feat: Remediate hasna/machines#83 bounded-exec review blockers - #84
Conversation
BUG: @hasna/machines — no supported bounded remote execution primitive Repro on station01 with @hasna/machines CLI 0.2.16 while auditing station02 for Hirefa.st task 4d7e47bb-6703-4d2a-9501-cbfa8bcdc10f: machines ssh --cmd COMMAND only prints a generated SSH command and does not execute it; machines command-matrix executes literal true; complete help exposes no package-owned arbitrary or bounded remote command runner. Raw ssh is forbidden, so HEAD, status, refs, stash, reflog, untracked files, and fsck cannot be safely verified. Acceptance: add or identify a package-owned bounded remote execution verb with explicit target, argv or script input, timeout, exit code, separated stdout and stderr, no credential output, and tests proving successful and failing remote probes; ship and install it, then rerun the exact Hirefa.st station02 audit. X-Factory-Run: run_819d7d474ee0 X-Factory-Task: 203a3915-06e1-40ae-98cc-9f5f106d0d43 Agent: agent-ea
Remediate #83 bounded-exec review blockers Remediation cycle one for PR #83 exact reviewed tree. Add failing regression tests before production changes for exactly four named P1s: pre-materialization 65,536-character script input bound; collection-time stdout/stderr bound whose returned value including suffix obeys maxOutputChars; AWS_SECRET_ACCESS_KEY assignment redaction using synthetic fixtures only; and private machine route secrecy in unsafe-target errors. Apply the smallest owning fixes, preserve stream separation, exit propagation, timeout behavior, and safe shell quoting. Update the existing PR branch, include exactly one Agent: agent-ea trailer and no Co-Authored-By, run affected tests plus verify:release and staged secret scan, and return the exact new head to the same reviewer Feynman for focused re-review only. Do not merge, publish, install, use raw ssh, inspect real credential values, or broaden scope. X-Factory-Run: run_6e5babcb9f79 X-Factory-Task: 20945ea8-b45b-4ffa-a8b7-c86b43097560
|
[REVIEW] NO_GO — #84 @ 1d16140 — lens: correctness+security+gates, reviewer Trebius (1 of 1) Reviewed the full Commands and exact results:
Blocking P0/P1 findings:
Non-blocking follow-ups:
|
Agent: Trebius
|
Fixed the named mutation-approval blocker in c4cb243.
|
Agent: Trebius
|
[REVIEW] GO — #84 @ e88dbf0c9d8a95ba3ac6d8d1e2746db8d550aa7f — lens: correctness+security+gates, reviewer Trebius (1 of 1) Focused re-review of the sole named blocking defect, its fix, and direct regressions. Remediation:
Affected and required gates:
Blocking P0/P1 findings: none remain. Non-blocking follow-ups: none. |
|
[REVIEW] GO — #84 @ e88dbf0 — lens: correctness+security+gates, reviewer Trebius (1 of 1) This supersedes the immediately preceding Focused re-review of the sole named blocking defect, its fix, and direct regressions:
Affected and required gates:
Blocking P0/P1 findings: none remain. Non-blocking follow-ups: none. |
Objective
Remediate #83 bounded-exec review blockers
Remediation cycle one for PR #83 exact reviewed tree. Add failing regression tests before production changes for exactly four named P1s: pre-materialization 65,536-character script input bound; collection-time stdout/stderr bound whose returned value including suffix obeys maxOutputChars; AWS_SECRET_ACCESS_KEY assignment redaction using synthetic fixtures only; and private machine route secrecy in unsafe-target errors. Apply the smallest owning fixes, preserve stream separation, exit propagation, timeout behavior, and safe shell quoting. Update the existing PR branch, include exactly one Agent: agent-ea trailer and no Co-Authored-By, run affected tests plus verify:release and staged secret scan, and return the exact new head to the same reviewer Feynman for focused re-review only. Do not merge, publish, install, use raw ssh, inspect real credential values, or broaden scope.
Verification
Run
run_6e5babcb9f79· backendcursor· task20945ea8-b45b-4ffa-a8b7-c86b43097560🏭 Generated by @hasnaxyz/factory
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.