Repository navigation
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose and policy decision
Addresses the cross-family composition portion of #16. The dispatcher eagerly evaluated all families but returned the first match, allowing an early filesystem classification to hide an already-detected exec, HTTP, or code-patch restriction.
Choose the highest applicable priority: block > approval > allow, with existing family order retained on ties. Configured blocks participate in both modes; configured and session-strict approvals participate only in operator-present mode, matching disposition behavior. Return the selected family's original classification, default decision, reason, and pattern evidence. Final disposition remains responsible for authorization.
The policy rationale and compatibility limits are in
docs/classifier-composition.md. Opaque/non-string command handling and within-family exec precedence remain open; this PR does not close all of #16.Changes
read_emailmatching, and preserve the overall PARTIAL classifier coverage claim.Development and verification
Environment: Windows 10.0.26200, supported Node v26.7.0, npm 11.19.0. Dependencies installed with
npm ci --ignore-scripts --no-audit --no-fundafter reviewing lifecycle scripts. CI uses the repository-pinned Node and standard clean install.npm run build:corenpm run test -w @fides-anima/fpp-enforcement-corenode --import tsx --test packages/enforcement-core/src/classifier-composition-runtime.test.tsnpm run self-testnpm run test:corpusnpm run verify:allgit diff --checkb130a0e5027f3b4ccb22bba29c9f96de9385d79bThe full local gate began on the first candidate; the final runtime refinement landed while later packaging checks were running. Final core build, all 277 enforcement tests, and the composition experiment were rerun afterward. The PR's completed CI is the authoritative complete gate for the final commit: full verification, public npm package dry-run, conformance/contextual trust e2e, security regressions, coverage thresholds, corpus, and assurance artifacts all passed. No CI step was skipped.
Independent review found and reproduced an unattended-mode bug in the first candidate: approval-list promotion could hide an intrinsic package-install approval and permit staging. Mode-aware priorities fix it. A separate standing-allow regression checks why equal priorities must keep stable family order.
Supplementary deterministic study against baseline
544adb5ed1966170374e1a96805ae8875e1c19a3: all 54 original corpus cases unchanged (25 expected-allow cases preserved); 188 below-strongest-family outcomes among 2,280 additional diagnostic probes became zero; 568 below-applicable-floor outcomes among 1,464 operator-present configuration probes became zero. No tested decision or existing floor weakened. These synthetic probes include normalized duplicates, use existing family outcomes as their reference, and are not independent trials or real-world accuracy estimates. The executable experiment, full observations, and logs are retained in the task's evidence bundle; the committed tests and corpus are the maintained regression checks.Limits