Skip to content

docs(handoff): nebula-verifier-guard — the two-tier split that hid a broken script, and a battery that cannot be certified - #1434

Open
ZacxDev wants to merge 4 commits into
mainfrom
docs/handoff-nebula-verifier-guard
Open

docs(handoff): nebula-verifier-guard — the two-tier split that hid a broken script, and a battery that cannot be certified#1434
ZacxDev wants to merge 4 commits into
mainfrom
docs/handoff-nebula-verifier-guard

Conversation

@ZacxDev

@ZacxDev ZacxDev commented Sep 9, 2026

Copy link
Copy Markdown
Member

Canonical handoff for the nebula-verifier-guard effort. New doc — no existing handoff references #1407 or #1420, and the four that mention apply-nebula-relay.sh do so only as untracked files blocking ship.sh.

The session's stated goal is DONE and verified: home-manager switch is clean on both hosts (only the upstream installadd line remains, which upstream fixed then reverted for Lix). #1384, #1398, #1407 merged and shipped; #1410 closed as obsolete.

What the doc is actually for is the work that goal uncovered:

It also advances an existing open item in the subsystem index: test_live_cotenants_sees_another_process_in_the_repo recurred, and #1340's diagnostic — the one that bullet's NEXT PROBE asked for — returned cwd='<gone>' cmdline='<gone>', so the capture has to move to detection time.

Ranked next steps carry forcing: tags; five of six are honestly forcing: none and flagged as not eligible to be worked.

ZacxDev and others added 4 commits September 9, 2026 00:16
…erences #1407 or #1420, and the

Claude-Session-Id: 4b14058c-f3f5-4988-ae42-90910f7dbe43
…able from its first commit

MEASURED on the merged tree (origin/main 8a9ebba + this branch), running the
doc-reading gates directly:

  FAILED scripts/tests/test_no_client_hostnames.py::test_no_client_subdomain_literal_is_committed
  1 failed, 692 passed in 278.03s

Four occurrences of a real client subdomain in a doc tracked by a PUBLIC repo.
TWO OF THEM (lines 136, 142) came from this branch's FIRST commit c578351, so
this PR has been red since it was opened and nobody had gated it — a docs-only
change reads as gate-exempt and is not: test_doc_path_rot, test_no_client_hostnames,
test_no_public_ips, test_no_captured_text and test_no_captured_markup all read
tracked files.

Redacted in place rather than allowlisted. Allowlisting would disarm a gate over
a genuine leak — the finding itself (rank 2: the literal is still reachable in
git history at 6d488a1, and all four content gates are blind to history) is
unchanged and still open. The meaning of each sentence is preserved; only the
literal is gone.

Not fixed by handoff_doc.py because its Gotchas/Open-investigations sections
APPEND: a merge cannot remove text from them, and three of the four occurrences
were in already-committed prose.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012Jq8nmf8ZHZkJ56enFiaM1
Claude-Session-Id: 9d71983b-623b-4cfb-b261-7263073b277e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant