Repository navigation
Security runs and the Security review: thirdshift finds, reproduces and fixes vulnerabilities - #556
Merged
Merged
Conversation
Ship Cloudflare security-audit as a Factory skill
Prefactor shared Pass lock, logging and command words
Trial the Security review's two modes
Fix macOS stdout-holder interruption test timing
On case-insensitive macOS filesystems, the lowercase candidate resolves to the tracked docs/THREAT-MODEL.md file, so discovery named the wrong spelling in the Session prompt. Require an exact match in the audited checkout's tracked paths before selecting an existing document. Keep the end-to-end regression unchanged. It failed with the CI symptom in a local replay of case-insensitive lookup and passes with this fix.
Add report-only Security runs
Record private repository Security findings as labelled issues
Ask about Security fixing during Setup
Support larger Security fixes and reuse private finding issues
…. Please try a different model.) 2026-10-08T20:34:30Z, host thirdshift. Uncommitted work at the time of failure is included in this commit.
Preserve failed Security-fix lifecycle tracking alongside Spec-sized fixes and reuse of private finding issues. Update the failure fixtures and help text, and cover failed Spec fixes pausing Security and Pickup until closure. Validation: cargo check --all-targets; cargo fmt --check; cargo clippy --all-targets -- -D warnings; cargo test --no-fail-fast (1605 passed, 0 failed, 1 ignored).
Pause Security after failed fixes and offer fixing
Add opt-in guidance Security reviews to Runs
Run guidance Security review once on Spec PRs
Preserve whole-Spec guidance Security reviews alongside private recording of pre-existing findings. Update the Spec review fixtures for the private report, pre-existing count, and pinned published merge base. Validation: cargo check --all-targets; cargo clippy --all-targets -- -D warnings; cargo fmt --check; UPDATE_PROMPTS=1 cargo test prompts_page; cargo test --no-fail-fast (1630 passed, 0 failed, 1 ignored).
Record old Security review findings privately
Keep Codex guidance reviews in one session across Resume while retaining security refusal checks, Model logging and the security thread cap. Record the scored severity of reproduced old review findings through the existing private-record update rules. Retain both review regressions.
JacobStephens2
marked this pull request as ready for review
October 9, 2026 11:21
Preserve Security settings and Ready issue exclusions alongside the configurable Pickup settling window. Put the notification Result line before Security audit metadata while retaining private finding redaction. Keep interrupted-work preservation assertions alongside upstream natural-expiry and delayed-cleanup regression coverage. Validation: cargo check --locked --all-targets; cargo clippy --locked --all-targets -- -D warnings; cargo test --locked --no-fail-fast -- --test-threads=8 (1659 passed, 0 failed, 1 ignored); cargo fmt --check; Node validator tests (65 passed).
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds Fencing with
thirdshift secureand opt-in guidance Security reviews. Findings are recorded privately and reproduced before an allowed fix becomes public work.security-findingissues. Records match fingerprints across states and preserve the Day shift's grades. Failed fixes keep their Claim and pause Fencing until closed.[security]settings control review, fixing and Harness choice; both features default off. Setup asks about review and fixing. Codex security sessions retain refusal checks, answering-Model logs and the raised thread cap; guidance reviews stay in one session, including Resume.c1c8a8c, including its Node validators. Adds README setup and cron examples, generated prompts and the Prompts and skills page. The graded trial records the Day shift's guidance-mode choice and its detection limits.Closes #427
Evidence
cargo test --test security_review guidance_security_review_on_codex_does_not_request_delegated_auditors -- --exact --nocapturefailed: Codex appended a delegation instruction to the single-session guidance review. After: passes; covers the initial session and Resume. The existing full-audit regression also passes with fresh sub-agents on both launches.cargo test --test security_review reproduced_old_review_finding_sets_the_private_advisory_severity -- --exact --nocapturefailed withnullinstead oflow. After: passes; new reproduced review records use the existing private-record update rules to write the scored severity and proof-of-concept.cargo nextest run --test-threads 8: 1,632 passed, one existing benchmark skipped.cargo testalso passed. Node validators: 65 passed.cargo fmt --checkandcargo clippy --all-targets -- -D warningspass. Generated-page checks pass in the Rust suite.Test seams
Unaddressed findings
Standards
None.
Spec
Inherited informational advisory grade decision: #567, originally raised by PR #566, remains open with only
needs-triage. The Spec asks for the rubric grade and proof-of-concept on the record, while the public advisory severity field cannot carryinformational.src/github/advisories.rs:500–506deliberately fails before writing an unsupported grade; private finding issues retain it. The Day shift must choose the representation, which the Spec has not settled.Focused runs both pass and exercise this exact boundary:
cargo test --test security_run an_informational_advisory_requires_a_day_shift_decision_without_an_invented_grade -- --exactverifies the deliberate public failure and unchanged evidence;cargo test --test security_run a_private_reproduction_accepts_the_rubrics_informational_severity -- --exactverifies private preservation. These runs document the deferred policy; they do not claim the public requirement is complete.Review coverage
Review fixed point:
mainat3a81a11; original Spec head:58bb0de. Both axes read all 106 changed files, including generated files, imported skill sources and tests. No changed file was left unread. Reports with each axis's final files-read list are saved as.thirdshift-review-igwNvs/standards.mdand.thirdshift-review-igwNvs/spec.md.Merge Danger
Door: two-way
The code and opt-in settings can be reverted. Enabled Security runs create private GitHub records; explicitly allowed fixing can publish issues and push code, disclosing the fixed vulnerability as described in ADR 0015.
Blast Radius: factory
Touches shared Pass, Harness and Delivery paths used by Runs, Spec runs, Base fixes and scheduled Passes. Security review and fixing stay off by default; the whole-repository audit and guidance review have separate execution policies.
Tickets
Built with codex · gpt-6.1-sol · xhigh