Repository navigation
BUZZ-272: Check webhook owner bans - #8242
Draft
bradseiler wants to merge 6 commits into
Draft
bradseiler wants to merge 6 commits into
bradseiler wants to merge 6 commits into
Conversation
Signed-off-by: seiler <seiler@squareup.com> Co-authored-by: Codex <noreply@openai.com> (cherry picked from commit 6ecd74515c01c407f817f7c25597337fcffa688a) Signed-off-by: Brad Seiler <seiler@squareup.com>
Complete the preserved 66663e19 remediation with a deterministic production-consumer regression, cancellation-safety documentation, and deadline diagnostics. Original recovered refs and their attribution remain unchanged. Co-authored-by: Codex <codex@openai.com> Signed-off-by: Brad Seiler <seiler@squareup.com> (cherry picked from commit f1674a2) Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Codex <codex@openai.com> Signed-off-by: Brad Seiler <seiler@squareup.com> (cherry picked from commit 3d02a44) Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Codex <codex@openai.com> Signed-off-by: Brad Seiler <seiler@squareup.com> (cherry picked from commit d43b957) Signed-off-by: Brad Seiler <seiler@squareup.com>
Co-authored-by: Codex <codex@openai.com> Signed-off-by: Brad Seiler <seiler@squareup.com>
Avoid comparing host and PostgreSQL clocks in the async enqueue guard regression. Assert strict lease ordering before releasing activation. Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Brad Seiler <seiler@squareup.com> (cherry picked from commit 893f81f) Signed-off-by: Brad Seiler <seiler@squareup.com>
This was referenced Oct 10, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Reject a workflow webhook when its saved owner is banned in the host-resolved community. Query authoritative restrictions immediately before creating a run; return the same generic 404 on a ban or lookup failure, with no queued run. Keep secret and channel-role checks in place, and restore admission after unban.
This is a point-in-time admission check. A ban committed after the lookup can race with run creation; existing runs and cron/event triggers keep their current behavior. Community timeouts do not block webhook admission in this change.
This draft includes the shared mesh receive fix needed for independent validation.
Related issue
BUZZ-272. Companion invitation replacement: #8237. Staging verification runbook: #8235. Regression coverage: #8239. Live-session revalidation: #8241.
Testing
Validated
d1c9dd341c3f8468ca976a99393ad1a7a0abefc6: full DB/relay packages and doctests passed; the complete discovered PostgreSQL suite passed 938/938; a freshly built relay passed the separate live rehearsal.Full repository
just ciandjust testpassed on that same head.Ordinary repository lanes retain configured infrastructure skips; the separate PostgreSQL suite uses isolated services. Existing ACP pipe-test leak warnings were reported with passing exit status.
The PostgreSQL regression checks wrong-secret denial, allowed admission, banned-owner denial without a run, another tenant's allowed control, unban, forbidden member roles, and failed restriction lookup. The separate-relay HTTP rehearsal verifies run counts at each denial/admission transition.
Independent agent review found no remaining blockers. Draft only: human testing and staging evidence remain outstanding.
Generated with Codex.