Skip to content

feat(advisor): Core-owned external-state consent gate and decision artifact - #28

Closed
Epslion404 wants to merge 1 commit into
Scaxlibur:masterfrom
Epslion404:feat/advisor-consent-gate
Closed

Epslion404 wants to merge 1 commit into
Scaxlibur:masterfrom
Epslion404:feat/advisor-consent-gate

Conversation

@Epslion404

Copy link
Copy Markdown
Collaborator

本 PR 是 RFC #20(advisor 插件类别,Draft)的阶段 2 实现:把「数据外发同意门」与 decision artifact 收归 Core。RFC 仍在 Draft,因此本 PR 先以 Draft 形式提出。

内容

  • src/wavebench/services/advisor_consent.py:Core 侧同意门
    • 默认关闭;发送前必须产出完整预览(payload、字节数、sha256、逐条 untrusted span 与来源),预览不联网;
    • 同意绑定 endpoint 集合、允许字段集与 run id,任一变化即失效;
    • 非交互场景一律拒绝;拒绝原因可区分(未开启/未注册字段/未注册 endpoint/仅预览/未确认);
    • 模块内没有网络代码(有用 AST 做的导入审计测试)。
  • src/wavebench/services/decision_artifacts.py:wavebench.decision.v1
    • 写入对应 run 目录的 decisions/,附加式、独占创建;无 run 目录时不落盘,不触碰 run.json / summary.csv / steps/*;
    • 「概率 → 动作」的阈值策略由 Core 拥有(ThresholdPolicy),插件不得自带。
  • src/wavebench/config.py + wavebench.example.toml:追加式的 [advisor] 段(enabled 开启时必须同时给出 endpoint_hosts 与 allowed_state_fields 白名单;阈值需满足 0 <= review <= accept <= 1)。
  • docs/reference/configuration.md:新增「Advisor 外发边界」小节。

不在本 PR 范围

  • 插件类别抽象(AdvisorPlugin / EgressDeclaration / advisor registry / 内置 rule_advisor)、package_inspect 与 lifecycle 支持、advisor ask CLI、文档页与 RFC 索引登记——分别是 RFC 的阶段 1/3/4,会单独提出。
  • 不含任何外部服务客户端、不含 API key 处理(按既有约定 key 只走环境变量),也不含网络调用。

验证

  • python -m pytest -q tests/test_advisor_consent.py tests/test_advisor_config.py tests/test_decision_artifacts.py tests/test_config_overrides.py tests/test_access_policy.py → 74 passed, 30 subtests passed(全离线,无网络、无 API key、无第三方 SDK)
  • python -m ruff check . → All checks passed
  • python .agents/skills/wavebench-docs/scripts/audit_docs.py --quiet-warnings → 0 errors
  • python scripts/generate_docs.py --check → 生成 Reference 与源码同步

说明

分支从 upstream/master 拉出,只包含上述 Core 改动,便于单独评审;RFC 里 advisor.external_state 是否纳入 access policy(裁定 5b 暂不纳入)与 decision artifact 是否并入 run report(裁定 6a 暂不并入)都不在本 PR 改动范围内。

Adds services/advisor_consent.py (default-off gate, deterministic preview, consent scoped to endpoint set, field set and run id) and services/decision_artifacts.py (wavebench.decision.v1 writer with exclusive creation and no run directory means no artifact). Extends config with an append-only [advisor] section whose enable switch requires both allowlists, documents the egress boundary in the configuration reference, and covers the contract with 29 offline tests.
@Epslion404 Epslion404 closed this Sep 29, 2026
Epslion404 pushed a commit to Epslion404/wavebench that referenced this pull request Sep 29, 2026
PR Scaxlibur#27 and the focused advisor draft PR Scaxlibur#28 are closed: upstream-facing changes now start from upstream/master, while this fork keeps the competition package.
@Epslion404
Epslion404 deleted the feat/advisor-consent-gate branch September 29, 2026 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant