Repository navigation
PyJWT relock record: redis decode search (D1), timing range from the outputs (D2), honest output labels - #529
Merged
seathatflowsinourveins merged 4 commits intoSep 30, 2026
Conversation
…is decode search, timing range from the outputs, honest output labels) Text and evidence only; the lock, pins.json, tests and .github/osv-scanner.toml are unchanged (the toml text was already correct at #525). - D1: the reason for staying on PyJWT 2.14.0 until the joint relock now covers every PyJWT decode found in the relocked venv (section K of the returned outputs, a static search of 10,746 installed .py files with its script published): google-auth (oauth2/id_token.py:153, a module nothing outside google-auth imports), LiteLLM (proxy modules, not run), oauthlib (common.py:221, no caller outside oauthlib), redis 7.2.1 (auth/token.py:89, verify_signature false on a token its configured credential provider supplies; nothing outside redis references redis.auth.token or JWToken) and mcp (encode only); the recipe's own code imports neither redis nor jwt. - D2: the two failing requests-oauthlib tests' miss (assertAlmostEqual of an integer expiry against a float one) is computed from the retained outputs (0.09 to 0.39 s) and explained: it follows the fractional second of the run's clock, so they fail on almost any run under oauthlib 3.3.1 and 4.0.0 alike. - Nits: the returned outputs' header rule now names its exceptions ('(abridged)', '(derived)', '#', excerpts, the ~ substitution and the rounding of window times), section D shows its real command, section G shows each command as run, and the builder script and the section K script are published (evidence/relock-2026-09-30.builder.sh.txt, .jwt-callers.py.txt). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…st commit) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…mports, google-auth :146, LiteLLM :1516, honest checks) Text, script and evidence only; the lock, pins.json, tests and .github/osv-scanner.toml are unchanged. - N1: section K's script now follows every PyJWT import form (`import jwt`, `import jwt as X`, `from jwt import ...`), counts only names bound to the jwt module, and so cites google-auth's PyJWT decode at oauth2/id_token.py:146 (the :153 `jwt.decode` beside it is google-auth's own jwt module) and adds LiteLLM's `import jwt as _jwt` decode at mcp_management_endpoints.py:1516. The conclusion (no decode of an attacker-controlled token reachable in the recipe venv) is unchanged. - N3: the recipe is searched recursively (12 files, not 8), the google-auth outside-reference check excludes only google/auth and google/oauth2, litellm.proxy gets its own outside-reference check, and the "10,746 files" wording says what it leaves out (PyJWT's own files and installer tooling). Section K reproduces byte for byte from the published script. - N2: the 0.38-0.43 s figure is stated as a first run's terminal output that was not retained; the 0.22-0.28 s figure is the one in this file's git history (f77612b). - N4: the outputs header names every exception (abridged commands, derived lines, comments, excerpts, path placeholders), command lines show the real loops and paths, `osv-scanner --version` is its own command, and the script and builder names agree. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…hot file, last commit) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
seathatflowsinourveins
deleted the
res-openhands-pyjwt-followup-20260930
branch
September 30, 2026 05:09
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
.pyfiles, script published), the two failing requests-oauthlib tests' timing miss is computed from the retained outputs and explained, and the returned outputs' header rule names its exceptions. No lock, pin, test or config change (requirements.lock,pins.json,tests/,.github/osv-scanner.tomlare byte-unchanged from main).f77612b6(main, after OpenHands recipe lock: PyJWT 2.14.0 relock closes ten advisories (unblocks the required osv-scanner check) #525).lane:foundation(registering the files inmanifests/evidence.jsonthrough the hot-file protocol does not make it shared).blueprints/runtime-workers/openhands/(research.md and evidence/),docs/decisions/2026-09-22-github-automation-closure.md,evidence/receipts/,manifests/evidence.json(last commit).SOTA sources
2.14.0; CHANGELOG.rst v2.14.0 read from the sdist), the GitHub global advisory API and OSV records for the ten advisories, OpenHands/software-agent-sdk@fcc102a697874d54a357e36004e02c95040dbdc0 (the recipe's pinned source and uv.lock), google/osv-scanner v2.6.0.redis/auth/token.py:83-91), google-auth 2.53.0 (google/oauth2/id_token.py:153), oauthlib 3.3.1 (oauthlib/common.py:221), litellm 1.93.0 and mcp 1.28.1, as pinned in the recipe lock and installed by its owninstall-container.shsequence into a scratch venv; and PyJWT 2.15.0's changelog (the Security item about deeply nested payloads).evidence/receipts/osv-openhands-pyjwt-relock-20260930.json.Evidence-class table
id_token.py:146, throughimport jwt as jwt_lib; no importer of that module outside google/auth and google/oauth2), LiteLLM (seven proxy modules, one throughimport jwt as _jwtatmcp_management_endpoints.py:1516; nothing outside litellm referenceslitellm.proxy; the proxy is not run), oauthlib (common.py:221, no caller outside oauthlib), redis (auth/token.py:89,verify_signaturefalse on a token its credential provider supplies; nothing outside redis referencesredis.auth.tokenorJWToken) and mcp (encode only); none of the recipe's 12.pyfiles (searched recursively) imports redis or jwtlocal_integration(static text search of installed.pyfiles, import aliases and from-imports followed; a name assembled at run time would not match; not a runtime trace)release_choice.decision_point_2_15_0; returned outputs section K;evidence/relock-2026-09-30.jwt-callers.py.txtoauthlib_4_0_0_precheck; returned outputs section J (full pytest output)source_review(reading the file against its builder)evidence/relock-2026-09-30.txt,evidence/relock-2026-09-30.builder.sh.txtLocal commands run
The full
unittestdiscovery runs in CI'svalidatecheck.Decision record
docs/decisions/2026-09-22-github-automation-closure.md, the dated 2026-09-30 addendum (rewritten in place for D1, with the as-of times refreshed); the overturn list is unchanged, and trigger (c) still fires at 2026-09-30T16:56:01Z if the recorded reason stops holding.Host evidence
This PR touches a receipt under
evidence/receipts/, notevidence/hosts/.scripts/validate.py(exit 0 above) validates the receipt and its registration.1ac08865(needs changes: aliased PyJWT imports missed by section K, the google-auth decode cited at the wrong line, an unretained figure cited as retained, unnamed exceptions in the outputs header); all are fixed in the repair round (head3f18398c), and section K reproduces byte for byte from the published script. Session 21 was asked to check the new head.platform_statuschange.Residuals
Checklist
🤖 Generated with Claude Code