Repository navigation
fix(policy): deny uninspectable ancestors and verify configured releases - #4
Conversation
…eleases Co-authored-by: Medulla <medulla@tinyhumans.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 1 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Resolved this pass
Before mergeNone. Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
There was a problem hiding this comment.
Requesting changes: 1 lane(s) blocking, worst finding is high.
Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.
$0.0107 · 137,514 in / 11,334 out · 18,004 cached (13%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0068 · 79,548 in / 6,807 out · 10,864 cached (14%) · gpt-5.6-luna, glm-5.3-flash
security: $0.0038 · 45,626 in / 2,338 out · 5,476 cached (12%) · gpt-5.6-luna
tests: $0.0001 · 4,751 in / 1,111 out · 64 cached (1%) · glm-5.3-flash
description: $0.0000 · 4,390 in / 108 out · 1,472 cached (34%) · glm-5.3-flash
Co-authored-by: Medulla <medulla@tinyhumans.ai>
There was a problem hiding this comment.
The previously-blocking findings are resolved. Clearing the changes request.
$0.0005 · 24,004 in / 2,325 out · 3,328 cached (14%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0004 · 3,881 in / 254 out · 0 cached (0%) · gpt-5.6-luna
tests: $0.0001 · 11,527 in / 1,030 out · 3,136 cached (27%) · glm-5.3-flash
description: $0.0000 · 5,025 in / 112 out · 64 cached (1%) · glm-5.3-flash
Ancestor resolution treated non-NotFound metadata failures as missing components after canonicalization returned NotFound. It now propagates permission and other inspection errors instead of reconstructing an authorized prospective path. Canonical forbidden-root aliases containing the workspace also preserve the documented workspace precedence; narrower forbidden subtrees remain denied.
Both behavior regressions failed before the fixes and pass afterward. Validation: 152 Linux tests plus the constructor compile-fail doctest, full all-features build, Clippy with warnings denied, formatting, native loader verification, and every production source file above 90% line coverage.
The v0.2.2 release bundles passed every platform's native verifier, but the final generic loader invoked the module with
{}, which is intentionally invalid initialization configuration. The release workflow now uses TinySecurity's existing configured verifier over the same GitHub archive/digest loader; it also exercises actual policy calls and SDK reinitialization. That verifier successfully loaded the published v0.2.2 archive, while the failing generic invocation is recorded in release run 38077126471. No configuration validation or policy checks are relaxed.Follow-up to #3 and OpenHuman issue tinyhumansai/openhuman#7328. OpenHuman's migration remains in tinyhumansai/openhuman#7331; these policy fixes need merging and a new published release before the host ships them.
Summary by CodeRabbit