fix: describe Trust Gate egress metadata as selected fields, not redacted - #130
Merged
Merged
Conversation
…cted The data-egress disclosure (doctor, MCP startup notice, and trust_gate_egress) described the transmitted metadata as 'selected redacted metadata'. That contradicts the actual behavior and the operator's correction: FAVA sends the full scope-resolved prompt, the full candidate body, and the complete selected metadata fields; agent_id and metadata.extra are excluded, not redacted. - Reword both llm-oneshot and decisions disclosures to 'selected metadata fields' and state that agent_id and metadata.extra are excluded and never sent - Align llm-oneshot data_sent lines with the decisions policy style - Correct _redact_metadata docstring (selection, not value redaction) - Update README-adjacent docs: AGENTS_SETUP_INSTRUCTIONS, FAQ, secret preflight, one-pager, codev integration README - Add regression coverage asserting no disclosure describes the transmitted metadata as 'redacted' for either policy and that the exclusions are stated explicitly - CHANGELOG entry under Unreleased/Fixed Diagnostic/docs repair confirmed during issue #125 installed-runtime acceptance on merged cefc7bd. Addresses #125.
timeleft--
approved these changes
Sep 29, 2026
timeleft--
left a comment
Member
There was a problem hiding this comment.
Captain review of exact head acac695: clean. The disclosure now accurately states that the full prompt, full candidate body, and complete selected metadata fields are transmitted, while agent_id and metadata.extra are excluded. Local exact-head validation: ruff passed; 108 affected trust-gate tests passed. The observed 0.45.1 CI failure occurred before tests because GitHub rate-limited the JJ release lookup (HTTP 403), not because of this patch.
This was referenced Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Repair of a confirmed diagnostic/docs defect found during issue #125 installed-runtime acceptance on merged
cefc7bd: the Trust Gate data-egress disclosure (doctor, MCP startup notice, andtrust_gate_egresson tool responses) described the transmitted metadata as "selected redacted metadata".That contradicts the actual behavior and the operator's explicit correction for #123/#125: FAVA sends the full scope-resolved Trust Gate prompt, the full candidate thought body, and the complete selected metadata fields;
agent_idandmetadata.extraare excluded — nothing sent is redacted.Changes
src/fava_trails/trust_gate.py: reword bothllm-oneshotanddecisionsdata_sent_summarytext to "selected metadata fields" and state thatagent_idandmetadata.extraare excluded and never sent; alignllm-oneshotdata_sentlines with the decisions policy style; correct the_redact_metadatadocstring (field selection, not value redaction).AGENTS_SETUP_INSTRUCTIONS.md,docs/fava_trails_faq.md,docs/secret-preflight.md,docs/fava_trails_onepager.html,src/fava_trails/integrations/codev/README.md.test_describe_metadata_disclosure_never_says_redacted_for_either_policy— no disclosure (either policy) may describe transmitted metadata as "redacted", and the exclusions must be stated explicitly.Verification
uv run pytest tests/test_trust_gate_egress.py tests/test_trust_gate.py tests/test_trust_gate_decisions.py— 108 passeduv run pytest(full suite) — 1095 passed; 5tests/test_jj_backend.pyfailures observed only in the full run and pass in isolation (pre-existing ordering flake, unrelated to this change)uv run ruff checkon all touched files — cleanAcceptance context (issue #125, supplied by Captain)
Installed-runtime acceptance on
cefc7bd(this wording defect confirmed there):Closes #125