feat: initial proxy outcome attribution library - #1
Conversation
pnlabs-dev
left a comment
There was a problem hiding this comment.
PN Labs review — CHANGES NEEDED before merge
CI is green, but I would keep this PR in draft until the attribution semantics are hardened. The repo's core promise is evidence-before-action, so false attribution here would undermine the exact thesis we want PN Labs to demonstrate.
Blocking — P0/P1
-
HTTP status is being used to infer the actor too aggressively.
403,429,451, and5xxare currently mapped directly toAttribution.TARGET/UPSTREAMwith high confidence. A status alone does not prove which hop emitted it; CDN/WAF/gateway/proxy-provider/intermediary responses can produce the same codes. Keep observed outcome orthogonal from root-cause attribution. Without emitter evidence, attribution should remain ambiguous/unknown rather than target-specific. -
Generic proxy-connect errors are too strong as bad-proxy + auto-rotation evidence.
ERR_PROXY_CONNECTION_FAILEDcan be caused by client/protocol incompatibility, browser proxy support, local/network policy, configuration, or endpoint failure. The currentbad_proxy_evidence=True+automatic_rotation_evidence=Truecan poison a healthy endpoint. Prefer aPROXY_PATH_FAILURE/transport outcome with no automatic demotion until a control probe or repeated endpoint-scoped evidence confirms it. -
All 3xx responses are classified as
SUCCESSwith confidence 1.0.
In scraping, redirects to login, consent, challenge, CAPTCHA, or an error route are common. A 302/307 is not automatically a usable success. Add a separate redirect outcome or require final-response context before calling success. -
HTTP 451is namedTARGET_GEO_RESTRICTION, which is too narrow.
451 means unavailable for legal reasons; geography may be involved, but is not guaranteed. A neutral name such asHTTP_LEGAL_RESTRICTION/ACCESS_RESTRICTIONwould preserve evidence without inventing cause.
CI hardening — P1
- Current tests bypass packaging.
tests/test_classifier.pymanually insertssrcintosys.path, so CI can stay green even ifpip install .or the console entry point is broken. Before first public merge, CI should install/build the package and smoke-test bothproxy-outcome classify ...andpython -m proxy_outcome ....
Non-blocking
- Actions currently emit Node-runtime deprecation warnings; update/pin the actions when convenient.
SECURITY.mdrefers to a private/public contact channel on the PN Labs profile; make sure that channel actually exists before relying on it.
What is already good
- 407 auth failure is correctly separated from automatic rotation.
- 403/429/451 do not automatically count as bad-proxy evidence.
- Ambiguous timeout fails closed.
- Zero runtime dependencies and machine-readable output are good choices.
- Design-partner benchmark framing is strong and avoids bypass positioning.
Recommendation: keep PR #1 draft, patch the semantic model first, extend CI to test installation/CLI, then rerun review + CI before merge.
pnlabs-dev
left a comment
There was a problem hiding this comment.
PN Labs follow-up review — initial blockers addressed
Second-pass review completed on head 2ace067a2b01e5c84757ecde06d3d2a55a1a2e74.
The initial blockers are resolved:
- HTTP response outcomes no longer invent target/upstream root cause from status alone;
- proxy-path failures are separated from endpoint-health evidence and automatic rotation;
- 3xx is a distinct redirect outcome rather than automatic usable success;
- HTTP 451 is represented as a legal-restriction observation rather than a geo claim;
- packaging is exercised by CI before tests;
- installed CLI entry points are smoke-tested;
- raw header values are not inspected by the classifier;
- CLI error handling avoids echoing malformed sensitive input;
- public security/data-minimization documentation and an explicit OSS/private boundary are present;
- repository hygiene gate passes without echoing matched values;
- workflow token permissions are read-only, checkout credentials are not persisted, and Actions are pinned to full release commit SHAs.
Final CI run 32394871111: Python 3.10 / 3.11 / 3.12 all PASS; package build/install, compile, 17 tests, CLI smoke tests, and public-repository hygiene check all PASS.
No remaining source-level merge blocker found in the reviewed scope. Keep the PR draft until explicit merge authorization.
75d10a3 to
ad43d43
Compare
pnlabs-dev
left a comment
There was a problem hiding this comment.
Final merge-prep review
Clean-history preparation is complete.
- feature branch reduced to one commit directly on top of
main; - final tree preserved exactly across the squash;
- current head:
ad43d432f6ce5d319510f227c1f1aff0eb79e100; - CI run
32397259192: PASS; - Python 3.10 / 3.11 / 3.12: PASS;
- public repository hygiene gate: PASS;
- source install/build + compile: PASS;
- unit tests: 17/17 PASS;
- installed CLI smoke tests: PASS;
- current public tree uses vendor-neutral hygiene labels and contains only the intended OSS baseline.
No source-level or CI-level merge blocker remains from this review. Merge is intentionally left as a separate authorized action.
Summary
Introduces the first public PN Labs implementation of
proxy-outcome: a deterministic, zero-runtime-dependency library that classifies HTTP/proxy observations without inventing root cause or endpoint-health evidence.Core model
The public API separates:
Key invariants:
ERR_PROXY_CONNECTION_FAILEDis a proxy-path failure, not automatic proof that the endpoint is unhealthy;Included
Security / public-repository hardening
This repository is intentionally limited to the transparent deterministic baseline.
.gitignoreblocks common secret/capture artifacts;Commercial control-plane implementation, private routing/scoring logic, provider-private configuration, private infrastructure details, and non-public datasets remain outside this repository.
Clean history
The feature branch was rebuilt from the final reviewed tree and force-updated to a single commit directly on top of
main.ab05187357a4dc4fa7079217e8f881a216c52067ad43d432f6ce5d319510f227c1f1aff0eb79e100Final validation
Validation on the clean-history head
ad43d432f6ce5d319510f227c1f1aff0eb79e100:CI run:
32397259192.Merge posture
The semantic, packaging, CI, public-security, IP-boundary, and branch-history review items are resolved. No merge has been performed by this preparation step.