Skip to content

fix(core): record administrator provenance for template changes - #11

Merged
sam2tom merged 1 commit into
betafrom
codex/sandbox-deployment-audit
Oct 6, 2026
Merged

sam2tom merged 1 commit into
betafrom
codex/sandbox-deployment-audit

Conversation

@sam2tom

@sam2tom sam2tom commented Oct 6, 2026

Copy link
Copy Markdown

Template changes through PUT /core/v1/sandbox/deployment rolled back with HTTP 400 because the handler omitted administrator provenance required by the transactional audit record. Attach the shared authenticated audit source before invoking the execution owner, so same-team E2B template changes can commit with their audit entry.

Adds a route regression for valid deployment-wide provenance, optional actor labels, authentication rejection and secret-free responses; updates the owning contract, Chinese translation and beta ledger. No SQL, schema, Runtime protocol or native dependency changes. The combined Runtime template built from 298957f remains compatible.

Validation: focused route regressions, focused route race checks, API regressions and vet, documentation/name guards, translation freshness, independent review.

Full API race execution hit the existing TestUnknownMembersRejectWithLinearAllocation memory-allocation threshold; no race was reported. Normal API regression and focused mutation race checks are tracked separately.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@sam2tom
sam2tom merged commit f6125c9 into beta Oct 6, 2026
21 of 38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant