docs(handoff): nebula-verifier-guard — the two-tier split that hid a broken script, and a battery that cannot be certified - #1434
Open
ZacxDev wants to merge 4 commits into
Open
Conversation
…), its headline guard proven re
…ack PASS on BOTH tiers, closin
…able from its first commit MEASURED on the merged tree (origin/main 8a9ebba + this branch), running the doc-reading gates directly: FAILED scripts/tests/test_no_client_hostnames.py::test_no_client_subdomain_literal_is_committed 1 failed, 692 passed in 278.03s Four occurrences of a real client subdomain in a doc tracked by a PUBLIC repo. TWO OF THEM (lines 136, 142) came from this branch's FIRST commit c578351, so this PR has been red since it was opened and nobody had gated it — a docs-only change reads as gate-exempt and is not: test_doc_path_rot, test_no_client_hostnames, test_no_public_ips, test_no_captured_text and test_no_captured_markup all read tracked files. Redacted in place rather than allowlisted. Allowlisting would disarm a gate over a genuine leak — the finding itself (rank 2: the literal is still reachable in git history at 6d488a1, and all four content gates are blind to history) is unchanged and still open. The meaning of each sentence is preserved; only the literal is gone. Not fixed by handoff_doc.py because its Gotchas/Open-investigations sections APPEND: a merge cannot remove text from them, and three of the four occurrences were in already-committed prose. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012Jq8nmf8ZHZkJ56enFiaM1 Claude-Session-Id: 9d71983b-623b-4cfb-b261-7263073b277e
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Canonical handoff for the
nebula-verifier-guardeffort. New doc — no existing handoff references #1407 or #1420, and the four that mentionapply-nebula-relay.shdo so only as untracked files blockingship.sh.The session's stated goal is DONE and verified:
home-manager switchis clean on both hosts (only the upstreaminstall→addline remains, which upstream fixed then reverted for Lix). #1384, #1398, #1407 merged and shipped; #1410 closed as obsolete.What the doc is actually for is the work that goal uncovered:
mainwas red for two unrelated reasons; one was feat(nebula): advertise a nebula relay — a read-only check, and the sudo apply beside it #1272 merging on a dev-host green while the nix sandbox — which has no/usrat all — failed 20 tests on a#!/usr/bin/envshebang.M-FH-1as SURVIVED for a mutation measured by hand as failing two tests. Box load 64–93 throughout.It also advances an existing open item in the subsystem index:
test_live_cotenants_sees_another_process_in_the_reporecurred, and #1340's diagnostic — the one that bullet's NEXT PROBE asked for — returnedcwd='<gone>' cmdline='<gone>', so the capture has to move to detection time.Ranked next steps carry
forcing:tags; five of six are honestlyforcing: noneand flagged as not eligible to be worked.