Skip to content

Forward-merge release/0.8 into main - #936

Merged
GPUtester merged 1 commit into
mainfrom
release/0.8
Aug 28, 2026
Merged

Forward-merge release/0.8 into main#936
GPUtester merged 1 commit into
mainfrom
release/0.8

Conversation

@rapids-bot

@rapids-bot rapids-bot Bot commented Aug 28, 2026

Copy link
Copy Markdown

Forward-merge triggered by push to release/0.8 that creates a PR to keep main up-to-date. If this PR is unable to be immediately merged due to conflicts, it will remain open for the team to manually merge. See forward-merger docs for more info.

#### Overview

Implements API-, ABI-, configuration-, and data-compatible hardening for the gateway, permission, dynamic-plugin, observability, and adaptive-cache threat-model findings.

- [x] I confirm this contribution is my own work, or I have the right to submit it under this project license.
- [x] I searched existing issues and open pull requests, and this does not duplicate existing work.

#### Details

- Add hidden authentication for managed, transparent, and generated hook clients; bind sessions to authenticated client identities; strip internal credentials before events and forwarding; and reject unsafe explicit-daemon exposure.
- Route final permission requests through the existing tool conditional-execution chain and bind decisions to the exact active tool call, name, and arguments. Claude Code permission requests intentionally omit the call identifier, so Relay resolves it only when exactly one active pre-tool record matches and denies ambiguous or changed requests.
- Preserve Claude Code host permission semantics: `PreToolUse` no longer pre-authorizes the action, and Relay returns Claude's event-specific permission decision shape only after final evaluation.
- Preserve user settings while ensuring the transparent Relay gateway overlay has final precedence for the launched Claude process.
- Require signed, trusted dynamic plugins at runtime startup by default while preserving existing manifest schemas, lifecycle management APIs, and conditional-middleware fail-open semantics.
- Minimize inherited worker-process environment variables.
- Confine ATOF and ATIF output beneath configured destinations, reject traversal and symlink targets, and use private files, private directories, and atomic ATIF replacement.
- Document cache namespace tenancy and add partitioning coverage for namespaces, providers, and allowlisted tenant headers.
- Preserve all Rust, Python, Node.js, Go, C, hook, provider, event, cache, ATOF, and ATIF interfaces and schemas. There are no breaking API or ABI changes.

Validation:

- `RELAY_E2E_TRANSPARENT_ONLY=1 just test-codex-plugin-e2e` — real Codex CLI tool-call round trip, second provider turn, lifecycle hooks, and balanced ATOF tool scope
- `RELAY_E2E_TRANSPARENT_ONLY=1 just test-claude-plugin-e2e` — real interactive Claude Code `PreToolUse` → `PermissionRequest` allow → tool execution → `PostToolUse` round trip and balanced ATOF tool scope
- `just test-rust` — 4,407 workspace tests plus native-plugin, worker-plugin, and language-binding example suites
- `just test-python`
- `just test-node`
- `just test-go`
- `cargo clippy --workspace --all-targets -- -D warnings`
- `just docs`
- `uv run pre-commit run --all-files`
- Targeted changed-file pre-commit validation after the E2E follow-up

#### Where should the reviewer start?

Start with `crates/cli/src/server/mod.rs` for the hidden ingress-authentication boundary and Claude permission response, `crates/cli/src/sessions/mod.rs` for session ownership and exact permission binding, and `crates/core/src/observability/private_file.rs` for trace-path confinement and private writes. The live client scenarios are in `scripts/test-codex-plugin-e2e.sh` and `scripts/test-claude-plugin-e2e.sh`. The dynamic-plugin compatibility boundary is in `crates/cli/src/plugins/policy.rs` and `crates/cli/src/plugins/lifecycle/mod.rs`.

#### Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)

- Relates to: none


## Summary by CodeRabbit

* **Security**
  * Strengthened gateway and hook authentication with client ownership checks, browser-origin blocking, and secure client tokens.
  * Restricted gateway binding and dynamic-plugin runtime environments with secure defaults.
  * Protected local observability files with private permissions, safe paths, symlink rejection, and atomic writes.

* **New Features**
  * Added validated permission-request handling and session-scoped authorization for Claude and Codex.
  * Improved Claude plugin argument handling and transparent tool-use workflows.

* **Documentation**
  * Clarified response-cache tenant configuration and dynamic-plugin runtime behavior.

Authors:
  - Will Killian (https://github.com/willkill07)
  - Maryam Najafian (https://github.com/mnajafian-nv)

Approvers:
  - Maryam Najafian (https://github.com/mnajafian-nv)

URL: #934
@rapids-bot
rapids-bot Bot requested a review from a team as a code owner August 28, 2026 02:57
@GPUtester
GPUtester merged commit ea471f0 into main Aug 28, 2026
2 checks passed
@rapids-bot

rapids-bot Bot commented Aug 28, 2026

Copy link
Copy Markdown
Author

SUCCESS - forward-merge complete.

@github-actions github-actions Bot added size:XL PR is extra large lang:python PR changes/introduces Python code lang:rust PR changes/introduces Rust code labels Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lang:python PR changes/introduces Python code lang:rust PR changes/introduces Rust code size:XL PR is extra large

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants