Skip to content

fix(strix): accept complete scans with benign model-quality advisory - #1255

Closed
seonghobae wants to merge 7 commits into
mainfrom
fix/strix-benign-quality-warning-20260823
Closed

fix(strix): accept complete scans with benign model-quality advisory#1255
seonghobae wants to merge 7 commits into
mainfrom
fix/strix-benign-quality-warning-20260823

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Purpose

A required Strix run rejected complete clean NVIDIA NIM scans solely because Strix prints its built-in MODEL QUALITY WARNING advisory for supported non-frontier models.

Fresh reproductions:

Both produced exact-model Vulnerabilities 0 evidence. The broad Warn|Warning classifier nevertheless marked the attempt as provider/infrastructure failure. #941 additionally proved the same advisory may occur in the newest structured report log.

Tracks #891.

Test-first repair

  • RED e21e421c3f9bc9a6034fcc7e5aeca7abdf7ec8f7: governed primary NIM HTTP-429 → clean fallback with the exact console quality-advisory banner failed for the historical reason.
  • GREEN 5bf2230c349da9f7882e34aa217c05df891891c7: exact console title is non-blocking; genuine provider warning/fatal and report failure controls remain blocking.
  • RED 09cb76e8ede836ed9e446a71f91ee43bfcb16189: the newest report-log quality-advisory variant failed separately.
  • Final GREEN head a1fc43a13085b4dbe9367a871e33461c4eea9ae0: one shared evidence-file classifier ignores only a line consisting of the exact decorative MODEL QUALITY WARNING title. Unknown warnings, fatal/denied/timeout signals, rate limits, provider errors, malformed/incomplete evidence, and genuine findings remain fail-closed.

Verification

Exact-head Strix Changed Path Quality CI run 32640211595, job 97196057984:

  • checkout attested a1fc43a13085b4dbe9367a871e33461c4eea9ae0;
  • 1393 passed, 1 skipped, 16 subtests passed;
  • full test_strix_quick_gate: PASS.

Focused local verification passed both console/report regressions and negative controls for generic provider warning, fatal output, report-only provider rate limit, known internal warning sanitization, and normal fallback.

Operational acceptance

Do not merge from source tests alone. Require all exact-current-head hosted workflows, zero valid unresolved threads, a current-head formal review verdict, ordinary protected-main integration, then unchanged #897/#941 reruns. The consumer canary passes only when a complete scan remains coherent; real provider exhaustion remains explicitly non-passing.

@coderabbitai

coderabbitai Bot commented Aug 23, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 6 minutes

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

Wait for the limit to reset, then comment @coderabbitai review or push new commits to the PR.

An organization admin can change what happens after included review limits in Billing.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 539ae048-0748-43ad-826f-4c65e51bd188

📥 Commits

Reviewing files that changed from the base of the PR and between 885f2cd and a1fc43a.

📒 Files selected for processing (2)
  • scripts/ci/strix_quick_gate.sh
  • scripts/ci/test_strix_quick_gate.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 2 new potential issues.

Open in Devin Review

Comment thread scripts/ci/strix_quick_gate.sh
Comment thread scripts/ci/strix_quick_gate.sh

Copy link
Copy Markdown
Contributor Author

@opencode-agent please perform a fresh formal review of exact head a1fc43a13085b4dbe9367a871e33461c4eea9ae0 against protected base 885f2cd251999f21cf562cab3e2d9cc3cc3ec737. The deterministic console RED (e21e421c…) and report-log RED (09cb76e8…) both reproduce the live #897/#941 false negative. Exact-head quality run 32640211595 / job 97196057984 checked out the current SHA, passed 1,393 tests + 16 subtests, and completed the full Strix quick-gate. Please verify that only the exact decorative MODEL QUALITY WARNING title is non-blocking and that generic warning/fatal/denied/timeout/provider/incomplete/finding paths remain fail-closed. Do not count prior comments or status-only evidence as a formal verdict.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review current-head review for a1fc43a13085b4dbe9367a871e33461c4eea9ae0.

Required strix still executes trusted strix_quick_gate.sh from protected main, so this PR cannot self-verify the MODEL QUALITY WARNING classifier. Independent current-head approval is required; job SUCCESS is not merge authorization.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Superseded by #1213 exact head 5edaf36. The active successor includes the console and newest-report clean model-quality cases, adds the exact Hugging Face advisory and malicious-suffix negative control, and documents the shared fail-closed boundary. Closing this duplicate without merge; reopen only if that scope is removed from #1213.

@seonghobae seonghobae closed this Aug 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant