Skip to content

fix(enforcement): preserve restrictive cross-family classification - #17

Open
ovrsr wants to merge 1 commit into
mainfrom
codex/classifier-restrictive-composition
Open

ovrsr wants to merge 1 commit into
mainfrom
codex/classifier-restrictive-composition

Conversation

@ovrsr

@ovrsr ovrsr commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Purpose and policy decision

Addresses the cross-family composition portion of #16. The dispatcher eagerly evaluated all families but returned the first match, allowing an early filesystem classification to hide an already-detected exec, HTTP, or code-patch restriction.

Choose the highest applicable priority: block > approval > allow, with existing family order retained on ties. Configured blocks participate in both modes; configured and session-strict approvals participate only in operator-present mode, matching disposition behavior. Return the selected family's original classification, default decision, reason, and pattern evidence. Final disposition remains responsible for authorization.

The policy rationale and compatibility limits are in docs/classifier-composition.md. Opaque/non-string command handling and within-family exec precedence remain open; this PR does not close all of #16.

Changes

  • Compose matching family results instead of returning the first result.
  • Pass mode-applicable configuration and one strict-mode snapshot through runtime classification and disposition.
  • Add 10 classifier tests, 7 runtime integration tests, and 5 corpus cases.
  • Document conservative escalations, including broad read_email matching, and preserve the overall PARTIAL classifier coverage claim.

Development and verification

Environment: Windows 10.0.26200, supported Node v26.7.0, npm 11.19.0. Dependencies installed with npm ci --ignore-scripts --no-audit --no-fund after reviewing lifecycle scripts. CI uses the repository-pinned Node and standard clean install.

Check Result
Baseline composition regressions 6 failed / 1 passed, before the fix
npm run build:core PASS on final source
npm run test -w @fides-anima/fpp-enforcement-core PASS: 277 tests, 0 failed, 0 skipped on final source
node --import tsx --test packages/enforcement-core/src/classifier-composition-runtime.test.ts PASS: 7 tests, 0 failed, 0 skipped
npm run self-test PASS
npm run test:corpus PASS: 59 cases
npm run verify:all PASS, including builds, typecheck, tests, and isolated package installs; 404 seconds
git diff --check PASS
Final-commit GitHub CI PASS: Verify run 36088006037, all steps successful on b130a0e5027f3b4ccb22bba29c9f96de9385d79b

The full local gate began on the first candidate; the final runtime refinement landed while later packaging checks were running. Final core build, all 277 enforcement tests, and the composition experiment were rerun afterward. The PR's completed CI is the authoritative complete gate for the final commit: full verification, public npm package dry-run, conformance/contextual trust e2e, security regressions, coverage thresholds, corpus, and assurance artifacts all passed. No CI step was skipped.

Independent review found and reproduced an unattended-mode bug in the first candidate: approval-list promotion could hide an intrinsic package-install approval and permit staging. Mode-aware priorities fix it. A separate standing-allow regression checks why equal priorities must keep stable family order.

Supplementary deterministic study against baseline 544adb5ed1966170374e1a96805ae8875e1c19a3: all 54 original corpus cases unchanged (25 expected-allow cases preserved); 188 below-strongest-family outcomes among 2,280 additional diagnostic probes became zero; 568 below-applicable-floor outcomes among 1,464 operator-present configuration probes became zero. No tested decision or existing floor weakened. These synthetic probes include normalized duplicates, use existing family outcomes as their reference, and are not independent trials or real-world accuracy estimates. The executable experiment, full observations, and logs are retained in the task's evidence bundle; the committed tests and corpus are the maintained regression checks.

Limits

  • No live gateway or real tool payload was executed; runtime tests use temporary workspaces and fixture adapters.
  • Classifier heuristics remain bypassable. No new shell parser or semantic tool analysis is claimed.
  • One selected class does not establish authorization for every effect of a compound tool call.
  • No constitution, signature, production key, mandate semantics, publishing configuration, package version, or coverage threshold changed.
  • No public agent-overlay trust, agent behavior, or cross-operator benefit is established by this patch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant