Repository navigation
fix(guardrail): translate user-facing guardrail messages to English - #167
Conversation
The Go guardrail engine emitted block/warn messages in Japanese (e.g. a .env write was denied with 保護パスへのファイル書き込み は禁止されています). Translate all user-facing strings to English so the messages are legible to non-Japanese operators: - R01-R13 deny/ask/warn reasons (rules.go) - protected-path operation labels (rules.go, helpers.go) - security-risk messages and the test-tampering warning (post_tool.go) - tampering pattern descriptions T01-T12 (tampering.go) Test assertions that matched the old Japanese substrings are updated in lockstep (post_tool_test.go, rules_test.go). Internal code comments and self-contained serialization test fixtures are left unchanged (not user-facing).
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (2)
Walkthroughガードレールの判定メッセージを日本語から英語へ置換し、保護パスの shell 書き込み判定で R03 の askResult を収集する制御フロー変更と、改ざん検知メッセージ表示フォーマットおよび関連テストを更新しました。 変更内容Guardrail i18n と保護パス処理
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes ポエム
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Warning There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure. 🔧 golangci-lint (2.12.2)level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain modules listed in go.work or their selected dependencies" Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 70d6310538
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| return &hookproto.HookResult{ | ||
| Decision: hookproto.DecisionDeny, | ||
| Reason: "sudo の使用は禁止されています。必要な場合はユーザーに手動実行を依頼してください。", | ||
| Reason: "sudo is not allowed. If it is required, ask the user to run it manually.", |
There was a problem hiding this comment.
Preserve Japanese guardrail output under ja locale
When the active Go guard path (harness hook pre-tool) runs with an explicit Japanese locale (CLAUDE_CODE_HARNESS_LANG=ja or i18n.language: ja), these replacement strings are now always English because EvaluatePreTool/EvaluateRules has no locale selection. The repo's i18n contract requires hook and system messages to keep the existing Japanese messages for explicit ja, so Japanese opt-in users now get English denial/ask prompts for cases like sudo; route these messages through the locale resolver instead of replacing the only Japanese variant.
Useful? React with 👍 / 👎.
| lines = append(lines, fmt.Sprintf("- [%s] %s\n location: %s", w.PatternID, w.Description, w.MatchedText)) | ||
| } | ||
| msg := fmt.Sprintf("[v4] テスト改ざん検出警告\n\n%s `%s` に疑わしいパターンが検出されました:\n\n%s\n\n【確認してください】\nこの変更がテストを意図的に無効化したり、実装品質を下げるものでないかを確認してください。\n改ざんと判断した場合は変更を元に戻してください。", | ||
| msg := fmt.Sprintf("[v4] Test-tampering warning\n\nSuspicious patterns detected in %s `%s`:\n\n%s\n\n[Please review]\nConfirm this change does not intentionally disable tests or reduce implementation quality.\nIf you determine it is tampering, revert the change.", |
There was a problem hiding this comment.
Update the Go E2E tampering assertion
This changes the PostToolUse tampering header to Test-tampering warning, but go/test-e2e.sh still treats the same scenario as passing only when the output contains テスト改ざん (line 36). After rebuilding bin/harness, the E2E script's PostToolUse tampering check will print FAIL even though the hook emitted the new warning, so the script should be updated to assert the English default (or run under the Japanese locale).
Useful? React with 👍 / 👎.
|
The Generated by Claude Code |
Chachamaru127
left a comment
There was a problem hiding this comment.
Reviewed locally against current main.
- Merges cleanly into
main(6 files, guardrail strings only). go test ./internal/guardrail/ ./internal/hookhandler/— all pass on the merged tree.- Rule IDs, severities, and decision behavior are unchanged; only user-facing message text is translated. Test assertions updated in lockstep (
post_tool_test.go,rules_test.go). - The earlier
validateCI failure was against a stale base; re-running after updating the branch to currentmain.
LGTM. Translating R01–R13 / T01–T12 operator-facing messages to English is a clear usability win for non-Japanese operators.
Generated by Claude Code
Problem
The Go guardrail engine (
go/internal/guardrail/) emits block/ask/warn messages in Japanese. A non-Japanese operator who trips a rule sees, for example, a denied.envwrite reported as:which is not actionable for them.
Change
Translate all user-facing guardrail strings to English:
rules.gorules.go,helpers.gopost_tool.gotampering.goBefore / After
保護パスへのファイル書き込み は禁止されています: .envfile write to a protected path is not allowed: .env[v4] テスト改ざん検出警告[v4] Test-tampering warningCodex モード中は Claude が直接...During Codex mode Claude cannot write files directly...Rule IDs, severities, and decision behavior are unchanged — only the human-readable message text.
Tests
Test assertions that matched the old Japanese substrings are updated in lockstep (
post_tool_test.go,rules_test.go). Internal code comments and self-contained serialization fixtures are intentionally left untouched (not user-facing).go test ./internal/guardrail/ ./internal/hookhandler/— passgo vet ./internal/guardrail/— cleango build ./...— cleanscripts/ci/check-consistency.sh— passSummary by CodeRabbit