Repository navigation
fleet_release_bins wet witness: clear the runner's credential env; pin the temp root - #12703
Conversation
…and pin the temp root A runner exporting a registry token, or a TMPDIR under a home holding .cargo/config.toml, turned the positive claims into CredentialInBuildEnvironment or AncestorCargoConfigPresent (RFM wet_witness_keyed_to_the_runner_not_its_subject). The fixture now unsets release_bins_credential_pattern names and pins mktemp under /tmp; the RED claims set their token or config afterward, so they still discriminate. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… nodes, not an eval'd string (review 73025) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Addressed review 73025 in Local wet receipt at — sent from neat-moth-20 |
Part of the wet-witness host-premise census (docs/plans/wet-witness-host-premise-census.md, #12652), the latent batch deep-ferret-305 chose.
test.claim.long.fleet_release_bins_key_witnessfixture_envdepended on two things about the runner. First, that it exports no credential-shaped variable (release_bins_credential_pattern). Second, that no ancestor ofmktemp -d(which followsTMPDIR) holds.cargo/config*. If either failed,release_bins_environment_statementsrefused withCredentialInBuildEnvironment, orrelease_bins_ancestor_statementsrefused withAncestorCargoConfigPresent, and the positive claims went red.The fixture now:
release_bins_credential_pattern, the same authority the guard reads;/tmp/gunbc_release_bins.XXXXXX.The RED claims export a credential or plant an ancestor config after the fixture runs, so they still discriminate.
Local wet receipt:
claim_batch --wet --source-root dag --source-root src/v2 --entry dag/test/claim/long/fleet_release_bins_key_witness_test.dag --functions <all 26>, uid 1000, with a hostile runner environment:CARGO_REGISTRY_TOKEN=runner-leakandTMPDIR=<dir>/t, where<dir>/.cargo/config.tomlexists.58969ecec589a4ad2ce4b7a83b50a590d274991a(the working tree, committed unchanged): exit 0, 26/26 PASS.release_bins_unchanged_inputs_key_equally,release_bins_release_opt_level_override_changes_the_key,release_bins_multiline_rustflags_keys_apart_from_its_first_line,release_bins_RED_compiler_override_refuses,release_bins_RED_ancestor_cargo_config_refuses. The two REDs fail because the credential refusal fires ahead of the refusal each one expects.🤖 Generated with Claude Code