forked from heavy-duty/ceremony
Four corrections from @codex-reviewer-andresmgsl on 9c17a9e:
- changelog.d/202.md keeps !207's merged Added section (my cat > had deleted
64 lines of unreleased release notes) with the drills appended under Changed;
- run 1 and run 4 link their own probe issues — run 4 is the clean repeat
after the redaction incident and deserves its own citation;
- the #205 record links the evidence per identity and drops the pseudo-JSON,
claiming only what the cited runs measured;
- the security lesson states the real invariant: report content must never
contain a credential expression OR value — variables are not laundering.
Refs #202
76 lines
3.6 KiB
Markdown
76 lines
3.6 KiB
Markdown
### Added
|
|
|
|
- `docs/RUNNER-PROBES.md` documents the standing runner-probe venue,
|
|
`heavy-duty/ceremony-runner-probe` — the place runner-only facts are measured
|
|
on demand, ruled as option A by the operator (#202).
|
|
|
|
- `drills/README.md` cross-links it beside the disposal rule, so the exception
|
|
is visible where the dangerous habit lives (#202).
|
|
|
|
- The runbook states that the drill disposal rule does **not** apply to it.
|
|
Archiving it defeats its purpose, and that is exactly how the three existing
|
|
drill repos each became unavailable (#202).
|
|
|
|
- It records that a probe must run as an Actions job under the workflow token:
|
|
the same call answers 500 there and 204 under a PAT, so a probe run any other
|
|
way produces a confident wrong answer (#202).
|
|
|
|
- Creating the repo is recorded as the operator's step, measured rather than
|
|
assumed: a fleet identity gets 403 on org repo creation and 201 in its own
|
|
namespace (#202).
|
|
|
|
- It carries an executable two-layer arming procedure: an immutable candidate
|
|
code SHA and an armed workflow commit on top of it. A single layer is
|
|
self-referential — rewriting a workflow makes a new commit, and a commit
|
|
cannot contain its own object ID (#202).
|
|
|
|
- Callers are pinned by layer: composite actions to the candidate code SHA,
|
|
reusable workflows to the armed SHA, which is the only revision whose inner
|
|
checkout points at the fork (#202).
|
|
|
|
- The arming gate asserts what each carrier IS, not only that the old literal
|
|
is gone: every `repository:` equals the fork, every `CEREMONY_SELF_REF` value
|
|
equal the candidate code SHA, and callers match the layer they belong to
|
|
(#202).
|
|
|
|
- It enumerates the carriers from the tree rather than encoding a count, and
|
|
distinguishes ceremony's internal self-checkouts from the consumer checkouts
|
|
that must stay `${{ github.repository }}` (#202).
|
|
|
|
- Both published snippets are ShellCheck-clean when extracted and linted
|
|
directly, not merely as part of the repository sweep (#202).
|
|
|
|
- The checker validates the MANIFEST against the target it was given, so a
|
|
manifest that describes a wrong arming consistently — wrong fork, or the
|
|
armed SHA where the candidate belongs — refuses instead of matching a tree
|
|
rewritten to the same wrong value (#202).
|
|
|
|
- The manifest is generated from the PRE-arming tree, which is the only order
|
|
that enumerates the carriers that must change (#202).
|
|
|
|
- Both published snippets were driven against a constructed candidate/probe
|
|
pair: deletion, both role swaps, wrong owner, wrong
|
|
SHA, wrong path, a deleted caller class and an extra carrier all refuse, and
|
|
the armed control passes (#202).
|
|
|
|
- The manifest records complete caller coordinates, so a path swapped under the
|
|
right owner and SHA is caught (#202).
|
|
|
|
- Generator and checker share one domain — ceremony callers — so a third-party
|
|
`actions/checkout` is neither manifested nor reported as unrecognised (#202).
|
|
|
|
- Probe results are written to an issue in the probe repo and carried to the
|
|
ceremony issue by a human, so the probe holds no path that can write to the
|
|
live board (#202).
|
|
|
|
### Changed
|
|
|
|
- `docs/RUNNER-PROBES.md` records the venue's first delivered drills — the
|
|
#192 asymmetry re-observed on demand under the workflow token, the dispatch
|
|
route's 204 under both identities, and #215's boundary finding — each with
|
|
the probe-issue URL it is recorded in (#202).
|
|
|
|
- Two venue lessons join the runbook where the next probe author will look:
|
|
findings must be written to issues because the venue's log route 404s for
|
|
non-admin reads, and report content sent to the forge must never contain a
|
|
credential expression or value (#202).
|