Skip to content

Retain journal checksum for absent installer configuration #881

Description

@bcdonadio

Observed behavior: The absent-config read calls assertBackendPublicationConfigReadAccess but discards its returned journal checksum and returns null. Two absent snapshots therefore cannot detect journal identity drift. Subsequent config creation still reauthenticates under exclusive locks, so no unauthenticated mutation was demonstrated.

Expected behavior / safe remediation: Return the admitted checksum for absent and present snapshots alike. Use harmless private fixture terminal-journal changes between reads to assert drift is rejected, without live daemon operations.

Evidence: Static review of Bug #783 candidate 5668f1c6c7bef61dc25db8ef2ed6bb06e96e2211, installer/install.ts:465-495. Accepted as P2 by independent-review synthesis and owner. No live installation, daemon, or exploitation reproduction. Candidate has not been published as a PR yet; link will be added at publication.

How to reproduce safely: Use the injected/private-fixture test described above against the named source path; do not manipulate live HOME or daemon locks.

Environment:

  • Agent: Opus 5 medium adjudication, Astra owner
  • Connector: static repository review
  • OS: Fedora Linux

Discovered during #783 / Epic #848, finding F6. Separate deferred native Bug outside S0; does not block the issue-scoped candidate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Fields

    Priority

    Medium

    Effort

    None yet

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions