Skip to content

test(support): bind support-bundle counts and secret redaction - #134

Draft
seonghobae wants to merge 8 commits into
mainfrom
codex/support-bundle-regression-coverage
Draft

seonghobae wants to merge 8 commits into
mainfrom
codex/support-bundle-regression-coverage

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem and bounded delta

Protected main already carries the shutdown-listener race repair, so the unique delta on this branch is the support-bundle regression contract only:

  • require top-level support-bundle runtime counts to match the KPI snapshot;
  • require the same counts to match buyer-evidence-manifest runtime counts;
  • serialize the support bundle and assert the quoted administrator secret is absent.

This is test-only hardening in src/lib.rs; it does not change production runtime behavior.

Protected-main adoption — refreshed 2026-09-11 KST

Protected/default main is exact f8260f1e03836039ff9463dd99fa982e4e270c4b. Reverse-direction restack #314 adopted that protected auth/security baseline normally into codex/support-bundle-regression-coverage, without force or destructive rebase, producing current exact head b6c1f2cfb9d05f36b5ef14c7be6004c00af762d4. Fresh comparison remains a single-file 38-line test delta in src/lib.rs; protected #155 behavior is inherited rather than copied.

All predecessor workflow/review conclusions are historical after #314.

Exact-current evidence

On unchanged exact b6c1f2cfb9d05f36b5ef14c7be6004c00af762d4 all principal repository/security lanes are now terminal:

  • CI 34572688789 — SUCCESS;
  • Fuzz 34572688651 — SUCCESS;
  • SAST Semgrep 34572688741 — SUCCESS;
  • Security Scan 34572688686 — SUCCESS;
  • required CodeQL PR 34572688797 — FAILURE at the delegated current-head terminal-settlement boundary.

The earlier queued snapshot is superseded. .github#1929 owns the central CodeQL settlement defect; current repair successor .github#2040 remains mutable owner-path work rather than Wardnet dependency authority. Wardnet does not add no-op commits, copy central workflows, promote predecessor verdicts, or use routine/guarded bypass while a required workflow is RED.

Because required CodeQL remains non-passing, this PR stays Draft. Live ruleset 18156473 also retains the generic solo-maintainer approval defect tracked by .github#772; self/model approval and routine administrator bypass remain forbidden.

Keep Draft until one unchanged exact head has terminal-valid deterministic/security/CodeQL/coverage/package/SBOM/provenance/review/thread/governance evidence and fresh protected-base compatibility. No gate weakening, force push, destructive rebase, mutable foreign dependency, source copy, cross-service SQL, or predecessor-evidence transfer.

Summary by CodeRabbit

  • 테스트
    • 지원 번들에서 관리자 인증 설정, 자격 증명 출처, 관련 데이터 수와 KPI 및 증거 매니페스트의 런타임 수치가 일치하는지 확인합니다.
    • 직렬화된 결과에 관리자 토큰이나 인증 헤더가 포함되지 않는지 확인합니다.

@coderabbitai

coderabbitai Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: d61bc2fd-10f4-40fd-94f0-45381d4e639d

📥 Commits

Reviewing files that changed from the base of the PR and between 4db7568 and b1758bb.

📒 Files selected for processing (1)
  • src/lib.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

지원 번들은 인증 설정과 자격 증명 출처를 검증합니다. 테스트는 번들의 런타임 카운트를 KPI 및 증거 매니페스트와 비교합니다. 직렬화된 JSON에 관리자 토큰 헤더 이름이나 토큰 값이 포함되지 않는지도 확인합니다.

Changes

지원 번들 검증

Layer / File(s) Summary
지원 번들 출력 검증
src/lib.rs
테스트에서 이름이 지정된 관리자 토큰으로 인증합니다. 인증 설정과 자격 증명 출처를 확인하고, 경로·위협·DNSBL·피드·이벤트·감사 카운트가 KPI 및 증거 매니페스트와 일치하는지 검증합니다. 직렬화된 JSON에 관리자 토큰 헤더 이름이나 토큰 값이 없는지도 확인합니다.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to b1758

The reviewed changes strengthen support-bundle tests and introduce no identified behavior risk. Confirm required checks against this revision through the normal merge process.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 지원 번들 수 검증과 관리자 비밀값 비직렬화를 포함한 테스트 변경을 정확하고 간결하게 설명합니다.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@seonghobae seonghobae changed the title fix(runtime): arm shutdown before readiness test(support): bind support-bundle counts and secret redaction Sep 1, 2026
@seonghobae
seonghobae enabled auto-merge (squash) September 1, 2026 10:14
@opencode-agent
opencode-agent Bot disabled auto-merge September 1, 2026 10:25
@seonghobae
seonghobae enabled auto-merge (squash) September 1, 2026 12:29
@opencode-agent
opencode-agent Bot disabled auto-merge September 1, 2026 17:47
@seonghobae
seonghobae enabled auto-merge (squash) September 2, 2026 17:34
@opencode-agent
opencode-agent Bot disabled auto-merge September 3, 2026 13:25
@seonghobae
seonghobae enabled auto-merge (squash) September 5, 2026 17:29
@seonghobae seonghobae added maintenance priority: medium Normal-priority or P2 work type: maintenance Maintenance, build, dependency, or operational upkeep labels Sep 7, 2026 — with ChatGPT Codex Connector
@opencode-agent
opencode-agent Bot disabled auto-merge September 7, 2026 23:23

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • src/lib.rs — Rust package behavior

Changed behavior

classDiagram
  class AppState
  class SocLlmConfig
  class ClearfolioConfig
  class seeded
  class load
  class with_kev_catalog_url
  class with_max_body_size
  class with_clearfolio
Loading

Changed API

  • AppState
  • SocLlmConfig
  • ClearfolioConfig
  • seeded
  • load
  • with_kev_catalog_url
  • with_max_body_size
  • with_clearfolio
  • with_soc_llm
  • with_rate_limit
  • with_admin_tokens
  • with_credentials_source
  • AppConfig
  • memory
  • SupportBundle
  • HealthStatus
  • build_app
  • export_events_ndjson
  • upstream_target
  • AdminPrincipal
  • parse_admin_tokens
  • parse_event_limit
  • parse_u32_env
  • parse_u64_env
  • run_from_env

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: ce58b6ec2968f314ea223ddb9ff7228fc4222e44
  • Workflow run: 34170689654
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

classDiagram
  class AppState
  class SocLlmConfig
  class ClearfolioConfig
  class seeded
  class load
  class with_kev_catalog_url
  class with_max_body_size
  class with_clearfolio
Loading

@opencode-agent

opencode-agent Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

…ression

chore(restack): adopt protected auth baseline into support-bundle regression
@seonghobae
seonghobae marked this pull request as draft September 11, 2026 07:20
The commercial support-bundle test now uses a distinct admin token and
checks that health reports auth as configured while the serialized bundle
omits the token and the header name. Direct AppConfig loads stay source none.
@seonghobae
seonghobae marked this pull request as ready for review September 28, 2026 06:40
@seonghobae
seonghobae enabled auto-merge (squash) September 28, 2026 06:40
@opencode-agent
opencode-agent Bot disabled auto-merge September 28, 2026 09:35

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The changes improve the test suite by replacing hardcoded secrets with a variable and adding comprehensive assertions to verify the correctness of support bundle counts and the effectiveness of secret redaction during serialization. The implementation maintains consistency across API requests and ensures that sensitive authentication tokens are not leaked in the diagnostic output.

Reviewed changed lines

  • src/lib.rs:4811 (RIGHT): Replacing the hardcoded 'secret' with a variable admin_token ensures consistency across the test case setup and subsequent API requests.
  • src/lib.rs:5025 (RIGHT): New assertions verify that support bundle counts are synchronized across kpis and evidence_manifest.runtime_counts, ensuring data integrity in diagnostic reports.
  • src/lib.rs:5064 (RIGHT): The assertions confirm that neither the sensitive token value nor the x-admin-token key are present in the serialized JSON, validating the redaction logic.

Adversarial validation

  • src/lib.rs:4811 (RIGHT) falsified: The replacement of the hardcoded 'secret' string with a variable admin_token across the test case introduces inconsistency or breakage in API request authorization. — The variable admin_token is defined at line 4811 and consistently used in all json_request calls (lines 4862, 4875, 4902, 4915).
  • src/lib.rs:5025 (RIGHT) falsified: The new assertions for support-bundle counts (lines 5025-5063) might be comparing incompatible types or incorrectly mapping fields from kpis and evidence_manifest. — The assertions correctly verify that the top-level summary counts in the support bundle are synchronized with both the kpis snapshot and the evidence_manifest.runtime_counts.
  • src/lib.rs:5064 (RIGHT) falsified: The redaction assertions (lines 5064-5065) are insufficient to prove that sensitive credentials are not leaked in the serialized output. — The test asserts the absence of both the key x-admin-token and the specific value of the admin_token, confirming effective redaction for the configured secret.
  • Residual risk: none

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: b1758bb838c7b315cdf4e55064985c3626f52e5e
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 05:40

Copy link
Copy Markdown
Contributor Author

Shared-owner RCA and repair

The exact-head Strix failure at b1758bb838c7b315cdf4e55064985c3626f52e5e (run 36387392997, job 109439414934) reached bounded continuation after 78 seconds, then central redispatch failed with HTTP 403 Resource not accessible by integration.

Root cause is owned by the reusable workflow in ContextualWisdomLab/.github: the consumer does not inherit the central PAT secret, and its repository-scoped github.token cannot dispatch ContextualWisdomLab/.github.

Owner repair: ContextualWisdomLab/.github#2540, stacked on .github#2532. It exchanges GitHub Actions OIDC for a short-lived repository-scoped OpenCode GitHub App token and removes the invalid consumer-token fallback. Exact owner-tree verification: 5162 passed, 10 skipped, 40 subtests passed.

Do not rerun the unchanged predecessor evidence. After the owner stack merges, revalidate this PR's then-current exact head; acceptance requires successful token exchange, central continuation dispatch, and a fresh terminal Strix verdict.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance priority: medium Normal-priority or P2 work type: maintenance Maintenance, build, dependency, or operational upkeep

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants