Skip to content

fix(errors): bound ValidationError rejected-value evidence - #133

Closed
seonghobae wants to merge 4 commits into
fix/exception-detail-snapshot-integrityfrom
fix/validation-error-value-confidentiality
Closed

seonghobae wants to merge 4 commits into
fix/exception-detail-snapshot-integrityfrom
fix/validation-error-value-confidentiality

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Closed unmerged — feasibility evidence for #132

Issue #132 identified a valid package-wide confidentiality footgun: protected-main ValidationError renders arbitrary rejected values with value!r and stores the original value in structured details by default. This Draft tested whether the generic constructor could be hardened immediately as a successor stacked on exact #105, which owns pg_llm_batch/exceptions.py.

Test-first experiment

  • RED 5a49c3883e283860aa3329fa2a5cddbecf66d61e added focused confidentiality contracts requiring a non-disclosing default, hostile-__repr__ isolation, and explicit reviewed opt-in for non-sensitive value evidence.
  • 7c910eeb2eb511f28753da5d6cc68aff7461b9f8 implemented that constructor policy on top of exact fix(errors): snapshot structured evidence inputs #105.
  • 243ec4eeebb26209258c563e1fd276b91ea4b667 strengthened the disclosure-authority type boundary.
  • f32f9217f5a2e71d938027ac2457926e28f7b2d8 exposed the integration problem: existing call-site contracts, such as provider endpoint validation, intentionally assert raw rejected-value evidence today.

Why this branch is not a feasible integration unit now

The generic default change is semantically package-wide. Making this successor green would require editing call-site tests and potentially production policy across surfaces currently owned by independent active PRs: #71 provider validation, #87 orchestrator/resource ownership, #104 request validation, and the #53 lifecycle stack. Continuing here would create a competing writer/integration branch rather than a narrow #105 successor. Those owners also need explicit classification of which rejected values are safe diagnostic evidence versus content-bearing/confidential values; blindly replacing every value with <redacted> would reduce useful diagnostics without a reviewed compatibility policy.

Therefore this experiment is closed unmerged. Its commits remain development evidence for #132, but no checks/reviews/approvals transfer and no behavior should be treated as shipped or as an accepted replacement for the active owners.

Next bounded path

Keep #132 open. After #105 and the relevant call-site owners reach protected main or are superseded, rebuild from the then-current protected result: establish the cross-package compatibility inventory first, classify each rejected-value surface, then apply the smallest safe constructor/call-site API with fresh RED→GREEN and exact-source evidence.

This closure is a failed-feasibility result, not a rejection of the privacy defect.

@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 4b6dc907-7da1-4950-bdd4-432d8d7aeed7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant