fix: propagate config fields to all layers - #6228
Conversation
…pec CLI mapping Add missing Section 5 CLI mapping entries for two security fields introduced in PRs #6197 and #6209: - security.legacySecurity → --legacy-security - security.securityMode → --security-mode (deprecated) Both fields exist in src/awf-config-schema.json, src/types/security-options.ts, src/config-file.ts, and src/config-mapper.ts but were not listed in the docs/awf-config-spec.md Section 5 CLI Mapping table. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Documents missing security configuration-to-CLI mappings.
Changes:
- Adds mappings for
legacySecurityand deprecatedsecurityMode.
Show a summary per file
| File | Description |
|---|---|
docs/awf-config-spec.md |
Adds security CLI mappings. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Medium
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @github-actions[bot] Add the |
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤 |
|
✅ Contribution Check completed successfully! PR #6228 follows the applicable CONTRIBUTING.md guidelines: it is a documentation-only mapping update, the description is clear and references related PRs, and the file is correctly located under docs/. No review comment is needed. |
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed... |
|
✅ Smoke Gemini completed. All facets verified. 💎 |
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded. |
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed... |
|
✅ Build Test Suite completed successfully! |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
|
🔑 Smoke Copilot PAT PAT auth validated. All systems operational. ✅ |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ |
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓 |
|
✅ Smoke Claude passed |
|
🦎🟣 Smoke gVisor Claude reports failed. gVisor + Claude compatibility issue detected. |
|
🦎 Smoke gVisor reports failed. gVisor compatibility issue detected. |
|
🦎🏗️ Smoke gVisor Build Test reports failed. gVisor build compatibility issue detected. |
|
🔌 Smoke Services — All services reachable! ✅ |
|
🐳🏗️ Smoke Docker Sbx Build Test completed. Docker sbx build test passed. ✅ |
|
🐳🔮 Smoke Docker Sbx Codex completed. Docker sbx + Codex smoke test passed. ✅ |
|
🦎🟣 Smoke gVisor Claude reports failed. gVisor + Claude compatibility issue detected. |
|
🦎 Smoke gVisor completed. gVisor smoke test passed. ✅ |
|
🦎🔮 Smoke gVisor Codex completed. gVisor + Codex smoke test passed. ✅ |
Smoke Test: Claude Engine Validation
Overall Result: PASS ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🔬 Smoke Test: PAT Auth
Overall: PARTIAL — template vars not expanded before agent execution. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Copilot BYOK (Direct) Mode
Running in direct BYOK mode ( Overall: PASS cc Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test Results
Overall: PASS — Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Services Connectivity
Overall: FAIL — Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🦎 gVisor Smoke Test Results
Overall: PASS (runtime unconfirmed pending plumbing) cc Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "example.com"
- "host.docker.internal"See Network Configuration for more information.
|
|
🦎🔮 gVisor + Codex runtime: confirmed\n✅ gVisor kernel detected\n✅ smoke file read: pass\n✅ github.com connectivity: 200\n❌ GitHub MCP PR-list check: denied by proxy\n✅ example.com blocked\nOverall status: FAIL Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "172.30.0.1"
- "example.com"See Network Configuration for more information.
|
Smoke Test: API Proxy OpenTelemetry Tracing
Overall: ✅ All scenarios pass. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
Smoke Test: Gemini Engine Validation
Overall status: FAIL Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "localhost"See Network Configuration for more information.
|
🦎🏗️ gVisor Build Test Results
Overall: FAIL Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "host.docker.internal"See Network Configuration for more information.
|
🔥 Smoke Test Results
Overall: PARTIAL — MCP connectivity confirmed; pre-computed smoke data was not injected (raw cc
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — ✅ PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
🐳🏗️ Docker Sbx Build Test Results
Overall: FAIL
|
Chroot Version Comparison
ALL_TESTS_PASSED: false — Python and Node.js versions differ between host and chroot. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"See Network Configuration for more information.
|
|
🐳🟣 Docker sbx + Claude
Overall: FAIL (egress control did not block non-allowlisted domain)
|
|
🐳🔮 Docker sbx + Codex\n✅ GitHub MCP: list_pull_requests reachable\n✅ GitHub.com: 200\n✅ File read: smoke artifact matched\n❌ Network isolation: example.com returned 200 (expected blocked)\nOverall: FAIL
|
Smoke Test
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "awmgmcpg"
- "registry.npmjs.org"See Network Configuration for more information.
|
Config Consistency Audit Fix
This PR fixes gaps found by the config consistency auditor for recently merged PRs.
Gaps Found
security.securityModedocs/awf-config-spec.mdSection 5 CLI Mappingsecurity.legacySecuritydocs/awf-config-spec.mdSection 5 CLI MappingWhat Was Fixed
Added two missing entries to the Section 5 CLI Mapping table in
docs/awf-config-spec.md:security.legacySecurity→--legacy-securitysecurity.securityMode→--security-mode(deprecated)Both fields are already present in all other required layers:
src/awf-config-schema.jsonanddocs/awf-config.schema.json(identical)src/types/security-options.tssrc/config-file.tssrc/config-mapper.tsVerification Checklist
tsc --noEmit— no TypeScript errors (doc-only change)security.*fields with CLI flagsWarning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
awmgmcpgSee Network Configuration for more information.