fix(supervise): reach the queue over RPC, get bot-bottle.db off the data plane
lint / lint (push) Failing after 57s
tracker-policy-pr / check-pr (pull_request) Successful in 14s
test / unit (pull_request) Failing after 37s
test / integration-docker (pull_request) Successful in 38s
test / integration-firecracker (pull_request) Successful in 3m16s
test / coverage (pull_request) Has been skipped
test / publish-infra (pull_request) Has been skipped
lint / lint (push) Failing after 57s
tracker-policy-pr / check-pr (pull_request) Successful in 14s
test / unit (pull_request) Failing after 37s
test / integration-docker (pull_request) Successful in 38s
test / integration-firecracker (pull_request) Successful in 3m16s
test / coverage (pull_request) Has been skipped
test / publish-infra (pull_request) Has been skipped
PRD 0070's rule — only the orchestrator opens bot-bottle.db; the data plane reaches state through the control-plane RPC — was not in force. Three data-plane daemons held a direct read-write handle on the shared SQLite file: the supervise MCP server, the egress DLP addon (the most attack-exposed process, TLS-bumping hostile traffic), and the git-gate pre-receive hook. An RCE in any of them could read every bottle's plaintext identity_token and forge attribution fleet-wide (issue #469). Add the agent half of the supervise flow to the control plane: POST /supervise/propose -> queue a proposal, 201 {proposal_id} POST /supervise/poll -> non-blocking decision poll, 200 {status,...} Both attribute the caller by (source_ip, identity_token) exactly like /resolve — never a caller-supplied slug — so a bottle can only ever queue or read its own proposals even if the data plane is compromised. A decided poll archives server-side, preserving the archive-after-read contract. Data plane: the supervise server, egress addon, and git-gate hook now queue/poll through PolicyResolver.propose_supervise / poll_supervise instead of opening the DB. supervise_server keeps its ~30s grace window by polling the RPC; egress keeps its safelist keyed by resolved bottle; the git-gate hook gets (source_ip, identity_token) from the CGI env. Packaging: drop the DB bind-mount and SUPERVISE_DB_PATH from the data-plane containers/VMs (docker gateway + infra, macOS infra, firecracker infra). The orchestrator remains the sole opener of the one file via BOT_BOTTLE_ROOT / host_db_path(). Update PRD 0070: the rule is now in force; remove the transitional caveat. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -167,11 +167,14 @@ class GitHttpHandler(BaseHTTPRequestHandler):
|
||||
"SERVER_PORT": str(self.server.server_port), # type: ignore
|
||||
"SERVER_PROTOCOL": self.request_version,
|
||||
})
|
||||
# Attribute the gitleaks-allow supervise proposal (written by
|
||||
# Attribute the gitleaks-allow supervise proposal (queued by
|
||||
# receive-pack's pre-receive hook, a child of the CGI we spawn below) to
|
||||
# the calling bottle. The namespaced root is `<base>/<bottle_id>`, so its
|
||||
# final component is the bottle id — the same per-bottle key egress uses.
|
||||
env["SUPERVISE_BOTTLE_SLUG"] = sandbox_root.name
|
||||
# the calling bottle. The hook queues over the control-plane RPC (PRD
|
||||
# 0070 / issue #469), which re-resolves the bottle from these — the same
|
||||
# (source_ip, identity_token) pair that selected the namespaced root
|
||||
# above — so it can only ever queue its own proposals.
|
||||
env["SUPERVISE_SOURCE_IP"] = self.client_address[0]
|
||||
env["SUPERVISE_IDENTITY_TOKEN"] = self.headers.get(IDENTITY_HEADER, "")
|
||||
for header, variable in (
|
||||
("accept", "HTTP_ACCEPT"),
|
||||
("content-encoding", "HTTP_CONTENT_ENCODING"),
|
||||
|
||||
Reference in New Issue
Block a user