Dear nootxlm
First, thank you sincerely for raising exactly the kind of questions we want EGA to be tested against.
Before responding, we want to make sure we understood your report correctly.
We summarized your two main claims as follows:
① Missing expected-root / fail-open claim
If expected-root is absent, no comparison is performed, yet the request is not rejected and hash.verified / workflow.verified can still be recorded as verified.
② Reference trust-source claim
The expected-root used by EGA as the verification reference may be supplied by the request being evaluated, rather than being established by an independently trusted source.
Is this an accurate representation of the two issues you were raising?
Using that interpretation, we independently tested both claims against canonical EGA V9 v1.0.6.
① Missing expected-root / fail-open claim
EGA V9 v1.0.6
NOOTXLM H1 — Missing Expected Replay Root
Canonical version:
v1.0.6
a94c8356d2ab661b2dfee92496f69f452b174ec0
Canonical runtime artifact:
SHA256 MATCH = YES
Official test:
guard-smoke.mjs
MODIFIED = NO
Expected replay root:
ABSENT
Observed runtime:
nextCalled = true
verified = true
containmentRequired = false
executionAllowed = true
Runtime exit:
0
H1 RESULT:
CONFIRMED
Our conclusion for H1 is therefore straightforward:
You were correct.
In canonical EGA V9 v1.0.6, we reproduced the behavior you described: with the expected replay root absent, the guard allowed execution and reported the request as verified.
② Reference trust-source claim
EGA V9 v1.0.6
NOOTXLM H2 — Reference Trust-Source
Canonical version:
v1.0.6
a94c8356d2ab661b2dfee92496f69f452b174ec0
Canonical runtime artifact:
SHA256 MATCH = YES
Expected replay root source:
REQUEST HEADER
x-ega-expected-replay-root
Canonical source inspection:
expectedReplayRoot obtained from request = YES
Runtime verification:
Case A — request supplies WRONG expected root
suppliedByRequest = true
suppliedRootRelation = WRONG
nextCalled = false
statusCode = 409
contextStatus = contained
detectionStatus = mismatch
containmentActivated = true
executionAllowed = false
verified = false
expectedEqualsActual = false
Case B — same governed request supplies ACTUAL root
as expected root
suppliedByRequest = true
suppliedRootRelation = ACTUAL_ROOT
nextCalled = true
statusCode = 200
contextStatus = verified
detectionStatus = match
containmentActivated = false
executionAllowed = true
verified = true
expectedEqualsActual = true
Observed comparison:
verificationOutcomeChanged = true
executionOutcomeChanged = true
Canonical trust-source inspection:
Independent trusted reference source = NOT_OBSERVED
Request-replacement prevention = NOT_OBSERVED
Guard-authority binding = NOT_OBSERVED
Documented deployment requirement = NOT_OBSERVED
Canonical integrity:
SOURCE MODIFIED = NO
HEAD CHANGED = NO
H2 RESULT:
CONFIRMED
Our conclusion for H2 is therefore:
You were correct.
In canonical EGA V9 v1.0.6, the expected replay root used by the guard is obtained from the request being evaluated.
Our runtime reproduction further showed that changing the request-supplied expected root changed both the verification outcome and the execution outcome.
We also did not observe, within canonical v1.0.6, an independently trusted reference source, request-replacement prevention mechanism, guard-to-authority binding, or documented deployment requirement that independently protects this verification reference.
Therefore, within the tested canonical v1.0.6 boundary, we classify H2 as:
CONFIRMED.
This conclusion does not establish that every possible external EGA deployment lacks separately implemented trusted middleware. Our finding is limited to the canonical EGA V9 v1.0.6 boundary that we inspected and reproduced.
Dear nootxlm,
Thank you. Your report identified two assumptions in EGA V9 v1.0.6 that our previous testing did not close.
We independently reproduced both.
For us, the principle is simple:
0 = 0. Proof, not promise.
If we do not know, we will say we do not know.
If we are wrong, we will say we were wrong.
If evidence contradicts our assumptions, the evidence wins.
We do not want EGA to be trusted because we claim it is safe. We want it to earn trust through independent challenge, reproducible evidence, and correction when the evidence shows we were wrong.
Your challenge made EGA better.
Thank you.