Skip to content

fix(e2e-exe-dev): validate the whole credential file as sent - #30

Merged
glifocat merged 2 commits into
mainfrom
fix/check-key-file-whole-value
Oct 1, 2026
Merged

glifocat merged 2 commits into
mainfrom
fix/check-key-file-whole-value

Conversation

@glifocat

@glifocat glifocat commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

What changes?

check_key_file in e2e-install.sh (added by #28) and the matching host check in exe-run.sh read only the first 4096 characters of the credential file. Every consumer sends the whole file with CR/LF removed: onecli secrets create on the gateway seam, auth --create [--force] --value on the legacy path, and KEY_VALUE for iron-proxy.

So a valid sk-ant- key, then enough blank lines to pass 4096 characters, then other text, passed the check, and the extra text was stored with the key. Since #29, NANOCLAW_E2E_FORCE_AUTH=1 then deleted the working old secret.

  • Both checks now read the file as bytes and check the whole value as sent (CR/LF removed). This matches proxmox-run.py, which already reads the whole file.
  • A file over 64 KiB is refused. The limit counts bytes, so CRLF padding cannot get around it.
  • The value is never printed, as before.

Plugin 0.12.4; CHANGELOG and catalog updated.

Validation

  • Offline, at 2e1f416 (on main 06dfa90), python -m unittest discover -s tests with skills/e2e-wizard/requirements.txt installed: 362 tests, one error. That error is test_payload_transport.test_alternate_owning_remote_transports_exact_selected_commit, which also fails on main.
  • New cases:
    • exe-run.sh driver: key + 5000 newlines + text is refused before any VM call (exit 66).
    • Installer, legacy path: same file is never seeded.
    • Installer, seam + FORCE_AUTH: same file fails, secrets create never runs, and the old secret stays in the vault.
    • Installer: a file over 64 KiB is refused, with LF and with CRLF padding.
  • All four fail against main's scripts and pass with this change.
  • Codex adversarial review, 2 rounds: 1 finding (CRLF slipped past the size limit because text mode counts characters), fixed; second round "No defects found".
  • No live run: this only changes the file check, before any gateway call.

check_key_file and exe-run.sh read only the first 4096 characters, but
every consumer sends the whole file with CR/LF removed. A valid key plus
enough blank lines and trailing text passed, the text was stored with
the key, and NANOCLAW_E2E_FORCE_AUTH=1 then deleted the working secret.
Check the full value and refuse files over 64 KiB.
Text mode folds CRLF before counting, so CRLF padding halved the
apparent size and slipped past the 64 KiB limit.
@glifocat
glifocat marked this pull request as ready for review October 1, 2026 17:16
@glifocat
glifocat merged commit da32732 into main Oct 1, 2026
2 checks passed
@glifocat
glifocat deleted the fix/check-key-file-whole-value branch October 1, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant