Skip to content

fix(admission): preserve uv provider evidence across global option values - #439

Merged
seonghobae merged 5 commits into
feat/agent-artifact-admissionfrom
codex/uv-global-python-provider-boundary-20260919
Sep 20, 2026
Merged

seonghobae merged 5 commits into
feat/agent-artifact-admissionfrom
codex/uv-global-python-provider-boundary-20260919

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Refs #438. Serialized child of exact #129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6.

Finding and ownership

Agent Artifact Admission's uv Python-provider classifier scanned raw run / pip token positions. A parser-valid uv global option can consume a value literally named run, so the raw scan could mistake that value for the top-level uv run command and erase causal provider-authority evidence.

Concrete hostile shape:

uv --project run pip install cwl-example==1.2.3 --require-hashes --no-deps --no-python-downloads --managed-python

run is the directory value consumed by global --project, not the active uv command. Wardnet owns only the Agent Artifact Admission policy/evidence decision here; this change does not discover, execute, mount, isolate, authorize egress for, or otherwise implement foreign-owner runtime behavior.

Hosted hostile RED

Test-only exact head ea9c817a8d0edd0e78052d18493a1f1f0954e91f changed only uv_global_python_provider_value_boundary_contract.rs. Fuzz run 35408397540 was GREEN. CI run 35408397572 reached repository tests after checkout/toolchain/format and failed the hostile contract with:

the value token run consumed by --project is not the uv run command and must not erase causal --managed-python provider evidence: [ForbiddenCommand]

Controls passed for an ordinary --project workspace value and for actual uv run behavior. This is the semantic RED; no runner/bootstrap failure is being used as evidence.

Minimum causal repair

Exact repair 1dfcdcb38b5ef9bc2bee25e48dc63a15e65117a5 removes the duplicate raw token-position heuristic and reuses the existing parser-aware policy::uv_active_command_index() boundary. Actual parser-active uv run still returns no install-provider authority; a run token consumed as a reviewed global option value no longer suppresses exact --managed-python / --no-managed-python evidence. Exact submitted argv hashing and the deliberately unsupported global-option command classification remain unchanged.

Fuzz 35428398273 is terminal SUCCESS on that repair head. CI 35428398285 failed only at cargo fmt --check in the newly added regression fixture after reaching checkout/toolchain/format; no production semantic failure was exposed. The subsequent commits through current exact head f84787e5b6bb4148be417a98957b24e102dd1137 only finish rustfmt's emitted canonical layout for that fixture. No second uv parser, runtime/execution authority, foreign source copy, mutable sibling dependency, force update, destructive rebase, self-approval, gate weakening, or bypass is introduced.

Exact-head acceptance — current

Current exact f84787e5b6bb4148be417a98957b24e102dd1137 remains based exactly on #129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6 and is mechanically mergeable.

  • CI 35460113884, rust job 105942336470: QUEUED on ubuntu-24.04; latest fresh job inventory has runner_id=0, no assigned runner/group and steps=[].
  • Fuzz 35460113893: QUEUED on the same unchanged exact source head.
  • The current-head runner/materialization specimen is handed to canonical central owner .github#712; it supersedes the prior d5ccf813... specimen without changing Wardnet ownership or the semantic repair.
  • Wardnet will not add no-op commits, synthesize GREEN, copy central runner logic, self-approve or weaken gates to replace missing exact-head execution evidence.

Queue state is incomplete evidence, not GREEN. Keep Draft until both exact-head repository lanes are terminal-valid, then re-read current reviews/threads and exact parent compatibility. Only after that should this child become Ready and integrate normally into #129 with fixed expected-head protection. Any child merge invalidates #129 predecessor evidence and requires fresh root execution. Issue #438 remains open until the effective delta reaches protected main or a verified complete successor.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 600231d4-bf71-4a0d-84a1-8b474e6f22e4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae changed the title test(admission): expose uv global Python-provider value boundary gap fix(admission): preserve uv provider evidence across global option values Sep 19, 2026
@seonghobae seonghobae added bug Something isn't working priority: high High-priority or P1 work labels Sep 19, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Fresh exact-head repair note (2026-09-20 KST): predecessor d5ccf81300ca7dfa830ab8431999728a8034a972 finally materialized on a hosted runner. Fuzz 35444660193 completed SUCCESS, while CI 35444660171 failed only at cargo fmt --check; job 105901407632 emitted three deterministic rustfmt differences: import ordering in pypi_python_interpreter_authority.rs, plus two long .to_string() lines in the new regression fixture. Tests/Clippy were skipped, so this is formatting evidence rather than a semantic regression.

Minimum repair applied without changing admission semantics: 0213b7eeee6f4714c07361ec9586a5bfabcf9c11 applies the exact import order, and current exact head f84787e5b6bb4148be417a98957b24e102dd1137 applies the remaining two exact rustfmt outputs. Base remains exactly #129@fdd3e3dbd73a2838ffdabad41134a9c156cddca6; PR is mechanically mergeable; reviews and inline review threads are currently empty. Fresh exact-head CI 35460113884 and Fuzz 35460113893 are queued. Keep Draft: queued evidence is not GREEN, and this child must not integrate until both repository lanes are terminal-valid on unchanged exact head and parent compatibility is re-read.

@seonghobae
seonghobae marked this pull request as ready for review September 20, 2026 00:01
@seonghobae
seonghobae merged commit 9efc804 into feat/agent-artifact-admission Sep 20, 2026
4 checks passed
@seonghobae
seonghobae deleted the codex/uv-global-python-provider-boundary-20260919 branch September 20, 2026 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high High-priority or P1 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant