Skip to content

w744: fff-vm vault-sync no longer removes the claude-tokens/ pool entries; --guest-only keeps the host scripts in step - #245

Merged
bryding merged 3 commits into
mainfrom
w744-vault-sync-pool
Oct 9, 2026
Merged

bryding merged 3 commits into
mainfrom
w744-vault-sync-pool

Conversation

@bryding

@bryding bryding commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Request: w744

TL;DR: install.sh --guest-only does not install the host's fff-vm and vault.sh, so after #241 the installer's sync (which runs vault.sh from the checkout) added the pool entries and sudo fff-vm vault-sync (which runs the installed, older vault.sh) removed them. Every mode of the installer now keeps the installed scripts in step, and a sync can no longer remove an entry whose file exists.

Root cause (path-traced; the host itself was not reachable from here)

  • deploy/vm/host/install.sh: --guest-only sets HOST=0; the step that writes /usr/local/lib/fff-vm/{lib,pathwatch,vault}.sh and /usr/local/sbin/fff-vm was step 10, inside the if [ "$HOST" = 1 ] block that ends at fi # HOST. So --guest-only never touched them.
  • deploy/vm/host/guest.sh (guest_setup) sources $here/vault.sh, the checkout's, for the installer's sync: new code, it knows people/<id>/claude-tokens/<name>, hence "added host-ben-claude-1 …".
  • fff-vm vault-sync sources $LIB/vault.sh = /usr/local/lib/fff-vm/vault.sh, the installed copy from before w738, w739: each person's Claude token pool; orchestrators and the ops worker on it; the dispatcher's reserve #241: it only looks for claude-token and github-token, finds none (lothsahn's host has only claude-tokens/), synced is empty, and the loop at the end removes every host-* entry ("its file is gone from /etc/fff-vm/secrets/people"), exactly the three lines reported.
  • Reproduced in the new test: with the pre-pool vault.sh (777ffd0) as the installed copy, the standalone sync makes no entry (red); with the fix it makes all three.
  • To confirm on the host (read-only): grep -c claude-tokens /usr/local/lib/fff-vm/vault.sh is 0 there, and /opt/ff-factory/deploy/vm/host/vault.sh has it.

The fix

  • install_host_scripts (host/lib.sh) copies lib.sh, pathwatch.sh, vault.sh, fff-vm.conf.example and fff-vm; install.sh calls it in the host part and, before the guest part, for --guest-only.
  • vault_sync: a file that exists is named as kept before its content is checked (a bad paste warns, the entry stays); a scan that finds no token file at all while host-* entries exist removes none and says sudo fff-vm vault-sync --prune.
  • fff-vm vault-sync [--prune].
  • Docs: bash -c, not sh -c (dash has no read -s); what the two sync paths are and --prune.

Evidence

deploy/vm/test/fff-vault-sync.test.sh (new, in lint.sh; fake ssh into a fake VM vault, no root): pool only (the report's three entries), the standalone path, the installer's path and the report's sequence (installer then fff-vm vault-sync), beside claude-token, a bad file keeps its entry, a deleted file removes it, non-host- entries untouched, the no-file guard and --prune, the installed scripts replaced and the second call silent, and install.sh calling install_host_scripts in both modes. shellcheck 0.11 clean on the touched scripts. No token value in any output (checked).

🤖 Generated with Claude Code

bryding and others added 3 commits October 9, 2026 00:39
…ol entries the installer added

install.sh --guest-only skipped the host part, which is the step that copies vault.sh (and fff-vm, lib.sh, pathwatch.sh)
to /usr/local. The installer's own sync ran the new vault.sh from the checkout and added host-<id>-claude-<name>; then
`fff-vm vault-sync` ran the installed vault.sh from before the pool (#241), which only looks for claude-token and
github-token, read every pool entry as one whose file was gone and removed it.

- install_host_scripts (host/lib.sh) is called in every mode of install.sh, --guest-only included.
- A sync names an entry as kept as soon as its file exists, even when it is not a token now (a bad paste).
- A scan that finds no token file at all while host-* entries exist removes none; `fff-vm vault-sync --prune` says it.
- New deploy/vm/test/fff-vault-sync.test.sh: a person with only claude-tokens/, beside claude-token, the standalone path,
  the installer's path and the sequence of the report, nothing removed whose file exists, the guard, the scripts follow
  the checkout (red against the pre-pool vault.sh).
- docs/vault.md: bash -c, not sh -c, for the hidden token prompt (dash's read has no -s).

Request: w744

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…cks an empty scan removes nothing without it

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@bryding
bryding merged commit 2917520 into main Oct 9, 2026
20 of 21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant