• Joined on 2026-03-08
ltms closed issue fleet/fleetd#190 2026-09-10 02:11:28 +02:00
Process argv is a credential channel we never enumerated: 4 secrets are readable by any local user via ps
ltms commented on issue fleet/fleetd#190 2026-09-10 02:11:23 +02:00
Process argv is a credential channel we never enumerated: 4 secrets are readable by any local user via ps

Re-measured on the Mac, 2026-09-10. The exposure no longer reproduces, and I nearly reported that it had got worse.

The measurement

fleetd.jar          1 process,  0 env-names in…
ltms commented on issue fleet/fleetd#388 2026-09-10 02:07:24 +02:00
The credential scrub does not run in a shell that is neither login nor interactive — .zshenv is the only file zsh always reads, and it is the one file the scrub is not in

The "Suggested fix" in the ticket body above is wrong. Use comment 15387 instead. I am leaving the body unedited so the correction stays readable, but read that comment before you read my…

ltms commented on issue fleet/fleetd#381 2026-09-10 02:04:47 +02:00
Members cannot run shell commands: the classifier refuses every one, so they cannot build, test or open a PR (3 members, 2 profiles)

Confirmed on a full implementer job, not just a probe. When I closed this I had verified the fix with a short spawn that ran real shell commands. That left the real question open: can a…

ltms closed pull request fleet/fleetd#389 2026-09-10 02:04:25 +02:00
#386: give the stall detector a real-time clock, log the divergence
ltms closed pull request fleet/fleetd#387 2026-09-10 02:04:18 +02:00
#382: give SpawnRequest a withProfile wither, guard it against the arity trap
ltms closed issue fleet/fleetd#386 2026-09-10 02:00:24 +02:00
Every fleetd timer freezes while the macOS host sleeps: System.nanoTime() stops, so the stall detector missed a member that was BUSY for 101 minutes
ltms commented on issue fleet/fleetd#386 2026-09-10 02:00:19 +02:00
Every fleetd timer freezes while the macOS host sleeps: System.nanoTime() stops, so the stall detector missed a member that was BUSY for 101 minutes

Merged as fd8650c (PR #389), plus a follow-up test in b9d09e0. Verified here.

What landed

FleetHealthMonitor takes a second clock, realtimeClock, used only inside the stall check.…

ltms pushed to main at fleet/fleetd 2026-09-10 01:59:51 +02:00
b9d09e044e t386: pin the per-member drift baseline the fix's own tests left open
fd8650cda4 Merge #386: correct the stall check for a monotonic clock frozen by host sleep
769f282408 #386: give the stall detector a real-time clock, log the divergence
Compare 3 commits »
ltms closed issue fleet/fleetd#384 2026-09-10 01:55:28 +02:00
"left no scrub report" has a third, benign cause it does not name — a group-shared ZDOTDIR cannot receive the receipt
ltms closed issue fleet/fleetd#382 2026-09-10 01:55:23 +02:00
SpawnRequest has the arity trap's two halves, but not yet a colliding arity — CompositePeerLauncher:372 will drop the next component added
ltms commented on issue fleet/fleetd#382 2026-09-10 01:55:18 +02:00
SpawnRequest has the arity trap's two halves, but not yet a colliding arity — CompositePeerLauncher:372 will drop the next component added

Merged as fb36c52 (PR #387). Verified here, not taken on the worker's word.

What landed. SpawnRequest.withProfile(String), and CompositePeerLauncher:372 now calls it instead of…

ltms pushed to main at fleet/fleetd 2026-09-10 01:55:00 +02:00
11050e24ed t384: fix javadoc indentation on the merged shareWithGroup lines
6f71f40047 Merge #384: pre-create the scrub receipt and give it group write
fb36c5238f Merge #382: SpawnRequest.withProfile() replaces the six-accessor rebuild
cc9cdc938b #384: write shared scrub receipts
5fede82468 #382: give SpawnRequest a withProfile wither, guard it against the arity trap
Compare 5 commits »
ltms commented on issue fleet/fleetd#384 2026-09-10 01:54:45 +02:00
"left no scrub report" has a third, benign cause it does not name — a group-shared ZDOTDIR cannot receive the receipt

Merged. I verified it myself rather than taking the worker's report.

What landed. generate() now pre-creates an empty scrub-report.txt, and shareWithGroup gives that one file rw-rw----…

ltms opened issue fleet/fleetd#388 2026-09-10 01:45:28 +02:00
The credential scrub does not run in a shell that is neither login nor interactive — .zshenv is the only file zsh always reads, and it is the one file the scrub is not in
ltms pushed to main at fleet/fleetd 2026-09-10 01:43:33 +02:00
1515025804 charter: a profile differs in liveness, not just model and cost
7754f53662 Merge t385 follow-up: pin the mid-turn redelivery ack
a507f7b31b t385: pin that a redelivery is acked even while the lead is mid-turn
71c322f104 Merge #385: a redelivered lead message must not write the pane twice
fde2c15627 t385: a redelivered lead message must not write the pane twice
Compare 5 commits »
ltms closed issue fleet/fleetd#381 2026-09-10 01:38:55 +02:00
Members cannot run shell commands: the classifier refuses every one, so they cannot build, test or open a PR (3 members, 2 profiles)
ltms commented on issue fleet/fleetd#381 2026-09-10 01:38:50 +02:00
Members cannot run shell commands: the classifier refuses every one, so they cannot build, test or open a PR (3 members, 2 profiles)

Root cause found, fixed and verified live on the Mac, 2026-09-10.

The axis was never time, and it was never the profile

My earlier comment said "compare time, not profile", and told the next…

ltms closed issue fleet/fleetd#385 2026-09-10 01:29:44 +02:00
A lead-coordination message can be delivered forever: ack() returns success when connection recovery cleared the held entry
ltms commented on issue fleet/fleetd#385 2026-09-10 01:29:36 +02:00
A lead-coordination message can be delivered forever: ack() returns success when connection recovery cleared the held entry

Fixed and merged to main as 71c322f (fix) and 7754f53 (a follow-up test).

What the fix does

Two changes, in two places, because two different things were wrong.

**LeadCoordLoop…