security: bound and validate discovered project configuration - #419
Conversation
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…ff-check-and-mypy-do-not-cover-the-compatibility-consum
…-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc
…wned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…07-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…e-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…urrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
…fecycle-logging-costs-107-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…ff-check-and-mypy-do-not-cover-the-compatibility-consum
…d-mypy-do-not-cover-the-compatibility-consum' into bug/387-20261003-bug-configure-logger-closes-consumer-owned-handlers-and-forc # Conflicts: # docs/integrations.md
…ogger-closes-consumer-owned-handlers-and-forc' into enhancement/381-20261003-perf-lifecycle-logging-costs-107-us-record-about-20x-stdlib
…fecycle-logging-costs-107-us-record-about-20x-stdlib' into bug/378-20261003-bug-run-bundle-retention-is-inoperative-on-native-windows
…retention-is-inoperative-on-native-windows' into enhancement/386-20261003-perf-retention-serializes-concurrent-invocations-on-an-untim
…tention-serializes-concurrent-invocations-on-an-untim' into security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confi
|
Re-verified at |
|
Resolved the merge conflicts by merging current main, including merged PR #418, into this branch in commit 2c2dc2f. Preserved the #385 project-configuration trust-boundary changes and current main logging recovery and tests. Local validation passed: full pytest, focused security/configuration tests (46), Ruff check and format, strict mypy, and documentation validation. GitHub reports the PR as conflict-free; hosted checks are running on the new head. The PR remains open and unmerged. |
JSON invocations now capture process descriptor 1 as well as Python stdout, so inherited subprocess output remains inside the single envelope. A concurrent drain avoids pipe deadlocks, the native path enforces the JSON capture limit, and descriptor restoration precedes envelope emission. The guides state the boundaries: wait for children, flush native stdio before returning, and use NDJSON for large output. A child retaining stdout causes a bounded capture error. Fixes #379. ## Branch maintenance Refs #426. Targets the branch for #419. Retarget and refresh after that parent is squash-merged; preserve the ordered stack. The branch was refreshed without rewriting history to include `main` at `a576cc279739eae5e4cfc33ffab2a7fb56de24de`. ## Current-head validation At `0441cec3b3098425d8c87aa9c8eaeee6e5496969`: uv lock freshness and baseline, runtime, strict typing, style, and contracts passed locally with all declared extras. Runtime result: 629 passed, 1 warning, 262 subtests passed in 9.37s. Hosted checks: 7/7 required checks passed; 0 checks pending; 0 unsuccessful checks at 2026-10-04T14:19:40.760978+00:00. See the PR Checks tab and #426 for subsequent results.
The convenience profile now bounds ancestor discovery, stops at project/filesystem boundaries, and validates discovered configuration permissions and path components before loading. Project environment files receive the same gate. An explicit opt-out supports knowingly shared workspaces; the Windows ACL limitation is documented.
YAML input is capped at 1 MiB and its composed graph is bounded before constructors expand merge aliases. Generic-profile behavior and merge precedence remain unchanged.
Fixes #385.
Branch maintenance
Refs #426. Targets the branch for #418. Retarget and refresh after that parent is squash-merged; preserve the ordered stack.
The branch was refreshed without rewriting history to include
mainata576cc279739eae5e4cfc33ffab2a7fb56de24de.Current-head validation
At
9012457f37a30f73ef54074cc65a3d85298f2580: uv lock freshness and baseline, runtime, strict typing, style, and contracts passed locally with all declared extras. Runtime result: 626 passed, 1 warning, 262 subtests passed in 9.20s.Hosted checks: 7/7 required checks passed; 0 checks pending; 0 unsuccessful checks at 2026-10-04T14:19:40.760978+00:00. See the PR Checks tab and #426 for subsequent results.