Fix review findings: secrets in snapshots, URL spoofing, migration data loss
Adversarial review of the branch produced findings across four areas. This addresses them, plus the Windows CI environment. Secrets. commit_container_snapshot baked the container's full env into the per-project snapshot image, so the shared OAuth token — and the AWS keys, git token and gateway master key — outlived revocation and were readable via docker inspect. Verified against Engine 29.6 that a commit body's config merges over the container's: keys cannot be dropped but can be overwritten, so all of them now commit as KEY=. clear_claude_token additionally rewrites images from earlier builds and reports honestly when a tag could not be rewritten. The recommendation to move the token out of env entirely was not taken, with reasoning: apiKeyHelper is a different auth method that outranks CLAUDE_CODE_OAUTH_TOKEN rather than a transport for it, and no file-based delivery exists. The durable exposure — the image — is what is closed here. Separately noted, not fixed: entrypoint.sh captures the token into the scheduler's .env inside the persisted volume. URL spoofing. Three call sites reached openUrl with container-controlled strings, one of which the review missed (the WebLinksAddon handler). The sign-in URL was scraped from container output with a longest-match tie-break and no userinfo check, so claude.ai@evil.tld rendered as "claude.ai…" in a truncating element. There is now one sanitizer in front of every sink — scheme allowlist, no userinfo, C0/C1 and quote rejection, host allowlist for the sign-in case, first-match — and the origin renders un-truncated. The toast is keyed so a changed URL remounts, closing a bait-and-switch where the user read one URL and clicked another. Migration. The rollback pin was best-effort: a tag failure was logged and the migration continued past remove_container, after which the final commit overwrote the only copy of the old system layer. It now aborts before anything destructive and reads the tag back. /var was destroyed while the ordinary recreate path preserves it — making the "safe" alternative to Reset more destructive than Reset's alternative; data-bearing subtrees are now detected and disclosed in the pre-flight rather than copied, since tarring a live database onto a different base's packages is a corruption risk. resume_migration now verifies the migration-state label instead of reporting success for a container that never swapped. dismiss actually resolves the record rather than leaving the feature permanently refusing to migrate. Start and Reset are guarded while a migration is live. Lifecycle. The gateway no longer publishes on 0.0.0.0 — bind address and advertised URL are derived together so they cannot drift. Disabling it now stops it. App exit runs teardown concurrently under a budget with a visible shutting-down state instead of blocking for minutes. Auto-starts retry when Docker is not up yet, and the polling-recovery path now reconciles, so interrupted migrations are still recovered. Auth-bridge forwards are capped, closing a container-driven fd exhaustion. Windows CI. build-windows failed on this branch with "linker link.exe not found". The runner had no MSVC build tools and the workflow assumed a hand-provisioned machine, so a bare runner registers, accepts jobs and fails at link time after downloading the whole crate graph. The job now installs the VC++ workload when vswhere cannot find it, matching how it already conditionally installs Rust and Node. 192 Rust tests, 274 frontend tests, both builds clean, zero warnings. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -18,6 +18,7 @@ const FRESH: ContainerStaleness = {
|
||||
apt_delta: [],
|
||||
npm_global_delta: [],
|
||||
verbatim_paths: [],
|
||||
unpreserved_data: [],
|
||||
outdated_package_count: 0,
|
||||
probe_error: null,
|
||||
};
|
||||
@@ -40,6 +41,7 @@ function migration(overrides: Partial<ContainerMigration> = {}): ContainerMigrat
|
||||
return {
|
||||
staleness: null,
|
||||
probing: false,
|
||||
probeSettled: true,
|
||||
running: false,
|
||||
recovered: false,
|
||||
interrupted: null,
|
||||
@@ -51,7 +53,7 @@ function migration(overrides: Partial<ContainerMigration> = {}): ContainerMigrat
|
||||
resume: vi.fn(async () => {}),
|
||||
keep: vi.fn(async () => {}),
|
||||
rollback: vi.fn(async () => {}),
|
||||
dismiss: vi.fn(),
|
||||
dismiss: vi.fn(async () => {}),
|
||||
refresh: vi.fn(async () => {}),
|
||||
...overrides,
|
||||
};
|
||||
@@ -173,7 +175,7 @@ describe("ContainerMigrationBanner", () => {
|
||||
});
|
||||
renderBanner(m);
|
||||
expect(
|
||||
screen.getByText(/A container base update was interrupted/i),
|
||||
screen.getByText(/The container base update did not finish/i),
|
||||
).toBeInTheDocument();
|
||||
expect(screen.getByText(/part-way onto the new base/i)).toBeInTheDocument();
|
||||
// The plain "Update container base…" call to action must not be what is
|
||||
@@ -207,6 +209,36 @@ describe("ContainerMigrationBanner", () => {
|
||||
expect(screen.getByRole("button", { name: "Resume update" })).toBeInTheDocument();
|
||||
});
|
||||
|
||||
it("distinguishes an unsettled probe from a running container", () => {
|
||||
// "Stop the container to update its base" on a container that is already
|
||||
// stopped — because the probe has not landed — reads as a bug.
|
||||
renderBanner(
|
||||
migration({ staleness: STALE, probing: true, probeSettled: false }),
|
||||
false,
|
||||
);
|
||||
expect(
|
||||
screen.getByText(/Checking what this container has/i),
|
||||
).toBeInTheDocument();
|
||||
expect(
|
||||
screen.queryByText(/Stop the container to update its base/i),
|
||||
).not.toBeInTheDocument();
|
||||
});
|
||||
|
||||
it("names the /var data that updating would destroy", () => {
|
||||
renderBanner(
|
||||
migration({
|
||||
staleness: {
|
||||
...STALE,
|
||||
unpreserved_data: [
|
||||
{ path: "/var/lib/postgresql", bytes: 41_000_000, file_count: 912 },
|
||||
],
|
||||
},
|
||||
}),
|
||||
);
|
||||
expect(screen.getByText("/var/lib/postgresql")).toBeInTheDocument();
|
||||
expect(screen.getByText(/back this up before updating/i)).toBeInTheDocument();
|
||||
});
|
||||
|
||||
describe("the report", () => {
|
||||
const CLEAN: MigrationReport = {
|
||||
phase: "succeeded",
|
||||
@@ -295,6 +327,39 @@ describe("ContainerMigrationBanner", () => {
|
||||
expect(screen.getByRole("button", { name: "Dismiss" })).toBeInTheDocument();
|
||||
});
|
||||
|
||||
it("never offers Keep over a container that is still mid-swap", () => {
|
||||
// The failing-commit path returns a report *and* leaves the record
|
||||
// interrupted. Keep would untag the rollback image and delete the record
|
||||
// while `triple-c-snapshot-<id>:latest` still points at the old lineage —
|
||||
// and the backend's own message on that record says to resume.
|
||||
const m = migration({
|
||||
staleness: STALE,
|
||||
interrupted: {
|
||||
phase: "interrupted",
|
||||
from_image_id: "sha256:aaa",
|
||||
to_base_id: "sha256:bbb",
|
||||
started_at: "2026-08-09T10:00:00Z",
|
||||
report: null,
|
||||
rollback_image: "triple-c-snapshot-p1:pre-migration-20260809-100000",
|
||||
staging_path: null,
|
||||
options: { replay_packages: true, copy_paths: true, keep_rollback: true },
|
||||
plan: null,
|
||||
},
|
||||
report: {
|
||||
...CLEAN,
|
||||
phase: "failed",
|
||||
message: "saving it failed. Resume it, or roll back.",
|
||||
},
|
||||
});
|
||||
renderBanner(m);
|
||||
expect(screen.queryByRole("button", { name: "Keep" })).not.toBeInTheDocument();
|
||||
expect(
|
||||
screen.getByRole("button", { name: "Resume update" }),
|
||||
).toBeInTheDocument();
|
||||
fireEvent.click(screen.getByRole("button", { name: "Roll back" }));
|
||||
expect(m.rollback).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
|
||||
it("does not describe rollback as a time machine", () => {
|
||||
renderBanner(migration({ staleness: FRESH, report: CLEAN }));
|
||||
expect(
|
||||
|
||||
@@ -2,7 +2,8 @@ import type { ContainerMigration } from "../../../hooks/useContainerMigration";
|
||||
import Button from "../../ui/Button";
|
||||
import StatusIndicator from "../../ui/StatusIndicator";
|
||||
import MigrationReportCard from "../MigrationReportCard";
|
||||
import { ROLLBACK_SCOPE, formatSnapshotDate, joinFeatures } from "../migrationCopy";
|
||||
import MigrationInterruptedCard from "../MigrationInterruptedCard";
|
||||
import { formatSnapshotDate, joinFeatures } from "../migrationCopy";
|
||||
|
||||
interface Props {
|
||||
migration: ContainerMigration;
|
||||
@@ -31,8 +32,38 @@ export default function ContainerMigrationBanner({
|
||||
canMigrate,
|
||||
onOpen,
|
||||
}: Props) {
|
||||
const { staleness, running, recovered, interrupted, report, phaseMessage, busy } =
|
||||
migration;
|
||||
const {
|
||||
staleness,
|
||||
probing,
|
||||
probeSettled,
|
||||
running,
|
||||
recovered,
|
||||
interrupted,
|
||||
report,
|
||||
phaseMessage,
|
||||
busy,
|
||||
} = migration;
|
||||
|
||||
// An unfinished migration outranks its own report. The report's action row
|
||||
// offers Keep, and Keep on a mid-swap container drops the rollback image
|
||||
// while `:latest` still points at the old lineage — the backend's message on
|
||||
// the very same record says to resume. Resume is the only honest primary
|
||||
// action here, so the report card is not rendered at all.
|
||||
if (interrupted) {
|
||||
return (
|
||||
<section
|
||||
className={`${SHELL} border-[var(--error)]/40 bg-[var(--error-muted)]`}
|
||||
aria-label="Container base update was interrupted"
|
||||
>
|
||||
<MigrationInterruptedCard
|
||||
record={interrupted}
|
||||
busy={busy || running}
|
||||
onResume={() => void migration.resume()}
|
||||
onRollback={() => void migration.rollback()}
|
||||
/>
|
||||
</section>
|
||||
);
|
||||
}
|
||||
|
||||
// The report outranks staleness: after a run, the outcome is the news.
|
||||
if (report) {
|
||||
@@ -50,7 +81,7 @@ export default function ContainerMigrationBanner({
|
||||
busy={busy}
|
||||
onKeep={() => void migration.keep()}
|
||||
onRollback={() => void migration.rollback()}
|
||||
onDismiss={migration.dismiss}
|
||||
onDismiss={() => void migration.dismiss()}
|
||||
/>
|
||||
</section>
|
||||
);
|
||||
@@ -90,53 +121,6 @@ export default function ContainerMigrationBanner({
|
||||
);
|
||||
}
|
||||
|
||||
// Nothing is driving this one. It outranks staleness because the container is
|
||||
// sitting mid-swap, and the one thing it must never do is look like a normal
|
||||
// out-of-date container that the user can take or leave.
|
||||
if (interrupted) {
|
||||
return (
|
||||
<section
|
||||
className={`${SHELL} border-[var(--error)]/40 bg-[var(--error-muted)]`}
|
||||
aria-label="Container base update was interrupted"
|
||||
>
|
||||
<StatusIndicator
|
||||
tone="error"
|
||||
label="A container base update was interrupted"
|
||||
className="text-[13px] font-semibold"
|
||||
/>
|
||||
<p className="text-xs text-[var(--text-secondary)] leading-snug">
|
||||
It started{" "}
|
||||
{formatSnapshotDate(interrupted.started_at) ?? "earlier"} and the app
|
||||
closed before it finished, so this container is part-way onto the new
|
||||
base. Resuming replays the same plan it was given.
|
||||
</p>
|
||||
<p className="text-xs text-[var(--text-secondary)] leading-snug">
|
||||
{ROLLBACK_SCOPE}
|
||||
</p>
|
||||
<div className="flex flex-wrap gap-1.5">
|
||||
<Button
|
||||
size="md"
|
||||
variant="primary"
|
||||
disabled={busy}
|
||||
onClick={() => void migration.resume()}
|
||||
>
|
||||
Resume update
|
||||
</Button>
|
||||
{interrupted.rollback_image && (
|
||||
<Button
|
||||
size="md"
|
||||
variant="danger"
|
||||
disabled={busy}
|
||||
onClick={() => void migration.rollback()}
|
||||
>
|
||||
Roll back
|
||||
</Button>
|
||||
)}
|
||||
</div>
|
||||
</section>
|
||||
);
|
||||
}
|
||||
|
||||
if (!staleness) return null;
|
||||
|
||||
// `stale` is deliberately false whenever `known` is false — an unestablished
|
||||
@@ -210,9 +194,32 @@ export default function ContainerMigrationBanner({
|
||||
</p>
|
||||
)}
|
||||
|
||||
{/* An out-of-date container that also has data under /var is the one
|
||||
case where updating can cost something, so it is said here and not
|
||||
only behind the button. */}
|
||||
{staleness.unpreserved_data.length > 0 && (
|
||||
<p className="text-xs text-[var(--text-primary)] leading-snug">
|
||||
Not carried across:{" "}
|
||||
<span className="font-mono text-[var(--text-secondary)]">
|
||||
{staleness.unpreserved_data.map((d) => d.path).join(", ")}
|
||||
</span>
|
||||
<span className="text-[var(--text-secondary)]">
|
||||
{" "}
|
||||
— back this up before updating.
|
||||
</span>
|
||||
</p>
|
||||
)}
|
||||
|
||||
{!canMigrate && (
|
||||
<p className="text-xs text-[var(--text-secondary)] leading-snug">
|
||||
Stop the container to update its base.
|
||||
{/* Distinguishing these matters: "stop the container" on a
|
||||
container that is already stopped, because the probe has not
|
||||
landed, reads as a bug. */}
|
||||
{!probeSettled
|
||||
? probing
|
||||
? "Checking what this container has that the current base does not…"
|
||||
: "That check did not complete, so what would be carried across is not known. Updating stays disabled until it does — try again once the container can be inspected."
|
||||
: "Stop the container to update its base."}
|
||||
</p>
|
||||
)}
|
||||
</div>
|
||||
|
||||
@@ -93,11 +93,17 @@ export default function ProjectHome({ projectId, active }: Props) {
|
||||
// Reset does — with the extra condition that there is a container to migrate.
|
||||
// An interrupted migration is excluded too: its action is Resume, on the
|
||||
// Overview banner, not a fresh pre-flight.
|
||||
//
|
||||
// `probeSettled` is the fourth condition and it is not cosmetic. The probe
|
||||
// takes ~6 s, and until it lands every delta the pre-flight renders reads as
|
||||
// empty — so the dialog would tell the user there was nothing to copy while
|
||||
// the backend was told not to copy anything.
|
||||
const canMigrate =
|
||||
isStopped &&
|
||||
!actions.busy &&
|
||||
!migration.running &&
|
||||
!migration.interrupted &&
|
||||
migration.probeSettled &&
|
||||
!!project.container_id;
|
||||
|
||||
return (
|
||||
|
||||
Reference in New Issue
Block a user