Skip to content

Fix Fable Advisor authentication and structured decisions - #30

Merged
Cjbuilds merged 2 commits into
mainfrom
codex/fix-fable-auth-structured
Jul 26, 2026
Merged

Cjbuilds merged 2 commits into
mainfrom
codex/fix-fable-auth-structured

Conversation

@Cjbuilds

@Cjbuilds Cjbuilds commented Jul 26, 2026 •

Copy link
Copy Markdown
Owner

Change summary

Fixes the Fable Advisor bootstrap failure on current Claude Code while keeping every trust boundary fail-closed.

  • accepts only exact first-party Pro, Max, or Team authentication tuples via auth status --json;
  • restores canonical POSIX USER and LOGNAME without trusting ambient identity or credential/provider overrides;
  • accepts the two reviewed Fable primary runtime identities plus only the exact reviewed Haiku helper, while keeping the separate Opus route strict;
  • requires schema-backed Advisor decisions, locally revalidates them, normalizes one unambiguous result object/event, and rejects raw prose, conflicts, error results, and unknown runtime identities;
  • keeps the POSIX identity regression portable by constructing its fake path before the test mocks global os.name;
  • bumps the plugin payload to 0.9.1.

Closes #18.

Validation

  • python3 scripts/preflight.py full — all available local gates passed, including full tests and disposable 0.9.0 → 0.9.1 lifecycle upgrade; hosted-only checks remained skipped locally.
  • python3 scripts/preflight.py portability --ci — every requested local portability gate passed after the Windows test-fixture repair.
  • Focused integration suite — 171 tests passed; the full Advisor module and exact Windows-sensitive regression also passed after the repair.
  • Independent exact-tree verification — passed all acceptance criteria and re-verified the Windows root cause and minimal repair.
  • python3 scripts/release_check.py --repo-root . --base-sha 109edaf20acfc2e67c5e20b2d6a623efd1d6fc55 --head-sha cb035c311cb9726102130bd7469794c88d38a07d --require-exact-shas — valid 0.9.1.
  • One bounded live Fable Advisor smoke through this bridge succeeded at high, reported only claude-fable-5, and returned a valid non-empty structured decision envelope. Review text and account metadata were not printed.

Review attestation

{
"schema": 1,
"risk_tier": "security-state",
"repository": "Cjbuilds/Codex-Orchestration",
"base_branch": "main",
"reviewed_head_sha": "cb035c311cb9726102130bd7469794c88d38a07d",
"reviewer_identity": "Codex independent verification worker",
"reviewer_route": "verification_worker / gpt-5.6-sol high",
"threat_model": {
"assets": [
"First-party Claude authentication state and account-metadata confidentiality",
"Configured Planner and Advisor route identity, effort, and runtime-model integrity",
"Model-authored plan and review content plus plugin release and cross-platform test integrity"
],
"threats": [
"Malformed or spoofed authentication metadata could authorize an invalid subscription tuple",
"Ambient environment overrides could redirect credentials, providers, endpoints, proxies, or telemetry",
"Runtime alias or helper confusion could execute an unreviewed model identity",
"Ambiguous, conflicting, raw-prose, or error output could be mistaken for Advisor approval",
"Platform-sensitive test setup could hide a real pre-subprocess security regression on Windows"
],
"mitigations": [
"Exact first-party Pro, Max, or Team tuple checks use JSON mode and return no subscription metadata",
"Minimal platform environment restores canonical POSIX identity while excluding override families",
"Route-specific primary intersection and exact helper allowlists fail closed for unknown identities",
"One exact JSON schema plus local validation rejects malformed, conflicting, and error results",
"The fake executable is constructed before mocking global os.name, preserving the intended cross-platform pre-subprocess assertion"
]
},
"negative_test_evidence": [
{
"category": "regression",
"evidence": "At the reviewed SHA, the required suite passed 99 tests, the full Advisor module passed 24 tests, local portability --ci passed every requested gate, and full preflight plus lifecycle passed."
},
{
"category": "negative",
"evidence": "Tests reject invalid auth tuples, helper-only and unknown runtime identities, raw prose, schema conflicts, secret-bearing failures, unauthorized route drift, and identity lookup failure before subprocess launch."
},
{
"category": "malformed",
"evidence": "Tests reject unhashable subscription containers, malformed modelUsage values, malformed JSON, empty or duplicate result events, error subtypes, and missing, extra, wrong, or blank review fields."
}
],
"findings_disposition": "All material findings resolved. The Windows failure was isolated to Path construction after a global os.name mock; commit cb035c3 moves only test fixture construction before the mock, preserves production behavior, and passes exact portability and security regressions. No findings remain open."
}

@Cjbuilds
Cjbuilds merged commit 61b84db into main Jul 26, 2026
9 checks passed
@Cjbuilds
Cjbuilds deleted the codex/fix-fable-auth-structured branch July 26, 2026 01:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Fable bridge rejects Claude Team auth and current runtime metadata in 0.7.1

1 participant