R-890: the test box (scratch 9202) may seed vaultwarden through its admin invite, inside the box
gates / gates (push) Successful in 7s
gates / gates (push) Successful in 7s
`09` §3 decision 149. box_admin_seed_allowed(): not the bench, FELHOM_BOX_ADMIN_SEED=1, demo-hp/9202 only, an app this run installed, the box on the drill catalog. The token is read inside the box and handed to curl on stdin; only HTTP codes come back. Tests: BoxAdminSeedGuard (red-proved). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -233,6 +233,9 @@ DRIVE = "/mnt/felhom-drives/scratch_hdd/userdata"
|
||||
# password back off the box — the household sees it once. So the value the harness itself
|
||||
# generated is kept here for the life of the run, and nowhere else.
|
||||
GENERATED = {}
|
||||
# The apps THIS run installed (deploy() adds one on its 202). The test-box admin seed refuses an app not in it: an app
|
||||
# the walk merely reused may be a household's (upgrade_fixtures_box.box_admin_seed_allowed, R-890).
|
||||
DEPLOYED_THIS_RUN = set()
|
||||
|
||||
|
||||
def deploy_values(name, sub):
|
||||
@@ -297,6 +300,7 @@ def deploy(name, sub, extra_values=None):
|
||||
say(f" [1] deploy -> {code} {str(d)[:120]}")
|
||||
if code != "202":
|
||||
return False
|
||||
DEPLOYED_THIS_RUN.add(name)
|
||||
# WAIT FOR `deployed`, NOT FOR `running`. Measured 2026-09-21 on tandoor: docker reported the
|
||||
# container `healthy` while the controller's own state read `unhealthy` — a gate on `running`
|
||||
# alone therefore times out on an app that is up. The state is RECORDED rather than required;
|
||||
|
||||
Reference in New Issue
Block a user