Files
felhom.eu/scripts/manifest_bearer_gate.py
T
admin 574f5df107
gates / gates (push) Failing after 17s
the decoy sweep: 29 gates read, 16 fooled, 10 fixed - and a gate that refuses the next one (R-421)
THE CLASS, now a row: an instrument that matches a LABEL rather than the fact it names. Five
instances - R-410, R-400, R-378, R-419, R-94 - and EVERY ONE was found by accident, by someone
looking at something else. The gates enforce every other rule in this project, including the rule
that findings must be written down rather than left in prose. Nothing had ever checked the gates.

METHOD, and it is the transferable part: for each gate, construct the label WITHOUT the fact - a
directory with the right name and no bake log, a handler case that exists only in a comment, a note
whose prose mentions the marker it lacks - run the gate, record what it says. No verdict was reached
by reading. Reading is how all five hid.

RESULT: 29 distinct scripts (35 registrations; three are shared across three runners). 19 sound, 4
holes left OPEN with rows, 6 that no plausible decoy could be built for and are named UNTESTED rather
than called sound. A gate nobody tried to fool is UNKNOWN.

SCOPE IS A FACT TOO - the largest single cause, and mundane. Eight gates decided what to look at with
os.listdir, one level. Every one was green AND CORRECT today, and every one would have gone blind the
moment anyone added a subdirectory. mojibake and docker-v already used os.walk, caught the identical
planted file, and are the control that proves the cause was the listing and not the decoy.

IN THIS REPO: hub-confirm and manifest-bearer now walk. observations_gate (R-419, CLOSED) requires a
marker at a line start or after a sentence boundary and strips inline code spans - a note SAYING it
carries no marker no longer satisfies the marker test. closed-register now CONVICTS on a row it
cannot parse instead of warning: FOUR rows were in that state, TWO of them written by the session
that closed them the day before, and every one was exempt from the only check that reads that file.
The rows were repaired first and the conviction added second - registering a failing gate refuses
every push.

THE META-GATE: decoy_coverage_gate.py refuses a gate registered without a decoy or a named exemption.
It convicted ITSELF the moment it was registered, which is how it came to have one. Coverage is a
DECLARATION the gate AST-parses, never a grep - searching a test file for a gate's name would be the
very shape this sweep exists to find. The 20 uncovered gates are listed by name (R-426).

NOT FIXED, each with a row and a decoy asserting TODAY's behaviour so the fix must be deliberate:
R-422 reuse-refs (only 7 extensions; a rotted .md citation is invisible), R-423 site (PAGES is a
hardcoded list of 7), R-424 one-register (a defect parked as `idea`), R-425 offbox-rename (fixed
FILES list). R-427: closed_register_gate checks ONE direction - twelve open rows carry a closed
verdict and were NOT moved, because telling finished from partly-finished is a judgement and R-378
is the record of a machine getting it wrong.

FIVE DECOYS WITHDRAWN AS ILLEGITIMATE, mine, named in the audit. A decoy nobody would write proves
nothing, and manufacturing a finding to fill a row is worse than an honest NO.

No product code. No version bump. No image. No golden owed. All four runners green.
Register: OPEN 172 -> 178, CLOSED 160 -> 161.
2026-09-01 12:39:45 +02:00

60 lines
2.9 KiB
Python

# -*- coding: utf-8 -*-
"""Manifest bearer-literal gate (v0.53.0, part of the hub bearer de-git) — no bearer-shaped
literal (64 hex chars, the `openssl rand -hex 32` shape every felhom bearer/API key uses) may
appear ANYWHERE in manifests/, comments included. Secrets ride out-of-band `kubectl create
secret` + secretKeyRef (documentation/runbooks/secrets.md); the manifests carry only
placeholders. The other known committed secrets in felhom.secret.yaml (passwords, non-hex
shapes) are a tracked backlog item (secrets.md) and are NOT matched by this gate — extend the
patterns when they are de-gitted.
Run from the repo root: python scripts/manifest_bearer_gate.py
Exit 1 on any hit.
(Named "bearer", not "secret": the repo .gitignore's `*secret*` pattern — which guards real
secret files — would silently un-track a gate with "secret" in its filename.)
"""
import io, os, re, sys
ROOT = "manifests"
# 64 hex chars with no hex/word neighbors (so longer blobs and sha256-of-file hexes embedded in
# longer strings still match at 64+, but ordinary short ids never do).
BEARER = re.compile(r"(?<![0-9a-fA-F])[0-9a-fA-F]{64}(?![0-9a-fA-F])")
# KNOWN BACKLOG (non-fatal, stays VISIBLE): felhom.secret.yaml commits pre-existing secrets
# (umami APP_SECRET is 64-hex) tracked for de-git in documentation/runbooks/secrets.md — out of
# the bearer-de-git scope (2026-07-13 operator ruling batch). Remove this carve-out when that
# file is cleaned; new bearer literals must NOT be hidden behind it.
KNOWN_BACKLOG = {"felhom.secret.yaml"}
def main():
total = 0
# AT ANY DEPTH. Was os.listdir(ROOT), one level only — measured 2026-09-01 to miss a
# bearer-shaped literal in manifests/overlays/ (R-421). There are no subdirectories today; an
# overlays/ or base/ directory is an ordinary thing to add, and the gate would have stayed green.
paths = []
for dirpath, _dirs, names in os.walk(ROOT):
for fn in sorted(names):
if fn.endswith((".yaml", ".yml")):
paths.append(os.path.join(dirpath, fn))
for path in sorted(paths):
fn = os.path.basename(path)
for lineno, line in enumerate(io.open(path, encoding="utf-8", errors="replace"), 1):
for m in BEARER.finditer(line):
masked = m.group(0)[:8] + "..." + m.group(0)[-4:]
if fn in KNOWN_BACKLOG:
print("%s:%d KNOWN-BACKLOG committed secret %s (secrets.md de-git backlog; not this gate's failure)"
% (path, lineno, masked))
continue
total += 1
print("%s:%d bearer-shaped literal %s" % (path, lineno, masked))
if total:
print("MANIFEST BEARER GATE FAILED: %d bearer-shaped literal(s) in manifests/" % total)
sys.exit(1)
print("manifest bearer gate OK - no bearer-shaped literals in manifests/")
if __name__ == "__main__":
main()