fix(pingora): enforce runtime policy on executable test modules - #1450
Draft
seonghobae wants to merge 6 commits into
Draft
fix(pingora): enforce runtime policy on executable test modules#1450seonghobae wants to merge 6 commits into
seonghobae wants to merge 6 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
Author
|
@opencode-agent review Review-only dispatch for unchanged exact head |
This was referenced Aug 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Causal defect
Protected main inherited #1435 with current-head review thread
PRRT_kwDOS_C14s6dgZuSunresolved. The scanner treated executabletests/test_pingora_edge_policy.pyas a blanket source fixture, so active Nginx runtime behavior at that path was accepted although the binding policy exempts only dedicated inert samples undertests/fixtures.Exact scope
main@1d8e872487838e16a003e96e76df9300c388e258;7779b20fd0f525c87baa6ccc156ee79c607fa9a1;tests/fixturessamples remain exempt; andRED → GREEN
Deterministic RED on test-only commit
e74db80e7da4099dc1779e4b94628f17cc0b9e6c:python3 -m pytest tests/test_pingora_edge_policy.py -q1 failed, 60 passedtest_policy_test_module_rejects_active_runtime_contentreceived an empty set because the executable pytest path was blanket-exempt.GREEN on exact current head
7779b20f...:62 passed;239/239 statements, 88/88 branches (100%);1,897 passed, 1 skipped, 21 subtests;9,966/9,966 statements, 3,926/3,926 branches (100%);100.0%.Exact-head operational evidence
For unchanged exact head
7779b20fd0f525c87baa6ccc156ee79c607fa9a1, all generated general security and supply-chain workflows are terminal GitHub-success:33311248027, job99256586045: expected and actual checkout SHA both equal the exact head before scanning and SARIF upload;33311248037: Trivy99256585643, dependency-review99256585754, Scorecard99256585700, and dual-revision OSV99256585778succeeded; every head-oriented job attested the exact contributor SHA and OSV separately attested live base1d8e8724...;33311248035, Python Security33311248029, OSV Scanner33311248208, SBOM33311248032, Secret Scan33311248028, and Scorecard33311248024succeeded.These results establish exact-current-head security evidence only. They are not a substantive formal review or merge authority.
Draft review-only acceptance boundary
Keep Draft/unmerged. A targeted
@opencode-agent reviewrequest for this unchanged exact head was authenticated and forwarded by mention-router run33313193198and invocation run33313202859. The authoritative scheduler run33313209748, job99261850925, validated PR #1450 and SHA7779b20f...but then returnedskip: draft PR, so no review workflow or formal verdict materialized.That is a central scheduler contract defect tracked on canonical owner PR #1443, not a reason to make this PR Ready merely to obtain review evidence. Acceptance requires protected-main integration of the review-only Draft path, followed by a fresh unchanged-head canary that leaves this PR Draft, dispatches an exact-head OpenCode review, and cannot mutate refs, merge, auto-merge, or lifecycle state. Reviews API currently has no formal submission and unresolved threads are zero. Local deterministic evidence and general security workflow success do not substitute for review or approval.