• Joined on 2026-03-08
ltms closed pull request fleet/fleetd#268 2026-09-04 03:26:38 +02:00
fleetd #266: rename SSH agent environment setting
ltms closed pull request fleet/fleetd#269 2026-09-04 03:26:36 +02:00
fleetd #184: stop claiming memberHerdrSocket proves a different OS user
ltms pushed to main at fleet/fleetd 2026-09-04 03:23:51 +02:00
2fa673d4c0 Merge #270: ArchUnit package-cycle test with explicit accepted exceptions (#131)
9020d01b40 Merge #268: rename sshAuthSock values to omit/inherit with a read-both shim (#266)
1006805027 fleetd #131: enforce package boundaries with an ArchUnit cycle test
d42c2bc204 fleetd #266: rename SSH agent environment setting
Compare 4 commits »
ltms pushed to main at fleet/fleetd 2026-09-03 15:27:45 +02:00
27aefbf9a0 Merge #269: stop claiming memberHerdrSocket proves a different OS user (#184 item 5)
3916adc372 fleetd #184: stop claiming memberHerdrSocket proves a different OS user
Compare 2 commits »
ltms opened issue fleet/fleetd#267 2026-09-03 15:10:34 +02:00
The #175 model-mismatch check never runs for opencode spawns without a provisioned worktree — the majority of them
ltms commented on issue fleet/fleetd#184 2026-09-03 15:06:26 +02:00
blocking SSH_AUTH_SOCK is not a control: the forge key is an unencrypted file the member can read

Split out #266 — memberCredentials.sshAuthSock's value names (block/allow) make the same kind of claim this ticket is about, one layer down. block names an effect fleetd does not have: it…

ltms opened issue fleet/fleetd#266 2026-09-03 15:05:20 +02:00
memberCredentials.sshAuthSock: rename the values block/allow to omit/inherit — "block" names something fleetd does not do
ltms commented on issue fleet/fleetd#184 2026-09-03 11:54:37 +02:00
blocking SSH_AUTH_SOCK is not a control: the forge key is an unencrypted file the member can read

Item 1 is done — merged as fa97f59 (PR #265). fleetd now logs the member trust model at startup, and the message changes when memberHerdrSocket is set. The unset branch says plainly…

ltms commented on pull request fleet/fleetd#265 2026-09-03 11:54:26 +02:00
fleetd #184: report member trust model

Merged to main as fa97f59.

I re-ran the mutation proof myself rather than taking the report on trust. Breaking the configured branch (if (false && ...)) turns MemberTrustModelReportTest…

ltms closed pull request fleet/fleetd#265 2026-09-03 11:53:39 +02:00
fleetd #184: report member trust model
ltms pushed to main at fleet/fleetd 2026-09-03 11:53:18 +02:00
fa97f598dd Merge #265: state the member trust model at startup (#184)
ea9aa4fd77 fleetd #184: report member trust model
Compare 2 commits »
ltms commented on issue fleet/fleetd#184 2026-09-03 11:45:17 +02:00
blocking SSH_AUTH_SOCK is not a control: the forge key is an unencrypted file the member can read

Item 1 progress — the "write down the truth" half is done, the startup warning is in flight.

Done: the config no longer lies

PR #264, merged as b5ddbe5, with a follow-up in a2b8caf. The…

ltms closed pull request fleet/fleetd#264 2026-09-03 11:43:24 +02:00
fleetd #184: correct sshAuthSock guidance
ltms commented on pull request fleet/fleetd#264 2026-09-03 11:43:19 +02:00
fleetd #184: correct sshAuthSock guidance

Merged to main as b5ddbe5, with a follow-up in a2b8caf. Build: 1262 tests, 0 failures.

The correction itself is right, and the four points I asked for are all there in plain language. Thank…

ltms pushed to main at fleet/fleetd 2026-09-03 11:43:01 +02:00
a2b8caf6b5 #184: keep the reason SSH_AUTH_SOCK matters, and the measurement
b5ddbe5757 Merge #264: sshAuthSock is not a control, and the config now says so (#184)
d223a93039 fleetd #184: correct sshAuthSock guidance
Compare 3 commits »
ltms commented on issue fleet/fleetd#184 2026-09-03 11:37:31 +02:00
blocking SSH_AUTH_SOCK is not a control: the forge key is an unencrypted file the member can read

I put this to an architect as a design question — "what is the honest security boundary we can actually build, and what should we stop claiming?" — rather than as an implementation job. Its…

ltms closed pull request fleet/fleetd#262 2026-09-03 11:36:10 +02:00
fleetd #103: document systemd worker secrets
ltms closed issue fleet/fleetd#103 2026-09-03 11:36:04 +02:00
CB-605: the systemd unit has launchd's login-shell secret gap, and does not mention the two tokens it drops
ltms commented on issue fleet/fleetd#103 2026-09-03 11:35:59 +02:00
CB-605: the systemd unit has launchd's login-shell secret gap, and does not mention the two tokens it drops

Fixed. PR #262 merged to main as e2fe861, with a follow-up correction in f0e7ac7.

What shipped

Route B — document it completely. The worker picked this over sourcing the secret store,…

ltms closed issue fleet/fleetd#257 2026-09-03 11:35:37 +02:00
fleet_list's free and the spawn gate now disagree by one on subscription profiles