Skip to content

feat(bridge): import the complete optional Kars Bridge application - #563

Draft
Pal Lakatos-Toth (pallakatos) wants to merge 123 commits into
kars-bridgefrom
public/bridge-application
Draft

Pal Lakatos-Toth (pallakatos) wants to merge 123 commits into
kars-bridgefrom
public/bridge-application

Conversation

@pallakatos

@pallakatos Pal Lakatos-Toth (pallakatos) commented Sep 11, 2026

Copy link
Copy Markdown
Collaborator

Complete Kars Bridge application, optional add-on

Draft; not beta/release-approved. Target: kars-bridge.
Head: f8f4a7faf31dbd6d506e219d039d7c0163cf385c.
Prerequisite: #554 merged from 8798a57bf9c35964754cab97fb294a5494c0078f.
Actual integration ancestor: e3d61351100e1091b0fc8b5220ac36e75a81848d.

This head includes the protected prerequisite merge, the scoped delegated source
attestation and a reproduced CI status-observation fix. Controller/router/BFF/web/
gateway/CLI production code and policies remain unchanged from qualified
aa405635.

Current blocker: all final execution and source gates passed. The remaining
failed check and unresolved review conversation are CodeQL IMDS alert 827,
which still needs an authorized disposition. The PR remains draft and unmerged;
no H100 deployment or normal release has been approved by this qualification.

Current CI fixture correction

The preceding b967c1e3 core workflow finished with 183 passed, one failed.
Only the KarsMemory honest-state assertion failed: it captured an empty phase,
then Ready=False / NoSandboxesReferencing. Its immediate diagnostic dump already
contained the valid complete Compiled/False/NoSandboxesReferencing status.

The actual shell fixture reproduced the same failure before this fix. It read
phase, Ready and reason in three separate API requests across one controller
status publication. The ConfigMap can also become visible before that status.
No controller/memory implementation defect is established by this observation.

The fixture now reads one JSON response, waits for complete current-generation
status while pinning identity/intent, and retains the existing deadlines and
accepted state tuples. The same split-read pattern is corrected in the related
InferencePolicy, KarsEval and EgressApproval assertions; evaluator Pending/False
settlement, egress host-count/finalizer checks and invalid-state failures remain.
API errors fail explicitly rather than receiving new retries.

All 19 new regressions plus 28 existing harness cases pass locally, including
the actual shell reproduction, malformed/stale/replaced snapshots and deadline
bounds. No controller, runtime, policy or timeout change is included. Fresh
hosted acceptance now passed: core CI 34908997660 completed all 21 jobs, and
Kind job 104199283421 reported 184 passed, zero failed, including the
correct coherent states for all four repaired observations. The earlier
183/1 result remains recorded as a failure, not relabeled.

Publishes the existing Bridge application under bridge/: Rust BFF, Next.js
Workspace/Console/Audit, optional Teams gateway, separate Helm chart, development
entrypoints, documentation and acceptance fixtures. The original snapshot is
0a10472ed7e2940235b714276e8def3c0d9190f4; all 398 imported product paths remain.
Private history, credentials, operator state, deployment overlays, caches and
frozen SDK/probe ancestry are excluded.

Core remains independently usable. Bridge has separate packages, opt-in builds
and a separate Helm release. Adding/removing Bridge must preserve core identities,
resources and customer data. /sandbox remains ephemeral; no PVC feature is added.

Reviewed functional repairs

Final application review found six concrete problems not covered by the previous
green suites. All six repairs are now published in this head, independently
re-reviewed, and qualified by actual component execution:

Finding Repair state
Active HTML/SVG artifacts inherit Bridge origin Safe download/sandbox response boundary; all four real-handler regressions passed
Operators bypass admin-only budget/retention controls Verified-session web and BFF middleware/handler checks; five Rust and six real-JWT web cases passed
Gateway uses positional calls incompatible with locked Kubernetes SDK Request-object API with SDK-derived types; real SDK HTTP cases passed
Completed remediation suppresses later same-package advisories History/in-flight authority preserved; all 16 renewal regressions passed
Separate-namespace gateway targets the wrong workspace Core-read/add-on-storage separation; rendered, SDK and uninstall/lifecycle cases passed
Filename matching is presented as recorded agent attribution Per-file explicit/inferred evidence; actual renderer regressions passed

