Repository navigation
Close ROADMAP:376 GitHub auth token model bypass - #1700
Conversation
Review — clean structural migration; PR body fix + minor design questionThis is exactly the right structural shape. Three substantive things plus one design question. What's right
Design question (non-blocking)
I lean (b) — defaults at the auth-fn declaration site is a reasonable authoring decision, and a If you read this as in-scope and small, adding a Fix before un-draftingPR body is 58 chars (dashboard stub). Replace with R3 per-PR debt receipt:
Mark ready-for-review after the body fix. |
|
Review metadata
APPROVE_WITH_COMMENTS — the bypass dissolution is clean: the Exploratory observations (non-blocking):
|
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
5375f39b· Trigger:schedule - Thinking:
173s wall
BLOCKING (1)
Root Cause
dsl/std/credentials.dagCredentialSourcemodels only where credential bytes come from, not the GitHub token claims needed to inhabitGitHubAuthToken→ add a typed credential policy/source that carries verified or declared scopes and expiry, or use a GitHub acquisition operation that returns those facts.
ROADMAP — Incomplete
- ROADMAP:376: The GCP Secret Manager bypass is narrowed, but closure still fabricates
GitHubAuthTokenscope/expiry facts for env-sourced tokens.
| } | ||
| return { | ||
| token: cred.token, | ||
| scopes: default_github_token_scopes, |
This comment was marked as resolved.
This comment was marked as resolved.
Sorry, something went wrong.
|
Review metadata
Verdict: APPROVE — closes ROADMAP:376 cleanly. Exploratory observation (non-blocking): |
|
Review metadata
1. Story of the diffThis PR closes the ROADMAP:376 “GitHub auth model bypass” row by replacing the old 2. Invariant categories
This violates Modeling Faithfulness / Fail-Closed:
No independent Rust style issue: the new model code keeps the interface explicit with
The new regression test correctly checks that the old GCP literals are gone at
The diff closes a ROADMAP/debt row, but it does not reference or alter a locked thesis/design decision in the changed lines.
3. VerdictREQUEST_CHANGES The PR removes the old Secret Manager bypass shape, but the replacement still appears to manufacture or reclassify scope/expiry metadata from an auth-source default into a |
|
Review metadata
Findings:
Verdict: REQUEST_CHANGES. The PR moves in the right direction by removing the GCP Secret Manager bypass and returning the typed carrier, but the new carrier currently conflates declared credential policy with observed token facts. |
|
Review metadata
Verdict: APPROVE Diff is narrowly scoped and closes the ROADMAP:376 bypass by returning Tests were not run, per review instructions. |
|
Review metadata
Verdict: APPROVE — diff cleanly dissolves the GitHub auth bypass per ROADMAP:376.
Exploratory observation (non-blocking): |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
f03c28ca· Trigger:schedule - Thinking:
216s wall
Non-blocking — Strengths
dsl/extdeps/github/auth.dagThe declared/unverified metadata bridge is documented, bounded to GitHubAuthToken scopes/expires_at, and names the introspection or installation-token issuance trigger.
ROADMAP — Verified
- ROADMAP:376: The GCP Secret Manager bypass is removed, github_token returns GitHubAuthToken, and the remaining token-metadata verification debt is tracked explicitly.
✅ No blocking concerns.
Ready to merge — reviewer sign-off4 CI green, mergeable, ready-for-review, body has the R3 debt receipt (2144 chars). Substantive contributions:
Cannot self-approve via API. Director / merge-cap holder may proceed. |
…1720) * docs(r3): retire F2/F5/F11/R1 + normalize row 54 status Closure-flip wave for the 2026-05-04 ingestion: four of five novel- finding rows retired in their first PR cycle. - F2 (Result/DivError span.file-keyed) → Retired by PR #1662 - F5 (service syntax authority) → Retired by PR #1664 - F11 (Diagnostic taxonomy mirror drift) → Retired by PR #1661 - R1 (??/% deletion regression, fix-forward) → Retired by PR #1663 (split path landed AND v3-supported subset consumed by parse tables; dissolution trigger met) - F12 (ExecuteCommand/ForAllTargets duplicate) remains Open, queued at Verification. Also normalizes row 54 (GitHub auth model bypass) status from "Closed 2026-05-04" → "Retired" with PR #1700 cite, restoring single status-vocabulary alignment with the rest of the catalog. Baseline Counts refreshed to 74-row total: 46 Open + 1 disposition pending + 9 Partial + 1 Partial (fold) + 17 Retired. The "Open / fix-forward regression" bucket is dropped since R1 retired in cycle. Per-PR Debt-Paydown receipt against rows 54, F2, F5, F11, R1. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(r3): mark F2/F5/F11/R1 retired in ROADMAP.md Per codex review on #1720: the debt-paydown ledger marked these rows Retired in this PR, but the ROADMAP.md authority still listed them as Open, creating a P2 single-authority violation between the two documents. Stamps "(retired 2026-05-04)" + "Closed by [PR #...]" on the F2/F5/ F11/R1 entries in `### Post-merge debt (2026-05-04 paired exploratory + reflective analyses)`. F12 stays Open. ROADMAP.md and the debt-paydown ledger now agree on retirement status for all five rows. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
R3 Debt Receipt
Debt paid: ROADMAP:376 closes.
github_token()now returns the full typedGitHubAuthTokenfromextdeps.github.github, carryingtoken, typedGitHubScopevalues, andexpires_atinstead of the former narrow{ token: Secret }/GitHubSecretManagerPatbypass. The hardcoded GCP Secret Manager policy (gunbai-secrets,github-token,gcp_secret_credential, ambientuses net: Network) is removed. Token bytes are now materialized throughdefault_github_auth_source.credential_source: CredentialSource = EnvVar { name: "GITHUB_TOKEN" }viastd.credentials.env_credential. Token metadata is explicitly modeled asGitHubTokenMetadataAuthority::DeclaredGitHubTokenMetadatainside the same typedGitHubAuthSource, so declared policy is not silently treated as provider-verified metadata.Debt newly found: verified GitHub token metadata remains a separate follow-up. The declared metadata bridge is tracked by
structural_coverage_gap_github_token_metadata_verificationwith triggerGitHub token introspection or installation-token issuance surface. A future real consumer that needs SecretManager or multiple env-var policies will need either a new auth function variant or callable-default support for non-primitiveCredentialSourceparameters; current function default validation rejects aggregate defaults on parameters.Remaining row: ROADMAP:376 closes for the tracked bypass: narrow-token return, hardcoded GCP provider policy, and ambient Network effect are gone. Verified-token-metadata acquisition and per-call credential-source override are separate follow-up classes, not retained narrow-token or hardcoded-provider bypasses.
Verification
CARGO_TARGET_DIR=/tmp/calm-tern-200-target cargo test -p v2-compiler-tests github_token_returns_typed_auth_token_from_credential_source -- --nocaptureCARGO_TARGET_DIR=/tmp/calm-tern-200-target cargo test -p v3-compiler github_auth_no_longer_derives_network_from_ambient_uses --test integration -- --nocaptureCARGO_TARGET_DIR=/tmp/calm-tern-200-target ./scripts/regenerate-stage0.shcargo fmt --all --check