Skip to content

fix(decisioning): preserve sanitized validation fallback - #1204

Merged
bokelley merged 1 commit into
mainfrom
conductor/fix-dispatch-validation-fallback
Sep 25, 2026
Merged

bokelley merged 1 commit into
mainfrom
conductor/fix-dispatch-validation-fallback

Conversation

@bokelley

Copy link
Copy Markdown
Contributor

If validation-error narrowing itself fails, _internal_error_details now returns its already sanitized fallback explicitly. Replacing the handler's pass with return details preserves the response and resolves the inherited Bandit B110 finding.

The added fault-injection regression exercises a narrowing iterator that yields partial data and then raises. The returned details contain neither the raw validation input nor the partial result or secondary exception message.

Validation on fe1a1cbd070bc94ec32685026ad39ec55058dc73:

  • 110 internal-error, validation-narrowing and structured-error tests passed, with no skips.
  • Pinned Bandit 1.7.10 passed. All 14 unchanged normal hooks passed over the inherited range from e3a44d281d019ebf6aec738c2cfe18f8bba97462 to this exact head. No scanner suppression, threshold, baseline exclusion or hook configuration change is included.
  • Direct parent: frozen wire b203bbcff51cb648c1fd605224fb74e5a3465a8f; tree: 208d0a7b75ac982ae52457d77db1aecbb7539b2e.

The exact-parent Bandit B110 result remains an original exit-1 red. Frozen b203 and runtime dba15 retain their inherited hook failures; this child's green result does not rewrite them. The earlier 93087395 documentation-only correction remains behavior-preserving documentation. The initial pre-freeze formatting failure is also retained separately from the corrected frozen checks.

The review shows only this two-file sibling delta (+35/-1) against conductor/fix-reporting-scope-selector-default at exact b203. This is a draft review leaf: delivery is through a later coordinator-approved ancestry-preserving integration into #1203, followed by fresh aggregate/main hooks and CI. It is not a package, merge or release approval. PR #1202 and #1203 remain unchanged.

No standalone package, PostgreSQL or full historical matrix was run for this bounded one-line production change. Only actually scheduled remote checks will be recorded; this leaf has no inherited claim to #1203 CI. Original focused test and normal-hook command streams are retained under .context/py-dispatch-b110-20260922/frozen-focused-controls/ and frozen-inherited-normal-hooks/, with the exact-parent red in pinned-parent-bandit-red/.

Base automatically changed from conductor/fix-reporting-scope-selector-default to main September 25, 2026 12:40
@bokelley
bokelley merged commit 25e0c72 into main Sep 25, 2026
4 checks passed
@bokelley
bokelley deleted the conductor/fix-dispatch-validation-fallback branch September 25, 2026 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant