Skip to content

fix(guard): prepare the resident state dir before package-authority requests - #4061

Open
zerocodefast wants to merge 1 commit into
mainfrom
fix/package-authority-resident-prerequisite
Open

zerocodefast wants to merge 1 commit into
mainfrom
fix/package-authority-resident-prerequisite

Conversation

@zerocodefast

Copy link
Copy Markdown
Collaborator

Summary

Package-authority requests (package_intent_parse_native and friends) went to the resident runtime without calling ensure_resident_prerequisite. Every other resident client does this first. On a fresh guard home the runtime refuses the request with native_resident_state_dir_create_failed. The Python side then returns no intent.

That is why the nightly "Linux contained runners" job fails at assert intent is not None in ci/containment/test_linux_containment.py. CI runners start with a fresh home.

Change

  • _resident_request in native_package_authority.py now calls ensure_resident_prerequisite(guard_home) after the feature check, the same way the data-flow, policy-bundle, supply-chain and git-inspection clients do.
  • New tests/test_native_package_authority_prerequisite.py checks that the prerequisite runs before the runtime is contacted, and that a failed prerequisite skips the request.
  • tests/test_native_stream_deadline.py stubs the prerequisite for the pool-exhaustion deadline test, which uses a fake runtime path.

Before / after

Reproduced with a release hol-guard-runtime build, HOL_GUARD_NATIVE=force, an empty HOME, and npx --no-install vitest run boundary.test.ts --reporter=dot:

  • Before: resident response {"error":"native_resident_state_dir_create_failed","retryable":false}; intent None.
  • After: status: ok; PackageIntent(package_manager='npx', intent_kind='execute', ...).

Local suite over the 34 test files that touch package authority: failures and errors are identical before and after (these are local-only native-binary fixtures); there are 2 new passes.

…equests

Package-authority requests went to the resident runtime without first
creating the guard home's resident state directory. On a fresh home the
runtime refused with native_resident_state_dir_create_failed, so package
intent parsing returned nothing and contained runner checks lost their
intent. Call ensure_resident_prerequisite the same way the other resident
clients do.

Signed-off-by: ZCF <291624129+zerocodefast@users.noreply.github.com>
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing

@coderabbitai

coderabbitai Bot commented Oct 11, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 4 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository UI (base), Organization UI (inherited)
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7843a532-9c01-43f0-b6d3-1447947888ba

📥 Commits

Reviewing files that changed from the base of the PR and between 0b277c2 and b7e4130.


📒 Files selected for processing (3)
  • src/codex_plugin_scanner/guard/native_package_authority.py
  • tests/test_native_package_authority_prerequisite.py
  • tests/test_native_stream_deadline.py

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

PR Summary by Qodo

Prepare resident state before package-authority requests

🐞 Bug fix 🧪 Tests 🕐 10-20 Minutes

Grey Divider

AI Description

• Provision the guard home's resident state before package-authority requests, fixing intent parsing
 on fresh homes.
• Skip the runtime request when provisioning fails.
• Test request ordering and preserve the deadline test's isolated runtime fixture.
Diagram

graph TD
  A["Package authority"] --> B["Runtime features"] --> C["Prepare state"] --> D{"Home ready?"}
  D -- Yes --> E["Resident client"] --> F["Native result"]
  D -- No --> G["Unavailable"]
  B -- Unsupported --> G
Loading
High-Level Assessment

Use the existing shared prerequisite at the package-authority transport boundary. It covers all operations through that transport and preserves the resident's established state-ownership contract; changing the resident to create its own state would be a broader behavioral change.

Files changed (3) +51 / -0

Bug fix (1) +3 / -0
native_package_authority.pyProvision resident state before package-authority transport +3/-0

Provision resident state before package-authority transport

• After checking runtime capabilities, '_resident_request' now ensures the guard home's resident prerequisite exists. If provisioning fails, it returns without contacting the runtime, preventing requests that would be refused on a fresh home.

src/codex_plugin_scanner/guard/native_package_authority.py

Tests (2) +48 / -0
test_native_package_authority_prerequisite.pyTest prerequisite ordering and failure handling +47/-0

Test prerequisite ordering and failure handling

• Adds parameterized tests confirming that provisioning receives the guard home and precedes the runtime request. The failed-provisioning case confirms no request is sent.

tests/test_native_package_authority_prerequisite.py

test_native_stream_deadline.pyStub provisioning in the pool-exhaustion deadline test +1/-0

Stub provisioning in the pool-exhaustion deadline test

• Stubs the new prerequisite so the deadline test can continue exercising its fake runtime and exhausted client pool without provisioning state.

tests/test_native_stream_deadline.py

@gitar-bot

gitar-bot Bot commented Oct 11, 2026 •

Copy link
Copy Markdown
CI failed: One test failure in the guard package-intent extraction: an npm install was detected when the selected guard home should have yielded no intent; relationship to this PR is unclear.

Overview

One unique error template was found across 1 analyzed log (commit b7e4130). The CI run had 1 failed test and 120 passing, with 1 rerun. The setup and dependency steps succeeded, so the failure is confined to the test run.

Failures

test_extract_uses_selected_guard_home_over_ambient_home (confidence: medium)

  • Type: test
  • Affected jobs: 114415783495
  • Related to change: unclear
  • Root cause: tests/test_guard_package_intent.py:31 expects extract_package_intent_request to return None for an unenrolled selected guard_home, but it returned a PackageIntent for npm install left-pad@<VER>. The log does not show why the eligibility or home-selection check passed. The PR title concerns preparing the resident state directory before package-authority requests, and the connection to package-intent extraction is not established by the available evidence.
  • Suggested fix: Inspect the eligibility and home-selection logic in package-intent extraction to confirm it honors the explicitly selected guard_home instead of ambient home state. Add or update coverage so an unenrolled selected home returns None, then rerun the failing test and related package-intent tests.

Summary

  • Change-related failures: None confirmed. The one failure has an unclear relationship to this PR.
  • Infrastructure/flaky failures: None identified. The test was rerun once and still failed, which points to a deterministic failure rather than flakiness.
  • Recommended action: Investigate the guard_home selection in package-intent extraction and confirm whether this PR's changes touch that path. If they do not, triage this as a pre-existing or separate issue.
Code Review ✅ Approved

🟡 Medium risk · Preparing the resident state directory changes package-authority request flow; a failed prerequisite could suppress package intent results.

Adds a call to ensure_resident_prerequisite(guard_home) in _resident_request so package-authority requests prepare the resident state directory before contacting the runtime, matching the other resident clients. No issues found.

Review coverage

📋 Rules 2 not applicable

🧪 Functional validation Not enabled · Set up

Tip

Comment Gitar fix CI or enable auto-apply: gitar auto-apply:on

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source

@qodo-free-for-open-source-projects

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Remediation recommended

1. Package requests can overrun their deadline 🐞 Bug ☼ Reliability
Description
_resident_request calls ensure_resident_prerequisite before calculating the remaining request
budget, and provisioning has no deadline. On a fresh guard home, secret initialization can wait up
to 30 seconds for a file lock, so an intent or advisory request can remain blocked well beyond its
caller's deadline or configured timeout.
Code

src/codex_plugin_scanner/guard/native_package_authority.py[R77-78]

+    if not ensure_resident_prerequisite(guard_home):
+        return None
Evidence
The changed call occurs after _resident_request checks an inherited deadline but before it
recalculates remaining time. The prerequisite constructs a GuardStore and provisions secret
material; that path accesses the secret store, whose initialization may wait up to 30 seconds for
its file lock. Package intent and advisory requests use five- and two-second transport timeouts,
respectively.

src/codex_plugin_scanner/guard/native_package_authority.py[57-81]
src/codex_plugin_scanner/guard/native_package_authority.py[144-162]
src/codex_plugin_scanner/guard/native_package_authority.py[189-207]
src/codex_plugin_scanner/guard/native_context.py[285-305]
src/codex_plugin_scanner/guard/store_secret_policy_integrity.py[431-457]
src/codex_plugin_scanner/guard/store_base.py[904-924]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
Package-authority prerequisite provisioning can block beyond the request's deadline before the transport budget is calculated.

## Fix Focus Areas
- src/codex_plugin_scanner/guard/native_package_authority.py[57-81]
- src/codex_plugin_scanner/guard/native_context.py[259-305]
- src/codex_plugin_scanner/guard/store_base.py[904-924]

## Recommended Fix
Make prerequisite provisioning respect the effective request deadline, including waits for secret initialization, and return without contacting the resident when the budget expires. Add a test covering contention during provisioning with a short inherited deadline.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
✅ Compliance rules (platform): 7 rules
Review mode: Auto: ⚖️ Balanced: Localized runtime prerequisite fix with meaningful behavioral and test-ordering risk.

Grey Divider

Tip of the day
💡 Did you know, you can tweak Display settings with a live preview to see your comment before it ships

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment on lines +77 to +78
if not ensure_resident_prerequisite(guard_home):
return None

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Package requests can overrun their deadline 🐞 Bug ☼ Reliability

_resident_request calls ensure_resident_prerequisite before calculating the remaining request
budget, and provisioning has no deadline. On a fresh guard home, secret initialization can wait up
to 30 seconds for a file lock, so an intent or advisory request can remain blocked well beyond its
caller's deadline or configured timeout.
Agent Prompt
## Issue description
Package-authority prerequisite provisioning can block beyond the request's deadline before the transport budget is calculated.

## Fix Focus Areas
- src/codex_plugin_scanner/guard/native_package_authority.py[57-81]
- src/codex_plugin_scanner/guard/native_context.py[259-305]
- src/codex_plugin_scanner/guard/store_base.py[904-924]

## Recommended Fix
Make prerequisite provisioning respect the effective request deadline, including waits for secret initialization, and return without contacting the resident when the budget expires. Add a test covering contention during provisioning with a short inherited deadline.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant