You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Addresses #301 through the existing low-cardinality batch-log privacy lane. This remains a Draft child of dependency-root #233; protected main is not written directly.
Fresh exact stack
live protected main: bdff1273d3885dedc5187632e1c8838b470c9b6d;
exact current head: a4271f1654ba3fd3c07b34a4ad4624a96794db64;
state: Draft, open, mechanically mergeable.
The previous body described predecessor head 4289f006...; all checks/reviews on that or earlier heads are historical after branch movement.
Bounded behavior
The lane removes provider file/batch identifiers from ordinary INFO success logs while preserving authorized API return values, lifecycle/retry/retention behavior, persistence, and provider request semantics. It does not broaden masking into a product-breaking blanket redaction policy.
The privacy source/test delta remains owned here; #233 separately owns the inherited recovery-evidence coverage arcs. Central CodeQL/runner and Strix evidence defects remain read-only .github owner concerns and are not converted into pg source findings.
Exact-current validation boundary
Fresh workflow inventory for exact a4271f1654ba3fd3c07b34a4ad4624a96794db64 is non-passing: CI 33722286086 and Release Acceptance 33722286053 are queued. No predecessor success, COMMENTED/model disposition, or central infrastructure state transfers to this head.
Integration boundary
Keep Draft until #233 integrates and the unchanged/reconciled final head obtains every then-live exact-current CI/security/SAST/coverage/docstrings/package/SBOM/provenance/release/review/thread gate. Reconcile non-destructively onto protected main after the predecessor lands.
No force push, destructive rebase, self-approval, gate weakening, source churn merely to retrigger infrastructure, or close-to-zero PR handling.
Fresh exact-head blocker RCA for #317@273a785642adcc5cb7ab72272a113e1ba6de8eae against protected main@b84f0c94154043a3473939c01bb6471de5a129ae:
Required Strix Security is terminal failure at run 33350356643, job 99363187573.
The trusted required workflow ran from central .github source SHA 046bc2beb2e0bb4be804255764bcbb4c49e973e9, materialized the exact PR head, and reached contextual-orchestrator provider routing.
Gateway preflight found one ready route, nvidia_nim_meta_llama_3_2_90b_vision_instruct (meta/llama-3.2-90b-vision-instruct), but the actual Strix request failed before the first model response with provider HTTP 400 / invalid_request_error, retryable: false. Three bounded attempts failed the same way; each produced 0 tokens and no authoritative vulnerability analysis. The wrapper correctly failed closed as STRIX_PROVIDER_UNAVAILABLE.
Therefore this failure is not evidence of a pg source/privacy defect and not evidence of zero vulnerabilities. Do not mutate this source lane to chase the provider failure; keep the PR Draft and require a fresh exact-head terminal Strix success after a material central/provider change.
Writer-collision correction: a fresh non-default-branch comparison shows no-PR branch agent/retry-after-parser-hardening@417e84bee6356d560201d36a760425c3d893646d is 4 commits ahead / 187 behind protected main and also modifies pg_llm_batch/batch_api_client.py. That is active-writer evidence on the same production file even though the branch is stale/diverged. Freeze further source mutation on #317 for this invocation; reconcile ownership/non-overlap before any future change to this file. The current #317 diff itself remains exactly two commits ahead / zero behind main and changes only pg_llm_batch/batch_api_client.py plus its focused privacy test.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
area: apiAPI, protocol, event, or external contractarea: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionpriority: mediumNormal-priority or P2 workstatus: blockedBlocked by conflict, dependency, or required prerequisitetype: bugDefect or incorrect behavior
1 participant
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Addresses #301 through the existing low-cardinality batch-log privacy lane. This remains a Draft child of dependency-root #233; protected
mainis not written directly.Fresh exact stack
main:bdff1273d3885dedc5187632e1c8838b470c9b6d;32469711f9a26a26ebcf4a7efcf20938bfdc94db;a4271f1654ba3fd3c07b34a4ad4624a96794db64;The previous body described predecessor head
4289f006...; all checks/reviews on that or earlier heads are historical after branch movement.Bounded behavior
The lane removes provider file/batch identifiers from ordinary INFO success logs while preserving authorized API return values, lifecycle/retry/retention behavior, persistence, and provider request semantics. It does not broaden masking into a product-breaking blanket redaction policy.
The privacy source/test delta remains owned here; #233 separately owns the inherited recovery-evidence coverage arcs. Central CodeQL/runner and Strix evidence defects remain read-only
.githubowner concerns and are not converted into pg source findings.Exact-current validation boundary
Fresh workflow inventory for exact
a4271f1654ba3fd3c07b34a4ad4624a96794db64is non-passing: CI33722286086and Release Acceptance33722286053are queued. No predecessor success, COMMENTED/model disposition, or central infrastructure state transfers to this head.Integration boundary
Keep Draft until #233 integrates and the unchanged/reconciled final head obtains every then-live exact-current CI/security/SAST/coverage/docstrings/package/SBOM/provenance/release/review/thread gate. Reconcile non-destructively onto protected main after the predecessor lands.
No force push, destructive rebase, self-approval, gate weakening, source churn merely to retrigger infrastructure, or close-to-zero PR handling.