At aa405635, public Bridge CI passed all 11 jobs. BFF job 104154078482 executed all
25 new Rust regressions by exact name, plus the full 259-library/4+2-integration
suite, with zero ignored cases. All 37 required regression registrations passed.
Web job 104154078446 passed all 50 contracts and the actual Next 16.3.3 build/
immutable-root startup. Gateway job 104154078031 ran locked Vitest 4.1.11:
84 normal cases passed, then all three actual Kind lifecycle cases passed.
These hosted results close the earlier local Next/Vitest cache limitations.
Its full core CI also passed all 21 jobs, and native acceptance passed all
18 cases, three cold API installs and the aggregate. The final source attestation
is now published. The newer current-base head still needs its own full
core/native/scanner gates; none of this is beta or H100 approval.

Current public qualification

Qualification Current run Status
Bridge components, BFF/web, dependency checks and add-on lifecycle 34908997571 All jobs passed on the fixture-fix head
Native API, controller/BFF lifecycle, TLS and CNI 34908997644 All 18 cases, three cold API installs and aggregate passed
Core with Bridge physically absent 34908997660 All 21 jobs passed; Kind 184/184, including all four coherent-status observations
Standalone prerequisite 34894935679 All 21 jobs and all required gates passed; merged as e3d6135
Source gates 34908997560 All source gates passed, including audit and copyright
CodeQL 34908997607 Analysis passed; alert check reports only the still-open IMDS HTTP alert 827

Artifact 10374607713 binds both revisions to f8f4a7fa: all 18 cases passed,
rotation in 84.49 seconds, runtime/network qualification true, active-SRE-combined
false. The repaired KarsMemory observation separately passed in the core Kind
job; the two workflows are not interchangeable evidence.

Preceding artifact 10372307257 binds both revisions to b967c1e3: all 18 cases
passed, rotation in 87.71 seconds, runtime/network-policy qualification true.
This remains the controlled-no-LLM/no-active-SRE lane, not live standing-Team
or active-SRE-combined approval.

Repaired-source artifact 10370845677 binds both native revisions to aa405635:
18 passed, zero failed or blocked, rotation in 85.68 seconds. Runtime and
network-policy qualification are true; active-SRE-combined qualification is false.

The preceding artifact 10367675286 binds both native revisions to 5e9a1fe5: 18 passed,
zero failed or blocked, rotation in 78.3 seconds. Runtime and network-policy
qualification are true; active-SRE-combined qualification remains false.
That head's separate API/CEL failure occurred before policy/workload cases while waiting
for a public CRD to be Established. Its cause was discarded by the command
wrapper and is not established. The identical standalone fixture passed.
Bounded public-schema diagnostics are now published without changing any timeout,
retry or acceptance assertion; no failure is relabeled.

The preceding application 1d0fc5c9 passed
all 21 core jobs,
all 11 Bridge component jobs,
and all 18 native cases, three cold API installs and the aggregate.
Core 03174dca also passed all 21 jobs.
Both Kind suites reported 184 passed, zero failed, including real historical
migration and metrics-dependent SRE acceptance. The intermediate 5e9a1fe5
changed only two CLI test expressions; the current head includes the six
application repairs and bounded CI corrections described above.

All qualification runs in Azure/kars. Current heads must establish their own
results; no historical outcome is substituted or failure waived.

CodeQL alerts 828/829, concerning API-group array membership rather than URL
validation, are now reported fixed after the exact-element-equality change.
Alert 827 flags the existing
fixed http://169.254.169.254 IMDS token request. That client bypasses proxies,
does not follow redirects, and is separate from HTTPS-only Foundry/AAD clients.
Azure documents IMDS as host-local HTTP;
changing this endpoint to HTTPS would not be a supported repair. Its alert
disposition is still open and requires authorization; no absent-user response
has been treated as approval. No dismissal, scanner suppression or authentication
change has been made.

Current corrections: preceding public copyright checks passed in both candidates.
Full CLI/Rust validation exposed a header-style regression in chart files also
read as raw YAML: Go-template comments are not valid for those readers. The
correction now preserves raw schema objects and original Helm document boundaries,
without changing CLI/Rust consumers or weakening tests. All twenty CRD inputs
retain exactly 21 schemas with zero added documents. Local full CLI suites pass:
1,995 app tests and 1,991 core tests, each with two existing local skips. All 61
targeted staging tests and 33 copyright tests pass per worktree. The corresponding
public Rust/schema regressions have also passed on this head.

A separate RustSec advisory published on 2026-09-14,
RUSTSEC-2026-0285,
affects core Rustls 0.23.43 and BFF Rustls 0.23.41. Local commits update both to
0.23.45 with the required aws-lc/webpki family. Provider/features and unrelated
locked package choices are unchanged; Cargo validates the minimized locked graph.
This security patch is published and its preceding public RustSec/cargo-deny and
separate BFF dependency audit pass.
Both preceding heads' Rust and CLI jobs passed. Native artifact 10365070493 binds core and
Bridge to 1d0fc5c9 and reports all 18 cases passed with zero failures or blocked
cases, including rotation/current-bearer/revocation in 83.61 seconds. Runtime
and network-policy qualification are true; active-SRE-combined qualification
remains false. No production timeout or retry was introduced for the earlier
unproven rotation delay.
The preceding native artifact 10360357779 reports 17 passes and one rotation
timeout: the workspace grant advanced to generation 4 while status remained at
generation 3. Initial observer readiness and other preceding cases passed.
The cause of that liveness symptom remains unproven. A bounded failure-only
snapshot now retains controller restart/termination facts and metadata-only
grant/observer resources before subsequent test cleanup can restart the controller.
Its eight regressions pass in the 188-test native suite. No speculative runtime
change, production logging, timeout extension or retry is included.

Verified preceding native result

At 24c85cd1, native run 34853257629
passed all 18 runtime cases, all three cold API installs and the required aggregate.
Artifact 10353631768 binds both revisions to that head and reports
runtimeQualified=true, networkPolicyEnforcementQualified=true, zero failures
and zero blocked cases. Executed checks include:

  • Fresh observer/privacy RPC and purpose-only pinned TLS/API negatives.
  • Positive 9447/9448 traffic and unauthorized-peer denial.
  • Current-bearer rotation, revocation and old-key rejection.
  • Writer uninstall/core continuity, source preservation and grant revocation.

This is the controlled-no-LLM-agent, no-active-sre-native lane.
activeSreCombinedQualified=false remains explicit. It is not proof of the real
standing-Team maintenance/PR journey or the full supported-pair matrix.
The preceding component workflow also passed all 11 jobs. Core 344a371f passed
all 21 core jobs and all twenty new observer-egress Rust regressions.

The original observer timeout was traced to actual Cilium API SYN denials.
A correctly targeted temporary allowance produced an authenticated API HTTP 200;
the controller-generated permanent policy then achieved observer Ready without
that intervention. Diagnostic outcomes were never promoted into passing cases.

Latest changes

Bounded CI acquisition

The previous app core workflow failed while fetching/applying metrics-server;
its single unchanged-source retry failed earlier on malformed Kind checksum input.
The current CI-only repair retains Kind v0.24.0, kubectl v1.30.5 and metrics
v0.7.2, with strict official Kind checksum/SHA validation before executable
publication. HTTPS acquisition, redirects and transient retries are bounded;
no integrity fallback or unverified cached binary is accepted.
Metrics download and local-manifest apply have separate diagnostics within the
existing 90-second/phase budget, with no Kubernetes mutation retry. Metrics retains
its existing HTTPS provenance, not a new checksum guarantee.

Repository-wide Microsoft/MIT coverage

The original 390 missing Bridge source headers were inserted without deleting
source bytes or existing author notices. Repo-wide coverage now accounts for all
2,307 tracked files: 2,056 inline headers and 251 explicitly covered strict-data,
legal, generated and third-party files. Binary/strict-data files are not claimed
to contain comment headers. Original ownership and MIT licensing are preserved.

