feat(permission): complete shadow review events for offline analysis

- key inner-cmd decisive review events by requestId so link decisions join offline
- record judge runtime id, prompt and tool schema versions, end-to-end and model latency, input and output usage, and evidence-quality flags on every judge result row
- record forwarded and session-mismatch preflight defers so they stay visible in the offline denominator
This commit is contained in:
2026-08-17 16:58:10 +08:00
parent 81f1da4100
commit 42f0a0aaab
6 changed files with 289 additions and 77 deletions
@@ -108,13 +108,17 @@ export const timeoutHandler: CommandHandler = {
);
switch (result.state) {
case "allow":
// `requestId` joins this link decision to the gate's
// permission_request.* entries for offline analysis.
log.review("inner_cmd.allow", {
requestId: details.requestId,
command: fullCommand,
innerCommand,
});
return { kind: "allow" };
case "deny":
log.review("inner_cmd.deny", {
requestId: details.requestId,
command: fullCommand,
innerCommand,
});
@@ -172,6 +172,7 @@ describe("authorizeInnerCommand — recognized wrapper verdicts", () => {
level: "review",
event: "inner_cmd.allow",
details: {
requestId: "req-1",
command: "timeout 30s pnpm test",
innerCommand: "pnpm test",
},
@@ -211,6 +212,7 @@ describe("authorizeInnerCommand — recognized wrapper verdicts", () => {
level: "review",
event: "inner_cmd.deny",
details: {
requestId: "req-1",
command: "timeout 30s rm -rf /",
innerCommand: "rm -rf /",
},
@@ -547,6 +549,7 @@ describe("authorizeInnerCommand — scaffolded commands", () => {
level: "review",
event: "inner_cmd.allow",
details: {
requestId: "req-1",
command: full,
innerCommand: "pnpm install --frozen-lockfile",
},