Repository navigation
fix(e2e-exe-dev): make NANOCLAW_E2E_FORCE_AUTH replace the vault secret - #29
Merged
Merged
Conversation
FORCE_AUTH created another anthropic secret beside the old one on both the gateway seam and the legacy auth --create --force path. OneCLI kept using an older duplicate, so a rerun with a good key still got "Invalid API key". Create the new secret, check it is listed, delete the older anthropic secrets for api.anthropic.com, and check they are gone. Also stop a running agent container that mounts this checkout's groups/e2e-agent at /workspace/agent, so the ping does not reuse the old session. Container names differ by core version, so selection is by mount. Bump to 0.12.3.
glifocat
force-pushed
the
fix/e2e-force-auth-replace
branch
from
October 1, 2026 16:13
1019d4a to
b19f0c4
Compare
glifocat
marked this pull request as ready for review
October 1, 2026 16:48
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes?
NANOCLAW_E2E_FORCE_AUTH=1is documented to replace the vault's Anthropic secret. It did not: on the gateway seam the installer ranonecli secrets createagain, and on the legacy pathsetup/auth.ts --create --forcealso only creates. Each rerun added anotheranthropicsecret forapi.anthropic.com, and OneCLI kept using an older one.Found during the nanocoai/nanoclaw#3980 e2e on 2026-10-01 (VM nc-x3980-eb45, nanoclaw 3290b9bf): after two FORCE_AUTH reruns the vault held 3 anthropic secrets, and the good-key run still got "Invalid API key". Deleting the two older secrets and stopping run 1's still-running agent container made the next run pass.
Secret replacement (
e2e-install.sh, seam and legacy paths):anthropicsecrets forapi.anthropic.combefore creating.anthropicsecrets for other hosts.Stale agent container (
FORCE_AUTH=1only):groups/e2e-agentat/workspace/agent.nanoclaw-v2-<folder>-<ms>toncl-<install>-<session>, and a name filter on old refs would also hit other installs on the same Docker daemon. The source is compared in its logical, physical-checkout and fully resolved forms, since Docker keeps the path the host passed.Plugin 0.12.3; CHANGELOG, catalog and the e2e-exe-dev SKILL.md are updated. Rebased onto nanoclaw-oss-dev-tools#28: the key-file check it added still runs first, then the old IDs are listed.
Validation
python -m unittest discover -s testswithskills/e2e-wizard/requirements.txtinstalled: 360 tests, one error. That error istest_payload_transport.test_alternate_owning_remote_transports_exact_selected_commit, which also fails on main.anthropicsecret for another host and a generic secret: only the duplicates are deleted, the new secret holds the key file's value, the create happens before the deletes, the stale container is stopped, another checkout's container and a backup container mounting the folder elsewhere are left running, and the ping passes.auth --create --force: old secret replaced.e2e-install.sh, 3 FORCE_AUTH tests fail. Withdocker stopmade a no-op, 2 fail (the fake ping answers "Invalid API key" while the stale container runs). Without the physical-checkout candidate, the symlink test fails.check_key_file(from fix(e2e-exe-dev): never score a failure notice as a ping reply #28) reads only the first 4096 characters, while the create sends the whole file. That is on main already and affects every seed, not only FORCE_AUTH.psandinspect; a daemon error that bad would also fail the ping. The tests do not prove inference against a real gateway; a live run covers that.6d8e0c91(gateway seam, OneCLI), installer from this branch at b19f0c4, one VM (nc-fa29-18c5), 2026-10-01:ping: no_reply, as expected. It left one anthropic secret and a runningncl-…agent container.NANOCLAW_E2E_FORCE_AUTH=1with a good OAuth token: the installer created the new secret, deleted the old ID and stopped the old container (d048000e0105). The ping started a new container and got a real reply. Result:STATUS: pass,PING: ok,verify: success, exit 0. Afterwards the vault held exactly one anthropic secret, the new one.AI assistance
Written with Claude Code (Opus 5.5); reviewed adversarially by Codex. Ethan reviews before it leaves draft.