knowledge: 2 insights — threading a parameter through an executor hop (scope-scan the path, a worker's exception is stored on the future → empty results exit 0), a restriction flag in a shared config that only some adapters enforce (refuse in non-enforcing adapters, gate on adapter id, pass pi --no-tools unconditionally) (2 new pages, 4 amended, 12 plan-gaps retired as local-layer) - #231
Open
choiyounggi wants to merge 1 commit into
Open
choiyounggi wants to merge 1 commit into
choiyounggi wants to merge 1 commit into
Conversation
- backend/common/change-impact/threading-a-parameter-through-executor-hops: scan every function on the path for a referenced-but-unbound name before tests; an exception inside an executor worker is stored on the future, so a caller that records only OK futures reports empty results with exit 0 - security/agent-exposure/capability-flag-across-adapters: census which adapters read a shared restriction flag, refuse it in non-enforcing adapters before spawning (CWE-636), gate at the caller on adapter id, pass the adapter-native lock-down switch unconditionally, test the true arm per adapter - back-links: call-site-enumeration, async-failure-handling, authorization-scope-persistence, unenforced-declarations; index rows; log - 12 t175 plan-gap rows retired as local-layer (listed in INGEST_REPORT)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Knowledge flush — 2 insight(s) (+12 plan-gap rows retired as local-layer)
Run id
20260928-191816-52426(inherited from the auto-flush parent). Claimed 14 rows: 2 generalcandidates from sessions
56be2ab9…(linkly t175) ande5d33b40…(linkly-crew t7), and 12plan-gapsrows taggedt175-find-by-lookup-key.Verified best-practice
1. Threading a new parameter through a call chain that crosses an executor (hash
157f9966ef1bfebb)Claim. When a new argument is threaded through Python helpers and one hop is a
ThreadPoolExecutor.submit(), enumerate every function on the path with a scope scan (namesreferenced but not bound as parameter/local/module) before running tests, and read "the parallel
block produced no results" as a possible exception stored on a future rather than a logic error.
Sources checked.
Future.result(): "If the call raised anexception, this method will raise the same exception";
Future.exception()returns the storedexception or
None;Executor.map(): the exception "will be raised when its value is retrieved fromthe iterator". Nothing surfaces at
submit()time.Function.get_parameters(),Function.get_locals(),Symbol.is_referenced(),Symbol.is_free(),SymbolTable.get_children()— the primitives the scan uses.How verified. Reproduction 2026-09-28 (CPython 3.14.4, macOS) in
.claude/tmp/flush-repro/(deleted after capture): a worker helper referencing an unbound
keysunder aThreadPoolExecutor(max_workers=4)whose caller appendsresult()only whenexception()isNoneprinted
results: []with exit code 0 and no traceback; callingresult()on one future raisedNameError: name 'keys' is not defined. The symtable scan printed exactly one line naming the brokenhelper on the original file (known-bad) and zero lines on the fixed copy (known-good), which then
returned three results.
Confidence: verified.
2. A capability-restriction flag in a shared config that only some adapters enforce (hash
2b935d298d7e036e)Claim. When a restriction flag (
tool_use, write confinement) lives in a config struct sharedby several adapters and only one implements it: census which adapters read it, make every
non-enforcing adapter refuse the flag with an explicit error before spawning, gate the flag at the
caller on adapter id, pass each adapter's native lock-down switch unconditionally, and test the
true arm per adapter.
Sources checked.
falling "back to a state that is less secure … such as using the most permissive access control
restrictions"; "causes administrators to have a false sense of security".
Privilege, Fail Securely, Secure by Default, Defense-in-Depth (quoted in the page).
--no-toolsto pi;confirmed on the installed CLI 2026-09-28:
pi --helpline 31--no-tools, -nt Disable all tools by default (built-in and extension); the package CHANGELOG (fetched viagh api) records "--no-toolsnow disables all tools by default rather than only built-ins" (#2835, #3452).
How verified. Directive matched against CWE-636 and the OWASP principles (fail closed, least
privilege, secure defaults); the adapter-native switch the directive names was confirmed on the
installed binary and in the upstream changelog; the field incident (crew-run
role_harness_cfgsettool_usefor all harnesses,pi.rsignored it, RED test showed pi spawned withtool_use=true) isrecorded as the field evidence row.
Confidence: verified.
Existing-layer check
Pages read: backend-python-concurrency-gil-and-concurrency-model, testing-quality-sequential-dispatch-assumption-under-concurrency, debugging-signals-stack-traces, debugging-concurrency-intermittent-failures, backend-common-change-impact-call-site-enumeration, backend-common-errors-async-failure-handling, backend-common-errors-exception-handling, testing-mocking-captured-call-arguments, security-authn-retiring-a-replaced-auth-gate, security-agent-exposure-authorization-scope-persistence, testing-quality-default-values-under-test, backend-common-integrations-consumer-required-fields, backend-common-api-design-unenforced-declarations
Also read:
INDEX.md,wiki/debugging/index.md,wiki/security/index.md,wiki/backend/index.md,wiki/backend/python/index.md, the agent-orchestration section ofwiki/infrastructure/index.md.wiki_searchtop-5 for candidate 1: testing-quality-sequential-dispatch-assumption-under-concurrency(0.751), backend-python-concurrency-gil-and-concurrency-model (0.748),
backend-common-errors-async-failure-handling (0.738), backend-java-kotlin-coroutines-dispatchers-and-blocking
(×2, 0.738/0.735). For candidate 2: infrastructure-deploy-rollout-and-rollback (0.748),
platforms-filesystems-paths-case-and-line-endings (0.726), testing-mocking-captured-call-arguments (0.723),
infrastructure-agent-orchestration-semantic-conflicts-after-parallel-merge (0.722),
platforms-toolchains-compiler-sysroot-on-macos (0.721). Repo-wide grep for the candidates' keywords
(
ThreadPoolExecutor|NameError|as_completed|future.result;capability flag|least.privilege|deny.by.default|silently ignor|adapter)ran with a positive control (
asyncio→ 3 files) and every hit was opened.Overlaps and verdicts.
