fix(update): drop untrusted fleet fallback version
When the state-file writer cannot be verified as the profile gateway, null code_version with the SHA so the row does not display a self-reported identity claim. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -327,9 +327,10 @@ def collect_fleet_versions(*, pre_restart_pids: Optional[list[int]] = None) -> l
|
||||
continue
|
||||
# A live non-gateway (or a gateway for another profile) can write a
|
||||
# plausible state file. Keep the fail-open visibility row, but never
|
||||
# let that file's SHA classify the process as current or stale.
|
||||
# let that file's self-reported SHA or version classify or label
|
||||
# the process — both claims have the same trust problem.
|
||||
if runtime_status_pid_is_live(record):
|
||||
results.append(_fleet_row(profile, pid, None, record.get("code_version"), None))
|
||||
results.append(_fleet_row(profile, pid, None, None, None))
|
||||
continue
|
||||
# Dead PID (or a live PID recycled by an unrelated process during the update's own
|
||||
# churn): a DOWN row only when this exact pid was alive at update start AND the record
|
||||
|
||||
@@ -325,6 +325,8 @@ class TestFleetClassification:
|
||||
assert len(fleet) == 1
|
||||
assert fleet[0]["pid"] == os.getpid()
|
||||
assert fleet[0]["state"] == "unknown"
|
||||
assert fleet[0]["code_sha"] is None
|
||||
assert fleet[0]["code_version"] is None
|
||||
|
||||
def test_current_gateway(self, monkeypatch, tmp_path):
|
||||
sha = "a" * 40
|
||||
@@ -397,6 +399,8 @@ class TestFleetClassification:
|
||||
|
||||
assert len(fleet) == 1
|
||||
assert fleet[0]["state"] == "unknown"
|
||||
assert fleet[0]["code_sha"] is None
|
||||
assert fleet[0]["code_version"] is None
|
||||
|
||||
def test_matrix_returns_true_only_on_stale(self, capsys):
|
||||
assert ur.print_fleet_version_matrix([]) is False
|
||||
|
||||
Reference in New Issue
Block a user