Skip to content

fix(ci): secure and bound sandbox evidence streams - #788

Draft
seonghobae wants to merge 2 commits into
mainfrom
fix/sandboxed-evidence-bounds-main
Draft

fix(ci): secure and bound sandbox evidence streams#788
seonghobae wants to merge 2 commits into
mainfrom
fix/sandboxed-evidence-bounds-main

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Purpose

Rebuild the reviewed sandbox confidentiality and availability controls from broad predecessor #767 directly on the current protected main baseline, without carrying stale dependency, scanner, or scheduled-security snapshots.

Intended focused scope

  • bounded stdout, stderr, and long-running service evidence with process-group termination on overflow;
  • complete credential redaction for commands, timeouts, nested JSON, service tails, and evidence notes;
  • structured argv and shell=False execution;
  • finite reader finalization, bounded service-tail reads, cleanup-failure evidence, and deterministic exit codes;
  • hostile Unicode, JSON, timeout, flood, stuck-reader, and readiness regressions;
  • permanent Python 3.14 integrated quality workflow enforcing 100% production statement, branch, and public-docstring coverage;
  • APA 7 doctoring, design/plan evidence, and CHANGELOG entries.

The branch currently contains a self-removing materialization workflow that imports only the reviewed feature files from immutable predecessor head 45e4929e1fc473211168b2d6360c9da2516e5341, validates them against current main, and publishes a focused commit. Keep Draft until the materializer removes itself and exact-head checks complete. Close #767 as superseded only after this replacement is materialized and reviewed.

No predecessor-head checks or approvals are reused.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d8eb8d04-7a8c-4c3b-a406-216535d48802

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant