Skip to content

fix(tangle): refuse native credential substitutions on replay - #397

Merged
drewstone merged 1 commit into
mainfrom
fix/provider-native-auth-replay-guards-20261001
Oct 1, 2026
Merged

drewstone merged 1 commit into
mainfrom
fix/provider-native-auth-replay-guards-20261001

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Change

Validate explicit credential and harness overrides before the existing exact-replay return.
Plain replay reads without backend overrides remain unchanged.
The admitted request, control reference and digest are never rewritten during replay.

Verification

  • Baseline: both credential-substitution replay regressions failed.
  • Corrected Provider suite: 508 tests pass.
  • Provider typecheck passes.
  • The additional consumer invokes Runtime startRetainedRun and verifies that the selected native reference reaches dispatch before the initial control reference is minted.
  • Fixtures are synthetic; no real credential values are present.

Evidence: /mnt/traces/provider-native-auth-turn-binding-20261001/replay-guard/.

Boundary

This is a shared replay guard, not the measured Sidecar streaming-schema login fix.
The production auth repair is tracked separately in agent-dev-container PR8657.
Existing exact replay and cancellation identities remain authoritative.

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — 0df123be

Blanket team auto-approval is intentional. The merge gates are CI and codex-p1.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-10-01T07:18:34Z

@drewstone
drewstone merged commit 09868d9 into main Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants