box/drill
claude-hdb 6f7c3bfd60 fix: run 17's four real findings — migrate retire, expose proxy, wait_box, grok PATH
The first drill run where every failure was the RELEASE CODE, not the
environment. 71 passed, 5 failed; all five traced to four bugs:

1. migrate-host --retire-legacy could NEVER succeed. Re-homing ADDS
   user.box=1 but never removed user.claudebox=1, and legacy_boxes()
   counted the old tag — so retire saw its own freshly-migrated box as
   un-migrated and refused forever ('legacy boxes still exist:
   legacybox'), leaving claudenet + claude-dev behind. Now: a verified
   re-home drops the legacy tag LAST (after the move is proven, so a
   failure anywhere above still leaves the box valid under one tag or
   the other), and legacy_boxes() ignores boxes already carrying
   user.box=1.

2. box expose died with a bare 'could not add the proxy device' — it
   swallowed incus's reason, exactly the sin this repo keeps punishing.
   Now it prints incus's error. And the mechanism is corrected: a VM's
   proxy needs NAT mode, which requires a static NIC address, so expose
   pins the box's current lease first (which also fixes the restart
   caveat — the exposure no longer points at a lease the box may lose).

3. wait_box's 2-minute window was too short: the legacy box was declared
   dead and then every migration check against it passed. 4 minutes.

4. The grok template hunted for a regular file named exactly
   'grok-build' under /home/grok and found nothing — an installer's drop
   may be a SYMLINK, and its binary name is upstream's to choose. Now it
   tries the plausible names and paths, falls back to any executable
   grok*, links both names, and SAYS what it found — or dumps what the
   installer actually left when it finds nothing. The drill likewise
   dumps the on-disk evidence and the cloud-init log on a --version
   failure instead of discarding the box.
2026-07-14 19:56:17 +00:00
..
doctor.sh feat: host lifecycle as verbs (setup-host/teardown-host/migrate-host) + .box/ convention 2026-07-14 18:01:34 +00:00
drill.sh fix: run 17's four real findings — migrate retire, expose proxy, wait_box, grok PATH 2026-07-14 19:56:17 +00:00
README.md chore: finish the debrand — env vars, install dir, docs are 'box', not 'claudebox' 2026-07-14 17:44:24 +00:00
RUNS.md docs(drill): record runs 11–13 — the contract measured at zero, from a bare host 2026-07-14 12:52:02 +00:00
wipe.sh fix: pin stdin on every non-interactive exec in the CLI — a mint wedged at 'status: done' 2026-07-14 15:07:01 +00:00

The drill

An end-to-end rehearsal of box against a real Incus: install the CLI, set up the host, mint boxes, drive the whole surface, check that the isolation actually holds — and run the full #15 audit, including a live rehearsal of the hardening #16 proposes. It ends with a block of audit answers to paste into #15.

It rearranges the host it runs on. Incus, a systemd unit, a network, an ACL, a profile, rewritten firewall rules — and, in the last phase, deliberate mutations to the network and profile. Run it on a machine you can format — a spare server, a cloud VM you'll destroy, a VM on your laptop. Not your workstation.

git clone https://github.com/heavy-duty/claudebox && cd claudebox
bash drill/drill.sh --yes      # run and forget; omit --yes to be asked first

Useful flags: --ref <branch> (drill a branch rather than main), --keep-boxes (leave the boxes up to poke at — note the last phase's network and profile mutations stay applied with them).

Exit 0 means every check passed. Roughly 20 minutes, most of it the cold box.

Something wrong with the host? bash drill/doctor.sh — it reports whether the host is fit to drill (network, profile, ACL, leftover boxes, whether a box can still resolve DNS), and --fix reverts what an aborted run left behind. The drill mutates the host in phase D; an aborted run can leave a network that mints boxes with no DNS.

Iterating on the drill? Read RUNS.md first — it is the run log: what the audit has answered so far, the bugs the drill has found in box, the traps this script has already fallen into (every one cost a run), how to diagnose a stall, and how to run a single probe by hand instead of paying for a whole run.

Why it exists

The repo has no tests and no CI, and the CLI is a shell script that shells out to incus. That means the interesting failures are not in the bash — they are in what Incus actually does, which is exactly what unit tests would stub out and get wrong. The drill runs the real thing.

What it checks

A. Incus semantics. The assumptions box is built on, probed directly: that incus config get <inst> user.claudebox returns 1 (this is on the path of every box command — if it lies, everything fails closed); that the user.claudebox=1 list filter selects our instances and excludes an untagged one; that --columns nstS gives four clean CSV fields; that the state column reads RUNNING; that incus rename really does refuse a running instance; that snapshot-list's first CSV field is the label; that an unset config key reads as empty with exit 0 (#15 B4); and that incus copy preserves user.* keys (#15 B2 — the whole template-metadata design in #17 rests on it).

B. The surface. Mint, list, info, snapshot, clone-from-a-snapshot-of-a- renamed-box, rename (running must refuse, stopped must work), the escape hatch and its isolation warning, the rm confirmation guard, and the CLI contract (typo'd command, typo'd flag, list <box>).

The boundary gets its own treatment: the drill launches an instance box did not mint, aims down, rm and the escape hatch at it, and requires all three to refuse — and the instance to still be standing afterwards.

C. Isolation baseline (#15 section A). From inside a real box: public egress works; the box cannot reach a listener on the host's claudenet gateway; RFC1918 is dropped; a sibling box is unreachable (a listener runs on the peer so "refused" — the packet arrived — cannot masquerade as "dropped"); whether DNS enumerates the sibling is recorded (#12 predicts it leaks today; that is audit data, not a failure); IPv6 is off; and the host cannot connect into a box.

D. Hardening rehearsal (#15 section B). The host is disposable, so the drill applies the exact changes #16 proposes and watches what breaks: dns.mode=none (must kill sibling resolution, must not kill egress), security.mac_filtering + security.ipv4_filtering on the NIC (the box and its in-box Docker must keep working), and @internal as an ACL drop destination on a bridge network (if accepted and egress survives, #16's sibling drop is renumber-proof by construction; if not, #16 derives the subnet instead). A FAIL in this phase is a design veto for #16, caught before the code is written.

What it does not check

claude /login — it's interactive by design, and the box is creds-free by design. The drill confirms Claude Code is installed and runnable; authenticating is yours.

If the host has no /dev/kvm, box falls back to container mode. The drill still runs, but it says loudly that the VM trust boundary was not validated rather than passing quietly on a weaker one.