Skip to content

chore: remove operator lab identifiers from tracked files (#2301) - #2318

Draft
thinmintdev wants to merge 6 commits into
mainfrom
claude/nice-clarke-swghxm-2301
Draft

thinmintdev wants to merge 6 commits into
mainfrom
claude/nice-clarke-swghxm-2301

Conversation

@thinmintdev

Copy link
Copy Markdown
Contributor

Summary

Closes #2301. This follows #2300, which untracked boxes.toml. It removes the remaining operator lab identifiers from the working tree: lab subnet addresses, the hypervisor address, the thin-mint ssh key name, operator-local paths (/mnt/mintdev, /home/halo, /home/cuken) and the operator's own domain used as test fixtures.

Decision: no history scrub. No credential was ever committed; only the key name and private-LAN addresses were. I checked for key material and token prefixes and found only placeholders. The operator rotates or retires the named key separately.

  • scripts/fresh-test-ct.sh: the default HAL0_TEST_KEY is now ~/.ssh/id_ed25519, matching release-test.sh.
  • Test fixtures:
    • Lab IPs become RFC 5737 192.0.2.x. Python classifies that range as private too, so no test's private/public classification changes.
    • Tests that need RFC 1918 specifically (test_peers, test_auth_client_ip, test_openrouter_auth_loopback) use generic 10.0.0.x.
    • *.thinmint.dev fixtures become hal0.example.com, and the Sentry fixture user "alexander" becomes "operator".
  • Comments, docs and release reports: addresses are dropped or replaced with placeholders. kit.toml run_root becomes a placeholder; no code reads it.
  • manifest.json _notes: reworded. Release tooling reads only toolbox_images digests from this file, so the JSON stays valid and no digests change.
  • CHANGELOG: only the one line that named a lab IP changed. Line 4204 stays as history.
  • New guard test: tests/scripts/test_no_operator_identifiers.py fails if any tracked file matches 10\.0\.1\., \.ssh/thin-mint, /mnt/mintdev or thinmint\.dev. Its only allowlist entry is the CHANGELOG history line.
  • Left alone on purpose:

Risk grade

  • low — test fixtures, comments, docs; the only script change is one default value
  • med
  • high

Touched surfaces

  • API (src/hal0/api/), comments only
  • Auth / sessions
  • Slots / dispatch
  • Models / capabilities
  • Installer
  • Updater
  • Board chat / MCP admin
  • Config / schema (comments in schema.py, manifest.json notes)
  • UI (comments and an e2e mock fixture)
  • Docs (docs/, release-validation reports, CHANGELOG line)
  • CI / release

§14.1 high-risk surfaces

  • Unauthenticated board routes
  • AUTONOMOUS_WRITE_TOOLS
  • Installer / updater RCE-class

Rollback

Rollback: revert the commit. Anyone who relied on the old HAL0_TEST_KEY default sets the env var.

Test tiers run

  • α unit: every touched test file, plus tests/release, tests/scripts, tests/packaging, tests/updater, tests/config, tests/runners, tests/registry. 3165 passed. The 2 failures in tests/updater also fail on untouched code in this container, because it runs as root. After merging current main: tests/scripts tests/release tests/upstreams and the touched API tests gave 583 passed. UI lint and typecheck pass; ruff is clean.
  • β integration (retired)
  • γ release-gate (not needed, low risk)

🤖 Generated with Claude Code

https://claude.ai/code/session_01JDmjmr5XP9VGp1sDwFm3rU


Generated by Claude Code

claude and others added 5 commits October 2, 2026 18:43
…ple.toml (#2271)

tests/release-validation/boxes.toml described the operator's private lab
(guest LAN addresses, hypervisor address, ssh key path), which CLAUDE.md
forbids in tracked files. Gitignore it, drop it from the index, and commit
a placeholder boxes.example.toml with the same schema. The ct151 reset
checklist test now reads the example, and two guards assert the example
carries no RFC 1918 address or real key path and that boxes.toml stays
untracked.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017bDysVfpfD2VTJfPcQwCcM
Signed-off-by: Claude <noreply@anthropic.com>
Working-tree only (no history rewrite, per owner decision):

- scripts/fresh-test-ct.sh: default test key is ~/.ssh/id_ed25519,
  matching scripts/release-test.sh.
- Test fixtures: lab addresses become RFC 5737 192.0.2.x; tests that
  need RFC 1918 semantics (auth client-ip, loopback rejection, peer
  host classification) use generic 10.0.0.x. Personal domain fixtures
  become example.com names; /home/cuken model paths become /srv/models.
- Comments, docstrings, README, UI notes, release-validation reports,
  kit.toml run_root, and manifest.json _notes no longer name lab IPs or
  operator-local paths.
- CHANGELOG: drop the lab IP from the one history line that named it.
- Add tests/scripts/test_no_operator_identifiers.py to keep them out.

Signed-off-by: Alexander <alexander@awideweb.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JDmjmr5XP9VGp1sDwFm3rU
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Comment thread tests/api/test_mcp_transport_security.py Fixed
Comment thread tests/api/test_mcp_transport_security.py Fixed
CodeQL (py/incomplete-url-substring-sanitization) read
`"hal0.example.com" in sec.allowed_hosts` as URL substring matching.
These are exact list-membership checks; expressing them as subsets of
set(...) asserts the same thing without the false positive.

Signed-off-by: Alexander <alexander@awideweb.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JDmjmr5XP9VGp1sDwFm3rU

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

repo: lab subnet addresses and the operator ssh key name remain in ~24 tracked files beyond boxes.toml

3 participants