fix(work): import hashlib and wire heal subparser into main CLI
This commit is contained in:
@@ -150,3 +150,41 @@ cat shared/operators/SOUL.md | ssh -o StrictHostKeyChecking=no -J super@34.139.3
|
||||
2. **Safety Gates on Amendments**: `box md amend` automatically validates that amendments do not remove checklists or revert `SOUL.md` to passive templates.
|
||||
3. **Relative Paths in Hatch RPC**: Hatch WebSocket RPC rejects absolute paths (`/SOUL.md` fails; `SOUL.md` succeeds).
|
||||
4. **Dual Access Redundancy**: If SSH reverse tunnels drop, Hatch WebSocket RPC is independent of SSH and can be used immediately to inspect logs, repair `authorized_keys`, or restart watchdog scripts.
|
||||
|
||||
---
|
||||
|
||||
## 5. SSH Access-Management Decisions (DRAFT — grill interview in progress)
|
||||
|
||||
> Status: DRAFT. Each decision below is written as the interview settles it.
|
||||
> Nothing here is Final until the owner explicitly accepts the full text.
|
||||
> Context: 2026-10-07 key-resolution run — all 5 agents refused dial-in key
|
||||
> install via chat relay (impersonation-pattern defense); keys were placed
|
||||
> via the operator Hatch channel instead; file modes remain the open gap.
|
||||
|
||||
### Scope contract (SETTLED — Draft)
|
||||
- **Artifact boundary**: Section 5 of this file (the decision record) PLUS
|
||||
approval of execution stages E1–E3 below. Out of scope: code changes,
|
||||
other doc rewrites, and any new PR or task program beyond E1–E3.
|
||||
- **Done means**: Scope + D1–D5 + E1–E3 all written as settled text; the
|
||||
owner explicitly accepts the full section; then it flips to Final.
|
||||
- **Stages**: E1–E3 are approved here as plans with named owners and
|
||||
verification steps. Ending the interview never authorizes
|
||||
implementation — execution needs a separate explicit request afterward.
|
||||
- Set by owner choice ("1" = wider-boundary alternative) on 2026-10-07.
|
||||
|
||||
### D1. `.ssh/authorized_keys` validator allowlist (UNRESOLVED)
|
||||
- Whether the exact-match allowlist in `agent_md.py` (`MD_ALLOWED_SUBPATHS`)
|
||||
stays as the permanent operator key-install mechanism.
|
||||
|
||||
### D2. Authority boundary: platform writes vs relayed instructions (UNRESOLVED)
|
||||
- Whether operator Hatch writes are a legitimate access-grant channel when
|
||||
agents refuse the same grant via chat relay, and under what conditions.
|
||||
|
||||
### D3. bl→VM jump-key provisioning (UNRESOLVED)
|
||||
- The sanctioned process for getting bl operator SSH access to the jump host.
|
||||
|
||||
### D4. def/dev tunnel restoration (UNRESOLVED)
|
||||
- Who provisions tunnel identities and VM-side authorization once jump works.
|
||||
|
||||
### D5. File-mode gap on the Hatch write path (UNRESOLVED)
|
||||
- How `authorized_keys` gets to 600 given the gateway cannot set modes.
|
||||
|
||||
Reference in New Issue
Block a user