backend-common-change-impact-call-site-enumerationenumeratescallers of a changed callee; this case is the intermediate hop that is a caller of nothing new, so
it is adjacent, not a duplicate.
backend-common-errors-async-failure-handlinghas the edge row"Future stored but never consumed"; the new case (a collection loop that records only OK futures) is
a sibling shape — added as a new edge row there pointing at the new page, not merged, because the
new page's directive (the pre-test scope scan) is a change-impact step that page does not own.
testing-quality-sequential-dispatch-assumption-under-concurrencycovers exact-count assertionsunder a parallelized loop — linked as related. No conflicting directive found.
backend-common-api-design-unenforced-declarationsis thenearest principle (recognized-but-unenforced declaration → accept-and-warn); the new page sharpens it
for a security restriction shared across adapters (refuse, not warn) and is linked both ways with an
edge row.
security-agent-exposure-authorization-scope-persistence(force flag must not bypass thegate) and
security-authn-retiring-a-replaced-auth-gate(deny default) are adjacent principles, notduplicates.
testing-mocking-captured-call-argumentsowns the "assert the spawn carries theconfinement argument" test shape — linked one-way from the new page only, because open PR knowledge: 15 insights — gitignore re-inclusion, union-merge reassembly, hook input fields, silenced-write redirection, jq unicode escape, EPIPE write ordering, fake-server forward-before-reply, shared-helper invariant (8 new pages, 5 amended, 100 plan-gaps retired) #223
rewrites that file.
Created:
wiki/backend/common/change-impact/threading-a-parameter-through-executor-hops.md,wiki/security/agent-exposure/capability-flag-across-adapters.md.Amended (related link + one edge row each): call-site-enumeration, async-failure-handling,
authorization-scope-persistence, unenforced-declarations. Index rows:
wiki/backend/index.md(change-impact),
wiki/security/index.md(agent-exposure),INDEX.mdsecurity route line (thebackend route line is left untouched because open PR #225 rewrites it; the domain index row carries the
route). Conflicts flagged: none.
Open-PR check
Open
knowledge/*heads listed 2026-09-28 19:19 KST: #223 (knowledge/choiyounggi-20260927-220735),#225 (
…-20260928-082803), #226 (…-092831), #227 (…-103056), #228 (…-134840),#229 (
…-145025), #230 (…-155239). Each head fetched;git diff origin/main origin/<head> -- wiki/grepped for both candidates' keywords (positive control:
gitignorein #223 → 13 hits) and eachhead's added/modified page list read.
157f9966ef1bfebb) executor-hop parameter threading2b935d298d7e036e) capability flag across adapterssecurity/agent-exposure/in-session-tool-exposure.mdandtesting/mocking/captured-call-arguments.md(WebMCP tool surfaces), which is why those two files receive no back-link edit hereplan-gapsrows (t175-find-by-lookup-key)pendingRouting decision
backend/common/change-impact/threading-a-parameter-through-executor-hopsdebugginghint is served by the edge row and related link fromasync-failure-handling, the page an agent debugging "side effects silently never happen" already loadssecurity/agent-exposure/capability-flag-across-adaptersNo new category was created.
Local-layer candidates
All 12
plan-gapsrows belong to the linkly compiler repository (seagrass); each directive nameslower.pyline numbers,RepositoryCallnodes,RFC-0052,RFC_ROUTES,LOOKUP_SUBJECT, and_resolve_lookup_key, and would be wrong in any other codebase. Excluded from this PR; runwiki-ingestinside that project.3d731255ec8e39e0by <ref>on read/update/deletewiki-local/backend/compiler/by-ref-trailing-clause-grammar.mdd5c058373a04ea49wiki-local/backend/compiler/lookup-ref-category-admission.mdfc8c4977a204266dbinding.fieldlookup keywiki-local/backend/compiler/lookup-key-derived-password-refusal.mde4ea213f6d9df04fwiki-local/backend/runtime/lookup-key-derivation.mdbe4216dd01e49baee4ea213f6d9df04f(revision of the same decision)c207e65da923f1a0setunder the lookup keywiki-local/backend/runtime/persist-set-under-lookup-key.md672134c2e2a71817update/delete … by <ref>execute keywiki-local/backend/runtime/update-delete-by-lookup-key.mdf5ba6ac93a2aedcainput.<field>first readswiki-local/backend/runtime/seed-key-rule-input-field.mdcaf95ea8520a2931f5ba6ac93a2aedca(revision of the same decision)4bf5070e2b5086fdwiki-local/backend/runtime/bound-ref-seeding-scope.mdd4fa24759b67ba37wiki-local/qa/rfc-process/rfc-0052-updates-chain.md4d689bc1190fc357wiki-local/qa/registries/rfc-registry-and-generated-reference-gates.md