fleetd #509: pin the pane-scan completeness fold; harden legacyPrincipal #515
Reference in New Issue
Block a user
Delete Branch "worker/509-4912f4-2"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes fleetd #509.
Unit 1 — Added a PaneLocatorTest case (
anEarlierClientsErrorSurvivesALaterClientsCleanNegative) that constructs a two-client PaneLocator where the lead client errors on the pane that would have owned the pid (incomplete, negative scan) and the member client cleanly reports no panes (complete, negative scan). The real fold at PaneLocator.java:117 (complete = complete && outcome.complete();) ANDs both into false; a mutant that keeps only the last client's outcome (complete = outcome.complete();) reads it as true. Verified: with the mutant applied, the new test fails withexpected: <false> but was: <true>; the file was restored byte-identical (sha256 unchanged before/after); control run afterwards is green.Unit 2 —
FleetMcp.legacyPrincipal's else-branch returnedPrincipal.primaryfor any caller the connection did not resolve to a worker pane, with none ofCallerResolver.java:254'sisLoopback/scanCompleteguards. Measured: no production caller passescallers == null(Fleetd.java:696 always builds a real CallerResolver), butFleetMcpAuthzTest.mcp(false)legitimately does, for its documented "legacy constructor leaves the gate open" test — so this is a supported legacy mode, not dead code (rules out option a). Took option (b): changed the else-branch toPrincipal.anonymous(), widenedlegacyPrincipalto package-private (mirroringdenyFor's precedent) so a new test (legacyPrincipalIsAnonymousNotPrimaryForAnUnresolvedCaller) pins it directly.Build:
mvn -f fleetd/pom.xml clean install— Tests run: 1696, Failures: 0, Errors: 0, Skipped: 0. BUILD SUCCESS.Nothing outside the assigned scope was touched. Not run: IDE diagnostics (no IDE MCP mount available to this worker).