Repository navigation
sdkharness: repository-owned leaf checks refuse to run outside a loopback simulator - #620
Merged
Merged
Conversation
The 33 conformance and 16 resilience leaf checks are executable on their own. Conformance leaves defaulted CONFORMANCE_TARGET to staging, mapped staging and production realms, and fell back to ambient B2_APPLICATION_KEY_ID/KEY, so a direct run could mutate an external account. Each leaf now calls a shared guard first: only the simulator target, only http://127.0.0.1:<port> (and https for the TLS URL, and the loopback control URL for resilience), and only the fixed test credential. client.simulator no longer carries unused realm/ambient credential helpers. Adds unit tests (54 fail on the previous leaves) and a README section for running one check locally.
sophiecarreras
requested review from
mpnowacki-reef and
ppolewicz
and removed request for
mpnowacki-reef and
ppolewicz
October 1, 2026 04:22
…nd IPv4 loopback; readiness wait in README Review follow-up for the PR: the health golden path read any non-empty B2_TEST_APPLICATION_KEY_* pair and passed it to the SDK; a real key could be disclosed to a loopback listener. It now refuses anything but the fixed simulator pair before the SDK is touched, accepts only 127.0.0.1 (like the other leaves), and the README waits for the simulator to be ready. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Contributor
Author
|
Follow-up commit e678272 for the independent review of this PR:
Not run here: the full nox matrix. CI on this PR shows the known unrelated live-encryption failures (#614) — I have not diagnosed them. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
An independent review of the repository-owned sdkharness tests (merged in #611 and #613) found that the 33 conformance leaf checks, which are executable directly, default
CONFORMANCE_TARGETtostaging, mapstaging/productionrealms, and fall back to ambientB2_APPLICATION_KEY_ID/B2_APPLICATION_KEY. The dispatchers (run-conformance,run-resilience) were safe, but a developer running a leaf by hand with real credentials in the environment could create, mutate or delete resources in an external account. This contradicts.sdkharness/README.md("never use a production B2 endpoint or real credentials").What
.sdkharness/tests/lib/loopback_guard.py:refusal(level)returns a reason unless the target issimulator,<LEVEL>_SIMULATOR_URLishttp://127.0.0.1:<port>, an optional<LEVEL>_SIMULATOR_HTTPS_URLishttps://127.0.0.1:<port>, and (resilience)RESILIENCE_CONTROL_URLis a loopback origin.FAIL (configuration -- ...)line with exit 1. Default target is nowsimulator; the staging/production realm entries and the ambient-credential fallbacks are removed (the fixedtest-key-id/test-keycredential is the only one).client.simulatorloses unused realm and ambient-credential helpers (it only drives the in-processRawSimulatorwith the network disabled).Verification
test/unit/test_sdkharness_conformance_resilience_contract.pyandtest_sdkharness_contract.py); the new tests (54 failing cases) fail on the previous leaves and pass now.files.upload,bucket.crud,enc.sse_c,client.simulatorPASS;api.backoff_503PASS;upload.retry_408FAIL as before (the known Retry-After/408 SDK findings). A direct leaf run withCONFORMANCE_TARGET=stagingand ambient keys exits 1 withFAIL (configuration ...).ruff checkandruff format --checkclean on.sdkharnessand the test file. Not run locally: the full nox matrix and integration suite (read from CI).+sdkharness-loopback-guard.infrastructure.md(no related issue; the contributing guide's convention for PRs without an issue).Review requested from the maintainers who merged recently. Nothing here changes SDK code.
🤖 Generated with Claude Code