Skip to content

fix(guardrail): translate user-facing guardrail messages to English - #167

Merged
Chachamaru127 merged 2 commits into
Chachamaru127:mainfrom
aryrabelo:fix/guardrail-messages-english
May 30, 2026
Merged

Chachamaru127 merged 2 commits into
Chachamaru127:mainfrom
aryrabelo:fix/guardrail-messages-english

Conversation

@aryrabelo

@aryrabelo aryrabelo commented May 27, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The Go guardrail engine (go/internal/guardrail/) emits block/ask/warn messages in Japanese. A non-Japanese operator who trips a rule sees, for example, a denied .env write reported as:

保護パスへのファイル書き込み は禁止されています: .env

which is not actionable for them.

Change

Translate all user-facing guardrail strings to English:

Area File
R01–R13 deny/ask/warn reasons rules.go
Protected-path operation labels rules.go, helpers.go
Security-risk messages + test-tampering warning post_tool.go
Tampering pattern descriptions (T01–T12) tampering.go

Before / After

Before After
保護パスへのファイル書き込み は禁止されています: .env file write to a protected path is not allowed: .env
[v4] テスト改ざん検出警告 [v4] Test-tampering warning
Codex モード中は Claude が直接... During Codex mode Claude cannot write files directly...

Rule IDs, severities, and decision behavior are unchanged — only the human-readable message text.

Tests

Test assertions that matched the old Japanese substrings are updated in lockstep (post_tool_test.go, rules_test.go). Internal code comments and self-contained serialization fixtures are intentionally left untouched (not user-facing).

  • go test ./internal/guardrail/ ./internal/hookhandler/ — pass
  • go vet ./internal/guardrail/ — clean
  • go build ./... — clean
  • scripts/ci/check-consistency.sh — pass

Summary by CodeRabbit

  • 改善
    • セキュリティアラートとシステムメッセージを英語に統一しました
    • 改ざん検知の表示形式を改善し、検出箇所の表示をわかりやすくしました
    • 保護パスへの書き込み判定の扱いを調整して応答の分岐を明確化しました
  • テスト
    • 警告文言の期待値を英語表記に更新する等、関連テストを修正しました

Review Change Stack

The Go guardrail engine emitted block/warn messages in Japanese (e.g. a
.env write was denied with 保護パスへのファイル書き込み は禁止されています).
Translate all user-facing strings to English so the messages are legible
to non-Japanese operators:

- R01-R13 deny/ask/warn reasons (rules.go)
- protected-path operation labels (rules.go, helpers.go)
- security-risk messages and the test-tampering warning (post_tool.go)
- tampering pattern descriptions T01-T12 (tampering.go)

Test assertions that matched the old Japanese substrings are updated in
lockstep (post_tool_test.go, rules_test.go). Internal code comments and
self-contained serialization test fixtures are left unchanged (not
user-facing).
@coderabbitai

coderabbitai Bot commented May 27, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 0347322c-7cb2-4c7a-9874-f45cbba2af6f

📥 Commits

Reviewing files that changed from the base of the PR and between 70d6310 and dda3e27.

📒 Files selected for processing (2)
  • go/internal/guardrail/helpers.go
  • go/internal/guardrail/rules_test.go
🚧 Files skipped from review as they are similar to previous changes (2)
  • go/internal/guardrail/rules_test.go
  • go/internal/guardrail/helpers.go

Walkthrough

ガードレールの判定メッセージを日本語から英語へ置換し、保護パスの shell 書き込み判定で R03 の askResult を収集する制御フロー変更と、改ざん検知メッセージ表示フォーマットおよび関連テストを更新しました。

変更内容

Guardrail i18n と保護パス処理

Layer / File(s) Summary
保護パス判定ロジック改善
go/internal/guardrail/helpers.go, go/internal/guardrail/rules.go
bashProtectedWriteHookResult の protectedPathDeny 分岐で R03 の askResult を即時 return せず収集するよう制御フローを変更。ask/warn 理由文字列を "shell write to a protected path" に統一。
セキュリティルール文言の英語化
go/internal/guardrail/rules.go
R01〜R13 の Reason/SystemMessage を日本語から英語に置換。protected-branch push ポリシー文面等も英語化。
改ざん検知パターンの国際化
go/internal/guardrail/tampering.go
T01〜T12 の Description を英語表記に変更。定義記述を簡潔化。
post_tool メッセージとフォーマット更新
go/internal/guardrail/post_tool.go
改ざん検知・セキュリティリスク検知の文言を英語化し、検出項目を "location:" 形式で整形。見出しも英語化。
テスト期待値の英語化
go/internal/guardrail/post_tool_test.go, go/internal/guardrail/rules_test.go
改ざん検知・Security risk・sudo/Codex 関連テストの期待値を英語表現に更新。

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

ポエム

🐰
I hopped through code with careful pace,
Swapping words to a common place.
Guards now speak in English bright,
Paths protected through the night.
Tiny changes, safety tight.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 11.11% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed プルリクエストのタイトルは、プルリクエストの主な変更内容である「ガードレールのユーザー向けメッセージを日本語から英語に翻訳する」ことを明確に要約しており、簡潔で具体的です。
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain modules listed in go.work or their selected dependencies"


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 70d6310538

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

return &hookproto.HookResult{
Decision: hookproto.DecisionDeny,
Reason: "sudo の使用は禁止されています。必要な場合はユーザーに手動実行を依頼してください。",
Reason: "sudo is not allowed. If it is required, ask the user to run it manually.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve Japanese guardrail output under ja locale

When the active Go guard path (harness hook pre-tool) runs with an explicit Japanese locale (CLAUDE_CODE_HARNESS_LANG=ja or i18n.language: ja), these replacement strings are now always English because EvaluatePreTool/EvaluateRules has no locale selection. The repo's i18n contract requires hook and system messages to keep the existing Japanese messages for explicit ja, so Japanese opt-in users now get English denial/ask prompts for cases like sudo; route these messages through the locale resolver instead of replacing the only Japanese variant.

Useful? React with 👍 / 👎.

lines = append(lines, fmt.Sprintf("- [%s] %s\n location: %s", w.PatternID, w.Description, w.MatchedText))
}
msg := fmt.Sprintf("[v4] テスト改ざん検出警告\n\n%s `%s` に疑わしいパターンが検出されました:\n\n%s\n\n【確認してください】\nこの変更がテストを意図的に無効化したり、実装品質を下げるものでないかを確認してください。\n改ざんと判断した場合は変更を元に戻してください。",
msg := fmt.Sprintf("[v4] Test-tampering warning\n\nSuspicious patterns detected in %s `%s`:\n\n%s\n\n[Please review]\nConfirm this change does not intentionally disable tests or reduce implementation quality.\nIf you determine it is tampering, revert the change.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the Go E2E tampering assertion

This changes the PostToolUse tampering header to Test-tampering warning, but go/test-e2e.sh still treats the same scenario as passing only when the output contains テスト改ざん (line 36). After rebuilding bin/harness, the E2E script's PostToolUse tampering check will print FAIL even though the hook emitted the new warning, so the script should be updated to assert the English default (or run under the Japanese locale).

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner

The validate failure here wasn't caused by this PR — it was a repo-wide version drift (harness.toml 4.13.0 vs VERSION/plugin.json 4.13.1, which made the sync step revert plugin.json and fail the check-consistency parity gate). That's now fixed on main (#178). A rebase on main should turn validate green; all other checks here are already passing. The message-translation change itself looks good.


Generated by Claude Code

@Chachamaru127 Chachamaru127 left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed locally against current main.

  • Merges cleanly into main (6 files, guardrail strings only).
  • go test ./internal/guardrail/ ./internal/hookhandler/ — all pass on the merged tree.
  • Rule IDs, severities, and decision behavior are unchanged; only user-facing message text is translated. Test assertions updated in lockstep (post_tool_test.go, rules_test.go).
  • The earlier validate CI failure was against a stale base; re-running after updating the branch to current main.

LGTM. Translating R01–R13 / T01–T12 operator-facing messages to English is a clear usability win for non-Japanese operators.


Generated by Claude Code

@Chachamaru127
Chachamaru127 merged commit 45df19a into Chachamaru127:main May 30, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants