From c8c72c24aaddd06064bc1e4db490a481892e5f1f Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Mon, 6 Jul 2026 01:06:54 +0200 Subject: [PATCH] =?UTF-8?q?chore(memory):=20capitalize=20=E2=80=94=20LRN-0?= =?UTF-8?q?04,=20EVAL-001,=20BDR-006=20update=20note,=20journal=202026-07-?= =?UTF-8?q?06?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .claude/memory/decisions.md | 1 + .claude/memory/evals.md | 9 +++++++++ .claude/memory/journal.md | 6 ++++++ .claude/memory/learnings.md | 10 ++++++++++ 4 files changed, 26 insertions(+) diff --git a/.claude/memory/decisions.md b/.claude/memory/decisions.md index a1ce7cb..3896892 100644 --- a/.claude/memory/decisions.md +++ b/.claude/memory/decisions.md @@ -108,6 +108,7 @@ rules: - **Why**: SEC-1 tour finding — stock `nginx:*-alpine` runs its master as root inside the container. Unprivileged image + port 8080 removes the root master; the rest shrinks blast radius. BDR-004's "port 80 / nginx:1.27-alpine / HSTS omitted at container" no longer matched the tree. - **Supersedes**: BDR-004 — topology unchanged (native front proxy → container on loopback); only the base image, internal port, and uid change. - **Reference**: `Dockerfile`, `docker-compose.yml`, `nginx.conf`, `nginx-security-headers.conf`. Fix commit `ba13d69`; drift caught by tour REC-1 (`.claude/audits/TOUR.md`, run 2026-07-05-2). +- **Update 2026-07-06**: base bumped `1.28-alpine` → `1.30-alpine` digest-pinned (nginx/1.30.3) — 1.28 branch retired, CVE-2026-42945 fixed 1.30.1+ only, no backport. Decision unchanged (unprivileged base, 8080, uid 101). Commit `1aa97f0`, tour 2026-07-05-3 REC-2. --- diff --git a/.claude/memory/evals.md b/.claude/memory/evals.md index 80575df..c7a6665 100644 --- a/.claude/memory/evals.md +++ b/.claude/memory/evals.md @@ -21,6 +21,15 @@ rules: | ID | Date | Output | Action | |----|------|--------|--------| +| EVAL-001 | 2026-07-06 | /tour run 2026-07-05-3 (3 it., converged) + residual closure | keep | + +## EVAL-001 — /tour run 2026-07-05-3 + residual closure pass + +- **Date**: 2026-07-06 +- **Output**: 3-iteration tour (security/clean/reconcile/doc, converged at bound) + closure of all 10 residuals on owner GO. Commits `1aa97f0`/`613bfc0`/`2f5e51a` + follow-up. +- **Method**: oracle-based — semgrep ×3 (deterministic PASS), PDF render-hash (LRN-003) for behavior-preserving proofs, docker oracles (build, nginx -t, header/dotfile/gzip/healthcheck curls), headless-browser screenshots 375+1440 (index font trim), brace counts, CSP-hash pinned==computed. +- **Anomalies**: (1) cso add-on caught a HIGH (base-image CVE) two same-day semgrep-only tours missed — gstack was OFF then → LRN-004. (2) Fresh clean sweeps surfaced new info-tier nits each iteration (N1–N4 at it2) — convergence needed explicit reporting threshold in it3 prompt; bound of 3 did its job. (3) Session limit killed both it3 agents mid-flight — SendMessage transcript-resume recovered both, zero re-audit gap. +- **Action**: keep