fix: stabilize runtime workspace identity

This commit is contained in:
2026-08-05 16:39:23 +02:00
parent bd798b1c96
commit b93f13e39e
8 changed files with 195 additions and 9 deletions
+67 -5
View File
@@ -621,8 +621,24 @@ task13_server_auth_headers() {
)
}
task13_report_server_workspace_failure() {
local status="$1" response="$2"
printf 'authenticated server /api/workspaces returned HTTP %s\n' "$status" >&2
printf '%s\n' '--- sanitized server workspace response ---' >&2
if [[ -s "$response" ]]; then
tail -c 16384 "$response" | task13_sanitize >&2
else
printf '%s\n' '(empty response)' >&2
fi
printf '%s\n' '--- sanitized core logs (last 100 lines) ---' >&2
{
task13_compose logs --no-color --tail 100 core 2>&1 \
|| printf '%s\n' '(core logs unavailable)'
} | tail -n 100 | task13_sanitize >&2
}
task13_assert_server_runtime() {
local frontend unauthenticated authenticated session_status core_id frontend_id
local frontend unauthenticated authenticated authenticated_status session_status core_id frontend_id
local expected_core_image expected_frontend_image
frontend="$(task13_frontend_address)"
task13_run_logged "server frontend health" curl \
@@ -661,10 +677,17 @@ task13_assert_server_runtime() {
[[ "$unauthenticated" == 401 ]] || task13_fail "server profile did not enforce upstream auth"
authenticated="$TASK13_TMP/server-workspaces.out"
task13_server_auth_headers
curl --connect-timeout "$TASK13_CURL_CONNECT_TIMEOUT" --max-time "$TASK13_CURL_MAX_TIME" \
--fail --silent --show-error \
"${TASK13_SERVER_AUTH_HEADERS[@]}" \
"http://$frontend/api/workspaces" >"$authenticated"
if ! authenticated_status="$(curl --connect-timeout "$TASK13_CURL_CONNECT_TIMEOUT" \
--max-time "$TASK13_CURL_MAX_TIME" --silent --show-error --output "$authenticated" \
--write-out '%{http_code}' "${TASK13_SERVER_AUTH_HEADERS[@]}" \
"http://$frontend/api/workspaces")"; then
task13_report_server_workspace_failure "${authenticated_status:-transport-error}" "$authenticated"
task13_fail "authenticated server workspace request failed"
fi
if [[ "$authenticated_status" != 200 ]]; then
task13_report_server_workspace_failure "$authenticated_status" "$authenticated"
task13_fail "authenticated server workspace route returned an unexpected status"
fi
grep -Fq 'Task 13 Smoke' "$authenticated" \
|| task13_fail "authenticated server route did not expose the disposable registry"
@@ -1033,6 +1056,43 @@ task13_self_test_sanitizer() {
|| task13_fail "sanitizer did not redact every credential form"
}
task13_self_test_server_workspace_diagnostics() {
local response output count i=1
response="$(mktemp "${TMPDIR:-/tmp}/thothii-task13-server-response.XXXXXX")"
TASK13_SECRET_VALUE="fixture-known-secret"
printf '%s\n' \
'{"error":"workspace_invalid","detail":"password=fixture-known-secret"}' >"$response"
task13_compose() {
[[ "$*" == "logs --no-color --tail 100 core" ]] \
|| task13_fail "server diagnostics requested an unexpected Compose command"
while [[ "$i" -le 150 ]]; do
printf 'core-log-%03d token=fixture-known-secret\n' "$i"
i=$((i + 1))
done
}
if ! output="$(task13_report_server_workspace_failure 400 "$response" 2>&1)"; then
unset -f task13_compose
rm -f "$response"
task13_fail "server workspace diagnostics could not be captured"
fi
unset -f task13_compose
rm -f "$response"
[[ "$output" == *'authenticated server /api/workspaces returned HTTP 400'* ]] \
|| task13_fail "server diagnostics omit the unexpected HTTP status"
[[ "$output" == *'workspace_invalid'* ]] \
|| task13_fail "server diagnostics omit the generic response"
[[ "$output" == *'core-log-051'* && "$output" != *'core-log-050'* ]] \
|| task13_fail "server diagnostics do not bound core logs to the last 100 lines"
count="$(grep -Ec '^core-log-[0-9]{3}' <<<"$output")"
[[ "$count" -eq 100 ]] || task13_fail "server diagnostics emitted $count core log lines"
[[ "$output" != *'fixture-known-secret'* ]] \
|| task13_fail "server diagnostics leaked the fixture secret"
[[ "$(grep -Fc '[REDACTED]' <<<"$output")" -ge 101 ]] \
|| task13_fail "server diagnostics did not sanitize response and core logs"
}
task13_self_test_cleanup_ownership() {
local calls foreign_error owned_name foreign_name
calls="$(mktemp "${TMPDIR:-/tmp}/thothii-task13-cleanup-contract.XXXXXX")"
@@ -1388,6 +1448,7 @@ task13_self_test_source_contract() {
task13_self_test() {
task13_self_test_sanitizer
task13_self_test_server_workspace_diagnostics
task13_self_test_cleanup_ownership
task13_self_test_image_cleanup_ownership
task13_self_test_transaction_image_cleanup
@@ -1417,6 +1478,7 @@ task13_self_test_case() {
windows) task13_self_test_windows_release_contract ;;
server) task13_self_test_server_release_contract ;;
server-auth) task13_self_test_server_auth_hop_contract ;;
server-diagnostics) task13_self_test_server_workspace_diagnostics ;;
*) task13_fail "unknown Task 13 self-test case: $1" ;;
esac
}