I repair software boundary failures where systems report the wrong state, retain the wrong authority, or cannot recover cleanly after failure.
39 direct upstream merges across 34 independent public repositories — including Apple, Microsoft, NIST, Kakao, Mercedes-Benz, ESA, Hyperledger, and others.
Typical failures I work on:
- Completion — a system reports success before the requested state actually exists.
- Authority — permissions, policy, or access survive beyond the boundary where they should end.
- Recovery — failure leaves stale state, lost diagnostics, or a broken retry path.
If your system has one of these failure modes, send me the failing path or reproduction: siriusa.paper@gmail.com
- Microsoft / Power Platform provider — HTTP 409 could report success before the requested remote state existed → the merged fix checks remote state before declaring success; otherwise it retries.
- Rundeck — project import permission could allow configuration changes without
configureauthorization → the merged fix requires both permissions for configuration imports. - NIST / mSCP — excluded rules appeared in the JSON manifest → the merged fix omits them; Shin is named in Release 27.0.
- Kakao / actionbase — an encoding exception could permanently remove a borrowed buffer from the pool → the merged fix returns it in
finally, preserving later reuse. - FOSSLight / fosslight_util — failed log-destination setup could detach the active file handler before the caller could record the failure → the merged fix prepares the destination first, preserving diagnostics and retryability.
- OpenSSL — recursive RAND seed-source construction exhausted the stack → clean failure in a maintainer-committed repair.
OpenSSL's maintainer adoption is excluded from the direct merge total.
- Mercedes-Benz / odxtools — length-prefixed diagnostic strings mixed UTF-8 byte counts with a different configured encoding → the merged fix uses one encoding consistently for the prefix and payload.
- Apple / Swift OpenAPI Generator — duplicate generated schema names crashed generation → the merged fix emits a deterministic error.
Additional upstream evidence
- ESA / pagmo2 — C++20 stateless lambdas broke BFE test assumptions → the merged tests and docs reflect the language change.
- Hyperledger Besu — ordinary
state-test --jsonmixed a human summary into JSONL → the merged fix keeps that output machine-readable. - Toyota Connected / emb_cli — packaging staging spawned
chmodonce per mode-bearing file → the merged fix batches destinations by mode within bounded argv chunks while preserving copy/permission order and failure handling.
View all upstream contributions →
Applying the same boundary-repair approach to bounded data loss after credential compromise.
Design the maximum loss after one credential is compromised.
If one administrator credential is abused, can it reach 100 records, 10,000, or effectively all of them?
I design bounded data-egress conditions across volume, time, approval, destination, and exception paths.
This work is relevant to questions such as personal data security design, maximum data extraction after credential compromise, one-credential blast radius, AI agent data egress, and stop / approval / recovery boundaries for systems that can access customer or sensitive data.
The service page includes a sample deliverable.
You can commission the design only. Your existing engineers or vendor can implement it internally.
Other projects: Decision-OS V13 LoopKit · Value-Locked Repository Recovery · AGENTS.md Compactor
Contact: siriusa.paper@gmail.com



