Files
fleetd/bridged
Dai Ha bb750cdba3
CI / build (pull_request) Successful in 1m7s
CI / contract (pull_request) Successful in 1m25s
CB-606: refuse an unrecognized auth.mode, per-profile placement, or top-level placement policy at config load
An auth.mode typo (e.g. "toekn") used to silently fall back to loopback-trust with no signal
anywhere — validateAuthExposure() only checks the pairing on a non-loopback bind, so on the
common loopback bind the daemon started cleanly and authenticated nobody. Per-profile placement
had the same shape, falling back to legacy pane placement. The top-level placement policy name
was already validated by PlacementPolicies.fromName, but only lazily at first spawn through
CompositePeerLauncher's Supplier; it is now checked eagerly at load, calling fromName itself as
the single source of truth.
2026-08-16 18:54:35 +02:00
..