fleetd #391: refuse lead fleet replies #402

Merged
ltms merged 2 commits from worker/reply-peer-refusal-391-5a34bd-7 into main 2026-09-10 04:18:37 +02:00
Member

Fixes fleetd #391 code half. fleet_reply rejects a PRIMARY lead before MessageService or the reply inbox. The error names both fleet_send peer routes and explains why reply cannot resolve a peer message.

Follow-up: removed the permissive three-argument reply overload. FleetMcp now has one reply method, and it requires Role. Every FleetMcpTest reply call passes the role explicitly. Dropping principal(exchange).role() from the real handler now fails at compile time.

Mutation compiler error:
method reply in class dev.ltms.fleet.mcp.FleetMcp cannot be applied to given types; required: dev.ltms.fleet.msg.MessageService,java.lang.String,dev.ltms.fleet.auth.Role,java.lang.String; found: dev.ltms.fleet.msg.MessageService,java.lang.String,java.lang.String; reason: actual and formal argument lists differ in length

Build: mvn clean install passed.
Tests run: 1473, Failures: 0, Errors: 0, Skipped: 0
BUILD SUCCESS

git diff --stat for this follow-up:
fleetd/src/main/java/dev/ltms/fleet/mcp/FleetMcp.java | 5 -----
fleetd/src/test/java/dev/ltms/fleet/mcp/FleetMcpTest.java | 22 +++++++++++-----------

I checked the other FleetMcp overloads. None omit a security-relevant argument and default to a permissive value. The optional lead-channel and observation-source overloads disable or omit optional features; they do not widen caller authority.

Fixes fleetd #391 code half. `fleet_reply` rejects a PRIMARY lead before MessageService or the reply inbox. The error names both fleet_send peer routes and explains why reply cannot resolve a peer message. Follow-up: removed the permissive three-argument `reply` overload. FleetMcp now has one `reply` method, and it requires `Role`. Every FleetMcpTest reply call passes the role explicitly. Dropping `principal(exchange).role()` from the real handler now fails at compile time. Mutation compiler error: `method reply in class dev.ltms.fleet.mcp.FleetMcp cannot be applied to given types; required: dev.ltms.fleet.msg.MessageService,java.lang.String,dev.ltms.fleet.auth.Role,java.lang.String; found: dev.ltms.fleet.msg.MessageService,java.lang.String,java.lang.String; reason: actual and formal argument lists differ in length` Build: `mvn clean install` passed. `Tests run: 1473, Failures: 0, Errors: 0, Skipped: 0` `BUILD SUCCESS` `git diff --stat` for this follow-up: `fleetd/src/main/java/dev/ltms/fleet/mcp/FleetMcp.java | 5 -----` `fleetd/src/test/java/dev/ltms/fleet/mcp/FleetMcpTest.java | 22 +++++++++++-----------` I checked the other FleetMcp overloads. None omit a security-relevant argument and default to a permissive value. The optional lead-channel and observation-source overloads disable or omit optional features; they do not widen caller authority.
agent added 1 commit 2026-09-10 03:44:21 +02:00
fleetd #391: refuse lead fleet replies
CI / contract (pull_request) Successful in 1m11s
CI / build (pull_request) Successful in 1m31s
3982ace544
agent added 1 commit 2026-09-10 04:13:19 +02:00
fleetd #391: require reply caller role
CI / contract (pull_request) Successful in 1m21s
CI / build (pull_request) Successful in 1m45s
cf8da1d5fa
ltms merged commit ddd81fe174 into main 2026-09-10 04:18:37 +02:00
Sign in to join this conversation.