Skip to content

Gate AC_add_package_to_executor behind a package allowlist - #492

Merged
JE-Chen merged 2 commits into
feat/coverage-to-80from
feat/package-gate
Oct 1, 2026
Merged

JE-Chen merged 2 commits into
feat/coverage-to-80from
feat/package-gate

Conversation

@JE-Chen

@JE-Chen JE-Chen commented Oct 1, 2026

Copy link
Copy Markdown
Member

Workspace X-12: AC_add_package_to_executor / AC_add_package_to_callback_executor imported any installed package and registered its members as commands, so an action list from a JSON file, the socket / REST / MCP servers or the scheduler could load os or subprocess.

  • PackageManager checks the name before importing. allow_packages(*names) is an allowlist (submodules included); set_allow_arbitrary_packages(bool) opens or closes the gate for everything else. A refusal raises AutoControlExecuteActionException, which becomes that action's failure.
  • Executor.allow_packages / Executor.set_allow_arbitrary_packages are the same switches as static methods. Neither is an AC_* command, so an action list cannot open its own gate (a test checks no command name contains them).
  • Unconfigured, any package still loads with a DeprecationWarning; flipping the default is recorded in Progress.md.
  • Same gate as WebRunner, APITestka, LoadDensity and MailThunder.

Docs: the three READMEs, the Sphinx package manager and executor pages, architecture.md §7, architecture_explore.md (counts re-measured with test_doc_line_counts.py --fix), CHANGELOG.md (Added, Deprecated), docs/updates U-20261001-07 (03–06 are taken by feat/jeffrey-rpa-gui-apis).

Stacked on feat/coverage-to-80 (#490), which also touches package_manager_class.py.

Tests: test/unit_test/headless/test_package_gate.py (8). Full headless suite on this branch: 10559 passed, 46 skipped.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 22 complexity · 0 duplication

Metric Results
Complexity 22
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

…s U-20261001-07, renumber the package gate entry to 08
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@JE-Chen
JE-Chen merged commit ce616be into feat/coverage-to-80 Oct 1, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant