# GH-528 Provider QA Reconciliation

Task: `GH-528-REAL-PROVIDER-ADVERSARIAL-QA`
Date: 2026-06-30

## Identifier Note

The local Orchestra task `GH-528-REAL-PROVIDER-ADVERSARIAL-QA` is not the same
as current GitHub issue #528. GitHub #528 now tracks compiled-path renderer
regression coverage and is already closed. The provider QA split was recorded
through child issues #547 through #551.

## Security Blocker Reconciliation

The original Security block required child stories to encode fail-closed checks
before implementation or provider execution:

- No hosted provider secrets for forks, Dependabot, or untrusted PR events.
- Real-provider suites protected/manual only.
- Local-provider egress opt-in and loopback/private-only by default.
- Adversarial fixtures sanitized and treated as data.
- CLI/API/MCP/browser evidence redacts tokens, auth headers, API keys,
  provider errors, raw prompts, stack traces, and unsafe internal details.

That split now exists and has implementation/evidence coverage:

| Child | Scope | Status on 2026-06-30 | Reconciliation |
| --- | --- | --- | --- |
| #551 | Stubbed provider and MCP PR-safe E2E suite | Closed | PR-safe deterministic suite exists. |
| #548 | Local provider egress controls | Closed | Local egress policy is opt-in and bounded. |
| #547 | Adversarial provider and MCP fixtures | Open before reconciliation | QA approved; current focused test passes offline without secrets. |
| #549 | Redacted provider evidence and CI policy | Open before reconciliation | Redaction implementation exists; current build and focused redaction tests pass. |
| #550 | Protected real-provider smoke suite | Open before reconciliation | Trusted-only workflow policy exists; current focused test passes with expected skip when secrets are absent. |

## Current Validation

Commands run on 2026-06-30:

- `npm run build`: pass.
- `node --test e2e/adversarial-provider-mcp.test.js test/provider-evidence-redaction.test.js e2e/protected-real-provider-smoke.test.js`: pass, 7 tests total, 6 pass, 1 expected skip for absent trusted provider secrets.

The protected real-provider smoke test does not execute hosted providers in this
local run. It validates that the suite remains trusted-only, redacted, and
records deferred evidence unless `ORCHESTRA_PROTECTED_REAL_PROVIDER_SMOKE=1`
and trusted `GPT_API_KEY`/`CLAUDE_API_KEY` secrets are available.

## Outcome

The parent task can move out of blocked state because the Security-required
child criteria have been encoded and current local validation passes. Real
provider execution remains protected/manual and is not a default PR gate.
