Uh oh!
There was an error while loading. Please reload this page.
feat(providers): make profiles authoritative - #2962
Conversation
🌿 Preview your docs:https://nvidia-preview-pr-2962.docs.buildwithfern.com/openshell |
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
This comment was marked as outdated.
This comment was marked as outdated.
Sorry, something went wrong.
Uh oh!
There was an error while loading. Please reload this page.
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
Maintainer Convergence Decision
The maintainer-requested corrective initial review independently covered the complete six-commit, 58-file merge-base-to-head patch. It validates eight existing obligations—two Critical credential-boundary regressions and six concrete upgrade, mutation, catalog, documentation, and TUI correctness regressions—and finds no additional blocker. Existing Gator threads remain the canonical detailed findings.
Action required: a verified maintainer must confirm which of these eight concrete obligations remain required and explicitly waive any that are acceptable as implemented. The author can then address the required set in one convergence round.
Root-cause findings:
GATOR-dc5184a4-03(Critical): profile adoption can grant endpoint-bound substitution authority to stored credentials the profile did not declare.GATOR-dc5184a4-05(Critical): alternate-upstream credentials can receive substitution authority at unrelated fixed public-vendor endpoints.GATOR-e438dcf8-02(Warning): unconditional profile-policy composition can activate incompatible persisted sandbox policy without an upgrade preflight.GATOR-dc5184a4-01(Warning): provider updates bypass authoritative profile credential rules enforced during creation.GATOR-dc5184a4-02(Warning): new built-in IDs can invalidate previously valid imported profiles with the same IDs.GATOR-dc5184a4-04(Warning): the authoritative TUI picker retrieves only the first page of the profile catalog.GATOR-dc5184a4-06(Warning): canonical provider documentation and agent references advertise creation contracts rejected by authoritative profile lookup.GATOR-dc5184a4-07(Warning): TUI Vertex autodetection drops supported provider configuration.
Scope growth:
- None identified by the complete review.
Reviewer-quality signals:
- The normalized replacement proposed eight carried blockers, zero new findings, zero resolved/waived re-raises, zero semantic duplicates, zero unchanged-code proposals, and zero evidence downgrades.
Maintainer action: review the eight canonical finding threads, explicitly confirm the required set, and waive any finding that is acceptable as implemented. No E2E dispatch or pipeline handoff occurs until this concrete convergence decision and resulting author obligations are resolved.
Gator metadata
- Validation: project-valid implementation of linked issue #1988; the PR author is a verified repository administrator
- Docs: broadly updated;
GATOR-dc5184a4-06tracks the remaining authoritative-reference mismatch - Checks: current-head
OpenShell / Branch Checksfails in Go SDK;OpenShell / Helm Lint, DCO, and docs preview are green - E2E:
test:e2eis required for provider credential flow, policy composition, gateway/supervisor interaction, and sandbox lifecycle; dispatch remains deferred while blocking review obligations are unresolved or unwaived - Head SHA:
dc5184a4574fb76115e8c32982a0c02a1ddd8b57 - Base SHA:
572843baf8a68263dda80a46441d1697e201ba74 - Merge base SHA:
c3993426498d5b602ec080bc1d3cbad5e8460f4a - Patch ID:
7e5b2eef9a0bd663685a2933149fcb0b3196ff60 - Gator payload:
7 - Review mode:
initial(maintainer-authorized complete full-PR same-SHA replacement) - Previous reviewed SHA:
dc5184a4574fb76115e8c32982a0c02a1ddd8b57(prior scope explicitly invalidated for this rerun) - Review budget exhausted: yes; the maintainer explicitly authorized this corrective full review
- Maintainer decision required: yes — eight independently validated obligations remain unresolved and unwaived
- Review telemetry: 3 finding-bearing rounds, 12 unique historical findings, 184 duplicate finding-ID occurrences, and current patch matches the last review; normalized replacement proposed 8 carried blockers with no duplicates, waived/resolved re-raises, unchanged-code proposals, or evidence downgrades
- Next state:
gator:blocked - Blocked reason:
review_convergence_decision_required
Closes#1988 Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
dc5184a to
74810bfCompareSigned-off-by: John Myers <johntmyers@users.noreply.github.com>
Label |
johntmyers
commented
Aug 27, 2026
/ok to test dbadf1d |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Thanks @johntmyers. I verified your dbadf1d4 remediation against the eight durable Gator obligations and reviewed only the author delta in the ledger-required critical-only mode. The startup preflight, create/update credential symmetry, catalog collision handling, secret endpoint boundaries, TUI pagination and Vertex discovery, and provider references now address the prior findings; no new Critical was found.
Action required: a maintainer must open current-head Branch E2E Checks run 33091164015 and choose Re-run all jobs, or the sandbox provider policy must be updated to permit that exact REST rerun. The test:e2e label and /ok to test dbadf1d491723063746fee8361243c48c42da238 are already present, but GitHub has not queued the required E2E attempt.
Blocking findings:
- No code-review blockers remain
Carried findings:
- None;
GATOR-e438dcf8-02andGATOR-dc5184a4-01throughGATOR-dc5184a4-07are resolved by the current delta
Gator metadata
- Validation: project-valid maintainer-authored implementation of review-ready issue #1988
- Docs: Fern provider docs, navigation, and related CLI/agent references cover the direct UX changes
- Checks: current-head Branch Checks, Helm Lint, DCO, docs preview, and published required gate statuses are green; CodeQL remains in progress
- E2E:
test:e2eapplied and current-head/ok to testposted; E2E Label Help requires rerunning run33091164015, but sandbox policy denied the REST rerun and rejected the exact policy proposal due overlap with the reserved provider rule - Head SHA:
dbadf1d491723063746fee8361243c48c42da238 - Base SHA:
37072ee81cd7b294c714bfa5ecc829b6927b3d70 - Merge base SHA:
37072ee81cd7b294c714bfa5ecc829b6927b3d70 - Patch ID:
ba60aed2c0d3e50abc89fe1981631f80014aa65e - Gator payload:
7 - Review mode:
critical_only - Previous reviewed SHA:
dc5184a4574fb76115e8c32982a0c02a1ddd8b57 - Review budget exhausted: yes
- Maintainer decision required: no; all durable review obligations are resolved
- Next state:
gator:blocked - Blocked reason:
test_dispatch_required
Summary
Make provider profiles authoritative for new provider creation and discovery, removing the Providers v2 compatibility switch and legacy public provider workflows.
Related Issue
Closes#1988
Changes
providers_v2_enabledand always composes attached profile policy for sandbox-scoped policiesopenaiandanthropicprofiles and retires publicgeneric,gitlab,opencode, andoutlookselection/discoveryTesting
mise run cimise run testmise run e2e:rustmise run e2e:python(89 passed, 84 skipped)mise run docs:build:strictcargo test --manifest-path e2e/rust/Cargo.toml --all-features --no-runcargo test --manifest-path examples/governance-interceptor/Cargo.tomlChecklist