fix(sandbox): replay redaction after fixture-history contamination - #906
fix(sandbox): replay redaction after fixture-history contamination#906seonghobae wants to merge 16 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent review Perform a fresh read-only semantic review of exact current head |
|
@opencode-agent review Perform a fresh read-only semantic review of exact current head |
|
Superseded by current-main successor #929 at exact head |
Replacement purpose
Supersede #888 after its reachable history was re-contaminated by a credential-shaped test fixture while repairing the current Docker/Podman login redaction defect. This branch starts from exact protected
main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dbaand carries only the corrected final blobs.RCA
#888 initially existed to replace #842's contaminated test history. A later test commit on #888 introduced the fixed literal
quartz-capybara-731-opaque. Replacing that line in a following commit did not repair the gate because Secret Scan correctly evaluates the whole PR commit range; run 31319880976 continued to report onegeneric-api-keyfinding in the reachable predecessor commit.Rejected:
Implemented:
Exact identity
6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;5ccf85f64c4a5689d89e64b528880262a22e6de7;285305291fdf602f31796f0c7ff1c2858406c08e;Exact-head evidence
d573d21752e07d3cbbf9845b4b413baf81ecea7c;sh -c/env -S/env --split-string=wrapper cases exposed the runtime-synthesized opaque credential before the repair;Current security scope
This Draft includes the direct Docker/Podman
login -p,-p=, and--password=repair plus the boundedenv -S/ shell-cimplementation tracked by #907. The latest repair fails closed when malformed outer wrapper quoting prevents safe tokenization while preserving the established non-wrapper fallback. Benign Docker publish ports, SSH-pports, env assignments/options, and valid--password-stdinregistries remain visible.The #907 source repair is
active_pr, not protected-main behavior; keep its issue open until integration and protected-main acceptance. Atomic multiline/duplicate-key JSON redaction and layout fidelity remains the stackedactive_prin #929 for #908. Keep this PR Draft until exact-head gates and current review pass and the #908 dependency is integrated or an explicitly reviewed narrower acceptance boundary is adopted. Output-memory and service-file quotas remain separate work in #766.Acceptance
Require exact-head Sandbox Log Redaction Quality CI, Secret Scan, all security/dependency checks, current source review, zero valid unresolved findings, a qualifying independent non-author formal approval, and repository protection. After protected integration, run synthetic protected-main acceptance for completed stdout/stderr, timeout evidence, and bounded service tails before closing the incident.