Repository navigation
w744: fff-vm vault-sync no longer removes the claude-tokens/ pool entries; --guest-only keeps the host scripts in step - #245
Merged
Conversation
…ol entries the installer added install.sh --guest-only skipped the host part, which is the step that copies vault.sh (and fff-vm, lib.sh, pathwatch.sh) to /usr/local. The installer's own sync ran the new vault.sh from the checkout and added host-<id>-claude-<name>; then `fff-vm vault-sync` ran the installed vault.sh from before the pool (#241), which only looks for claude-token and github-token, read every pool entry as one whose file was gone and removed it. - install_host_scripts (host/lib.sh) is called in every mode of install.sh, --guest-only included. - A sync names an entry as kept as soon as its file exists, even when it is not a token now (a bad paste). - A scan that finds no token file at all while host-* entries exist removes none; `fff-vm vault-sync --prune` says it. - New deploy/vm/test/fff-vault-sync.test.sh: a person with only claude-tokens/, beside claude-token, the standalone path, the installer's path and the sequence of the report, nothing removed whose file exists, the guard, the scripts follow the checkout (red against the pre-pool vault.sh). - docs/vault.md: bash -c, not sh -c, for the hidden token prompt (dash's read has no -s). Request: w744 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…cks an empty scan removes nothing without it Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Request: w744
TL;DR:
install.sh --guest-onlydoes not install the host'sfff-vmandvault.sh, so after #241 the installer's sync (which runsvault.shfrom the checkout) added the pool entries andsudo fff-vm vault-sync(which runs the installed, oldervault.sh) removed them. Every mode of the installer now keeps the installed scripts in step, and a sync can no longer remove an entry whose file exists.Root cause (path-traced; the host itself was not reachable from here)
deploy/vm/host/install.sh:--guest-onlysetsHOST=0; the step that writes/usr/local/lib/fff-vm/{lib,pathwatch,vault}.shand/usr/local/sbin/fff-vmwas step 10, inside theif [ "$HOST" = 1 ]block that ends atfi # HOST. So--guest-onlynever touched them.deploy/vm/host/guest.sh(guest_setup) sources$here/vault.sh, the checkout's, for the installer's sync: new code, it knowspeople/<id>/claude-tokens/<name>, hence "added host-ben-claude-1 …".fff-vm vault-syncsources$LIB/vault.sh=/usr/local/lib/fff-vm/vault.sh, the installed copy from before w738, w739: each person's Claude token pool; orchestrators and the ops worker on it; the dispatcher's reserve #241: it only looks forclaude-tokenandgithub-token, finds none (lothsahn's host has onlyclaude-tokens/),syncedis empty, and the loop at the end removes everyhost-*entry ("its file is gone from /etc/fff-vm/secrets/people"), exactly the three lines reported.vault.sh(777ffd0) as the installed copy, the standalone sync makes no entry (red); with the fix it makes all three.grep -c claude-tokens /usr/local/lib/fff-vm/vault.shis0there, and/opt/ff-factory/deploy/vm/host/vault.shhas it.The fix
install_host_scripts(host/lib.sh) copieslib.sh,pathwatch.sh,vault.sh,fff-vm.conf.exampleandfff-vm;install.shcalls it in the host part and, before the guest part, for--guest-only.vault_sync: a file that exists is named as kept before its content is checked (a bad paste warns, the entry stays); a scan that finds no token file at all whilehost-*entries exist removes none and sayssudo fff-vm vault-sync --prune.fff-vm vault-sync [--prune].bash -c, notsh -c(dash has noread -s); what the two sync paths are and--prune.Evidence
deploy/vm/test/fff-vault-sync.test.sh(new, inlint.sh; fake ssh into a fake VM vault, no root): pool only (the report's three entries), the standalone path, the installer's path and the report's sequence (installer thenfff-vm vault-sync), besideclaude-token, a bad file keeps its entry, a deleted file removes it, non-host-entries untouched, the no-file guard and--prune, the installed scripts replaced and the second call silent, and install.sh callinginstall_host_scriptsin both modes. shellcheck 0.11 clean on the touched scripts. No token value in any output (checked).🤖 Generated with Claude Code