CB-539 + CB-542: subscription-profile opt-in, with the env: bypass closed #14
Reference in New Issue
Block a user
Delete Branch "worker/cb-542-subscription-env-bypass-dd2a67-6"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Opened by the lead on the worker's behalf: the
gx10profile has nogitTokenEnv:set, so the worker had noGITEA_TOKENand could not create this itself. That gap is being addressed separately — it is not a defect in this change.What this is
Two commits.
73f6b12is CB-539 rebased onto currentmain(its original baseef1e014is now far behind).5afe8e1is CB-542, which closes a hole I found while reviewing CB-539 and which blocked it from merging.CB-539 —
subscription: trueLets a worker profile deliberately run on the operator's Claude subscription instead of an off-subscription endpoint. Mutually exclusive with
baseUrl; setting both is a configuration error, and spawning one logs a warning that it will bill the subscription.CB-542 — the hole that had to be closed first
subscription: trueskipsguard.assertWorkerand stops the adapter writingANTHROPIC_BASE_URL. But a profile'senv:block is layered into the worker environment separately bybaseEnv. On the old path the adapter's value overwrote anythingenv:set and the guard vetted it; on the subscription path the adapter writes nothing, so anANTHROPIC_BASE_URLsitting inenv:survived into the worker having passed no guard at all:offSubscriptionHostsnever saw it. This also falsified a published claim in wiki chapter 11, that "anenv:entry cannot repoint a worker past theSubscriptionGuard".Closed in two layers, deliberately:
validateSubscriptionProfiles(), called fromBridgedbeside the other fatal validations. It names the profile and the offending keys. Fatal rather than sanitised:subscription: trueplus anenv:repoint is a contradiction in the same waysubscription: trueplus abaseUrlis, and the operator should be told, not silently cleaned up after.The invariant landed: there is no configuration in which a worker reaches an Anthropic endpoint that no guard vetted.
Verification
I built and tested this myself in a clean worktree at
5afe8e1, rather than relying on the worker's report:mainis at 464, so this adds 10 — including a launcher test that fails without the strip and config-load tests that fail without the refusal.Review notes
ClaudeCodeLauncherTest.java, against CB-533's--modelwork. Both sides' tests were kept; I checked the region directly and confirmedtheModelFlagComesLastSoItOutranksTheOperatorsOwnArgvandaProfileWithNoModelGetsNoModelFlagboth survive intact.cb-542-subscription-env-doc), sincewiki/is a submodule. The submodule pointer is deliberately not bumped here; I do that on merge.