Conversation
`environment-domains-and-dev-certificates.md` §4 puts the development-certificate minting tooling in this repo, "parametric over root, domains and validity", because the scheme is shared by metacraft-labs, agent-harbor and blocksense and each of them runs its own root CA under it. So the tool names no org: everything comes from a JSON spec, which is the consumer repo's `lib/dev-certificates.nix` evaluated. Three subcommands. `init-root` generates the root key and self-signed root, and refuses to overwrite either — re-minting a root invalidates every issued leaf and every machine's trust store at the same instant, so that is never an overwrite. `mint` issues one leaf per spec row, keys for the caller to seal and `fullchain.pem` to commit in the clear. `report` is §4.1: it prints remaining validity for every leaf and EXITS NON-ZERO below the threshold, counting a never-minted leaf as a failure rather than a skip. The guard worth having is the reserved-TLD refusal. A private root that can issue for `codetracer.com` is a private root that can impersonate production to everyone who trusts it, and every workstation in the org will trust this one. The spec is hand-edited, so the refusal sits next to the key rather than in review, and it covers `.local` explicitly — §2 rules mDNS out by name, and a guard that accepted it would route around that. §7 says certificates being installed is not evidence that TLS works, so the test is not a file-shape assertion: it mints a real root and real leaves and completes a real verified handshake against `openssl s_server`, both for a wildcard name and for the apex. Three negative controls make that mean something — a name the leaf does not carry must be REJECTED on a verification error (not on a refused connection), and a client with no trust anchor must refuse the leaf. 35 assertions, green by hand and inside the Nix sandbox at this commit. Two of those controls earned their place immediately. The reserved-TLD guard shipped rejecting every legitimate name, because `local name="$1" bare="$name"` expands all of `local`'s words before performing any of its assignments, so `bare` was empty and every name fell through to the refusal. And the handshake's own readiness probe consumed `-naccept 1`'s single slot, so the client met a closed port — at which point the negative control passed for exactly that wrong reason. It now asserts on the verification message.
|
Thanks for your Pull Request! Below you will find a summary of the cachix status of each package, for each supported platform.
|
`prek run --all-files` is red on `dev` for two files neither of which this
branch touches, so it is red on every PR opened against it. Red lint is not
pre-existing noise to merge past — it is the thing to fix first — so it is fixed
here, in its own commit.
`terraform/github/README.md` had a closing code fence with prose on the same
line:
```
repositories = map (r: r // (…)) inventory.repositories;
``` The `mergeQueues` output reports each queued
Prettier's own fix for that is to escalate the fence to FOUR backticks, which is
why this is worth a careful look rather than an `--all-files --fix`: a 4-backtick
fence would have swallowed the next seventy lines of prose — through the
`protectedRepos` paragraph and the second code block — into one code block. The
defect is the fence, so the fence is what is repaired: it closes on its own line
and the sentence starts a new paragraph. Prettier then wants no change at all.
`upstream-patches/garm-busy-runner-reap/fix.patch` ended with a blank line.
end-of-file-fixer removes it; the last content line keeps its newline, so the
patch is unchanged as a patch.
`prek run --all-files` is clean at this commit.
`__darwinAllowLocalNetworking = true` on the check derivation. macOS's Nix sandbox denies even loopback unless a derivation asks for it, so the four handshake subtests would have failed on an aarch64-darwin builder while passing on Linux — the exact asymmetry that makes a green Linux leg misleading. The attribute is ignored on other platforms, so it is set unconditionally. This is preemptive and the darwin leg stays UNVERIFIED: no darwin builder was available, and the aarch64-darwin CI batch that would have exercised it died with "the self-hosted runner lost communication with the server" before reporting anything. Both the check and this commit message say so rather than implying coverage. Also: the EXIT trap now kills the TLS server. `stop_srv` runs on the happy path, but a failed assertion between `serve` and it would leave an `openssl s_server` holding a port on a shared self-hosted runner for as long as the machine stays up. 35/35 by hand and in the Nix sandbox at this commit.
On the five failing checks: four are pre-existing on
|
| Check | Verdict | How |
|---|---|---|
t_garm_pools_labels |
pre-existing | drv path byte-identical to origin/dev (m6jhrg8f…-vm-test-run-t_garm_pools_labels.drv) — and it is the same path the job reported building. Same inputs cannot give a different result |
t_garm_webhook_delivery |
pre-existing | drv path byte-identical to origin/dev |
mcl-devops-no-stale-references |
pre-existing, and a false positive | built the dev variant: same message, same line — checks/pre-commit.nix:50, a comment about a flake-parts config.mcl, which is a different mcl. The gate's own output labels it [tool named in prose] |
deployment-no-default-cachix-deploy-call |
pre-existing | built the dev variant: same AssertionError: workflow must default non-nix-runner to the ephemeral Linux class |
ci / batch 3/6 | aarch64-darwin |
infrastructure | the only annotation is "The self-hosted runner lost communication with the server". No test failed; the log is gone |
The last two of those four have different drv paths from dev, because both
hash the whole source tree — adding any file changes the hash. That difference is
not evidence of causation, which is why I compared the messages instead. "The drv
differs" is the easy wrong conclusion there.
