Repository navigation
dusk qwen 2 - #13656
dusk qwen 2#13656briansrls wants to merge 2 commits into
Conversation
…s tool module, not hand-typed Replace the two hand argv literals in the fleet reach/identity probe with home-module builders, dissolving the last hand argv in that module (roadmap shell-dag-host-reach-identity-probe; Lane B of the transport-argv anemia dissolution). - extdeps.tools.id: id_user_name_argv() -> [id, -un] (login name, no operand: id(1) with no operand answers from the calling process's own credentials, which is exactly the account the SSH session IS). - extdeps.tools.hostname: hostname_read_argv() -> [hostname] (bare, full configured name). The -s decision the row's first_slice names resolves to the bare read: the probe compares its output for exact equality against the enrolled short slot label, so -s (first label) would re-derive a label. - host_reach_identity_probe: probe_reachable_with_principal and probe_ready_target_once now call id_user_name_argv() and hostname_read_argv() instead of the literal [id,-un] and [hostname]. - witness: the_probe_argv_is_spelled_by_its_tool_module_builders pins each builder's materialized argv to the exact words the probe has always executed, so the flags cannot drift out from under the builder.
…626 review WIP per operator wind-down — NOT a finished slice. Folding stern-boar-596's 5-point review of 13626 into a follow-up, stopped mid-edit. Done in this WIP (points 1,2,4 + half of 3): - point 1: the probe's hostname read moves from the bare hostname_read_argv (possibly-FQDN) to the existing hostname_short_read_argv (hostname -s). The grain is short: enrolled slot labels are short (srv1,...) and the model's short-hostname read (HostIdentityShortHostnameRead) is hostname -s; a bare read of an FQDN-configured host (srv1.example.com) exact-equality-fails the short slot label srv1 -> fail-closed identity refusal against a host whose short name IS enrolled. The bare hostname_read_argv row is deleted (dead; the bare FULL read stays alive only as hostname_read_command). - point 2: id.dag -u/-n comment corrected (u selects the effective-user FIELD, n renders it as the NAME). - point 4: hostname_short_read_argv now [hostname_program().invocation, -s]. - point 3 (partial): probe_ready_target_argv / probe_principal_argv expose each op's argv and *_route_argv the seam's wire form (shape_ssh_shell_exec). NOT done (stopped): the route-asserting witness (point 3) and the witness test still imports the now-deleted hostname_read_argv, so that witness module does NOT typecheck at this head. Not interpreter-verified. Next step: rewrite the witness to assert probe argv == builder and the route.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8255a8f1bd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| import gunbc.network_identity_subsumption { srv3_post_install_lease_table_fixture } | ||
| import gunbc.srv3_os_install_diagnostic { srv3_install_hang_no_router_lease_ms } | ||
| import extdeps.tools.id { id_user_name_argv } | ||
| import extdeps.tools.hostname { hostname_read_argv } |
There was a problem hiding this comment.
Update the witness to use the surviving hostname builder
The commit deletes hostname_read_argv from extdeps.tools.hostname, but this changed witness still imports and calls it, so loading this witness fails during name resolution and prevents its claims from running. Import hostname_short_read_argv (or the probe-facing projection) instead and update the assertion to expect ["hostname", "-s"], matching the production probe introduced in this commit.
Useful? React with 👍 / 👎.
|
Closing in the v1 closeout. This is a wind-down WIP push (8255a8f) of the #13626 follow-up on FQDN vs short-hostname identity. That decision is still open, and review 78372 shows the WIP contradicts itself: the probe calls hostname_short_read_argv (-s), the witness pins the bare hostname_read_argv, the two comments argue opposite positions, and the new *_route_argv functions have no consumer. It's recorded as outstanding work in docs/plans/v1-closeout-pr-accounting.md on #13641. Decide short vs bare first, then one comment, a witness over probe_ready_target_argv()/probe_principal_argv(), and no unconsumed route fns. Branch kept. — sent from neat-wolf-604 |
Auto-opened by session-dashboard for session
deep-crab-89.Pushing to
session/deep-crab-89-followupadvances this PR.Worker attestation
Before flipping this PR to ready for review, confirm each item:
npm test,cargo test) and the result.Closes #Ndirective.Summary
TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.
Test plan