Skip to content

fix(tests): isolate standalone Stratum authentication fixture - #572

Merged
pithead-reviewer[bot] merged 1 commit into
developfrom
codex/issue-570
Oct 3, 2026
Merged

pithead-reviewer[bot] merged 1 commit into
developfrom
codex/issue-570

Conversation

@pithead-developer

@pithead-developer pithead-developer Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Closes #570

Standalone stratum-auth previously changed only the primary password, so the original endpoint or a fallback could supply work instead of the authenticated fixture. The phase now installs one temporary plain-Stratum pool at PITHEAD_URL, preserves the primary user, and removes inherited endpoint settings and fallback pools. URL/password data enters constant jq programs through stdin; setup failures emit fixed diagnostics. Authentication refusal, acceptance, rejection/no-work, recovery and byte-identical EXIT/runtime restoration remain mandatory.

Hardware-free regressions start with a foreign primary and usable fallback, preserve payout identity and donation, inspect jq arguments, exercise special-character passwords, and check restoration after edit, initial apply, rejection apply, recovery apply and restart failures from both active and stopped states. The phase documentation describes isolation and transport.

Ponytail review (author-side fallback; the named skill is unavailable): lean and scoped. Reused the existing editor and restoration helpers; retained required tests, documentation and error handling, with no new abstraction or dependency.

Validation:

  • timeout 60 bash "$TMPDIR/rigforge-570-check.sh" — PASS: focused driver sources the actual suite regression and extracts the real phase/editor/dispatch/EXIT helpers; 124 assertions pass, zero fail.
  • Mutations restoring password-only setup, retaining the foreign target, retaining fallback pools, exposing recovery credentials in argv, or allowing raw setup diagnostics — each regression FAIL as expected; final implementation PASS. No live rig was touched.
  • CI-pinned ShellCheck 0.11.0: timeout 60 "$TMPDIR/rigforge-570-tools/shellcheck-v0.11.0/shellcheck" --severity=warning tests/e2e-pithead.sh tests/test-stratum-auth-gate.sh — PASS.
  • CI-pinned shfmt 3.14.1: timeout 60 "$TMPDIR/rigforge-570-tools/shfmt" -i 4 -d tests/e2e-pithead.sh tests/test-stratum-auth-gate.sh — PASS.
  • make lint-topology, FILE_BUDGET_REQUIRE_BASE=1 bash scripts/lint-file-budget.sh, git diff --check — PASS.
  • Repeated verifier and security-reviewer subagents — clean after fixing diagnostic leakage and ensuring setup errors return to the parent for fixed diagnostics.

Local limitations: full make lint was stopped during repository-wide ShellCheck; only the focused pinned lint commands above claim PASS. make lint-md could not run because npx is unavailable. Full suite, coverage, container e2e and repository-wide lint belong to GitHub CI; no local container or full-suite PASS is claimed. Unrelated live hardware phases are outside scope. All eight GitHub checks passed at 833b338e5ee2e6758e94e7509ea338711f64615d: Test suite, Coverage, Docker e2e, shell lint, Markdown lint, YAML lint, Gitleaks and Zizmor. The narrow current-head hardware proof also passed. The PR remains draft for the runner's independent review; no merge will be performed by this session.

Completed proof: bench-ci#1183 is closed following managed devops job 2100@833b338e5ee2e6758e94e7509ea338711f64615d. I read its full status, complete log and sole retained 306-byte harness artifact. It executed all four authentication assertions at the unchanged PR head, with all seven steps successful and both baseline verification and rig restoration confirmed. Restoration also verified the temporary stack fixture was restored byte for byte and the borrowed worker returned to active baseline mining.

The earlier job 2094 never ran the harness because the preflight egress recheck failed; it provides no authentication proof. The original transient cause remains unknown. The successful proof used the installed preflight policy, which omitted the second probe because the preceding job had verified restoration. Devops reported no manual runtime repair or gate change. This resolves the operational blocker without changing this PR's implementation or acceptance criteria; no additional submission is needed at the same SHA.

Final verifier and security-reviewer passes at this SHA are clean; the verifier independently reran the focused driver with 124 passing assertions and no failures. Both generated job evidence blocks below were freshly printed after the completed proof. The stale client recurrence remains recorded on bench-ci#1148; the supported current scratch client retrieved evidence. Unrelated hardware phases were not run because only Stratum targeting/isolation changed. No release, payout configuration or production operation is part of this fix.

bench-ci job 2094@833b338e5ee2e6758e94e7509ea338711f64615d · rigforge · tier4-e2e

  • options: {"phases": ["stratum-auth"]}
  • status: completed · conclusion: error · exit none · 0m 55s
  • baseline verified: yes · rig restored: yes
  • node guard: not recorded · no comparison recorded
  • steps: checkout success · reserve success · preflight failure · run skipped · collect skipped · restore success · cleanup success
  • rows: 0 pass · 0 fail · 0 skip
  • error: live stack unhealthy before the run; refusing: 10 containers healthy; Tor clearnet egress unverified
    Generated by bench-ci evidence 2094@833b338e5ee2e6758e94e7509ea338711f64615d; re-run it to check.

bench-ci job 2100@833b338e5ee2e6758e94e7509ea338711f64615d · rigforge · tier4-e2e

  • options: {"phases": ["stratum-auth"]}
  • status: completed · conclusion: success · exit 0 · 2m 27s
  • baseline verified: yes · rig restored: yes
  • node guard: not recorded · no comparison recorded
  • steps: checkout success · reserve success · preflight success · run success · collect success · restore success · cleanup success
  • rows: 4 pass · 0 fail · 0 skip
    Generated by bench-ci evidence 2100@833b338e5ee2e6758e94e7509ea338711f64615d; re-run it to check.

@pithead-developer

Copy link
Copy Markdown
Contributor Author

Blocked on bench preflight proof

bench-ci#1183 prevents completing the hardware acceptance criteria. Job 2094@833b338e5ee2e6758e94e7509ea338711f64615d ended with a preflight Tor egress verification error before the Stratum harness ran. Full status/log and the empty artifact inventory were read; baseline verification and rig restoration succeeded, but no authentication assertions executed.

Draft PR #572 contains fixture isolation, secret-safe setup diagnostics, corrected documentation and regressions covering targeting, fallbacks and all three apply-failure stages. The focused driver passed 124 assertions; pinned focused lint, topology and exact file-budget gates passed, and repeated verifier/security reviews are clean. Six GitHub checks have passed; Test suite and Coverage are pending on the current head. No local container/full-suite PASS is claimed.

Bench maintainers must diagnose and resolve #1183 through the managed workflow. When it closes, resume with a fresh narrow pushed-SHA Stratum job and read its full logs/artifacts, confirming acceptance, rejection/no-work, recovery and verified restoration before readiness. No identical retry or manual bench action was performed. The stale client recurrence is recorded on bench-ci#1148; a current scratch client retrieved the supported evidence without changing the submitted job.

@pithead-developer pithead-developer Bot added stage/blocked its issue waits on another issue and removed stage/in-progress labels Oct 3, 2026
@pithead-developer pithead-developer Bot added stage/in-progress and removed stage/blocked its issue waits on another issue labels Oct 3, 2026
@pithead-developer

Copy link
Copy Markdown
Contributor Author

Ready for review

Standalone Stratum authentication now selects only the authenticated fixture supplied by PITHEAD_URL, preserves the primary worker identity, and removes foreign endpoints, fallbacks and inherited endpoint settings. Constant jq programs receive URL/password data through stdin; failures emit fixed diagnostics and the original config bytes and service state are restored on EXIT. The regression starts from a foreign primary and usable fallback and detects broken targeting, retained fallbacks, argument exposure and diagnostic leaks.

At 833b338e5ee2e6758e94e7509ea338711f64615d, all eight GitHub checks passed. The focused regression has 124 passing assertions; the exact file-budget gate passed again, and final verifier/security-reviewer passes are clean. Job 2100@833b338e5ee2e6758e94e7509ea338711f64615d proves actual correct-password mining, wrong-password rejection/no-work and recovery, with successful baseline and rig restoration. I read its full status/log and complete retained harness artifact and refreshed both generated evidence blocks in the PR body. Bench-ci#1183 is closed; the earlier preflight error supplies no authentication proof and its original transient cause remains unknown.

I did not run unrelated hardware phases or local containers. GitHub supplies the full suite, coverage, container e2e and repository-wide lint; the narrow live job covers the changed contract. The implementation and tested SHA remain unchanged. The PR stays draft for the separate reviewer session; no merge was performed.

@pithead-developer pithead-developer Bot added stage/in-review a reviewer session is on it now and removed stage/in-progress labels Oct 3, 2026
@pithead-reviewer

Copy link
Copy Markdown
Contributor

adversarial-review: PASS at 833b338, round 1, by the pithead-reviewer reviewer (a fresh session that did not produce this head; gpt-6.1-sol).

PASS at 833b338: standalone Stratum authentication isolates the supplied fixture, preserves worker identity, protects credentials and retains authentication and restoration gates. Independent regressions, mutation checks, all eight current-head GitHub checks and deployed bench job 2100 satisfy issue #570. No blocking correctness, security, topology or scope findings remain.

Evidence

  • pwd; git status --short; git rev-parse HEAD; git remote -v — correct repository, clean tracked tree, head 833b338; local path withheld.
  • cat AGENTS.md CONTRIBUTING.md — read branching, validation, topology, file-budget and merge rules.
  • cat/sed of the catalog graphify, ponytail and ponytail-review skills — read and applied; skill locations remain private.
  • gh pr view 572 --repo p2pool-starter-stack/rigforge --json title,body,author,baseRefName,headRefName,headRefOid,isDraft,comments,files,commits — read complete claim and latest Ready for review comment; base develop; one implementation commit; three changed test/documentation files.
  • gh issue view 570 --repo p2pool-starter-stack/rigforge --json title,body,author,state,comments — acceptance requires fixture selection/isolation, unchanged payout identity, secret-safe transport/diagnostics, mandatory refusal/authentication/recovery/restoration, hardware-free regression and pushed-head narrow hardware proof.
  • gh issue view 559 --repo p2pool-starter-stack/rigforge --json title,body,author,state,comments — read direct prerequisite context; this PR resolves fixture isolation, while the broader credential remediation remains separate.
  • gh pr view 561 --repo p2pool-starter-stack/rigforge --json title,body,author,state,comments — read complete linked PR and comments; its failed proofs establish context, not validation for fix(tests): isolate standalone Stratum authentication fixture #572.
  • Runner-prefetched bench-ci#1183 and #1148 — read supplied bodies, comments, states and timestamps without changing credentials. #1183 is closed after managed proof; #1148 remains open for historical client discovery.
  • git diff origin/develop...HEAD -- tests/README.md tests/e2e-pithead.sh tests/test-stratum-auth-gate.sh — reviewed all hunks. Three phase edits correct targeting and credential transport; documentation replaces its previous description; tests retain existing assertions.
  • gh pr checks 572 --repo p2pool-starter-stack/rigforge — repeated through close-out: all eight checks pass; none skipped or pending.
  • graphify --help; graphify update . --no-cluster — structural graph generated: 1158 nodes, 2043 edges; twelve data files yielded no nodes. Generated graph subsequently moved out of the review tree.
  • graphify query 'phase_stratum_auth set_cfg snapshot_config _cleanup' --budget 1500 — located phase/editor/restoration relationships; used source inspection for correctness conclusions.
  • sed/cat of tests/e2e-pithead.sh, tests/test-e2e-gate-fail-closed.sh, tests/test-stratum-auth-gate.sh, tests/run.sh and Makefile — traced standalone dispatch, editor failure propagation and EXIT restoration; confirmed hardware-free regression is included in the suite.
  • cat of the previous private focused driver — file unavailable; reconstructed the driver from committed suite assertions and helpers instead.
  • source ~/.config/bench-ci/env; ~/code/pithead-ci/bin/bench-ci evidence 2094@833b338e5ee2e6758e94e7509ea338711f64615d — completed/error, preflight failure, zero rows, verified baseline/restoration. Printed block exactly matches the PR; bench-ci#1183 owns this superseded bench failure.
  • source ~/.config/bench-ci/env; ~/code/pithead-ci/bin/bench-ci evidence 2100@833b338e5ee2e6758e94e7509ea338711f64615d — completed/success, exit 0, seven successful steps, four pass/zero fail/zero skip, verified baseline/restoration. Printed block exactly matches the PR.
  • bench-ci --help; bench-ci log --help; bench-ci artifacts --help; bench-ci status --help — confirmed supported read-only evidence interfaces.
  • bench-ci status --json 2094@833b338e5ee2e6758e94e7509ea338711f64615d — confirms exact head, skipped run/collection and successful restoration.
  • bench-ci log 2094@833b338e5ee2e6758e94e7509ea338711f64615d — read all 18 lines; harness never ran. Initial health passed, recheck failed, restoration health passed; historical cause remains unproven.
  • bench-ci artifacts 2094@833b338e5ee2e6758e94e7509ea338711f64615d — empty inventory.
  • bench-ci status --json 2100@833b338e5ee2e6758e94e7509ea338711f64615d — exact current head, tier4-e2e, stratum-auth requested; all four authentication rows pass and both restoration flags are true.
  • bench-ci log 2100@833b338e5ee2e6758e94e7509ea338711f64615d — read all 39 lines. Runner checked out the branch in the rig install, enabled the temporary authenticated fixture, ran acceptance/rejection/no-work/recovery, restored the checkout and worker, restored fixture bytes and verified stack health.
  • bench-ci artifacts 2100@833b338e5ee2e6758e94e7509ea338711f64615d — inventory contains one 306-byte harness artifact.
  • bench-ci artifacts 2100@833b338e5ee2e6758e94e7509ea338711f64615d e2e-pithead-stratum-auth.log --out ; wc -c; cat — downloaded and read all 306 bytes: four named assertions pass, zero fail.
  • gh api repos/p2pool-starter-stack/rigforge/commits/833b338e5ee2e6758e94e7509ea338711f64615d/check-runs — runner wrapper refused this read route; used permitted workflow-run reads to verify the head instead.

@pithead-reviewer
pithead-reviewer Bot marked this pull request as ready for review October 3, 2026 22:22
@pithead-reviewer
pithead-reviewer Bot merged commit bdf42c1 into develop Oct 3, 2026
9 checks passed
@pithead-reviewer
pithead-reviewer Bot deleted the codex/issue-570 branch October 3, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stage/in-review a reviewer session is on it now

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Standalone stratum-auth must isolate the authenticated fixture pool

1 participant