Repository navigation
chore: remove operator lab identifiers from tracked files (#2301) - #2318
Draft
thinmintdev wants to merge 6 commits into
Draft
thinmintdev wants to merge 6 commits into
thinmintdev wants to merge 6 commits into
Conversation
…ple.toml (#2271) tests/release-validation/boxes.toml described the operator's private lab (guest LAN addresses, hypervisor address, ssh key path), which CLAUDE.md forbids in tracked files. Gitignore it, drop it from the index, and commit a placeholder boxes.example.toml with the same schema. The ct151 reset checklist test now reads the example, and two guards assert the example carries no RFC 1918 address or real key path and that boxes.toml stays untracked. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017bDysVfpfD2VTJfPcQwCcM Signed-off-by: Claude <noreply@anthropic.com>
…oxes' into claude/nice-clarke-swghxm-2301
Working-tree only (no history rewrite, per owner decision): - scripts/fresh-test-ct.sh: default test key is ~/.ssh/id_ed25519, matching scripts/release-test.sh. - Test fixtures: lab addresses become RFC 5737 192.0.2.x; tests that need RFC 1918 semantics (auth client-ip, loopback rejection, peer host classification) use generic 10.0.0.x. Personal domain fixtures become example.com names; /home/cuken model paths become /srv/models. - Comments, docstrings, README, UI notes, release-validation reports, kit.toml run_root, and manifest.json _notes no longer name lab IPs or operator-local paths. - CHANGELOG: drop the lab IP from the one history line that named it. - Add tests/scripts/test_no_operator_identifiers.py to keep them out. Signed-off-by: Alexander <alexander@awideweb.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JDmjmr5XP9VGp1sDwFm3rU
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Comment |
CodeQL (py/incomplete-url-substring-sanitization) read `"hal0.example.com" in sec.allowed_hosts` as URL substring matching. These are exact list-membership checks; expressing them as subsets of set(...) asserts the same thing without the false positive. Signed-off-by: Alexander <alexander@awideweb.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JDmjmr5XP9VGp1sDwFm3rU
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #2301. This follows #2300, which untracked
boxes.toml. It removes the remaining operator lab identifiers from the working tree: lab subnet addresses, the hypervisor address, thethin-mintssh key name, operator-local paths (/mnt/mintdev,/home/halo,/home/cuken) and the operator's own domain used as test fixtures.Decision: no history scrub. No credential was ever committed; only the key name and private-LAN addresses were. I checked for key material and token prefixes and found only placeholders. The operator rotates or retires the named key separately.
scripts/fresh-test-ct.sh: the defaultHAL0_TEST_KEYis now~/.ssh/id_ed25519, matchingrelease-test.sh.192.0.2.x. Python classifies that range as private too, so no test's private/public classification changes.test_peers,test_auth_client_ip,test_openrouter_auth_loopback) use generic10.0.0.x.*.thinmint.devfixtures becomehal0.example.com, and the Sentry fixture user"alexander"becomes"operator".kit.tomlrun_rootbecomes a placeholder; no code reads it.manifest.json_notes: reworded. Release tooling reads onlytoolbox_imagesdigests from this file, so the JSON stays valid and no digests change.tests/scripts/test_no_operator_identifiers.pyfails if any tracked file matches10\.0\.1\.,\.ssh/thin-mint,/mnt/mintdevorthinmint\.dev. Its only allowlist entry is the CHANGELOG history line.src/hal0/agents/pi_coder/driver.py:506is product behaviour, filed as pi_coder driver hardcodes an operator-local path in mapPathToBank #2315.packaging/proxmox/hal0-test-template/provision.shuses/home/halo, but that's the template's own user, not an operator path.Risk grade
Touched surfaces
src/hal0/api/), comments onlyschema.py,manifest.jsonnotes)docs/, release-validation reports, CHANGELOG line)§14.1 high-risk surfaces
AUTONOMOUS_WRITE_TOOLSRollback
Rollback: revert the commit. Anyone who relied on the old
HAL0_TEST_KEYdefault sets the env var.Test tiers run
tests/release,tests/scripts,tests/packaging,tests/updater,tests/config,tests/runners,tests/registry. 3165 passed. The 2 failures intests/updateralso fail on untouched code in this container, because it runs as root. After merging currentmain:tests/scripts tests/release tests/upstreamsand the touched API tests gave 583 passed. UI lint and typecheck pass; ruff is clean.🤖 Generated with Claude Code
https://claude.ai/code/session_01JDmjmr5XP9VGp1sDwFm3rU
Generated by Claude Code