fix(decisioning): preserve sanitized validation fallback - #1204
Merged
Merged
Conversation
This was referenced Sep 22, 2026
Base automatically changed from
conductor/fix-reporting-scope-selector-default
to
main
September 25, 2026 12:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If validation-error narrowing itself fails,
_internal_error_detailsnow returns its already sanitized fallback explicitly. Replacing the handler'spasswithreturn detailspreserves the response and resolves the inherited Bandit B110 finding.The added fault-injection regression exercises a narrowing iterator that yields partial data and then raises. The returned details contain neither the raw validation input nor the partial result or secondary exception message.
Validation on
fe1a1cbd070bc94ec32685026ad39ec55058dc73:e3a44d281d019ebf6aec738c2cfe18f8bba97462to this exact head. No scanner suppression, threshold, baseline exclusion or hook configuration change is included.b203bbcff51cb648c1fd605224fb74e5a3465a8f; tree:208d0a7b75ac982ae52457d77db1aecbb7539b2e.The exact-parent Bandit B110 result remains an original exit-1 red. Frozen b203 and runtime dba15 retain their inherited hook failures; this child's green result does not rewrite them. The earlier
93087395documentation-only correction remains behavior-preserving documentation. The initial pre-freeze formatting failure is also retained separately from the corrected frozen checks.The review shows only this two-file sibling delta (+35/-1) against
conductor/fix-reporting-scope-selector-defaultat exact b203. This is a draft review leaf: delivery is through a later coordinator-approved ancestry-preserving integration into #1203, followed by fresh aggregate/main hooks and CI. It is not a package, merge or release approval. PR #1202 and #1203 remain unchanged.No standalone package, PostgreSQL or full historical matrix was run for this bounded one-line production change. Only actually scheduled remote checks will be recorded; this leaf has no inherited claim to #1203 CI. Original focused test and normal-hook command streams are retained under
.context/py-dispatch-b110-20260922/frozen-focused-controls/andfrozen-inherited-normal-hooks/, with the exact-parent red inpinned-parent-bandit-red/.