fix(supervise): reach the queue over RPC, get bot-bottle.db off the data plane
PRD 0070's rule — only the orchestrator opens bot-bottle.db; the data plane reaches state through the control-plane RPC — was not in force. Three data-plane daemons held a direct read-write handle on the shared SQLite file: the supervise MCP server, the egress DLP addon (the most attack-exposed process, TLS-bumping hostile traffic), and the git-gate pre-receive hook. An RCE in any of them could read every bottle's plaintext identity_token and forge attribution fleet-wide (issue #469). Add the agent half of the supervise flow to the control plane: POST /supervise/propose -> queue a proposal, 201 {proposal_id} POST /supervise/poll -> non-blocking decision poll, 200 {status,...} Both attribute the caller by (source_ip, identity_token) exactly like /resolve — never a caller-supplied slug — so a bottle can only ever queue or read its own proposals even if the data plane is compromised. A decided poll archives server-side, preserving the archive-after-read contract. Data plane: the supervise server, egress addon, and git-gate hook now queue/poll through PolicyResolver.propose_supervise / poll_supervise instead of opening the DB. supervise_server keeps its ~30s grace window by polling the RPC; egress keeps its safelist keyed by resolved bottle; the git-gate hook gets (source_ip, identity_token) from the CGI env. Packaging: drop the DB bind-mount and SUPERVISE_DB_PATH from the data-plane containers/VMs (docker gateway + infra, macOS infra, firecracker infra). The orchestrator remains the sole opener of the one file via BOT_BOTTLE_ROOT / host_db_path(). Update PRD 0070: the rule is now in force; remove the transitional caveat. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -112,11 +112,13 @@ class TestGitHttpBackend(unittest.TestCase):
|
||||
).strip()
|
||||
self.assertEqual(head, cloned)
|
||||
|
||||
def test_consolidated_push_stamps_bottle_slug_for_the_hook(self):
|
||||
# In consolidated mode the backend attributes the push by source IP and
|
||||
# stamps SUPERVISE_BOTTLE_SLUG=<bottle_id> into the CGI env, so the
|
||||
# gitleaks-allow pre-receive hook queues its proposal under the right
|
||||
# bottle. The hook here just records what it received.
|
||||
def test_consolidated_push_stamps_supervise_attribution_for_the_hook(self):
|
||||
# In consolidated mode the backend attributes the push by (source IP,
|
||||
# identity token) and stamps SUPERVISE_SOURCE_IP + SUPERVISE_IDENTITY_TOKEN
|
||||
# into the CGI env, so the gitleaks-allow pre-receive hook can queue its
|
||||
# proposal over the control-plane RPC (which re-resolves the bottle from
|
||||
# exactly that pair — PRD 0070 / issue #469). The hook here just records
|
||||
# the source IP it received.
|
||||
from http.server import ThreadingHTTPServer
|
||||
|
||||
bottle_id = "bottleab12"
|
||||
@@ -130,10 +132,10 @@ class TestGitHttpBackend(unittest.TestCase):
|
||||
["git", "-C", str(bare), "config", "http.receivepack", "true"],
|
||||
check=True,
|
||||
)
|
||||
capture = root / "slug-capture"
|
||||
capture = root / "source-ip-capture"
|
||||
hook = bare / "hooks" / "pre-receive"
|
||||
hook.write_text(
|
||||
f"#!/bin/sh\nprintf '%s' \"${{SUPERVISE_BOTTLE_SLUG:-UNSET}}\" > "
|
||||
f"#!/bin/sh\nprintf '%s' \"${{SUPERVISE_SOURCE_IP:-UNSET}}\" > "
|
||||
f"{capture}\ncat >/dev/null\nexit 0\n"
|
||||
)
|
||||
hook.chmod(0o755)
|
||||
@@ -166,7 +168,7 @@ class TestGitHttpBackend(unittest.TestCase):
|
||||
["git", "push", url, "HEAD:refs/heads/main"],
|
||||
cwd=work, check=True, capture_output=True, text=True, timeout=5,
|
||||
)
|
||||
self.assertEqual(bottle_id, capture.read_text())
|
||||
self.assertEqual("127.0.0.1", capture.read_text())
|
||||
|
||||
def test_post_forwards_git_cgi_headers(self):
|
||||
from http.server import ThreadingHTTPServer
|
||||
|
||||
Reference in New Issue
Block a user