fix(strix): fail closed on incomplete provider scans - #1153
Conversation
|
Current-main successor for #1138: head |
|
Warning Review limit reached
Next review available in: 40 minutes Limit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?Wait for the limit to reset, then comment An organization admin can change what happens after included review limits in Billing. How do review limits work?CodeRabbit enforces per-developer PR review limits within each organization. For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (10)
🚧 Files skipped from review as they are similar to previous changes (2)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughStrix에 PR-head 컨텍스트 수집과 격리된 작업 디렉터리 실행이 추가되었습니다. ChangesStrix 스캔 경계와 컨텍스트
Estimated code review effort: 4 (Complex) | ~60 minutes Merge Risk: ⚪ Minimal · up to The change is merge-ready after normal checks and review; no actionable merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-head review request for PR #1153:
Please provide a fresh independent review for this exact head. Protected current-head checks and qualifying approval remain required before merge. |
|
Current-head verification for |
|
@opencode-agent Review exact current head |
Keep Vulnerabilities [1-9] fail-closed. A scanner-model error without a numbered finding is infrastructure noise, not a security result.
998ad7b to
51c3815
Compare
|
@opencode-agent Review exact current head 51c3815 against main@2cce96f8. Rebased the Strix ModelBehaviorError classifier onto current main; only a qualified exception with no numbered vulnerability/severity finding neutralizes a backend flake, while real findings remain fail-closed. Verified: 63 focused Strix/queue tests, actionlint, compileall, and git diff --check passed. |
|
Exact-head control-plane contradiction on A scanner turn that terminated with Deterministic counter-evidence is preserved at commit Please keep this PR unmerged unless incomplete provider/model execution returns an explicit typed non-passing result. A genuine complete zero-finding scan can still pass; actual findings remain independently fail-closed. |
|
@opencode-agent Review exact current head |
|
@opencode-agent Review current exact head |
|
@opencode-agent Review exact current head SHA 86c262c. Confirm the typed STRIX_PROVIDER_UNAVAILABLE evidence, nonzero required result, current checks, and test/coverage evidence. Return a formal structured current-head verdict. |
|
@opencode-agent Review the current exact head as the sole current-main successor to #1138. Verify the classifier only treats trusted Strix-process |
|
@opencode-agent review exact current head |
|
Integrated current main normally and restored the unrelated main-document merge artifacts; current PR diff is scoped to the Strix workflow, doctoring, changelog, and two contract-test files at 119d563. Focused Strix/queue suite passed (77 tests, 16 subtests), actionlint, ruff, and diff checks passed. Re-review this exact HEAD. @OpenCode review this exact HEAD and report only current-head findings. |
|
@opencode-agent review this exact current HEAD. Use the current commit SHA, current Checks, and current diff; do not reuse prior approvals or prior-head evidence. |
|
Exact current head |
|
Already queued @cwl-noema-review on this exact request for PR #1153 at head |
|
Exact-head formal review requested for |
|
Current-head review of
|
|
Current-head validation for
|
|
Exact-head Strix dependency-context update:
Hosted Organization Quality run @opencode-agent review-only exact head |
Exact-head Strix package-context convergenceCurrent exact head: This head absorbs the valid Fresh verification on the exact local tree published above:
Hosted checks and an independent exact-current-head Reviews API verdict remain required; predecessor evidence is not inherited. @opencode-agent review-only Please provide a substantive formal verdict for exact head |
Final exact-head single-writer convergenceCurrent exact head: This head additionally absorbs the valid Rust workspace scope from now-closed competing writer #1173. Rust Fresh exact-tree verification:
Hosted exact-head jobs and an independent exact-current-head formal verdict remain required. No predecessor check or review is inherited. @opencode-agent review-only Please submit a substantive Reviews API verdict for exact head |
|
Current canonical head |
Hosted exact-head Strix evidenceFinal exact head
The same exact head also has successful organization-policy run |
|
Exact-head repair receipt
@cwl-noema-review @opencode-agent Please review this exact head only. Approve only if the current head and current required checks support it; do not treat provider-rate-limit evidence as a source vulnerability. |
|
Exact-head documentation follow-up
@cwl-noema-review @opencode-agent review |
|
Correction: the exact current head is |
Outcome
Strix provider/backend exhaustion and scanner
ModelBehaviorErrornow produce typedSTRIX_PROVIDER_UNAVAILABLEevidence while preserving the scanner's nonzero result. An incomplete scan can no longer satisfy the required check; genuine complete no-finding scans still pass, and reported findings remain fail-closed.Causal repair
STRIX_PROVIDER_UNAVAILABLEand exits with the original nonzero Strix result.Vulnerabilities [1-9]or aseverity:finding continues through the security-finding failure path.HTTP 410token. Target-output prefixes, missing factors,4100,4104, and standalone retirement-brownout phrases cannot mark the provider family unavailable.loginAsGuest, bounded retries, curl exit 7, exact loopback port 48080) is typed as unavailable infrastructure only when no vulnerability finding exists; any genuine finding remains blocking.strix_runsstate is isolated in a private working directory outside the canonical absolute scan target, then preserved only as gate evidence. PR scopes live under the gate-owned runtime directory, and PostgreSQL introspection security helpers are included when that package exists.TDD evidence
85523e166f03b0552f6dfa0b0f65df10874d4e60: run32333482589, job96318479338, failed exactly the two new non-pass assertions;1234 passed,16 subtests passed.a06e6e7c6e6debd8a2a61e98cf15fc49ae7ca6b2: run32333666263, job96318958629, exposed one stale neutral-wording assertion;1235 passed,16 subtests passed.1, made only the primary-model call, and did not enter bounded fallback.4100,4104, target-output spoof, and standalone brownout phrase) fail closed without fallback.b3ce110714016b13d02292884ca2088e3e32b17ewith the tests only: the no-finding bootstrap outage was not classified (1 failed, 14 passed); the real-finding negative control remained blocking.e21951d73fbe05a3b9dda871b18c7480f1fe3e41: all 15 focused outer-workflow classification tests pass.e21951d73fbe05a3b9dda871b18c7480f1fe3e41: Strix Changed Path Quality CI run32352471689, job96374420561, checked out the exact head, passed1238tests plus16subtests, and completedtest_strix_quick_gate: PASS.32352471604, job96374420153, checked out the same head, passed 34 tests, and proved 100% statement/branch coverage for the governed policy module.e21951d73fbe05a3b9dda871b18c7480f1fe3e41produced 8 expected failures, including target-as-cwd and missing canonical absolute target; the behavioral fixture exited 81 because the scanner inherited the untrusted scan target as cwd.2e8e78271481a5ac0d7c6502973aa9ee8cfbc206: the focusedscan-working-directory-isolatedcase, shell syntax checks,git diff --check, and the complete local Strix harness pass.32358562547, job96392998076, checked out2e8e78271481a5ac0d7c6502973aa9ee8cfbc206, passed1238tests plus16subtests, and completedtest_strix_quick_gate: PASS; Organization Quality run32358562748, job96392998558, checked out the same head, passed 34 tests, and measured the policy module at 100% statement/branch coverage.Protected-main integration remains required before unchanged consumer acceptance. No predecessor, queued, status-only, or provider-incomplete evidence is merge authority.
Summary by CodeRabbit
버그 수정
문서
Latest provider-exhaustion fail-closed correction
9ddda5bfaa59907120c01b55d13fa731a69bcba9, non-destructively merged with protectedmain@55a8b576725451dfe0a21a57d36a2f1a41619b24.9a4d1e1439bbafa8781971fbf22ab695ae126271, the two added commits are only the protected-main integration and its release: attest exact sealed SBOM evidence #797 exact-artifact SBOM control-plane files; the Strix repair remains unchanged.956ae2b8db7acdda333c76537425ab8cb85c82f2: exhausted providers after an unchanged-baseline finding returned exit0; the new contract failed both the required nonzero result and typed-message assertions.STRIX_PROVIDER_UNAVAILABLE. Observed baseline attribution cannot prove completeness after provider exhaustion.4100,4104, target-output spoofing, and standalone brownout controls all pass.96589601993, checked out9ddda5bfaa59907120c01b55d13fa731a69bcba9, passed1287tests plus16subtests, and completedtest_strix_quick_gate: PASS.96589601448, passed 34 tests and measured the governed policy module at 380/380 statements and 88/88 branches.Latest exact-head diagnostic disclosure repair
a82b8012be5d57f99c1a2b029f08837d4d10d564.GitHubClientdiagnostics. The current head keeps the allowlisted HTTP method names and emits[REDACTED_METHOD]for any other diagnostic value.git diff --checkpassed.96618858687, checked out the exact head, passed 1,288 tests plus 16 subtests, and completedtest_strix_quick_gate: PASS.96618858361, checked out the same head, passed 34 tests, and measured 382 statements / 88 branches at 100%.96618858955, checked out the same head, passed 49 contracts, and measured 226 statements / 82 branches at 100%.