R-890: the test box (scratch 9202) may seed vaultwarden through its admin invite, inside the box
gates / gates (push) Successful in 7s

`09` §3 decision 149. box_admin_seed_allowed(): not the bench, FELHOM_BOX_ADMIN_SEED=1,
demo-hp/9202 only, an app this run installed, the box on the drill catalog. The token is read
inside the box and handed to curl on stdin; only HTTP codes come back.
Tests: BoxAdminSeedGuard (red-proved).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-06 13:39:48 +02:00
parent 65130c6c03
commit 6b4877d556
4 changed files with 185 additions and 3 deletions
+4
View File
@@ -233,6 +233,9 @@ DRIVE = "/mnt/felhom-drives/scratch_hdd/userdata"
# password back off the box — the household sees it once. So the value the harness itself
# generated is kept here for the life of the run, and nowhere else.
GENERATED = {}
# The apps THIS run installed (deploy() adds one on its 202). The test-box admin seed refuses an app not in it: an app
# the walk merely reused may be a household's (upgrade_fixtures_box.box_admin_seed_allowed, R-890).
DEPLOYED_THIS_RUN = set()
def deploy_values(name, sub):
@@ -297,6 +300,7 @@ def deploy(name, sub, extra_values=None):
say(f" [1] deploy -> {code} {str(d)[:120]}")
if code != "202":
return False
DEPLOYED_THIS_RUN.add(name)
# WAIT FOR `deployed`, NOT FOR `running`. Measured 2026-09-21 on tandoor: docker reported the
# container `healthy` while the controller's own state read `unhealthy` — a gate on `running`
# alone therefore times out on an app that is up. The state is RECORDED rather than required;