The shared checker/applier handles appropriate comment syntax and preserves
shebangs, encoding declarations, Docker directives, frontend directives and
Markdown frontmatter. Generated-source coverage requires reviewed exact paths;
authored files cannot bypass checks merely by appearing beneath build, dist
or similar names. Unknown first-party formats fail.

Byte-sensitive inputs—including the verbatim Helm AGT profile and its runtime
digest—remain unchanged under explicit license coverage. No templates or product
logic were rewritten to accommodate headers. Legal notices, upstream assets and
vendored payloads retain their licensing.

Validation and preserved contracts

Both worktrees passed 33 copyright, 27 acquisition and 28 harness tests, existing
size/copyright checks, type/manifest checks and preserved Helm renders. The native
188-test contract suite also passed locally after the header pass. Local npm-cache
versions differ from the lock; hosted results remain authoritative.

The bounded runtime corrections preserve original namespace/claim/UID/RV fences,
current authorization, actual pause/revocation/refill, consumed revisions and
old-Pod retirement. Only the controller gained management of namespaced Cilium
policies required by enrolled observers; no CNI installation, world/node allowance,
UID-1000 bypass, agent/BFF privileges or TLS/authentication weakening was added.
The native test now distinguishes the two real retirement-phase Pod baselines
while retaining identity, data, root, rotation and old/new-key assertions.

Existing receipt pinning, standard digest/signature adapters and the explicit
legacy-v1 credential-key compatibility boundary remain unchanged. Their scoped
reviews and regressions are not whole-application security sign-off.

Remaining gates and rollout boundary

Complete current-head CI, the authorized IMDS alert disposition and required PR
review before merge. Scoped source attestations are published under the recorded
delegation; they do not waive these gates or claim another human review.
No signature, ownership claim, alert dismissal or approval is fabricated.
Three earlier tentative BFF claims were not established as
current-flow defects; the subsequent six concrete findings above have reviewed
repairs and actual component regression closure. Complete flow acceptance and
the remaining current-head gates are still required.

Land the core prerequisite first, then activate stable Bridge component/native
requirements while retaining existing branch protections before application merge.
Once the integrated public kars-bridge branch is beta-ready, H100 acceptance will
exercise core alone, optional Bridge installation, the real authenticated standing
Team/maintenance/evidence/review/revision flow, explicitly authorized merge, and
Bridge removal with core intact. The current BFF leaves actual merges to a human
GitHub action; no automatic merge authority is introduced.

No main or normal-release change, image publication, H100 deployment or private
repository visibility change is included in this PR.

Keep independent application packages, images and Helm release. Qualify core and Bridge at one immutable public source revision. Preserve existing core builds and explicitly retain remaining source and native gates.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
@github-actions

github-actions Bot commented Sep 11, 2026

Copy link
Copy Markdown

Dependency Review Summary

The full dependency review summary was too large to display here (1765KB, limit is 1024KB).

Please download the artifact named "dependency-review-summary" to view the complete report.

View full job summary

Comment thread bridge/teams-gateway/tests/chart.test.ts Fixed
Comment thread bridge/web/src/app/workspace/teams/[name]/runs/[run]/page.tsx Fixed
Comment thread bridge/web/src/app/api/[...path]/route.ts Fixed
Comment thread bridge/web/src/app/dex/[...path]/route.ts Fixed
Comment thread bridge/web/src/app/workspace/new/intake-flow.tsx Fixed
Comment thread bridge/web/src/app/workspace/teams/[name]/team-tabs.tsx
Comment thread cli/src/lib/private-activation.test.ts Fixed
Comment thread bridge/web/src/components/intent-entry.tsx
Override only the inherited Cargo.lock and artifact-directory ignore rules. Restore exact imported blobs and require critical application inputs to be tracked, not merely present in a developer worktree.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Resolve both core install commands from bridge/ and distinguish historical preview evidence from public qualification. Guard chart path resolution in the monorepo regression suite.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Comment thread bridge/bff/src/routes/foundry.rs Fixed
Comment thread controller/src/credential_grants/observer_runtime.rs Fixed
Filter each file once without changing any marker, scope, exception, exit status or diagnostic. Regression fixtures preserve all canonical matches and cap grep invocations at three per file; actual public130 findings remain byte-identical and failing.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use the existing locked TypeScript parser to recognize form fields and Tailwind variants without suppressing comments, string values or unfinished declarations. Preserve source coverage and fail closed on parsing/tool errors. Add eleven scope, marker and syntax regressions; keep the application audit explicitly unsigned.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve all64 route exports and32 tests through mechanical extraction. Every resulting task source file is at most800lines; rustfmt and normalized source parity were checked. Actual Rust compilation remains pending hosted Azure CI, not inferred from syntax checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…visory

Share trusted-anchor resolution between receipt and whole-log verification. Bind configured key IDs to raw-key fingerprints and reject mismatched or invalid pins. Preserve unpinned cluster-anchor behavior and receipt wire bytes. Add signed replacement-anchor, pin matrix and no-witness checkpoint regressions; Rust execution remains pending hosted qualification.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Include the full current credential prerequisite repair ancestry; no source or native gate failure is waived.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Comment thread ci/no-stubs-ts.mjs Fixed
Fix the exact hosted Clippy failures without suppressing warnings. Require all anchor regressions and the signed-fork endpoint case in the actual Cargo test inventory before full execution.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Mechanically retain170declarations and13tests across the existing facade and nine modules, all at most800lines. Formatting and normalized token parity were checked; hosted compilation remains required.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Build/test core without the Bridge directory, require locked CLI validation, and classify all runtime/shared/unknown changes without rename or missing-diff bypasses. Emit stable component/native aggregates and reject unqualified skips. Preserve full reusable-release qualification. Hosted validation and required branch-policy activation remain pending; no protection or release channel is changed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve24exports,18tests, proposal/approval semantics and exact orchestration prompt content through mechanical extraction. All resulting compose files remain below800lines; hosted compilation is pending.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Build the locked same-source core CLI and exercise real grant preview/apply instead of posting an unqualified writer grant. Preserve exclusive creation, workspace/writer UID and key checks, private review storage and controller readiness. No fabricated activation or Ready status; native and shared-workspace continuity remain unqualified until hosted proof.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep CLI stderr out of public logs while reporting fixed preview/apply categories and allowlisted source locations. Exercise actual failing subprocesses and redaction. Preserve real operator commands and all authority checks;104native harness and19gateway regressions passed locally.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use versioned structured remediation IDs without folding Git path or package case. Reuse legacy IDs only with complete matching original source metadata, preserving history and links and surfacing ambiguity. PR-title matches now guide investigation rather than suppressing work or claiming delivery. Add framing, migration, state-continuity and title-only coverage regressions. Rust execution pending hosted CI; no local compile below disk floor.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Move verifier types and implementation with exact-byte parity, retaining receipt API exports and test-only pin injection. Preserve all wire formats, trust checks and existing test inventory. Syntax/formatting checked; hosted Rust execution remains required.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Existing legacy and v2 remediation work both retain the human-review gate when rehydrated, without changing IDs, runs or backlog state. Added regression awaits hosted Rust execution.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Restore the exact never-merge contract exercised by existing hosted regression without removing its assertion or changing candidate-only coverage semantics.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve the existing Team facade and lifecycle contracts through mechanical extraction. Focused read-only review found no significant issues, and scoped formatting passed. Hosted Rust compilation and full test execution remain required; no source-audit sign-off is implied.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Mechanical extraction preserves121public methods,11public types,158normalized function signatures/bodies and19registered tests.123inherent bodies and940literals remain identical, including trace and objective digest framing. Rustfmt/offline metadata passed; hosted compilation remains required.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Restore the test-only PAE helper facade required by existing signed-statement regressions after verifier extraction. Keep framing unchanged and avoid widening the production API or suppressing compiler checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep caller-owned byte framing, case semantics and digest widths, consolidate GitHub connection naming, and require independent known-answer tests in hosted inventory. Credential V1 secret-key derivation and signature verification are not reclassified or changed. No scanner exception added; Rust qualification remains pending.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep the signed receipt fixture's independent SHA256 dependency explicit instead of inheriting it from production imports. Remove needless borrows for the new generic digest adapter without changing pinned key bytes or warning policy.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reread only recognized moving snapshots before judging an empty projection or typed lineage-template refusal. Preserve the rejected snapshot's transition check, all authority and data fences, actual withdrawal/pause/refill witnesses, and the existing deadline. Recheck identity after lineage before settlement. Native diagnostics retain fixed typed-error and writer-failure categories without publishing private values.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep runtime acceptance and production deadlines unchanged. Emit a closed boolean restoration comparison on the existing refusal and project it through native diagnostics without values or hashes. Expand failure-only template comparisons to writer restoration. Exercise actual kubectl printing with a delayed response and bounded fixture budgets; retain safe child-failure facts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Recover only a confirmed Pausing Sandbox conflict after full scope, runtime, Task, private-key and root revalidation. Require a different live revision before another guarded update, cap attempts at three within the existing deadline, and preserve all other failures. Exercise the native Pending-induced status race, bounded recovery, expiry, stale identities/intent and already-applied pause behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Observe endpoint-filtered Cilium drop, trace and policy verdicts before and during the existing failure-only experiment. Retain only bounded validated facts with provenance checks and exact-child cleanup. Keep packet receipt timing distinct from request freshness and policy realization; do not change the original failed outcome, shipping network policy, or readiness deadlines.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Require the full native diagnostic unittest inventory in the existing scope job and assert that wiring in CLI workflow contracts. Keep real API and runtime acceptance mandatory; unit diagnostics do not qualify live behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…tics

Do not copy pod-template-hash into a Cilium endpoint selector: the pinned Cilium release excludes it from security identity labels. Verify source-qualified sandbox and namespace labels against CEP and agent identities, while retaining complete rollout, Pod UID, process and inventory fences. Reject old, foreign, orphaned, duplicate, paginated and changed consumers. Production policy and native acceptance remain unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The Sandbox reconciler can pause and revoke its projection while the independent Task controller remains Ready. Require the witnessed owned pause and empty projection without inventing a mandatory transient Task status. Preserve current Task authorization, fresh refill and consumed grant/Deployment revisions, old-Pod retirement, and all identity/data fences. Observed Task withdrawal still requires fresh attestation. Cover both schedules and double the negative authority matrix.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reuse canonical exact API targets in the owned observer policy. For installed Cilium, manage only a namespaced API-entity policy with validated ports and effective selectors. Preserve original namespace/claim/UID/RV fences, remove stale extensions, and retain a cleanup hint for interrupted retirement. Grant CNP management only to the controller; no new CNI installation, global settings, agent privileges, TLS or deadline changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record only a fixed failure category and actual exit status before removing private logs. Reap the owned child without a stale-PID cleanup attempt. Preserve the one-shot startup and all authentication, scope and cleanup assertions; do not retry an unexplained failure.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Comment thread cli/src/testing/credential-grant-contract.test.ts Fixed
Comment thread cli/src/testing/credential-grant-contract.test.ts Fixed
Map only a successful namespace recheck to unit, preserving validation and error propagation. Split lifecycle/fencing regressions into a shared-fixture child module so every new file meets the existing size limit. Retain all twenty regression functions and assertions; no gate exception or policy behavior change.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The real operator may replace Pods during writer retirement before recording the private-key retirement baseline. Verify that neither generation survives and bind the Qualified receipt to the original runtime, Task authorization, Deployment and admin Secret instead of requiring different phase UID sets to be identical. Preserve source/root data, key rotation and old/new-key HTTP assertions. Add positive phase-ordering and negative binding/data/auth regressions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Conform imported Bridge source to the existing repository copyright check and MIT license. Insert headers only; preserve all original source bytes, existing author notices, file modes and shebang positions. No runtime code, license change or gate exemption.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve pinned Kind, kubectl and metrics-server versions. Validate official checksums before executable publication, bound HTTPS acquisition and transient retries, and separate metrics manifest acquisition from one-shot Kubernetes apply. Keep global deadlines, integrity checks and runtime assertions; exercise real partial-transfer cleanup and exact topology preservation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Cover all tracked first-party comment-capable formats while preserving source bytes, directives, frontmatter, modes and existing notices. Explicitly account for strict data, legal files, generated artifacts and upstream ownership without corrupting payloads or changing licensing. Restrict generated coverage to reviewed exact paths; reject unknown authored formats. Keep existing checker/applier entrypoints and test enforcement.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Raise the existing TLS dependency floor to 0.23.45 in core and the separate BFF without changing provider/features. Update only Rustls and its required aws-lc/webpki dependency family, retaining unrelated locked package choices; Cargo workspace-locked resolution validates both minimized graphs. Do not suppress the newly published advisory.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Capture bounded controller lifecycle, grant generation and metadata-only observer resource facts at the original failure hook, before later teardown changes the evidence. Preserve original failure classification, request defaults and production behavior; keep unknown reconciliation progress explicitly unavailable.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use YAML comments for dual-use plain templates and whitespace-neutral Go comments only for leading Helm actions. Place hash headers after the original initial document separator. Preserve original body bytes, modes, schemas and document counts across all twenty CRD inputs; do not relax CLI/Rust readers or assertions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Preserve all rendered controller-only CNP authority assertions. Compare API-group array elements by exact equality rather than an Array.includes expression classified as a URL substring check.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Carry the same bounded current issuer/cache review evidence as the core prerequisite. Close stale source-wiring wording while retaining live GitHub/operator acceptance and final audit requirements; no signature or approval is added.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Require a newly added fully signed capability record even when historical audit notices change, without demanding retrospective signatures on already completed scopes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record exact reviewed source, independent-context coverage and executed public evidence under the existing explicit maintainer delegation. Preserve historical failures and limits on live GitHub, active-SRE combined, Bridge and H100 acceptance; no human review, check waiver or deployment approval is implied.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Keep active and unknown artifact bytes downloadable without inheriting the authenticated Bridge origin. Enforce existing budget and retention admin boundaries in BFF middleware and handlers, and use verified session roles in the web gate. Require the nine Rust regressions to be registered and run all web contract files in hosted qualification.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Expose the existing public-schema diagnostic for CRD establishment waits, without changing any acceptance assertion, context, request/child deadline or retry behavior. Extract the unchanged command body for real-child redaction and argument regressions, and preserve the workload-proof context binding. The prior hosted failure cause remains unclassified.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use the locked Kubernetes SDK request-object contracts without compatibility casts. Watch and bind teams in the configured core workspace while retaining conversation storage and ServiceAccount authority in the add-on namespace. Cover real SDK HTTP calls, both chart namespace layouts and owned uninstall preservation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ibution

Aggregate current Dependabot evidence and create bounded follow-up work without overwriting completed or in-flight identities, authority, inputs or PR history. Prefer explicit artifact producers over filename inference and retain per-file labels. Keep test and renderer modules bounded, and require all sixteen renewal regressions in hosted Rust qualification.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record the exact source, independent integration review and three closure rounds, all twenty-five executed Rust regressions and locked web/gateway qualification under explicit maintainer delegation. Preserve remaining full-stack, IMDS disposition and live H100/GitHub acceptance conditions without claiming a second human review or waiving gates.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Include actual protected integration e3d6135. Resolve only duplicate CI-fixture insertion/order and the existing Bridge protection heading; the complete resulting tree is byte-identical to 1f2c483. Preserve all source gates and regression cases.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record all completed repaired-head core and native outcomes and the tree-identical incorporation of the protected credential integration. Preserve current-head qualification, open IMDS disposition and live H100/GitHub acceptance requirements.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Reproduce and fix the native KarsMemory assertion combining phase from before status publication with Ready/reason from later GETs. Read one complete JSON snapshot and settle within the existing fixture deadlines; preserve all accepted tuples and evaluator semantics, reject identity/intent changes, and fail explicitly on API errors. Cover the shared InferencePolicy, KarsMemory, KarsEval and EgressApproval observation pattern without controller or policy changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants