test(conformance): shared Swift/Rust vectors in CI; align Linux AuthPolicy - #41
Merged
Merged
Conversation
…olicy with the oracle
conformance/{auth,reverse_attach}_vectors.json (16 + 23 cases, from the rpi1
suites) now live in the repo and run on both sides: Swift
ConformanceVectorTests (the oracle) and Rust auth::conformance /
attach::conformance; the Linux CI job gains cargo test.
Running them exposed drift in the shipped Linux AuthPolicy: the Bearer scheme
was case-sensitive, deny reasons differed, and a request carrying
X-Forwarded-For could still count as local. Rewritten as a pure decide() with
the Swift algorithm and reason strings; check() adapts a request to it.
Mutation-checked: a changed reason or close code fails with the exact diff.
Refs #24 #32.
This was referenced Sep 29, 2026
Merged
jinwei-pikmin
added a commit
to jinwei-pikmin/instance-mcp
that referenced
this pull request
Sep 30, 2026
auth::conformance and attach::client::conformance read the language-neutral vectors in conformance/ (Swift is the oracle, openabdev#24/openabdev#41): 16/16 AuthPolicy cases including exact deny reasons, 23/23 reverse-attach close-code, handshake-status and attachURL cases pass unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #24 (and #32 item 2).
What:
conformance/auth_vectors.json(16) andconformance/reverse_attach_vectors.json(23), previously only in scratch folders on rpi1, now in the repo and run by both implementations on every PR:ConformanceVectorTests— passes on macmini.auth::conformance,attach::conformanceviacargo test, newly added to the Linux CI job.Drift found and fixed. The shipped Linux
AuthPolicydid not match the oracle: Bearer scheme case-sensitive (Swift: case-insensitive), different deny reason strings, and a request withX-Forwarded-Forcould still be treated as local underMCP_INSECURE_LOCAL(Swift: never local if relayed — a small tightening). Rewritten as a puredecide()with Swift's algorithm;check()adapts the request. Deployed nodes (token + allow-login behindtailscale serve) are unaffected.Mutation check: changing
bad token→wrong tokenand dropping 4010 from the stop set fails both tests with the exact case diffs; restored → green.Still open on #24: MCP-surface wire fixtures, and the parity checklist for the retire-Swift gate.