Sitelet https://github.com/shin4141
Skip to content
View shin4141's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report shin4141

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
shin4141/README.md

I repair software boundary failures where systems report the wrong state, retain the wrong authority, or cannot recover cleanly after failure.

39 direct upstream merges across 34 independent public repositories — including Apple, Microsoft, NIST, Kakao, Mercedes-Benz, ESA, Hyperledger, and others.

Typical failures I work on:

  • Completion — a system reports success before the requested state actually exists.
  • Authority — permissions, policy, or access survive beyond the boundary where they should end.
  • Recovery — failure leaves stale state, lost diagnostics, or a broken retry path.

If your system has one of these failure modes, send me the failing path or reproduction: siriusa.paper@gmail.com

Selected upstream repairs

State / completion truth

  • Microsoft / Power Platform provider — HTTP 409 could report success before the requested remote state existed → the merged fix checks remote state before declaring success; otherwise it retries.

Authority / policy boundaries

  • Rundeck — project import permission could allow configuration changes without configure authorization → the merged fix requires both permissions for configuration imports.
  • NIST / mSCP — excluded rules appeared in the JSON manifest → the merged fix omits them; Shin is named in Release 27.0.

Recovery / failure integrity

  • Kakao / actionbase — an encoding exception could permanently remove a borrowed buffer from the pool → the merged fix returns it in finally, preserving later reuse.
  • FOSSLight / fosslight_util — failed log-destination setup could detach the active file handler before the caller could record the failure → the merged fix prepares the destination first, preserving diagnostics and retryability.
  • OpenSSL — recursive RAND seed-source construction exhausted the stack → clean failure in a maintainer-committed repair.

OpenSSL's maintainer adoption is excluded from the direct merge total.

Representation / boundary consistency

  • Mercedes-Benz / odxtools — length-prefixed diagnostic strings mixed UTF-8 byte counts with a different configured encoding → the merged fix uses one encoding consistently for the prefix and payload.
  • Apple / Swift OpenAPI Generator — duplicate generated schema names crashed generation → the merged fix emits a deterministic error.
Additional upstream evidence
  • ESA / pagmo2 — C++20 stateless lambdas broke BFE test assumptions → the merged tests and docs reflect the language change.
  • Hyperledger Besu — ordinary state-test --json mixed a human summary into JSONL → the merged fix keeps that output machine-readable.
  • Toyota Connected / emb_cli — packaging staging spawned chmod once per mode-bearing file → the merged fix batches destinations by mode within bounded argv chunks while preserving copy/permission order and failure handling.

View all upstream contributions →

Applied work

Sensitive Data Egress Gate

Applying the same boundary-repair approach to bounded data loss after credential compromise.

Design the maximum loss after one credential is compromised.

If one administrator credential is abused, can it reach 100 records, 10,000, or effectively all of them?

I design bounded data-egress conditions across volume, time, approval, destination, and exception paths.

This work is relevant to questions such as personal data security design, maximum data extraction after credential compromise, one-credential blast radius, AI agent data egress, and stop / approval / recovery boundaries for systems that can access customer or sensitive data.

The service page includes a sample deliverable.

You can commission the design only. Your existing engineers or vendor can implement it internally.

Projects and contact

Other projects: Decision-OS V13 LoopKit · Value-Locked Repository Recovery · AGENTS.md Compactor

Contact: siriusa.paper@gmail.com

Pinned Loading

  1. decision-os-paper decision-os-paper Public

    Research gateway for Decision-OS (V4–V14): papers, Zenodo citations, public implementations, and scoped validation evidence.

    4 4

  2. decision-os-v13-loopkit decision-os-v13-loopkit Public

    V12→V13 LoopKit: turns completion records into governed next-loop decisions using GO / HOLD / CAP / BLOCK.

    Python 38 21

  3. output-surface-integrity output-surface-integrity Public

    Restart long-running human–AI work with less rereading by preserving the compact operational state needed to continue.

    6

  4. value-locked-repository-recovery-public value-locked-repository-recovery-public Public

    Public front for Value-Locked Repository Recovery — evidence-bounded boundary audits for open-source and AI-assisted systems.

    1

  5. agents-md-compactor agents-md-compactor Public

    Route conditional AGENTS.md guidance into reconnectable guides while keeping the active file smaller, local, and source-traceable.

    JavaScript 2 1

  6. sensitive-data-egress-gate-reference sensitive-data-egress-gate-reference Public

    Minimal fictional reference for bounded sensitive-data egress and escalation approvals. Not a production security product.

    Python