Repository navigation
fix: opa - use --stdin-input instead of --input /dev/stdin (Windows) - #3913
Merged
MohammadHaroonAbuomar merged 3 commits intoSep 14, 2026
Merged
MohammadHaroonAbuomar merged 3 commits into
MohammadHaroonAbuomar merged 3 commits into
Conversation
Fernando Marino` (fer-marino)
requested review from
MohammadHaroonAbuomar and
liamcrumm
as code owners
September 9, 2026 08:34
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Contributor
Author
|
@microsoft-github-policy-service agree |
MohammadHaroonAbuomar
requested changes
Sep 10, 2026
MohammadHaroonAbuomar
left a comment
Collaborator
There was a problem hiding this comment.
- Commit bc35531 has no Signed-off-by trailer. The DCO check has not run yet because the fork workflows are gated, but it will fail once a maintainer approves them. Please
git rebase --signoffand force-push; everything else in this PR is already verified and this is the only remaining item.
OPAEvaluator's local CLI mode constructed `opa eval --input /dev/stdin`
and piped the input JSON via subprocess.run(input=...). /dev/stdin is a
real special file on Linux/macOS, so this happened to work there, but it
doesn't exist on Windows: every call failed with
opa eval failed: open /dev/stdin: The system cannot find the path specified.
Because _evaluate_opa_cli catches the non-zero opa eval exit and returns
OPADecision(allowed=False, ...) rather than raising, this was worse than
a crash: every policy check silently came back denied on Windows,
including cases that should have been allowed - the project's own
test_opa.py demonstrates this precisely, since it asserts allowed=True
in several cases.
Confirmed both ways by actually running tests/test_opa.py on Windows with
opa v1.20.2 on PATH:
- Before this change: 10 of 26 tests fail, every one an `assert ...
allowed is True` on a policy that should have matched.
- After this change: 25 of 26 pass. The one remaining failure
(test_evaluation_timing, asserting evaluation_ms < 100) is unrelated
to this fix and pre-existing: opa eval's own subprocess-spawn cost is
~550-650ms on this machine regardless of the /dev/stdin bug, so that
assertion looks environment-dependent rather than something this
change touches.
Fix: opa eval has a dedicated, portable flag for exactly this -
-I/--stdin-input, which reads the input document from the process's
actual stdin rather than a file path. Swapping to it removes the platform
dependency entirely.
Signed-off-by: Fernando Marino <fernando.marino85@gmail.com>
Fernando Marino` (fer-marino)
force-pushed
the
fix/opa-stdin-input-windows
branch
from
September 11, 2026 07:06
bc35531 to
36a5827
Compare
Contributor
Author
San-Hsien (SanHsien)
added a commit
to SanHsien/agent-governance-toolkit
that referenced
this pull request
Sep 12, 2026
, microsoft#3916, microsoft#3924, microsoft#3853, advance watermarks
Fernando Marino` (fer-marino)
added a commit
to fer-marino/agent-governance-toolkit
that referenced
this pull request
Sep 14, 2026
The merge from origin/main silently reintroduced --input /dev/stdin in _evaluate_opa_cli: main's own version of this function (still without microsoft#3913, per carloshvp's review comment) matched closely enough around _rego_file_for_cli() that git took main's flag without flagging a conflict. Caught by rerunning the test suite post-merge - 25 opa-CLI tests failed with the exact original bug's symptom (every policy check denied). Restored --stdin-input; full suite (190 tests) passes again except the known pre-existing timing test.
Fernando Marino` (fer-marino)
requested a review
from Prayag (prayagupa)
as a code owner
September 14, 2026 07:26
MohammadHaroonAbuomar
approved these changes
Sep 14, 2026
Yuvraj Singh (yuvrajsingh2428)
pushed a commit
to yuvrajsingh2428/agent-governance-toolkit
that referenced
this pull request
Oct 1, 2026
…icrosoft#3913) OPAEvaluator's local CLI mode constructed `opa eval --input /dev/stdin` and piped the input JSON via subprocess.run(input=...). /dev/stdin is a real special file on Linux/macOS, so this happened to work there, but it doesn't exist on Windows: every call failed with opa eval failed: open /dev/stdin: The system cannot find the path specified. Because _evaluate_opa_cli catches the non-zero opa eval exit and returns OPADecision(allowed=False, ...) rather than raising, this was worse than a crash: every policy check silently came back denied on Windows, including cases that should have been allowed - the project's own test_opa.py demonstrates this precisely, since it asserts allowed=True in several cases. Confirmed both ways by actually running tests/test_opa.py on Windows with opa v1.20.2 on PATH: - Before this change: 10 of 26 tests fail, every one an `assert ... allowed is True` on a policy that should have matched. - After this change: 25 of 26 pass. The one remaining failure (test_evaluation_timing, asserting evaluation_ms < 100) is unrelated to this fix and pre-existing: opa eval's own subprocess-spawn cost is ~550-650ms on this machine regardless of the /dev/stdin bug, so that assertion looks environment-dependent rather than something this change touches. Fix: opa eval has a dedicated, portable flag for exactly this - -I/--stdin-input, which reads the input document from the process's actual stdin rather than a file path. Swapping to it removes the platform dependency entirely. Signed-off-by: Fernando Marino <fernando.marino85@gmail.com> Co-authored-by: Fernando Marino <f.marino@rheagroup.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3912.
OPAEvaluator's local CLI mode constructed
opa eval --input /dev/stdinand piped the input JSON via subprocess.run(input=...). /dev/stdin is a real special file on Linux/macOS, so this happened to work there, but it doesn't exist on Windows: every call failed withBecause _evaluate_opa_cli catches the non-zero opa eval exit and returns OPADecision(allowed=False, ...) rather than raising, this was worse than a crash: every policy check silently came back denied on Windows, including cases that should have been allowed - the project's own test_opa.py demonstrates this precisely, since it asserts allowed=True in several cases.
Confirmed both ways by actually running tests/test_opa.py on Windows with opa v1.20.2 on PATH:
assert ... allowed is Trueon a policy that should have matched.Fix: opa eval has a dedicated, portable flag for exactly this - -I/--stdin-input, which reads the input document from the process's actual stdin rather than a file path. Swapping to it removes the platform dependency entirely.
Related Issue
Problem & Solution
Impact on Your Work
Timeline
Alternatives Considered
Type of Change
Package(s) Affected
Core & runtime:
Governance & security:
Platform & tooling:
CLI plugins:
Shared / other:
Testing
Unit Testing
Manual Testing
Checklist
Attribution & Prior Art
Prior art / related projects (if any):
AI Assistance
If AI tools materially shaped this change, briefly note what was used:
IP, Patents, and Licensing