Repository navigation
Keep OTLP configuration out of AWF agent sandboxes - #67242
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
|
@copilot update compiler threat spec |
There was a problem hiding this comment.
🟡 Changes recommended
Evals sandboxes and legacy AWF pins can still receive OTLP credentials through --env-all.
1 open finding
What changed in this PR
This PR prevents OTLP collector credentials and endpoints from entering AWF agent and threat-detection sandboxes.
Changes:
- Adds OTLP variables to
--exclude-env. - Propagates exclusions to threat detection.
- Adds regression tests and regenerates affected workflows.
Review found unresolved gaps for evals sandboxes and AWF versions older than v0.25.3.
| File | Description |
|---|---|
pkg/workflow/awf_command_builder.go |
Adds OTLP exclusions to AWF commands. |
pkg/workflow/threat_detection_external.go |
Propagates exclusions to detection. |
pkg/workflow/awf_env_test.go |
Tests agent and detection arguments. |
pkg/workflow/threat_detection_isolation_test.go |
Tests compiled sandbox isolation. |
.github/workflows/workflow-normalizer.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/windows.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/update-astro.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/spec-enforcer.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-github-codex.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-gemini.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-codex-bare-auto.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-codex-auto.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-claude-copilot.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-claude-copilot-auto.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-claude-auto.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/smoke-agy.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/security-review.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/schema-feature-coverage.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/schema-consistency-checker.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/release.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/pdf-summary.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/notion-issue-summary.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/lint-monster.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/issue-arborist.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/gpclean.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/functional-pragmatist.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/firewall.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/feature-grower.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/example-permissions-warning.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/example-failure-category-filter.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-pydantic-ai.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-opencode.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-kiro.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-goose.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-gemini.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-deepseek-harness.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-cursor.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-crush.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-copilot.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-codex.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-claude.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-aider.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/engine-conformance-agy.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-token-consumption-report.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-team-evolution-insights.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-semgrep-scan.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-security-red-team.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-max-ai-credits-test.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-malicious-code-scan.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-harness-experiment-proposer.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-go-test-stubs-aider.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-documentation-diagram.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-code-debt-aider.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-cli-tools-tester.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-cache-strategy-analyzer.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-arxiv-researcher.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/daily-architecture-diagram.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/copilot-centralization-drilldown.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/codex-github-remote-mcp-test.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/chaos-pr-bundle-fuzzer.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/bot-detection.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/auto-triage-issues.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/artifacts-summary.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/agy-conformance-reusable.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/agentic-token-optimizer.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/ace-editor.lock.yml |
Regenerates affected AWF commands. |
.github/workflows/ab-testing-advisor.lock.yml |
Regenerates affected AWF commands. |
🧠 Review effort: Balanced
| if isOTLPEnabled(config.WorkflowData) { | ||
| for _, name := range otlpSandboxExcludedEnvVarNames { | ||
| if !slices.Contains(sortedExclude, name) { | ||
| sortedExclude = append(sortedExclude, name) | ||
| } | ||
| } | ||
| } |
There was a problem hiding this comment.
Fixed in 8e413e6: evals now carries the host OTLP exclusions into its minimal WorkflowData. Added Copilot/Claude/Codex enabled, disabled, and dry-run coverage plus compiled agent/detection/evals coverage; regenerated affected workflows, including artifacts-summary, and updated CTR-017. Regression tests and workflow drift checks passed. Thread resolution is unavailable through the exposed tools, so it remains open for manual resolution.
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Updated the compiler threat specification in 7bd4e0f: CTR-017 now documents OTLP sandbox exclusions, host-side retention, AWF compatibility, and regression coverage. Bumped the spec to 1.0.45 and updated its changelog. Conformance tests and the repository validation gate passed. |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 7bd4e0f
|
…rter-otlp-headers Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Merged latest main with |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: 8e413e6
|
…rter-otlp-headers Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Merged latest main with |
|
@copilot address the following outstanding work in one pass:
Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI. Sous-chef head: aa83bea
|
|
@copilot resolve the merge conflicts on this branch. |
…rter-otlp-headers # Conflicts: # specs/compiler-threat-detection-changelog.md # specs/compiler-threat-detection-spec.md Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

With OTLP configured,
awf --env-allpassed collector headers and endpoints into the agent and threat-detection sandboxes. This exposed collector credentials and could cause the Copilot CLI to export duplicate telemetry.OTEL_EXPORTER_OTLP_ENDPOINT,OTEL_EXPORTER_OTLP_HEADERS, andGH_AW_OTLP_ENDPOINTSfrom both AWF invocations when OTLP is enabled. The values remain available to host-side exporters.