9b50dd69d8
Part of #145 (CB-632), under epic #125. The product is called fleet and the daemon is called fleetd, but the code still said bridge everywhere. This renames the Java half: package dev.ltms.bridged -> dev.ltms.fleet Bridged -> Fleetd (the main class) BridgedConfig -> FleetConfig BridgeMcp -> FleetMcp BridgedApp -> FleetApp BridgedMetrics -> FleetMetrics The package root is dev.ltms.fleet, not dev.ltms.fleetd. The trailing d means daemon, which names a process, not a namespace. What this commit deliberately does NOT change: - The module directory stays bridged/, and <finalName> stays bridged. The installed launchd plist names bridged/target/bridged.jar and its KeepAlive is armed, so renaming the jar on its own strands a restart. Both change at the cutover, together with the plist, in one step. - The bridge_* MCP tool aliases. CB-622 shipped both names on purpose. One test names a local variable viaBridge because it holds the result of the deprecated call; the rename collided with it and the compiler caught it. That variable is back. - BRIDGED_* env var names, and bridged.yaml. Both are operator contracts and need a read-both shim, which is a later unit. Two things a plain search-and-replace would have missed: - logback.xml and logback-test.xml name the package twice, once as a turboFilter class= attribute. The compiler never checks those. - BSD sed does not support \b. The word-boundary expression matched nothing and said nothing, while the other ten in the same command worked. Checked the leftovers instead of trusting the exit code. Verified: mvn clean install green, 51 test classes, 878 tests, 0 failures -- the same count as before the rename.
40 lines
1.7 KiB
Java
40 lines
1.7 KiB
Java
package dev.ltms.fleet.auth;
|
|
|
|
/**
|
|
* What a caller is allowed to be on the bus (CB-501).
|
|
*
|
|
* <p>The ordering matters conceptually: {@link #PRIMARY} is the <em>most</em> privileged role
|
|
* (it spawns, stops, sends to any session, and drains any inbox), not the least. Before CB-501
|
|
* the daemon reached {@code PRIMARY} by <em>failing</em> every other check — any caller that did
|
|
* not resolve to a known worker pane was treated as the primary. That is inverted here:
|
|
* {@link #ANONYMOUS} is the fallback, and {@code PRIMARY} must be established.
|
|
*/
|
|
public enum Role {
|
|
|
|
/**
|
|
* The orchestrating session. Established either by being a loopback caller that is not a
|
|
* worker pane (under {@code loopback-trust}) or by presenting a valid bearer token (under
|
|
* {@code token} mode).
|
|
*/
|
|
PRIMARY,
|
|
|
|
/**
|
|
* A worker peer, identified by its herdr pane. Unforgeable: derived from the connection's
|
|
* loopback peer PID via herdr's PID→pane map, never from a request argument.
|
|
*/
|
|
WORKER,
|
|
|
|
/**
|
|
* A config-declared architect slot (CB-548): a gateway-local named session on a strong-model
|
|
* profile that coordinates and delegates turns but does not own the fleet. Unforgeable like a
|
|
* worker's — derived from the connection's pane and the live terminal→slot binding, never from
|
|
* a request argument. May {@code SEND} a turn, {@code REPLY}/{@code ASK} only as its own pane,
|
|
* and {@code READ}/{@code METRICS}; may <em>not</em> {@code SPAWN}/{@code STOP}/{@code DRAIN}
|
|
* (those stay the primary's, to keep lifecycle in one pair of hands).
|
|
*/
|
|
ARCHITECT,
|
|
|
|
/** Authenticated as nothing. Authorized for nothing but {@code /healthz}. */
|
|
ANONYMOUS
|
|
}
|