One real fix came out of chasing it
376eab2 adds __darwinAllowLocalNetworking = true to the check. macOS's Nix
sandbox denies even loopback unless a derivation asks, so the four handshake
subtests would have failed on an aarch64-darwin builder while passing on Linux —
the exact asymmetry that makes a green Linux leg misleading. The darwin leg is
still unverified: no darwin builder was available here, and the batch that
would have exercised it is the one whose runner died.
It also makes the EXIT trap kill the TLS server, so a failed assertion cannot leave
an openssl s_server holding a port on a shared self-hosted runner.
35/35 by hand and in the Nix sandbox at 376eab2.
What this means for merging
This PR cannot reach an all-green CI while dev is red, so merging it is a
judgement about the four known failures rather than about this branch. The issue
above is the record to check them against.
Update: the failure count moved to 7, and one of the new ones I can only partly attributeRe-running changed the darwin picture, so correcting my own table rather than
On batch 5/6, what I can and cannot show. But I am not claiming that settles it, because the drv named in the CI log is So: two runner drops, three established pre-existing, and one darwin package failure |
environment-domains-and-dev-certificates.md§4 puts the development-certificateminting tooling in this repo, parametric over root, domains and validity,
because the scheme is shared by metacraft-labs, agent-harbor and blocksense and
each runs its own root CA under it. The tool therefore names no org — everything
comes from a JSON spec, which is the consumer repo's
lib/dev-certificates.nixevaluated:
What it does, and the one thing it refuses
init-rootgenerates the root key (umask before keygen, not chmod after)and a self-signed root with
CA:true,pathlen:0. It refuses to overwriteeither output: re-minting a root invalidates every issued leaf and every
machine's trust store at the same instant, so that is never an overwrite.
mintissues one leaf per spec row, verifies each one against the root itwas just signed by and that it carries every requested SAN, then writes
fullchain.pem(leaf first, then root) and a mode-600 key.reportis §4.1: remaining validity for every leaf, exit non-zerobelow the threshold, and a never-minted leaf counts as a failure, not a skip.
The refusal that matters is the reserved-TLD guard. A private root that can
issue for
codetracer.comis a private root that can impersonate production toeveryone who trusts it — and every workstation in the org will trust this one.
The spec is hand-edited, so the guard sits next to the key rather than in review.
It covers
.localexplicitly, because §2 rules mDNS out by name and a guard thatquietly accepted it would route around that.
It deliberately does not seal anything. Sealing needs the consumer repo's
agenix recipient set, which is an evaluation of that flake; reaching for it
here would make this package depend on a tree it cannot see. The caller seals.
The test is a handshake, not a file-shape assertion
§7: "certificates being installed is not evidence that TLS works." So
scripts/tests/dev-certificates-minting.shmints a real root and real leaveswith real openssl and completes a real verified handshake against
openssl s_server— for a wildcard name and for the apex — with three negativecontrols so the positive one means something:
not on a refused connection;
35 assertions, 35 passing, by hand and inside the Nix sandbox, at
d741a43. It runs in CI as the flake checkdev-certificates-minting, and isrunnable by hand with
bash scripts/tests/dev-certificates-minting.sh(bash,openssl, jq).
Two of those controls earned their place immediately, which is the honest
argument for writing them:
local name="$1" bare="$name"expands all oflocal's words beforeperforming any of its assignments, so
barewas empty and everything fellthrough to the refusal. A positive-only test would have called that a pass.
-naccept 1's single slot,so the client met a closed port — and the negative control then passed for
exactly that wrong reason. It now asserts on the verification message.
Checks run locally at
d741a43nix build .#checks.x86_64-linux.dev-certificates-minting— 35/35.nix build .#packages.x86_64-linux.mint-dev-certificates— builds; thewrapper is ShellCheck-clean via
writeShellApplication.shellcheck -S warningon both scripts — clean.prek run --files <the five touched files>in.#pre-commit— all hooks pass.aarch64-darwin was not available here; the script handles the GNU/BSD
statanddatesplits explicitly, and the check runs under nixpkgs' bash rather than thesystem one, but the darwin leg is unverified.
Follow-on
The consumer side lands in
metacraft-labs/infra: the declared domain set(
lib/dev-certificates.nix, PR #1677), the agenix-sealed leaf keys, and theNixOS / nix-darwin module that installs §5's
/etc/mcl-dev-certslayout plusthe system trust store.