Repository navigation
fix(tests): isolate standalone Stratum authentication fixture - #572
Conversation
|
Blocked on bench preflight proof bench-ci#1183 prevents completing the hardware acceptance criteria. Job Draft PR #572 contains fixture isolation, secret-safe setup diagnostics, corrected documentation and regressions covering targeting, fallbacks and all three apply-failure stages. The focused driver passed 124 assertions; pinned focused lint, topology and exact file-budget gates passed, and repeated verifier/security reviews are clean. Six GitHub checks have passed; Test suite and Coverage are pending on the current head. No local container/full-suite PASS is claimed. Bench maintainers must diagnose and resolve #1183 through the managed workflow. When it closes, resume with a fresh narrow pushed-SHA Stratum job and read its full logs/artifacts, confirming acceptance, rejection/no-work, recovery and verified restoration before readiness. No identical retry or manual bench action was performed. The stale client recurrence is recorded on bench-ci#1148; a current scratch client retrieved the supported evidence without changing the submitted job. |
|
Ready for review Standalone Stratum authentication now selects only the authenticated fixture supplied by At I did not run unrelated hardware phases or local containers. GitHub supplies the full suite, coverage, container e2e and repository-wide lint; the narrow live job covers the changed contract. The implementation and tested SHA remain unchanged. The PR stays draft for the separate reviewer session; no merge was performed. |
|
adversarial-review: PASS at 833b338, round 1, by the pithead-reviewer reviewer (a fresh session that did not produce this head; gpt-6.1-sol). PASS at 833b338: standalone Stratum authentication isolates the supplied fixture, preserves worker identity, protects credentials and retains authentication and restoration gates. Independent regressions, mutation checks, all eight current-head GitHub checks and deployed bench job 2100 satisfy issue #570. No blocking correctness, security, topology or scope findings remain. Evidence
|
Closes #570
Standalone
stratum-authpreviously changed only the primary password, so the original endpoint or a fallback could supply work instead of the authenticated fixture. The phase now installs one temporary plain-Stratum pool atPITHEAD_URL, preserves the primaryuser, and removes inherited endpoint settings and fallback pools. URL/password data enters constant jq programs through stdin; setup failures emit fixed diagnostics. Authentication refusal, acceptance, rejection/no-work, recovery and byte-identical EXIT/runtime restoration remain mandatory.Hardware-free regressions start with a foreign primary and usable fallback, preserve payout identity and donation, inspect jq arguments, exercise special-character passwords, and check restoration after edit, initial apply, rejection apply, recovery apply and restart failures from both active and stopped states. The phase documentation describes isolation and transport.
Ponytail review (author-side fallback; the named skill is unavailable): lean and scoped. Reused the existing editor and restoration helpers; retained required tests, documentation and error handling, with no new abstraction or dependency.
Validation:
timeout 60 bash "$TMPDIR/rigforge-570-check.sh"— PASS: focused driver sources the actual suite regression and extracts the real phase/editor/dispatch/EXIT helpers; 124 assertions pass, zero fail.timeout 60 "$TMPDIR/rigforge-570-tools/shellcheck-v0.11.0/shellcheck" --severity=warning tests/e2e-pithead.sh tests/test-stratum-auth-gate.sh— PASS.timeout 60 "$TMPDIR/rigforge-570-tools/shfmt" -i 4 -d tests/e2e-pithead.sh tests/test-stratum-auth-gate.sh— PASS.make lint-topology,FILE_BUDGET_REQUIRE_BASE=1 bash scripts/lint-file-budget.sh,git diff --check— PASS.Local limitations: full
make lintwas stopped during repository-wide ShellCheck; only the focused pinned lint commands above claim PASS.make lint-mdcould not run becausenpxis unavailable. Full suite, coverage, container e2e and repository-wide lint belong to GitHub CI; no local container or full-suite PASS is claimed. Unrelated live hardware phases are outside scope. All eight GitHub checks passed at833b338e5ee2e6758e94e7509ea338711f64615d: Test suite, Coverage, Docker e2e, shell lint, Markdown lint, YAML lint, Gitleaks and Zizmor. The narrow current-head hardware proof also passed. The PR remains draft for the runner's independent review; no merge will be performed by this session.Completed proof: bench-ci#1183 is closed following managed devops job
2100@833b338e5ee2e6758e94e7509ea338711f64615d. I read its full status, complete log and sole retained 306-byte harness artifact. It executed all four authentication assertions at the unchanged PR head, with all seven steps successful and both baseline verification and rig restoration confirmed. Restoration also verified the temporary stack fixture was restored byte for byte and the borrowed worker returned to active baseline mining.The earlier job 2094 never ran the harness because the preflight egress recheck failed; it provides no authentication proof. The original transient cause remains unknown. The successful proof used the installed preflight policy, which omitted the second probe because the preceding job had verified restoration. Devops reported no manual runtime repair or gate change. This resolves the operational blocker without changing this PR's implementation or acceptance criteria; no additional submission is needed at the same SHA.
Final verifier and security-reviewer passes at this SHA are clean; the verifier independently reran the focused driver with 124 passing assertions and no failures. Both generated job evidence blocks below were freshly printed after the completed proof. The stale client recurrence remains recorded on bench-ci#1148; the supported current scratch client retrieved evidence. Unrelated hardware phases were not run because only Stratum targeting/isolation changed. No release, payout configuration or production operation is part of this fix.
bench-ci job 2094@833b338e5ee2e6758e94e7509ea338711f64615d · rigforge · tier4-e2e
Generated by
bench-ci evidence 2094@833b338e5ee2e6758e94e7509ea338711f64615d; re-run it to check.bench-ci job 2100@833b338e5ee2e6758e94e7509ea338711f64615d · rigforge · tier4-e2e
Generated by
bench-ci evidence 2100@833b338e5ee2e6758e94e7509ea338711f64615d; re-run it to check.