fix(admission): preserve uv provider evidence across global option values - #439
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh exact-head repair note (2026-09-20 KST): predecessor Minimum repair applied without changing admission semantics: |
Refs #438. Serialized child of exact
#129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6.Finding and ownership
Agent Artifact Admission's uv Python-provider classifier scanned raw
run/piptoken positions. A parser-valid uv global option can consume a value literally namedrun, so the raw scan could mistake that value for the top-leveluv runcommand and erase causal provider-authority evidence.Concrete hostile shape:
uv --project run pip install cwl-example==1.2.3 --require-hashes --no-deps --no-python-downloads --managed-pythonrunis the directory value consumed by global--project, not the active uv command. Wardnet owns only the Agent Artifact Admission policy/evidence decision here; this change does not discover, execute, mount, isolate, authorize egress for, or otherwise implement foreign-owner runtime behavior.Hosted hostile RED
Test-only exact head
ea9c817a8d0edd0e78052d18493a1f1f0954e91fchanged onlyuv_global_python_provider_value_boundary_contract.rs. Fuzz run35408397540was GREEN. CI run35408397572reached repository tests after checkout/toolchain/format and failed the hostile contract with:the value tokenrunconsumed by --project is not the uv run command and must not erase causal --managed-python provider evidence: [ForbiddenCommand]Controls passed for an ordinary
--project workspacevalue and for actualuv runbehavior. This is the semantic RED; no runner/bootstrap failure is being used as evidence.Minimum causal repair
Exact repair
1dfcdcb38b5ef9bc2bee25e48dc63a15e65117a5removes the duplicate raw token-position heuristic and reuses the existing parser-awarepolicy::uv_active_command_index()boundary. Actual parser-activeuv runstill returns no install-provider authority; aruntoken consumed as a reviewed global option value no longer suppresses exact--managed-python/--no-managed-pythonevidence. Exact submitted argv hashing and the deliberately unsupported global-option command classification remain unchanged.Fuzz
35428398273is terminal SUCCESS on that repair head. CI35428398285failed only atcargo fmt --checkin the newly added regression fixture after reaching checkout/toolchain/format; no production semantic failure was exposed. The subsequent commits through current exact headf84787e5b6bb4148be417a98957b24e102dd1137only finish rustfmt's emitted canonical layout for that fixture. No second uv parser, runtime/execution authority, foreign source copy, mutable sibling dependency, force update, destructive rebase, self-approval, gate weakening, or bypass is introduced.Exact-head acceptance — current
Current exact
f84787e5b6bb4148be417a98957b24e102dd1137remains based exactly on#129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6and is mechanically mergeable.35460113884, rust job105942336470: QUEUED onubuntu-24.04; latest fresh job inventory hasrunner_id=0, no assigned runner/group andsteps=[].35460113893: QUEUED on the same unchanged exact source head..github#712; it supersedes the priord5ccf813...specimen without changing Wardnet ownership or the semantic repair.Queue state is incomplete evidence, not GREEN. Keep Draft until both exact-head repository lanes are terminal-valid, then re-read current reviews/threads and exact parent compatibility. Only after that should this child become Ready and integrate normally into #129 with fixed expected-head protection. Any child merge invalidates #129 predecessor evidence and requires fresh root execution. Issue #438 remains open until the effective delta reaches protected
mainor a verified complete successor.