Status: Accepted Date: 2026-09-19 Supersedes: none Related: Phase 2, ADR-A30, ADR-A27, ADR-A28, Surface workflow architecture
Surface generation, parity, and invalidation run existing compiler code over graph content. Letting an AMQP request choose file paths, command strings, Turtle payloads, or which process to execute would create arbitrary execution and data-exfiltration risks. Invalidation also has two different input roles: generated manifest evidence and source graphs.
Accept only scoped graph references in Surface jobs. A trusted GraphMaterializer resolves authorized immutable references to canonical local bytes. SurfaceCompilerExecutor requires the returned path to remain inside its private work directory, requires a regular file, and computes SHA-256 over those canonical bytes before compiler invocation. The calculated digest must equal the graph reference revision hash. SurfaceCompilerExecutor constructs one fixed compiler argument vector for each closed job type and returns output digests and safe diagnostics. The request cannot select executable commands or filesystem paths.
Require manifestGraph as a separate graph reference for invalidation jobs. It cannot be represented by source-graph ordering. The executor passes it only to the compiler’s --manifest argument and passes source graphs only to --sources.