fix(errors): bound ValidationError rejected-value evidence - #133
Closed
seonghobae wants to merge 4 commits into
Closed
seonghobae wants to merge 4 commits into
seonghobae wants to merge 4 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closed unmerged — feasibility evidence for #132
Issue #132 identified a valid package-wide confidentiality footgun: protected-main
ValidationErrorrenders arbitrary rejected values withvalue!rand stores the original value in structured details by default. This Draft tested whether the generic constructor could be hardened immediately as a successor stacked on exact #105, which ownspg_llm_batch/exceptions.py.Test-first experiment
5a49c3883e283860aa3329fa2a5cddbecf66d61eadded focused confidentiality contracts requiring a non-disclosing default, hostile-__repr__isolation, and explicit reviewed opt-in for non-sensitive value evidence.7c910eeb2eb511f28753da5d6cc68aff7461b9f8implemented that constructor policy on top of exact fix(errors): snapshot structured evidence inputs #105.243ec4eeebb26209258c563e1fd276b91ea4b667strengthened the disclosure-authority type boundary.f32f9217f5a2e71d938027ac2457926e28f7b2d8exposed the integration problem: existing call-site contracts, such as provider endpoint validation, intentionally assert raw rejected-value evidence today.Why this branch is not a feasible integration unit now
The generic default change is semantically package-wide. Making this successor green would require editing call-site tests and potentially production policy across surfaces currently owned by independent active PRs: #71 provider validation, #87 orchestrator/resource ownership, #104 request validation, and the #53 lifecycle stack. Continuing here would create a competing writer/integration branch rather than a narrow #105 successor. Those owners also need explicit classification of which rejected values are safe diagnostic evidence versus content-bearing/confidential values; blindly replacing every value with
<redacted>would reduce useful diagnostics without a reviewed compatibility policy.Therefore this experiment is closed unmerged. Its commits remain development evidence for #132, but no checks/reviews/approvals transfer and no behavior should be treated as shipped or as an accepted replacement for the active owners.
Next bounded path
Keep #132 open. After #105 and the relevant call-site owners reach protected main or are superseded, rebuild from the then-current protected result: establish the cross-package compatibility inventory first, classify each rejected-value surface, then apply the smallest safe constructor/call-site API with fresh RED→GREEN and exact-source evidence.
This closure is a failed-feasibility result, not a rejection of the privacy defect.