Repository navigation
host_reach_identity_probe: the identity probe's argv is spelled by its tool module, not hand-typed - #13626
Closed
gunbai-bot[bot] wants to merge 1 commit into
Closed
host_reach_identity_probe: the identity probe's argv is spelled by its tool module, not hand-typed#13626gunbai-bot[bot] wants to merge 1 commit into
gunbai-bot[bot] wants to merge 1 commit into
Conversation
…s tool module, not hand-typed Replace the two hand argv literals in the fleet reach/identity probe with home-module builders, dissolving the last hand argv in that module (roadmap shell-dag-host-reach-identity-probe; Lane B of the transport-argv anemia dissolution). - extdeps.tools.id: id_user_name_argv() -> [id, -un] (login name, no operand: id(1) with no operand answers from the calling process's own credentials, which is exactly the account the SSH session IS). - extdeps.tools.hostname: hostname_read_argv() -> [hostname] (bare, full configured name). The -s decision the row's first_slice names resolves to the bare read: the probe compares its output for exact equality against the enrolled short slot label, so -s (first label) would re-derive a label. - host_reach_identity_probe: probe_reachable_with_principal and probe_ready_target_once now call id_user_name_argv() and hostname_read_argv() instead of the literal [id,-un] and [hostname]. - witness: the_probe_argv_is_spelled_by_its_tool_module_builders pins each builder's materialized argv to the exact words the probe has always executed, so the flags cannot drift out from under the builder.
Contributor
Author
|
Verified the review's points against this head (53ec22c); no changes needed — the diff already matches the row's acceptance contract (roadmap
Validation on the — sent from deep-crab-89 |
This was referenced Oct 9, 2026
Closed
Closed
Closed
Closed
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lane B of the transport-argv anemia dissolution (roadmap row
shell-dag-host-reach-identity-probe): replace the last hand argv in the fleet reach/identity probe with home-module builders.Change
extdeps.tools.id—id_user_name_argv() -> [id, -un]: the login name, no operand.id(1)with no operand answers from the calling process's own credentials, which is exactly the account the SSH session IS (the probe records the account it was granted, not a numeric uid, not a queried user).extdeps.tools.hostname—hostname_read_argv() -> [hostname]: the bare, full configured name. The row'sfirst_slicedecision — "decide whether-sbelongs in the hostname read" — resolves to bare: the probe compares its output for exact equality against the enrolled short slot label, so-s(first label) would re-derive a label instead of reading the name the host reports.host_reach_identity_probe—probe_reachable_with_principalandprobe_ready_target_oncenow callid_user_name_argv()/hostname_read_argv()instead of the literals["id","-un"]/["hostname"].the_probe_argv_is_spelled_by_its_tool_module_builderspins each builder's materialized argv to the exact words the probe has always executed, so the flags cannot drift out from under the builder.Verification
.dag-only change; validated by running thegunbcinterpreter (the corpus is interpreted at runtime;cargo buildalone proves nothing about it):--claim-runof the witness module: exit 0 (new witness + existing regression tests, 641-file closure typecheck/resolve).["hostname","-s"]makes the witness fail (exit 1) — it genuinely pins the flags.fleet_host_key_enrollmentwitness (imports the probe): exit 0.