Repository navigation
S25 wiring: policy inheritance in shadow mode (SHIP_POLICY_SHADOW) - #43
Merged
Merged
Conversation
…th disagreement report Record-only comparison of resolvePolicy against mayDo, effectiveAuthority, resolveNetworkTier, normalizeEgressAllow, assertRepoAllowed and the enqueue daily budget. Default off installs nothing. Adds 'policy shadow-report'. Service accounts are id-only matches; their role is still undecided. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VqsBNqvaWezf1DwQrAnVgX
Resolves imports in cli.ts (policy shadow report and stack detect) and the budget path in runtime.ts (shadow observation first, then the budget gate). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01VqsBNqvaWezf1DwQrAnVgX
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
Shadow mode only. Nothing is enforced and no outcome changes.
src/shadow-hook.ts(new, leaf, type-only imports): an observer seam. The decision points report their outcome after deciding. The observer is null unlessSHIP_POLICY_SHADOW=oninstalls one, and its errors are swallowed.src/policy-shadow.ts(new):SHIP_DAILY_BUDGET_USDwhen it is set. project: the project record plus the daily cap actually applied. user / service_account: the principal. Optional declared layers come frompolicy-layers.json(SHIP_POLICY_LAYERS_FILE).resolvePolicynext to each decision.policy-shadow.jsonl,SHIP_POLICY_SHADOW_FILE) that records disagreements and shadow errors.summariseShadowandrenderShadowReport.mayDo(this also covers webmay()and the delivery re-check),effectiveAuthority,resolveNetworkTier,normalizeEgressAllow,assertRepoAllowed(a wrapper that observes both the allow and the throw), andassertDailyBudget(both the daily and the weekly comparison).fileRuntimeandnucleusRuntimecallinstallPolicyShadowFromEnv(), which does nothing unless the flag is on.teploy-ship policy shadow-report [--json].[service-account].Checks
pnpm run lintis clean.pnpm test: 1871 of 1871 pass in the main suite (20 new tests inpolicy-shadow.test.ts).swebench/andscripts/suites show 3 failures inscripts/grader-sensitivity.test.mjs(pj-b-deploy-recovery,deploy.sh). They fail identically on a cleanorigin/maincheckout and this PR does not touch them.mayDohook: 6 tests fail.web/is untouched, so I did not run the web tests or the web build.Not verified / still open
assertRepoAllowedis compared through a proxy: the clone host against the policy's egress rules.worker.tsintake budget check is not hooked, to avoid conflicts with other agents. Only the enqueue budget check is.🤖 Generated with Claude Code
https://claude.ai/code/session_01VqsBNqvaWezf1DwQrAnVgX
Generated by Claude Code