Conversation
- remove data-governance.ts, the data-governance-policy and data-disclosure-acknowledgements schemas, their semantic gates, route digests and every DATA_GOVERNANCE_* / DATA_DISCLOSURE_* diagnostic; ULTRAFUZZ_DATA_GOVERNANCE_POLICY, ULTRAFUZZ_DATA_DISCLOSURE_ACKNOWLEDGEMENTS and ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK are no longer read - stop writing and sealing data-governance.json and bump the run plan to ultrafuzz.run-plan.v4 without data_governance; v2 and v3 plans fail with an unsupported-version diagnostic - drop the per-adapter route re-check, the private clean-target checks at planning, submission and task preparation, and the native-continuation governance restore, so native resume no longer refuses a run whose claimed control seal is missing - move trustedGitExecutable into source-revision.ts and the credential-route helpers into provider-credential-environment.ts; rename the adapter hook to workflowCredentialAgent - drop smol-toml from the runtime package Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ain (#1269) - remove assertStandaloneModalBenchmarkAllowed, the R-26 disclosure gate that refused private standalone launch and overseer recovery - keep the public candidate_commit, no-public-recovery and execution-budget checks Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- drop the ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK default from the cli and lifecycle-command test harnesses - drop the public policy from the campaign-resume e2e environment Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…1269) - docs/security.md: replace "Campaign data governance" with "Inference provider data handling", which tells operators to review each provider's retention, training, region and DPA terms - docs/schemas.md: drop the two governance schema IDs and their gate note - reference docs: run plan is now ultrafuzz.run-plan.v4; adapter policy wording no longer mentions data governance - CHANGELOG: breaking-change entry with the upgrade steps for runs planned by an earlier release Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- CHANGELOG: drop the two Unreleased route-ID entries and the acknowledgement clause that describe removed behavior; list every command that refuses a v3 plan; drop the internal ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK marker from the operator variables - docs/security.md: scope "does not record, restrict, or verify" to agent traffic and name the eval LLM judge endpoint as a destination - migration table: rewrite the run-plan row so only that row changes Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Ultrafuzz had a campaign data-governance feature: a policy (
ULTRAFUZZ_DATA_GOVERNANCE_POLICY), disclosure acknowledgements (ULTRAFUZZ_DATA_DISCLOSURE_ACKNOWLEDGEMENTS), provider route IDs (model:<agent>-route-<digest>) re-checked by each adapter, private/public campaign modes with a clean-Git-target requirement,data-governance.jsonrun provenance, and Modal/evals gates (the public-benchmark marker and the R-26 private-eval disclosure gate). Agents run unsandboxed, so this only recorded intent. It did not stop any data. It also caused failures such asDATA_GOVERNANCE_PRIVATE_TARGET_UNBOUNDon targets with uncommittedultrafuzz initfiles, and "provider route changed after disclosure acknowledgement" when a CLI rewrote its own config. Where campaign data goes is a trust assumption about the inference providers the operator chooses, not something Ultrafuzz can enforce.Change
This is a breaking change. There is no fallback, no compatibility layer, and no reader for old policy, acknowledgement or provenance documents.
packages/runtime/src/data-governance.tsand its tests.data-governance-policyanddata-disclosure-acknowledgementsschemas, their schema-registry entries and semantic gates, route digests, the per-adapter route re-check, private/public modes, the clean-target checks, and everyDATA_GOVERNANCE_*/DATA_DISCLOSURE_*diagnostic.ULTRAFUZZ_DATA_GOVERNANCE_POLICYandULTRAFUZZ_DATA_DISCLOSURE_ACKNOWLEDGEMENTSare no longer read. The Modal worker no longer sets the internalULTRAFUZZ_MODAL_PUBLIC_BENCHMARKmarker.data-governance.json.plan.jsonmoves toultrafuzz.run-plan.v4withoutdata_governance. v2 and v3 plans fail with an unsupported-version diagnostic in every command that reads the run's sealed workflow (status,why,events,node,timeline,snapshots,pause,cancel,resume,replay,fork).inspectandpsstill show such runs.ultrafuzz-modallaunches and oversees private standalone benchmarks again; the R-26 gate is removed.trustedGitExecutabletosource-revision.ts, and the credential-route helpers toprovider-credential-environment.ts.smol-tomlis dropped from runtime.docs/security.mdreplaces "Campaign data governance" with "Inference provider data handling", which tells operators to check each provider's retention, training use, region and DPA terms, and lists where data goes (agent providers, Modal, and the optional eval LLM judge endpoint).schemas.md, the reference docs and the migration table are updated. CHANGELOG gets a breaking-change entry with upgrade steps, and earlier Unreleased entries that described route-ID or acknowledgement behavior are removed.Kept on purpose:
ULTRAFUZZ_EVAL_JUDGE_ALLOW_PRIVATE_DATAgate and the eval targetsensitivityfield stay. They predate the governance feature, andsensitivityalso drives lineage and ground-truth handling.Behavior changes worth a reviewer's look
ordinary resume bypasses legacy control-seal and link-journal gaps).worktreeBaseBranchno longer falls back to the governance commit whensourceRevisionis null. Launch always captures a source revision, so this only affects targets where HEAD can't be resolved; the verifier test now assertsundefinedthere.ultrafuzz.run-plan.v3) can't be resumed, paused, cancelled, replayed or forked, andcleanrefuses a selection that includes one. The CHANGELOG entry gives the manual cleanup steps.Tests
source-revisioncoverage for the movedtrustedGitExecutable(it never runs agitbinary inside the target).pnpm -w format:check,lint,lint:strict:ci,docs:check,typecheckandknipall pass.runtime.test.tsin 8 shards: 349 pass.generated-workflow-verifiertests that fail the same way onunstable(6b93d6f).scripts/ci79, and the CLI unit tests: all pass.campaign-resume.test.ts) passes withoutULTRAFUZZ_DATA_GOVERNANCE_POLICY.typecheckrebuildingdist/mid-run). Each one passed when rerun alone.Closes #1269
Closes #1226 (
initno longer leaves a target that failsDATA_GOVERNANCE_PRIVATE_TARGET_UNBOUND, because that check is gone). Supersedes #1261.🤖 Generated with Claude Code
The PR appears safe to merge under its stated removal of data governance and documented breaking-change policy.
Summary
Removes campaign data-governance policy, acknowledgements, route checks, and provenance while retaining provider credential filtering and other independent controls.
Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[Campaign inputs] --> B[Plan and validate run] B --> C[Run plan v4] C --> D[Sealed workflow] D --> E[Provider-scoped agent environment] E --> F[Configured inference provider] B --> G[Optional Modal benchmark]Reviews (1) · Last reviewed commit: "docs: reconcile the data-governance remo..."