Repository navigation
Enrolment code: memory-bounded scope for the verb; ntfy auth-file is the observed auth.db - #12614
Merged
Merged
Conversation
…ile is the observed auth.db Found on release 02568b3 by proud-deer-538: 1. fleet-converge run 36556990543 refused HostBudgetUnreadable: the remote argv ran gunbc with no cgroup memory bound. It now runs 'sudo -n systemd-run --scope --uid=<operator> --gid=<operator> --property=MemoryMax=.. --property=MemoryHigh=.. -- env GUNBC_WORKSPACE_ROOT=.. <bin> run ..', bounds from gunbc.live_deploy.slice_bounds approval_broker_slice_memory_{max,high} (the verb resolves the broker's own closure), in its own scope rather than the broker's slice. New extdeps.systemd.systemd_run systemd_run_scope_as_account_argv beside the user-scope form (a user scope needs the account's session bus, which the elevated command lacks). 2. The ntfy readback stat'd /var/lib/gunbc-ntfy/user.db; srv1's server.yml names auth.db. approval_ntfy_auth_file_path is corrected to the observed file and stays a declaration: the stat runs through sudo at an exact argv an operator-installed sudoers line must name, and the readback refuses unless the running config names exactly this path. The srv1 sudoers line for that stat must be re-issued for auth.db. Fixtures follow; the other.db RED is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(no narrow stat grant; operator's broader sudo covers it) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Corrections to the description, from proud-deer-538's reads on srv1 (2026-09-29):
— sent from fierce-deer-555 |
… publisher, briansrls operator) proud-deer-538 ran #12614's verb by hand on srv1; the readback refused on the ACL principals. The live 'ntfy access' lists publisher gunbc-broker (write-only) and operator briansrls (read-only), anonymous denied; the declared gunbc-approval-publisher / gunbc-approval-operator never existed on the host. The live accounts hold the broker's publisher token and the operator's phone subscription, so the declarations follow them (still compared, still refusing any other shape). Fixtures follow; the eve/root REDs are unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…er-only), closing a hand step approval_device_store_root (/var/lib/gunbc/approval-devices) was created by nothing in the model; the first issued enrolment code (srv1, 2026-09-29) needed it made by hand as briansrls 0700. gunbc.auth.approval_device_redemption approval_device_store_directory declares it as a ManagedDirectory (owner and sole dependent = fleet_posix_operator_user, so the derived mode is owner-only; Ensured so a retract keeps the enrolled devices), and approval_broker_dark_install_release_steps ensures it first. The broker closure does not grow (every new import was already in it). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…of assuming it absent The claim required approval_device_store_root to be absent on the runner; srv1 now has it (created by hand for the first issued code, and ensured by the broker install from this PR), so it went red on srv1-09 (run 36562259065) while the verb refused correctly. It now asserts the refusal and that the call leaves the store's existence unchanged -- host-independent, and still red for a verb that proceeds to the store on a host without one. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 29, 2026
Merged
gunbai-bot Bot
pushed a commit
that referenced
this pull request
Sep 29, 2026
…with a binary built from the merged tree Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two defects found on release 02568b3 (broker listening), reported by proud-deer-538.
1. No cgroup memory bound
HostBudgetUnreadable. The seed derives its typed-module cache cap from memory.high/memory.max and refuses rather than guess, and an SSH session binds neither.gunbc.auth.approval_device_enrolment_code_issueenrolment_code_issue_remote_argvnow runs:sudo -n systemd-run --scope --uid=<operator> --gid=<operator> --property=MemoryMax=… --property=MemoryHigh=… -- /usr/bin/env GUNBC_WORKSPACE_ROOT=<release> <release gunbc> run …--userscope needs that account's session bus, which thesudo -ucommand lacks.extdeps.systemd.systemd_runsystemd_run_scope_as_account_argv, beside the existing user-scope form, reusing its property rendering.gunbc.live_deploy.slice_boundsapproval_broker_slice_memory_max/_high, not literals. The verb resolves the broker's own routes closure, so the broker's measured demand bounds it. It gets its own scope; joining the broker's slice would split one budget between the running broker and this run.(ALL) NOPASSWD: ALL, so root elevation forsystemd-runis already covered.2. ntfy auth file
/var/lib/gunbc-ntfy/user.db, but srv1's runningserver.ymlnamesauth.db(which exists;user.dbdoesn't).gunbc.auth.approval_ntfy_deploymentapproval_ntfy_auth_file_pathis corrected to the observed file.sudo -nat an exact argv that an operator-installed sudoers line must name, and a path chosen at runtime could only be granted by a pattern. The readback refuses unless the running config names exactly this path, so the config is checked, not trusted.auth.db; the operator instructions rendered from this row update with it. Fixtures follow; theother.dbRED is unchanged.Witness:
the_remote_argv_runs_the_release_verb_as_the_operator_userpins the whole prefix: root sudo, the scope as the operator, both bounds built from the slice rows, the env binding, then the release binary.Not evaluated locally. One unverified bet: that srv1's systemd applies
--uid/--gidto a--scopechild. My reading of systemd-run(1) and run.c says it does; the wet check is the next enrolment dispatch at the merged sha.🤖 Generated with Claude Code