Skip to content

PR C: enforce hosted workspace ownership boundaries - #209

Merged
chenmingtang830 merged 4 commits into
mainfrom
codex/workspace-ownership
Sep 30, 2026
Merged

chenmingtang830 merged 4 commits into
mainfrom
codex/workspace-ownership

Conversation

@chenmingtang830

@chenmingtang830 chenmingtang830 commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Revalidate server-issued principal contexts before hosted authorization, policy resolution, execution reservation, or audit attribution.
  • Bind legacy policy, provider key, Owner assistant, and workspace label defaults to one designated workspace. An additional workspace requires an explicit saved policy; missing policy fails closed.
  • Scope execution attempt completion and execution/Judge recovery to the selected workspace and principal. Startup dispatches recovery per registered workspace.
  • Document the ownership contract. Production bootstrap remains single-workspace; no ownership schema or historical-data migration is included.

Shared-database isolation coverage

The A/B fixture uses the same SQLite database, identical owner/agent strings, topic and retry keys, deliberately colliding content IDs, distinct policy digests, and synthetic provider keys. Negative cases cover governed and staged reads, graph and MCP paths, foreign evidence and claim/relation lifecycle writes, run/receipt/experiment links, Owner inspection and session behavior, OAuth token families, policy and secret fallback, execution and Judge recovery, local export, and exception/concurrency cleanup. It also checks one-workspace restart and idempotent replay.

Verification

  • Full local Python suite: 415 tests passed.
  • Focused isolation and architecture tests: 28 tests passed.
  • python -m ruff check src tests and git diff --check passed.
  • GitHub CI runs on this PR; merge only after required checks and review are complete.

Boundary

This prepares workspace ownership isolation; it does not activate shared hosting or replace the separate pilot restore, rollback, credential/job/log isolation, and incident-owner gates. The audit is an implementation draft, not admitted governed context.

@vercel

vercel Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
proofpress Ready Ready Preview Sep 29, 2026 7:13pm UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T19:16:13.282641Z 3a97a05 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chenmingtang830

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Already looking forward to the next diff.

Reviewed commit: b3cbb29dcf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chenmingtang830
chenmingtang830 merged commit 3492755 into main Sep 30, 2026
11 checks passed
@chenmingtang830
chenmingtang830 deleted the codex/workspace-ownership branch September 30, 2026 01:55

This branch was successfully deployed

1 active deployment
Preview — 3a97a059 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant