gates pass. Existing audit Root2026-10-08 09:00 Europe/Rome, pinned candidate above and successor delta/unresolved gates only. Source is ready for review; no status override/admin bypass.

@Orazen
Orazen marked this pull request as ready for review October 7, 2026 19:33
@Orazen
Orazen merged commit c95e6cb into main Oct 7, 2026
16 of 17 checks passed
@Orazen

Orazen commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Root normal integration: PR117 merged through the ordinary repository merge command, exact reviewed/tested head632435c32b97fba7c74f8118d3218504dae2b8f3, mergec95e6cb5aa9748898dfc3fbd4cb84c7d9da83c8c. No override, force push, branch deletion or bypass.

Actual candidate hosted CI37671467360 succeeded13/13 jobs/132 steps:525files,8808passed,9skipped,0failed;84auxiliary,217browser,194Mac and568companion-core tests. Raw log SHA256827431edee144f2921511668cd2a305fb619a329aed43d159b2bb796ae85e50e. Separate local524/8804/8/0+84 receipt and nonauthor ACCEPT533d070d remain pinned to candidate tree735514d3; current-main3path integration review2f981a00 preserved1984other leaves.

This closes the exact strict-NULL local backport correction, not upstream Forge/braces patched-version claims, advisory closure, LinuxARM64Oxlint, Android device or signing acceptance. Root continues the actual connector/auth composite; account/device and TestSprite mapping gates remain open.

@Orazen

Orazen commented Oct 7, 2026

Copy link
Copy Markdown
Owner Author

Main follow-up: actual CI 37675421022 at normal merge c95e6cb5aa9748898dfc3fbd4cb84c7d9da83c8c ended CANCELLED:11jobs succeeded, browser cancelled, dependent build skipped. The browser job hit its30-minute maximum during pnpm exec playwright install --with-deps chromium; it never reached application build or browser assertions. Ubuntu package-mirror retries are in the log, but the underlying stall is not established. This is neither a main CI pass nor evidence of a product assertion failure. Candidate117's13-job success/actual merge-tree proof and local mitigation receipt remain separate.

Next owner Root: the current61-path successor is running its isolated full gate; after source/local review and normal integration, require fresh hosted primary/browser/build acceptance and exact-current-main CI. No rerun, step omission, disabled finding or manual deployment occurred in this diagnosis. Diagnosis SHA256 7fafe1599ffb3fc0399ffc0637ec79a08e3e6e9e247eeaacdd050be84b705e91.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants