Skip to content

fix: reject mismatched AI provider fallbacks (F5) - #594

Merged
Pigbibi merged 1 commit into
mainfrom
fix/audit-f5-provider-identity-20260908
Sep 7, 2026
Merged

fix: reject mismatched AI provider fallbacks (F5)#594
Pigbibi merged 1 commit into
mainfrom
fix/audit-f5-provider-identity-20260908

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Report review unavailable without ai_gateway_client rather than submit independent-review tasks to Codex execution.
  • Reject non-Codex providers and non-execute tasks before authentication or HTTP in local fallback.
  • Preserve legitimate Codex execute/verify in review_only mode, using endpoint identity instead of arbitrary caller labels.

Validation

  • Offline tests-first: 13 failures on original source, then 47 passed and 95 subtests passed across provider, reviewer, Codex integration, CLI and candidate notification regressions.
  • Targeted ruff and git diff --check passed. Normal SDK analyze provider identity and local Codex execute/verify remain covered.
  • No provider calls, paid AI, credentials, deployment, public schema or dependency changes.

Adoption boundary

Only the provider module and its existing tests change. QPK_PIN remains unchanged. External strategy pins and their independent drift review workflow are not upgraded by this change; source fix is not production adoption evidence.

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit 20734f4 into main Sep 7, 2026
1 check passed
@Pigbibi
Pigbibi deleted the fix/audit-f5-provider-identity-20260908 branch September 7, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant