Skip to content

Reject ignored execution flags on account commands in Rust - #45

Merged
irl-dan merged 3 commits into
mainfrom
codex/imp-089-agent-parity
Oct 6, 2026
Merged

irl-dan merged 3 commits into
mainfrom
codex/imp-089-agent-parity

Conversation

@irl-dan

@irl-dan irl-dan commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Rust account/package commands silently ignored execution-only runner globals, while Bun rejected them. An agent could supply --harness, --cwd or --timeout and receive success even though the control had no effect.

Reject execution-only globals before credential access, preserving the existing service-operation error envelope, exit 2 and rendering options. Shared controls cover 18 denied prefixes across five commands and three rendering positives. Malformed fixture data proves rejection precedes credential parsing. Bun already implements this boundary.

Validation: unchanged Rust fails the regression; corrected Rust passes all 93 controls. Bun passes 549 assertions. Independent exact-head review and replay found no findings. Full CI caught two strict Rust lint issues; the follow-up extracts account routing and fixes a needless test borrow. Strict CLI Clippy and the regression now pass. Final full CI passes all 15 checks. The baseline, failed CI and review evidence are retained in workspace IMP-089.

No new Python, model call, credential mutation, release or deployment.

Final head f9f57ce passes all 15 checks. Both source-admission platforms executed the shared Rust and Bun credential-boundary controls. Full logs and check identities are retained in IMP-089.

@irl-dan
irl-dan merged commit 7eab7e4 into main Oct 6, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant