Skip to content

Retain Claude federation diagnostics and pinned vendor documentation - #961

Merged
seathatflowsinourveins merged 3 commits into
mainfrom
codex/ns2604-gha-p1-federation-20261010
Oct 10, 2026
Merged

seathatflowsinourveins merged 3 commits into
mainfrom
codex/ns2604-gha-p1-federation-20261010

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Scope

Retain the fixed zero-cost Claude error diagnosis in all three federation workflows while continuing to reject the run. This PR delivers diagnostics and documentation from the audit plan's P1 code/docs scope. Console rule correction and one native acceptance dispatch are owner work; the broad schedule stays off and harness audit stays disabled until that acceptance succeeds.

  • Base commit: f6ae0de74c151dce9204f6b6bdae7ea048932881, current main when this separate P1 worktree started.
  • Current head: cb9678203762c96f9d418db99dcd81cab2b8b0ab, after the CC-cued single landing rebase onto main fcdeae42c82b2279ccd5a0ee3867fd70ba1beff2.
  • Lane: lane:foundation.
  • The follow-up retains three exact reviewed vendor captures plus a revision/locator index and README; binds the two decisions, workflow comments and this description to them; adds the hosted S2 shape to the diagnostic subtest and corrects the derived pull_request form and conditional harness header.
  • Its publication-validator correction permits only the two exact registered Claude Markdown paths at their reviewed whole-file hashes to contain public vendor UUID examples. Other credential/private-path checks remain active. Altered/rehashed data, other paths and missing registration remove that UUID-only classification. This necessary false-positive correction is covered by the complete validator suite and is explicitly part of review.
  • Each privacy negative arm now gets a fresh publication fixture for each reviewed Claude snapshot. The assertion names that target's UUID refusal, so another file cannot satisfy it. Controls cover changed/rehashed bytes, a different path, missing registration and the wrong registered hash. Removing path or registration predicates fails the relevant isolated arms; production privacy predicates and approved snapshot bytes remain unchanged.
  • Two source-claim regressions bind to the retained documentation revisions: the PR subject stays explicitly derived from the native repository prefix and separately documented event suffix; the harness header requires Console acceptance and rejects a denied historical run as acceptance evidence. Restoring each prior decision/header independently fails its corresponding control.
  • Registration uses the documented scripts.host_receipts.register_file routine, followed by sorted-manifest and FULL validation. No snapshot bytes are redacted, encoded or refetched.

The fixed error class requires is_error == true, total_cost_usd == 0 and modelUsage == {}; it describes that shape and does not establish a Console denial reason. Raw provider strings stay out of record, summary and console. Toolkit accounting retains incomplete totals as null and checks every result. The actual hosted S2 subtype-success/is_error-true/num_turns-1 shape is exercised synthetically.

P3 resolver/cron/cache work stays separate. The local review worker #953 is adopted from actual main after it lands.

SOTA sources

  • CPython v3.13.16:Lib/unittest/case.py:647 calls setUp before the test method at:651; subTest at:538 is a context manager inside that case. It does not reset its fixture, so each privacy arm owns a fresh TemporaryDirectory/copytree publication. Native source was verified at this release.

  • anthropics/claude-code-action@2dca132ff0e0c4094ce6048b422c6915a071210b:base-action/src/run-claude-sdk.ts:141: the result fields is_error, total_cost_usd, modelUsage; line 222 retains execution records; lines252–256 treat subtype success with is_error true as a failure.

  • The same action:base-action/src/workload-identity.ts:51 and examples/claude-wif.yml:31: supported GitHub federation and its permission.

  • GitHub OIDC reference: retained evidence/artifacts/claude-federation-docs-20261010/docs.github.com_actions_reference_security_oidc.txt:352–359, revision sha256:35d79cb17e94732a467c63e59c3a01d18029b47f4b5f9cbf15d92037164b03cd, retrieved 2026-10-10, 37248 bytes. Vendor URL. The separate pull_request suffix is at332–336; combining it with the native REST sub_claim_prefix is explicitly derived, not quoted from the immutable-subject section.

  • Claude WIF GitHub guide: retained evidence/artifacts/claude-federation-docs-20261010/platform.claude.com_wif-providers_github-actions.md:316, revision sha256:edc97bf1872a1292911b08600aadfc494295009cc6db1da232279dae46c0429b, retrieved 2026-10-10, 14693 bytes. Vendor URL. Opaque exchange denial and native history supply distinct evidence.

  • Claude WIF concepts: retained evidence/artifacts/claude-federation-docs-20261010/platform.claude.com_workload-identity-federation.md:42, revision sha256:d929e36810bcfdcc7a9bf5de39df8b08fbfde60a6d4c138b097f0940feb13bb7, retrieved 2026-10-10, 25749 bytes. Vendor URL. All configured subject/audience/claim matchers must pass.

  • evidence/artifacts/claude-federation-docs-20261010/snapshots.json binds those three source URLs, content revisions, dates, sizes and claim-line locators. The reviewed source packet was staged at 2026-10-10T07:03:18Z; individual request times were not recorded, so that timestamp is not relabeled as an exact retrieval time.

  • Repository-supported registration: scripts/host_receipts.py:register_file, documented in docs/lanes.md and recipes/saturation-sweep.md; current CI-supported kjanat/actionlint 1.17.0 and zizmor 1.30.1 remain the native workflow checks.

