Skip to content

fix: describe Trust Gate egress metadata as selected fields, not redacted - #130

Merged
timeleft-- merged 1 commit into
mainfrom
automation/fava-trails-125
Sep 29, 2026
Merged

timeleft-- merged 1 commit into
mainfrom
automation/fava-trails-125

Conversation

@yia-mw-agent

Copy link
Copy Markdown
Contributor

What

Repair of a confirmed diagnostic/docs defect found during issue #125 installed-runtime acceptance on merged cefc7bd: the Trust Gate data-egress disclosure (doctor, MCP startup notice, and trust_gate_egress on tool responses) described the transmitted metadata as "selected redacted metadata".

That contradicts the actual behavior and the operator's explicit correction for #123/#125: FAVA sends the full scope-resolved Trust Gate prompt, the full candidate thought body, and the complete selected metadata fields; agent_id and metadata.extra are excluded — nothing sent is redacted.

Changes

  • src/fava_trails/trust_gate.py: reword both llm-oneshot and decisions data_sent_summary text to "selected metadata fields" and state that agent_id and metadata.extra are excluded and never sent; align llm-oneshot data_sent lines with the decisions policy style; correct the _redact_metadata docstring (field selection, not value redaction).
  • Docs aligned: AGENTS_SETUP_INSTRUCTIONS.md, docs/fava_trails_faq.md, docs/secret-preflight.md, docs/fava_trails_onepager.html, src/fava_trails/integrations/codev/README.md.
  • Regression coverage: updated existing disclosure assertions and added test_describe_metadata_disclosure_never_says_redacted_for_either_policy — no disclosure (either policy) may describe transmitted metadata as "redacted", and the exclusions must be stated explicitly.
  • CHANGELOG entry under Unreleased / Fixed.

Verification

  • uv run pytest tests/test_trust_gate_egress.py tests/test_trust_gate.py tests/test_trust_gate_decisions.py — 108 passed
  • uv run pytest (full suite) — 1095 passed; 5 tests/test_jj_backend.py failures observed only in the full run and pass in isolation (pre-existing ordering flake, unrelated to this change)
  • uv run ruff check on all touched files — clean

Acceptance context (issue #125, supplied by Captain)

Installed-runtime acceptance on cefc7bd (this wording defect confirmed there):

  • Jev approved a quality memory at Noul probability 0.90 with threshold 0.5
  • Jev rejected a vague memory at probability 0.04
  • Server restart preserved the approved record and Decisions provenance
  • Invalid credential produced a sanitized HTTP 401 fail-closed result with no governed promotion; restored credential returned a valid probability

Closes #125

…cted

The data-egress disclosure (doctor, MCP startup notice, and
trust_gate_egress) described the transmitted metadata as 'selected
redacted metadata'. That contradicts the actual behavior and the
operator's correction: FAVA sends the full scope-resolved prompt, the
full candidate body, and the complete selected metadata fields;
agent_id and metadata.extra are excluded, not redacted.

- Reword both llm-oneshot and decisions disclosures to 'selected
  metadata fields' and state that agent_id and metadata.extra are
  excluded and never sent
- Align llm-oneshot data_sent lines with the decisions policy style
- Correct _redact_metadata docstring (selection, not value redaction)
- Update README-adjacent docs: AGENTS_SETUP_INSTRUCTIONS, FAQ, secret
  preflight, one-pager, codev integration README
- Add regression coverage asserting no disclosure describes the
  transmitted metadata as 'redacted' for either policy and that the
  exclusions are stated explicitly
- CHANGELOG entry under Unreleased/Fixed

Diagnostic/docs repair confirmed during issue #125 installed-runtime
acceptance on merged cefc7bd. Addresses #125.

@timeleft-- timeleft-- left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Captain review of exact head acac695: clean. The disclosure now accurately states that the full prompt, full candidate body, and complete selected metadata fields are transmitted, while agent_id and metadata.extra are excluded. Local exact-head validation: ruff passed; 108 affected trust-gate tests passed. The observed 0.45.1 CI failure occurred before tests because GitHub rate-limited the JJ release lookup (HTTP 403), not because of this patch.

@timeleft--
timeleft-- merged commit f4f7e27 into main Sep 29, 2026
12 of 14 checks passed
@timeleft--
timeleft-- deleted the automation/fava-trails-125 branch September 29, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

test: verify installed Decisions end to end before calibration

2 participants