Repository navigation
Fixes found bringing up the srv1 lab: sudoers install regression, ALL grant, subshell truncation, host-keyed Claude offer, placement-record type - #13720
Merged
Conversation
…ht operand poisoned the sudoers install #13705 replaced grep -Fqx with grep -Fx >/dev/null. The bash serializer refuses a redirect on a pipeline's right operand, so deploy_sudoers_install_shell emitted its refusal marker and every deploy stopped there (srv1 lab apply, 2026-10-10). deploy_mutation_gate_witness and live_deploy/emit each went red on it. grep -Fx without -q still reads its whole input, so the SIGPIPE fix holds. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit a721201)
…command An operator principal whose sudoers entry is (ALL) NOPASSWD: ALL read as holding no roster command, so the operator-local deploy refused every grant-list probe right after installing the drop-in (srv1 lab apply, 2026-10-10). The typed reading and its shell twin now admit an ALL line whose run-as is (ALL), (ALL : ALL) or (root); any other run-as still grants nothing as root. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 49a4a61)
…-else body rendered only its left operand) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 9de9ff7)
…rv1 lab offers it too Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit 405e441)
…ts Name=value assignment session_placement_record_write declares unit_properties: List<String>, but the spawn has passed List<SystemdRunProperty> since the typed systemd-run options landed (#13257), so every harness spawn died with 'split expects a string, got Record' after writing its request binding and before starting its unit. The assignment is now spelled once (extdeps.systemd.systemd_run systemd_run_property_assignment) and read by both option forms and the record. The typechecker admitted the List<SystemdRunProperty> -> List<String> argument. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> (cherry picked from commit dfa390a)
…(a source annotation inside a fn body is a blocking error) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… typed row (review 78587); witness it Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Executed on srv1 at
At Live: srv1's — sent from bright-moth-475 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
These five fixes were made and run live on the srv1 lab (branch
bright-moth-475/lab-dev) on 2026-10-10/11. Each is cherry-picked onto main with-x. The first one repairs a regression main has right now.1. #13705 poisoned the sudoers install (main is broken for every deploy)
grep -Fqxwithgrep -Fx >/dev/null. The bash serializer refuses a redirect on a pipeline's right operand, sodeploy_sudoers_install_shellemits its__GUNBC_BASH_EMIT_REFUSED__marker and every deploy stops there.deploy_mutation_gate_witness(12/13) andlive_deploy/emit(83/84) were red on Deploy blockers: tailnet door binds in a service-owned directory; grant-list probe reads its whole listing #13705. Its author (me) merged before reading them.grep -Fx, which still reads its whole input, so the SIGPIPE fix holds.extdeps.sudo.nopasswd_execute_probe_check_opsudo_nopasswd_grant_list_shell_condition.2. A
(ALL) NOPASSWD: ALLgrant read as holding no roster commandsudo_nopasswd_grant_list_line_admits_probe) and its shell twin now admit an ALL line whose run-as is(ALL),(ALL : ALL)or(root). Any other run-as still grants nothing as root.3.
bash_build_subshellgiven an or-else body dropped the right operand( A || B )rendered as( A ). The builder now constructs the subshell from a statement list (bash_build_subshell_from_stmts).bash_fold_flatten_stmt_list) still silently drops children of a malformed body. That's tracked in the convergence-coverage program (cause B), not papered over here.4. The Claude offer belonged to one instance id, not the host
executor=claudedispatch on the srv1 lab refused ("no provider offer matches the requested selection shape"), although the lab shares srv1's provider state and Claude credential.declared_provider_inventory_for_instancenow keys the offer onhost_identity.5. Every harness spawn crashed with
split expects a string, got Recordbelt_session_container_createpassedList<SystemdRunProperty>tosession_placement_record_write(unit_properties: List<String>).Name=valueis now spelled once (extdeps.systemd.systemd_runsystemd_run_property_assignment) and read by both option forms and the record.product_value_at_a_scalar_formal_is_accepted), not fixed here.Evidence
deploy_mutation_gate_witness13/13,live_deploy/emit84/84.roadmap_serve/roadmap_belt_tick_cliat this head: results to follow as a comment.🤖 Generated with Claude Code