Evidence-class table

Claim Evidence class Command / receipt
Original zero-cost accounting diagnosis gap synthetic Actual original workflow shell failed before keeping a record; original red proof retained
Reviewed vendor documentation revision and exact bytes source_review Three supplied captures copied byte-for-byte, independently SHA/size checked, registered; claim locators and provenance in snapshots.json
Missing revision contract local_integration New source-provenance regression failed first without the snapshot index; final index/hash/size/locator/registry checks pass
Public-example UUID false positive local_integration Original FULL validator refused both exact public sources; eight isolated arms name their target's UUID error. Path, registration, registered-hash and content-hash mutations fail without harness errors; other privacy-pattern controls pass
Derived PR subject and conditional harness acceptance local_integration Two retained-revision source assertions pass; independently restored prior workflow header, decision paragraph and harness header each fail their relevant assertion
Complete validator/diagnostic/workflow modules local_integration 253 tests, no skips, rc0, 34.815s; all five complete modules. S2 is a subtest, not a native exchange replay
FULL publication integrity/scope local_integration scripts/validate.py rc0:11404 hashed files,239 receipts,70 components,4 profiles
Landing same-change local_integration All nine affected Python ASTs/workflow YAML values equal the reviewed6353fadf source; all three vendor captures byte-identical. Range-diff retains three mapped commits; only regenerated registry bindings and cited/comment/prose P3 changes
Local secrets scan local_integration gitleaks8.30.1, fully redacted PR range only, without size cap; rc0, three commits, no leaks
Correct Console rule and accepted native Opus review source_review Remaining owner/CC operational acceptance; no new model/federation run claimed

Local commands run

python3 -m unittest tests.test_validate tests.test_claude_federation_diagnostics tests.test_claude_pr_review_workflow tests.test_claude_pr_toolkit_review_workflow tests.test_claude_harness_audit_bounds
# rc0, 253 tests, no skips, 34.815s.

python3 scripts/validate.py
# FULL rc0,11404 hashed files.

python3 scripts/evidence_manifest.py --check
# Sorted current-main registry and owned bindings refreshed via register_file.

gitleaks git . --config .gitleaks.toml --redact=100 --no-banner --log-opts="fcdeae42c82b2279ccd5a0ee3867fd70ba1beff2..HEAD"
# rc0, three PR commits scanned, no size cap, no leaks.

git diff --check
# rc0.

Decision record

docs/decisions/2026-10-10-claude-federation-diagnostics.md: final diagnostics/documentation scope, pinned vendor references, immutable-subject derivation, retained source boundary and operational acceptance procedure. The audit plan's O7/O8 remains on the separate owner list; broad review scheduling and harness re-enablement wait for accepted native federation.

Host evidence

No files under evidence/hosts/ are changed.

Checklist

  • Existing full action pins, top-level permissions and job grants retained.
  • Three reviewed vendor source files are registered and byte-identical, with stable revision/date/hash/size/locators.
  • Privacy correction is restricted to exact registered public document bytes and the UUID heuristic; all other patterns remain.
  • No credentials, private runtime identifiers or local user paths published.
  • No new hosting, subscription, billing or required secret.
  • Peer worktrees, held heads and local WIP preserved.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 10, 2026
@socket-security

socket-security Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@seathatflowsinourveins seathatflowsinourveins changed the title fix(ci): retain zero-cost Claude federation diagnostics Retain Claude federation diagnostics and pinned vendor documentation Oct 10, 2026
@seathatflowsinourveins
seathatflowsinourveins force-pushed the codex/ns2604-gha-p1-federation-20261010 branch from 6353fad to cb96782 Compare October 10, 2026 13:20
@seathatflowsinourveins
seathatflowsinourveins marked this pull request as ready for review October 10, 2026 13:33
@seathatflowsinourveins
seathatflowsinourveins merged commit c677746 into main Oct 10, 2026
38 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the codex/ns2604-gha-p1-federation-20261010 branch October 10, 2026 13:47
seathatflowsinourveins added a commit that referenced this pull request Oct 10, 2026
…ent (#968)

The owner ruled on 2026-10-10 (relayed by the command center, paraphrased)
that CI Claude review authenticates with an Anthropic API key, not workload
identity federation, which refused every run so far. The key is the
environment secret ANTHROPIC_API_KEY of `claude-review`, whose deployment
branch policy allows main only, so a workflow pushed on another branch gets
no key.

claude-pr-review.yml, claude-pr-toolkit-review.yml and harness-audit.yml
pass anthropic_api_key from that secret and no federation input. The job
that uses the key declares environment: claude-review, and no job holds
id-token: write. They pass github_token, so the pinned action (2dca132f)
requests no GitHub OIDC token (src/github/token.ts:160-168,
base-action/src/workload-identity.ts:43-47). Every other guard is unchanged:
dispatch and schedule on main only, the owner and first-attempt guards, the
bounds step, the daily ceiling and the read-only tools.

The federation exemption and the three id-token write grants leave
tests/test_workflow_policy.py. The new
tests.test_workflow_hardening.ClaudeApiKeyAuthTests requires the secret once
per workflow, the key-using job in the environment, no federation input, no
id-token, no pull request trigger, and the secret in no other workflow. It
fails on main's workflows and passes here. The decision records and
docs/github-automation.md carry the ruling, paraphrased. #961's federation
diagnostics record is marked superseded for CI review; its vendor snapshots
stay retained and tested, and its two workflow-header tests now require the
API-key environment and no federation claim. #961's error_class logic in the
three workflows is kept.

Co-authored-by: seathatflowsinourveins <234074349+seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant