security: reconstruct exact connection-pool policy boundary on current stack - #151
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by #169. This Draft remains pinned to predecessor snapshot |
Purpose
Replace stale stacked PR #117 with a bounded test-first reconstruction of issue #116 on the current accepted predecessor candidate #149. Historical #117 remains immutable evidence only; none of its checks, reviews, approvals, base identity, or mergeability transfers.
Exact stack and RED boundary
security/reconstruct-timeout-policy-type-d3498ec;b803faac4ace5946f168c9e7403bfa529e6a1c2d;fb61d280415ff4a0bdfd663aef4e8e4963924afd;tests/test_connection_pool_policy_type_boundary.py.The regression requires both public policy constructors to reject an
EgressConnectionPoolPolicysubclass before subclass-controlled attributes can replace reviewed finite pool ceilings. The expected RED is the currentisinstance(...)acceptance boundary inEgressPolicy.__post_init__. Any unrelated failure is new evidence and must be investigated rather than normalized.Planned narrow GREEN
After exact-head CI reproduces only the intended boundary, change only the shared construction guard to exact
EgressConnectionPoolPolicytype acceptance, rerun the exact boundary, then reconstruct only directly affected operator/research guidance, documentation contract, and[Unreleased]parity test-first. Preserve #149's exact timeout-policy boundary and current protected-main release-evidence history.No destination authority, DNS, TLS, proxy, request/response policy, timeout values, pool defaults, dependency, workflow, credential, publisher/release authority, public builder signature, or protected ref is widened.
Keep Draft while predecessor #149 is unintegrated. Predecessor checks/reviews do not transfer. Aggregate Security Scan success is not dependency-review acceptance while the organization-owned actual pinned
Dependency reviewaction is skipped.