Skip to content

Isolate console LLM credentials - #559

Merged
mkultraWasHere merged 4 commits into
mainfrom
codex/isolate-ambient-llm-credentials
Sep 30, 2026
Merged

mkultraWasHere merged 4 commits into
mainfrom
codex/isolate-ambient-llm-credentials

Conversation

@mkultraWasHere

@mkultraWasHere mkultraWasHere commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Changed

  • Console security documentation now defines the credential boundary for launcher and backend subprocesses.
  • dreadgoad-console explicitly registers OpenRouter, Anthropic, OpenAI, and any custom selected LLM credential.

Fixed

  • Registered LLM credentials no longer reach dependency, frontend, CLI, cloud, Terraform, or Ansible processes.
  • Only the selected provider credential is restored to the LLM backend; deployment credentials remain available to child processes.
  • dreadgoad-console no longer invokes external tools before normal-launch credential isolation.

Prevent ambient OpenRouter and selected provider credentials from reaching
build, dependency, deployment, or other non-LLM subprocesses.

Co-Authored-By: Codex <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Credential-boundary changes are security-sensitive and warrant final human validation.

Review effort: Balanced
Findings: None

What changed in this PR

Isolates LLM credentials across launcher, build, frontend, and backend subprocess boundaries.

Changes:

  • Scrubs default and selected provider credentials before external tooling runs.
  • Restores credentials only for the backend and removes them from backend children.
  • Adds documentation and credential-isolation tests.
File Description
dreadgoad-console Implements early credential isolation and backend-only restoration.
console/​SECURITY.md Documents credential boundaries.
console/​README.md Updates launcher security guidance.
console/​backend/​subprocess_env.py Tracks and scrubs multiple credential names.
console/​backend/​tests/​test_subprocess_env.py Tests launcher and backend isolation behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Scrub known ambient provider keys before external tools run while restoring
only the selected provider credential to the LLM backend.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The no-external-tools regression test does not actually detect handled or redirected external command attempts.

Review effort: Balanced
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Medium severity Strengthen no-external-tools test with marker-writing command stubs

console/​backend/​tests/​test_subprocess_env.py:156

This assertion does not verify the stated no-external-tools guarantee. With PATH empty, a command whose failure is redirected or handled can still be attempted and the launcher can still print USAGE; for example, the removed python3 ... 2>/dev/null || printf ... path would pass this test. Put marker-writing stubs for the removed early commands (at least python3, tput, and basename) on PATH and assert that no marker was written, so a credential-exposing regression actually fails.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The credential isolation is consistently implemented, documented, and covered by focused tests.

Review effort: Balanced
Findings: None

@mkultraWasHere
mkultraWasHere added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 0b8d421 Sep 30, 2026
9 checks passed
@mkultraWasHere
mkultraWasHere deleted the codex/isolate-ambient-llm-credentials branch September 30, 2026 04:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants