c033b3b617
gates / gates (push) Successful in 20s
Measured 2026-09-16: 25 minutes after a successful bind AND claim the console still showed the pairing code under a line promising the screen refreshes itself. print_bound_banner is printed the moment the bind delivery lands. It does NOT name the dashboard URL: the one-shot delivery carries the customer id, passphrase and mode, not the domain, so naming an address would mean inventing one. The residue — the console still does not reflect the later CLAIM, because this unit has exited by then — is recorded in the changelog rather than implied away. Not published: the built image needs the release gate and the operator's yes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
43 lines
2.7 KiB
Plaintext
43 lines
2.7 KiB
Plaintext
## 2026-09-16T15:03:10Z Part C.1 — the grant, narrowest role FIRST, measured at every step
|
|
--- BEFORE: effective permissions of felhom@pbs at the datastore ROOT (where R-534 failed):
|
|
Privileges with (*) have the propagate flag set
|
|
|
|
--- try the NARROWER role first: DatastorePowerUser
|
|
Privileges with (*) have the propagate flag set
|
|
|
|
Path: /datastore/felhom-offsite
|
|
- Datastore.Backup (*)
|
|
- Datastore.Prune (*)
|
|
## 2026-09-16T15:03:42Z DatastorePowerUser does NOT carry Datastore.Modify (measured above: Backup + Prune only).
|
|
## PBS has no role-create command and no custom roles, so the next role up is the narrowest that works.
|
|
--- apply DatastoreAdmin at the datastore ROOT for the hub user only:
|
|
--- remove the DatastorePowerUser line so exactly one entry remains:
|
|
--- AFTER: effective permissions at the datastore root:
|
|
Privileges with (*) have the propagate flag set
|
|
|
|
Path: /datastore/felhom-offsite
|
|
- Datastore.Audit (*)
|
|
- Datastore.Backup (*)
|
|
- Datastore.Modify (*)
|
|
- Datastore.Prune (*)
|
|
- Datastore.Read (*)
|
|
- Datastore.Verify (*)
|
|
--- AFTER: the full ACL table (nothing else changed):
|
|
+========================+=======================================+===========+=================+
|
|
| ugid | path | propagate | roleid |
|
|
+========================+=======================================+===========+=================+
|
|
| felhom@pbs | /datastore/felhom-offsite | 1 | DatastoreAdmin |
|
|
+------------------------+---------------------------------------+-----------+-----------------+
|
|
| felhom@pbs | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
|
+------------------------+---------------------------------------+-----------+-----------------+
|
|
| felhom@pbs | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
|
+------------------------+---------------------------------------+-----------+-----------------+
|
|
| felhom@pbs | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
|
+------------------------+---------------------------------------+-----------+-----------------+
|
|
| felhom@pbs!demo-felhom | /datastore/felhom-offsite/demo-felhom | 1 | DatastoreBackup |
|
|
+------------------------+---------------------------------------+-----------+-----------------+
|
|
| felhom@pbs!demo-hp | /datastore/felhom-offsite/demo-hp | 1 | DatastoreBackup |
|
|
+------------------------+---------------------------------------+-----------+-----------------+
|
|
| felhom@pbs!tester-1 | /datastore/felhom-offsite/tester-1 | 1 | DatastoreBackup |
|
|
+========================+=======================================+===========+=================+
|