Skip to content

refactor!: remove campaign data governance (#1269) - #1275

Open
aviggiano wants to merge 5 commits into
unstablefrom
refactor/1269-remove-data-governance
Open

aviggiano wants to merge 5 commits into
unstablefrom
refactor/1269-remove-data-governance

Conversation

@aviggiano

@aviggiano aviggiano commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Ultrafuzz had a campaign data-governance feature: a policy (ULTRAFUZZ_DATA_GOVERNANCE_POLICY), disclosure acknowledgements (ULTRAFUZZ_DATA_DISCLOSURE_ACKNOWLEDGEMENTS), provider route IDs (model:<agent>-route-<digest>) re-checked by each adapter, private/public campaign modes with a clean-Git-target requirement, data-governance.json run provenance, and Modal/evals gates (the public-benchmark marker and the R-26 private-eval disclosure gate). Agents run unsandboxed, so this only recorded intent. It did not stop any data. It also caused failures such as DATA_GOVERNANCE_PRIVATE_TARGET_UNBOUND on targets with uncommitted ultrafuzz init files, and "provider route changed after disclosure acknowledgement" when a CLI rewrote its own config. Where campaign data goes is a trust assumption about the inference providers the operator chooses, not something Ultrafuzz can enforce.

Change

This is a breaking change. There is no fallback, no compatibility layer, and no reader for old policy, acknowledgement or provenance documents.

  • Remove packages/runtime/src/data-governance.ts and its tests.
  • Remove the data-governance-policy and data-disclosure-acknowledgements schemas, their schema-registry entries and semantic gates, route digests, the per-adapter route re-check, private/public modes, the clean-target checks, and every DATA_GOVERNANCE_* / DATA_DISCLOSURE_* diagnostic.
  • ULTRAFUZZ_DATA_GOVERNANCE_POLICY and ULTRAFUZZ_DATA_DISCLOSURE_ACKNOWLEDGEMENTS are no longer read. The Modal worker no longer sets the internal ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK marker.
  • Runs no longer write data-governance.json. plan.json moves to ultrafuzz.run-plan.v4 without data_governance. v2 and v3 plans fail with an unsupported-version diagnostic in every command that reads the run's sealed workflow (status, why, events, node, timeline, snapshots, pause, cancel, resume, replay, fork). inspect and ps still show such runs.
  • ultrafuzz-modal launches and oversees private standalone benchmarks again; the R-26 gate is removed.
  • Shared helpers move to the modules that still use them: trustedGitExecutable to source-revision.ts, and the credential-route helpers to provider-credential-environment.ts. smol-toml is dropped from runtime.
  • Docs: docs/security.md replaces "Campaign data governance" with "Inference provider data handling", which tells operators to check each provider's retention, training use, region and DPA terms, and lists where data goes (agent providers, Modal, and the optional eval LLM judge endpoint). schemas.md, the reference docs and the migration table are updated. CHANGELOG gets a breaking-change entry with upgrade steps, and earlier Unreleased entries that described route-ID or acknowledgement behavior are removed.

Kept on purpose:

  • Anything with another purpose stays: credential redaction, sensitive-env filtering, provider-home safety checks, source-revision provenance, and Modal public bundle redaction.
  • The eval LLM judge's ULTRAFUZZ_EVAL_JUDGE_ALLOW_PRIVATE_DATA gate and the eval target sensitivity field stay. They predate the governance feature, and sensitivity also drives lineage and ground-truth handling.
  • "Governance" in audit prompts means smart-contract/protocol governance and is unchanged.

Behavior changes worth a reviewer's look

  • Native resume no longer refuses a run whose claimed control seal is missing. fix(runtime): preserve launch policy and failed attempts during continuation #1117 added that refusal only to restore governance policy, so this goes back to the earlier behavior and test name (ordinary resume bypasses legacy control-seal and link-journal gaps).
  • worktreeBaseBranch no longer falls back to the governance commit when sourceRevision is null. Launch always captures a source revision, so this only affects targets where HEAD can't be resolved; the verifier test now asserts undefined there.
  • Runs planned by an earlier release (ultrafuzz.run-plan.v3) can't be resumed, paused, cancelled, replayed or forked, and clean refuses a selection that includes one. The CHANGELOG entry gives the manual cleanup steps.

Tests

  • Removed the governance tests. Updated the run-plan, CLI, lifecycle-command and campaign-resume e2e fixtures to run without a policy, and added source-revision coverage for the moved trustedGitExecutable (it never runs a git binary inside the target).
  • Gates: build of runtime, cli, modal and evals; pnpm -w format:check, lint, lint:strict:ci, docs:check, typecheck and knip all pass.
  • Suites, run locally on this branch:
    • runtime.test.ts in 8 shards: 349 pass.
    • Runtime supporting files: all pass, except 2 generated-workflow-verifier tests that fail the same way on unstable (6b93d6f).
    • Bun adapter contracts: 47 pass. The 6 removed tests were governance route checks.
    • artifacts 329, config 92, topology 73, prompts 60, security 23, references 22, modal 522, evals 383, scripts/ci 79, and the CLI unit tests: all pass.
    • The CLI e2e campaign (campaign-resume.test.ts) passes without ULTRAFUZZ_DATA_GOVERNANCE_POLICY.
    • A few tests failed only while other suites ran in parallel (load average about 20, or typecheck rebuilding dist/ mid-run). Each one passed when rerun alone.

Closes #1269
Closes #1226 (init no longer leaves a target that fails DATA_GOVERNANCE_PRIVATE_TARGET_UNBOUND, because that check is gone). Supersedes #1261.

🤖 Generated with Claude Code

RetriggerConfidence Score: 5/5

The PR appears safe to merge under its stated removal of data governance and documented breaking-change policy.

Summary

Removes campaign data-governance policy, acknowledgements, route checks, and provenance while retaining provider credential filtering and other independent controls.

  • Moves run plans to v4 and documents the incompatibility with earlier plans.
  • Re-enables private standalone Modal benchmarks and updates operator-facing data-handling guidance.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Campaign inputs] --> B[Plan and validate run]
  B --> C[Run plan v4]
  C --> D[Sealed workflow]
  D --> E[Provider-scoped agent environment]
  E --> F[Configured inference provider]
  B --> G[Optional Modal benchmark]
Loading

Reviews (1) · Last reviewed commit: "docs: reconcile the data-governance remo..."

aviggiano and others added 5 commits October 2, 2026 13:33
- remove data-governance.ts, the data-governance-policy and
  data-disclosure-acknowledgements schemas, their semantic gates, route
  digests and every DATA_GOVERNANCE_* / DATA_DISCLOSURE_* diagnostic;
  ULTRAFUZZ_DATA_GOVERNANCE_POLICY, ULTRAFUZZ_DATA_DISCLOSURE_ACKNOWLEDGEMENTS
  and ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK are no longer read
- stop writing and sealing data-governance.json and bump the run plan to
  ultrafuzz.run-plan.v4 without data_governance; v2 and v3 plans fail with
  an unsupported-version diagnostic
- drop the per-adapter route re-check, the private clean-target checks at
  planning, submission and task preparation, and the native-continuation
  governance restore, so native resume no longer refuses a run whose
  claimed control seal is missing
- move trustedGitExecutable into source-revision.ts and the credential-route
  helpers into provider-credential-environment.ts; rename the adapter hook to
  workflowCredentialAgent
- drop smol-toml from the runtime package

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ain (#1269)

- remove assertStandaloneModalBenchmarkAllowed, the R-26 disclosure gate that
  refused private standalone launch and overseer recovery
- keep the public candidate_commit, no-public-recovery and execution-budget
  checks

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- drop the ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK default from the cli and
  lifecycle-command test harnesses
- drop the public policy from the campaign-resume e2e environment

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…1269)

- docs/security.md: replace "Campaign data governance" with "Inference
  provider data handling", which tells operators to review each provider's
  retention, training, region and DPA terms
- docs/schemas.md: drop the two governance schema IDs and their gate note
- reference docs: run plan is now ultrafuzz.run-plan.v4; adapter policy
  wording no longer mentions data governance
- CHANGELOG: breaking-change entry with the upgrade steps for runs planned
  by an earlier release

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- CHANGELOG: drop the two Unreleased route-ID entries and the
  acknowledgement clause that describe removed behavior; list every
  command that refuses a v3 plan; drop the internal
  ULTRAFUZZ_MODAL_PUBLIC_BENCHMARK marker from the operator variables
- docs/security.md: scope "does not record, restrict, or verify" to agent
  traffic and name the eval LLM judge endpoint as a destination
- migration table: rewrite the run-plan row so only that row changes

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@aviggiano
aviggiano requested a review from a team as a code owner October 2, 2026 18:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant