Skip to content

fix(presentation): redact Windows local paths - #5754

Open
mikamikasuki wants to merge 4 commits into
loopx-project:mainfrom
mikamikasuki:codex/loopx-presentation-path-safety
Open

mikamikasuki wants to merge 4 commits into
loopx-project:mainfrom
mikamikasuki:codex/loopx-presentation-path-safety

Conversation

@mikamikasuki

@mikamikasuki mikamikasuki commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

  • Outcome basis / optional anchor: Existing maintainer direction in [Architecture]: two modules both claim to own "private-looking text" #5136, direction 3 (local paths).
  • Goal/source and gap: Presentation public-safety helpers left Windows drive paths, ordinary UNC paths, extended UNC paths, volume-GUID paths, and GLOBALROOT device paths unchanged and accepted them at the public boundary.
  • Observable before → after: On tested main, these Windows local and device path forms were returned verbatim and the scanner reported ok: true; after the patch they are replaced with a generic local-path marker and the scanner reports an absolute-local-path warning.
  • Issue/task and intended base: Related to #5136; base main at 73f429a.

Author Declaration

  • Written by: model_agent — OpenAI Codex (GPT-6 Luna, OpenAI)

Implemented against

Criterion Disposition Symbol / path Test or command
Public output rejects or redacts local paths while keeping one shared text-classification owner implemented loopx/public_safe_text.py, loopx/presentation/public_safety.py tests/control_plane/test_presentation_public_safety.py
Preserve the existing colon-prefixed Unix path behavior implemented PRESENTATION_LOCAL_PATH_PATTERNS test_colon_prefixed_unix_paths_keep_the_existing_boundary
  • Self-check before submission: Reproduced the extended UNC, volume-GUID, and GLOBALROOT device-path gaps on a clean main worktree, reviewed the final diff, and checked safe non-path cases including ordinary URLs, times, ratios, and relative paths. No UI or TypeScript changes.

Scope And Continuation

  • Completed scope and remaining work: Fixes the presentation public-safety path gap for Windows drive, UNC, extended UNC, volume-GUID, and GLOBALROOT device-path inputs; centralizes the path and boundary pattern definitions.
  • Slice boundary / successor: This is one path-classification slice of [Architecture]: two modules both claim to own "private-looking text" #5136; the broader issue remains open for its other acceptance items.

Validation

  • Tested revision: ccc055f
  • Run state: finished
  • Input classes: synthetic
Check kind Result Public-safe evidence / limitation
regression_parity passed At baseline 73f429a, plain and path-prefixed extended UNC, volume-GUID, and GLOBALROOT device paths were unchanged and accepted; the GLOBALROOT regression cases fail at baseline and pass at head.
unit passed 110 focused tests passed across presentation and shared local-path classifiers; drive, UNC, extended UNC, volume-GUID, and GLOBALROOT device paths with and without a path: prefix are rejected, while URL/time/ratio/relative text remains accepted.
static passed Ruff and Mypy passed for the changed source; Python compile checks passed.
static passed Standard premerge canary: 2 selected, 2 passed, 0 failures or warnings.
static passed loopx check found 0 boundary errors across the three changed files; it reported 2 warnings because the optional local registry is absent.
  • Coverage and gaps: Tests exercise Windows path strings with synthetic input on macOS; no native Windows host run was performed. The redaction/scanner contract, shared pattern ownership, colon-prefixed Windows forms, extended path namespaces including GLOBALROOT device paths, and safe non-path cases are covered directly.

Frontend / Visual Evidence

  • UI impact: none
  • Before: N/A
  • After: N/A
  • States and viewports shown: N/A
  • Source data: none
  • Attention review: N/A; no UI changes.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

Shared-authority RFC fixture impact

  • Production-scale fixture schema: N/A
  • Semantic dimensions changed, or reviewed no-impact rationale: N/A; Python presentation boundary only.
  • Provider conformance arms run: N/A
  • Read-only legacy/file/PostgreSQL three-arm rehearsal: N/A

Boundary Checklist

  • The diff and PR text contain no private state, credentials, internal links, or local machine paths.
  • This change does not duplicate maintainer-owned benchmark work.
  • The change is scoped to the linked issue slice.
  • UI impact is marked none.
  • Every commit includes a DCO Signed-off-by trailer.

@mikamikasuki
mikamikasuki force-pushed the codex/loopx-presentation-path-safety branch from ccc055f to 74ef2cd Compare October 6, 2026 09:43
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
@mikamikasuki
mikamikasuki force-pushed the codex/loopx-presentation-path-safety branch from 74ef2cd to 7d933f3 Compare October 6, 2026 09:51

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant