Skip to content

Qualify packaged Earendil CLI synthetic provider login - #1483

Merged
piclaw-bot merged 1 commit into
mainfrom
audit/1458-packaged-cli-auth
Oct 1, 2026
Merged

piclaw-bot merged 1 commit into
mainfrom
audit/1458-packaged-cli-auth

Conversation

@piclaw-bot

Copy link
Copy Markdown
Collaborator

Qualification

Exercise the official Earendil 0.99.1 packaged interactive CLI through its public entry and /login//quit commands. Eight synthetic PTY cases cover OpenAI and Codex success, denied token exchange, bad state and cancellation.

Changes

  • Require distinct loopback-only Linux network namespaces before CLI startup; clear supplementary groups/capabilities and forbid privilege elevation. Minimal environment and owned disposable profiles.
  • Validate exact no-op browser launcher arguments by hash; stable preload intercepts bundled Codex fetch-polyfill replacement. Separate fetch counters from OS external-egress denial.
  • Assert completed CLI status, exact provider credentials, PKCE exchange and restored-editor clean exit. Negative cases assert expected rejection and no credentials.
  • Pin the verified official archive's 70-file JS bundle, OAuth modules and lockfile in ordinary-CI receipt/refusal tests.
  • Document prerequisites, initial failures and scope limitations.

Validation

  • Focused actual terminal suite plus receipt/refusal: 3 passed, 104 assertions, all eight provider/mode combinations.
  • Independent review gaps corrected and re-reviewed with no blockers.
  • Scoped strict TypeScript, Oxlint, silent-swallow and local-entrypoint checks passed.
  • Canonical gate: 5,972 passed / 8 existing or opt-in skips / 0 failures, plus 25 feature tests and 9 web checks. Optional PTY flows run separately.
  • Pack hygiene: 24,742 files. Five typechecks passed; compose retains 95 unchanged baseline diagnostics. Private Bun cache; no shared-cache permission changes.

Limits

Synthetic official Earendil CLI authentication under Bun 1.4.2 only. Piclaw distributable/production authentication routes, Node CLI, live providers, automatic browser callback, CLI refresh/logout, historical cleanup, Delegate and native MCP acceptance remain unqualified. No inference, deployment or restart. The UID retains ordinary filesystem access; no hostile-code sandbox is claimed. #1442/#1458 stay open.

The first unsandboxed probe was stopped after unexpected provider-facing validation text and excluded from qualification. Subsequent runs require OS isolation. Mounted-sysfs namespace checking and scope/error assertion mismatches were corrected; initial failures are retained locally.

Refs #1458, #1442.

@piclaw-bot
piclaw-bot merged commit f071d71 into main Oct 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants