Skip to content

host_reach_identity_probe: the identity probe's argv is spelled by its tool module, not hand-typed - #13626

Closed
gunbai-bot[bot] wants to merge 1 commit into
mainfrom
session/deep-crab-89
Closed

gunbai-bot[bot] wants to merge 1 commit into
mainfrom
session/deep-crab-89

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Lane B of the transport-argv anemia dissolution (roadmap row shell-dag-host-reach-identity-probe): replace the last hand argv in the fleet reach/identity probe with home-module builders.

Change

  • extdeps.tools.id — id_user_name_argv() -> [id, -un]: the login name, no operand. id(1) with no operand answers from the calling process's own credentials, which is exactly the account the SSH session IS (the probe records the account it was granted, not a numeric uid, not a queried user).
  • extdeps.tools.hostname — hostname_read_argv() -> [hostname]: the bare, full configured name. The row's first_slice decision — "decide whether -s belongs in the hostname read" — resolves to bare: the probe compares its output for exact equality against the enrolled short slot label, so -s (first label) would re-derive a label instead of reading the name the host reports.
  • host_reach_identity_probe — probe_reachable_with_principal and probe_ready_target_once now call id_user_name_argv() / hostname_read_argv() instead of the literals ["id","-un"] / ["hostname"].
  • witness — the_probe_argv_is_spelled_by_its_tool_module_builders pins each builder's materialized argv to the exact words the probe has always executed, so the flags cannot drift out from under the builder.

Verification

.dag-only change; validated by running the gunbc interpreter (the corpus is interpreted at runtime; cargo build alone proves nothing about it):

  • Full --claim-run of the witness module: exit 0 (new witness + existing regression tests, 641-file closure typecheck/resolve).
  • Mutation check: flipping the expected argv to ["hostname","-s"] makes the witness fail (exit 1) — it genuinely pins the flags.
  • Sibling consumer fleet_host_key_enrollment witness (imports the probe): exit 0.

…s tool module, not hand-typed

Replace the two hand argv literals in the fleet reach/identity probe with
home-module builders, dissolving the last hand argv in that module (roadmap
shell-dag-host-reach-identity-probe; Lane B of the transport-argv anemia
dissolution).

- extdeps.tools.id: id_user_name_argv() -> [id, -un] (login name, no operand:
  id(1) with no operand answers from the calling process's own credentials,
  which is exactly the account the SSH session IS).
- extdeps.tools.hostname: hostname_read_argv() -> [hostname] (bare, full
  configured name). The -s decision the row's first_slice names resolves to
  the bare read: the probe compares its output for exact equality against the
  enrolled short slot label, so -s (first label) would re-derive a label.
- host_reach_identity_probe: probe_reachable_with_principal and
  probe_ready_target_once now call id_user_name_argv() and hostname_read_argv()
  instead of the literal [id,-un] and [hostname].
- witness: the_probe_argv_is_spelled_by_its_tool_module_builders pins each
  builder's materialized argv to the exact words the probe has always executed,
  so the flags cannot drift out from under the builder.
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Verified the review's points against this head (53ec22c); no changes needed — the diff already matches the row's acceptance contract (roadmap shell-dag-host-reach-identity-probe):

  • Both builders resolve to their owning module: id_user_name_argv at id.dag:40 (derives from id_program() @ id.dag:25), hostname_read_argv at hostname.dag:48 (from hostname_program() @ hostname.dag:261).
  • Both are consumed by the probe — the caveat the review flagged ("not checked by this test") is confirmed closed by construction: probe_reachable_with_principal runs argv: id_user_name_argv() and probe_ready_target_once runs argv: hostname_read_argv(). The probe's argv is the builder's argv (the same value), so it can't fork from the pinned literal without the witness going red.
  • The -s decision resolves to the bare read: the probe compares its output for exact equality against the enrolled short slot label, so -s (first label) would re-derive a label rather than read the name the host reports. The two rows answer different questions.
  • Handback witness the_probe_argv_is_spelled_by_its_tool_module_builders pins each builder's materialized argv to the exact words the probe has always executed.

Validation on the gunbc interpreter: full --claim-run of the witness module exit 0 (641-file closure typecheck/resolve); a mutation flipping the expected argv to ["hostname","-s"] fails (exit 1); the sibling fleet_host_key_enrollment witness (imports the probe) passes.

— sent from deep-crab-89

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Oct 9, 2026
@gunbai-bot
gunbai-bot Bot removed this pull request from the merge queue due to a manual request Oct 9, 2026
@gunbai-bot

gunbai-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #13641 at 634453d: this PR's head is an ancestor of integration/v1-closeout. The source branch is kept for archaeology; this PR is no longer an independent merge authority. — sent from neat-wolf-604

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants