6bef94ea0d03cd95a3e9af52b9d2c3e44a7839cc
3
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
6bef94ea0d |
fix(mosaic): close dup-proxy race + verify listener identity (re-review #2, #790)
ci/woodpecker/pr/ci Pipeline was successful
Addresses the three items from PR #793 re-review #2, all TDD red-first on this branch: F1 (BLOCKER, dup-proxy race) — ensureProxyRunning no longer falls back to nohup after `systemctl start` is ACCEPTED. An accepted-but-not-yet-healthy systemd unit may bind late or be restarted; spawning nohup then would create a second proxy contending for :18765. Once systemd accepts the job we poll to the startup deadline and, on a miss, report a managed-service startup failure. nohup is now reachable only when systemd never accepted the job. New test: "does NOT fall back to nohup after systemd accepts but never binds". F2 (BLOCKER, CWE-345) — a 2xx on /healthz is liveness, not identity. Added verifyListenerIdentity(): an OS-level check (via `ss` + /proc) that the process owning :18765 is the current uid running the expected proxy executable, failing CLOSED (`unknown`) when identity can't be established — needs no upstream shared-secret/unix-socket support. ensureProxyRunning now gates EVERY trust point on it: an already-present responder that fails identity returns `untrusted` without starting anything; a started proxy is trusted only once it is both live AND identity-verified. probeLiveness doc-comment updated to record the residual CWE-345 risk and point at the identity check (multi-user warning deferred). F3 (SHOULD-FIX) — parseAuthStatus no longer treats a signal-terminated check (status null) with an auth-looking line as valid; a clean exit 0 is required. Regression test: { status: null, stdout: 'Authenticated' } → unknown. Gates green: typecheck, lint, format:check; full mosaic suite 1110 passing; claudex-proxy.ts coverage 92.3% stmts/lines, 88.13% branch (>= 85%). Co-Authored-By: Claude Opus 4.8 <[email protected]> |
||
|
|
7f987f52fc |
fix(mosaic): harden claudex proxy preflight per review (P1 of #790)
ci/woodpecker/pr/ci Pipeline was successful
Addresses the four findings from the independent review of #793 (exact head
|
||
|
|
0e41a5c264 |
feat(mosaic): claudex proxy preflight + lifecycle helpers (P1 of #790)
ci/woodpecker/pr/ci Pipeline was successful
P1 of the `mosaic yolo claudex` launcher (#790): pure, dependency-injected preflight and lifecycle helpers for `raine/claude-code-proxy` (the local Anthropic->Codex translation proxy on 127.0.0.1:18765). No session launch yet; the isolated CLAUDE_CONFIG_DIR composition + env-injection land in PR-2. Authored test-first (spec written and run red before implementation, then green). 39 unit tests, 89.6% statement/line coverage on the new module; the only uncovered lines are the process-spawning system wrappers (systemd/nohup/wait), which are integration glue unsuitable for unit spawning. Helpers: - checkProxyBinary — binary presence via an injectable `which` resolver. - parseAuthStatus / checkAuthStatus — coarse OAuth state from `codex auth status`. Carries NO token material (state + optional expiry only) so token-shaped output can never leak downstream. - runDeviceReauth — `codex auth device` with stdio:'inherit' so the device code streams to the user's TTY; the launcher never captures/logs it or sees the resulting token. - probeLiveness — gotcha #1: ANY HTTP response (incl. non-2xx) = alive; only a transport failure/timeout = dead. NEVER `curl -f` (that spawned duplicate proxies). Bounded by an explicit timeout race so a hung socket can't wedge. - buildSystemdUnitContent / systemdUnitPath / installSystemdUnit — systemd --user unit management; unit carries no credential material. - runProxyPreflight — structured binary+auth+liveness report. - ensureProxyRunning — no-op when live, else systemd-preferred with nohup fallback, re-probing after each attempt so it never spawns a duplicate. Refs #790. Not part of the #758 fleet DAG. Co-Authored-By: Claude Opus 4.8 <[email protected]> |