Repository navigation
fix(policy-engine): fail closed unavailable FFI fetch limits - #4025
Conversation
Reject URL fetch limit configuration until the pinned engine can enforce it, preventing callers from receiving a misleading success result. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
Verified at d85a4aa: the setter now fails before touching its arguments, the removed field was write-only on main (assigned at ffi.rs:551-556, never read), the new upstream_compatibility test fails against main's ffi.rs and passes with the fix, fmt/clippy clean, 68 tests pass, all checks green, commit signed off. The only in-repo ABI consumer never bound this symbol and acs_builder_from_url keeps its default budget, so nothing regresses.
One non-blocking follow-up: the comment at ffi.rs:250-252 still tells callers to tighten the budget with acs_builder_set_url_fetch_limits, which now always returns -1; worth rewording when the limits are actually threaded through after the upstream release.
…ft#4025) Reject URL fetch limit configuration until the pinned engine can enforce it, preventing callers from receiving a misleading success result. Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Summary
Make the C ABI reject URL fetch-limit configuration when the pinned
agent-control-specrelease cannot enforce it. This prevents hosts from treating a success result as an outbound-fetch security control.Problem
acs_builder_set_url_fetch_limitsstored values that no dispatcher consumed, while returning success. The limits-aware upstream API is merged but has not been published in an eligible release, so accepting the configuration would remain misleading.Closes #3942.
Changes
policy-engine/sdk/rust/src/ffi.rspolicy-engine/sdk/rust/tests/upstream_compatibility.rspolicy-engine/docs/acs-retarget.mdTesting
cargo fmt --all -- --checkcargo clippy --locked --workspace --all-targets -- -D warningscargo test --locked --workspacewith verified OPA v1.20.2 andAGENT_CONTROL_REQUIRE_OPA=1(120 passed, 0 failed)