Commit graph

3637 commits

Author SHA1 Message Date
Bryan Helmkamp
31dc4a78f7
route app state reload through dense server settings 2026-04-23 17:13:09 -04:00
Bryan Helmkamp
83fc1602ea
route cli settings loads through dense config 2026-04-23 17:09:21 -04:00
Bryan Helmkamp
c21498a55a
Merge pull request #170 from fabro-sh/fix/manifest-git-working-directory
fix(cli): use working_directory for manifest git detection
2026-04-23 17:00:58 -04:00
Bryan Helmkamp
96b904c24a
switch workflow operations to dense settings 2026-04-23 16:59:56 -04:00
Marcel Hild
8a6f83bb08
fix(cli): use working_directory for manifest git detection
build_manifest_git() was called with the CLI's cwd, which detects the
wrong repo/branch when fabro is invoked from a workspace directory that
differs from the target repo (e.g. via `[run] working_dir = "repos/foo"`
in .fabro/project.toml). Now resolve working_directory once in
build_run_manifest, share it with resolve_manifest_goal (dropping the
duplicate resolution), and pass it to build_manifest_git.

Also rename the build_manifest_git parameter from `cwd` to `repo_path`
to reflect that it now receives the resolved working directory.

Add a regression test that spins up a workspace git repo and a
separate target git repo beneath it, points `[run] working_dir` at the
target, and asserts the manifest's git branch and origin come from the
target repo.

Ports https://github.com/durandom/fabro/pull/2 to the post-v2-schema
code (Settings -> SettingsLayer).

Closes #159

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 16:53:55 -04:00
Bryan Helmkamp
8d472bb6ed
use run settings builder in manifest preflight 2026-04-23 16:51:09 -04:00
Bryan Helmkamp
eaca3daac4
cache dense workflow settings in workflow loader 2026-04-23 16:48:07 -04:00
Bryan Helmkamp
134d8c32d5
add dense run settings builder 2026-04-23 16:37:00 -04:00
Bryan Helmkamp
8eb92b5a74
dedupe dense settings resolution in create 2026-04-23 16:35:04 -04:00
Bryan Helmkamp
235b25750b
fix(docs): point Get Started button to docs.fabro.sh introduction
Was linking to https://fabro.dev/getting-started/quick-start (wrong
domain, 404). Use relative /getting-started/introduction so it resolves
correctly on docs.fabro.sh.

Fixes #167

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 16:33:32 -04:00
Bryan Helmkamp
cdec45cbc3
cache manifest run settings for system info 2026-04-23 16:33:24 -04:00
Bryan Helmkamp
3667330e79
cache dense run settings in command context 2026-04-23 16:28:56 -04:00
Bryan Helmkamp
15cda5ab8a
keep workflow loader tolerant for invalid run settings 2026-04-23 16:24:50 -04:00
Bryan Helmkamp
4ce91cdc64
use dense run settings in manifest and workflow loaders 2026-04-23 16:20:14 -04:00
Bryan Helmkamp
3cc094316b
add dense run goal and working dir helpers 2026-04-23 16:20:11 -04:00
Bryan Helmkamp
45a4802c65
drop raw settings cache from app state 2026-04-23 16:13:06 -04:00
Bryan Helmkamp
a05dc101f2
route system info through dense server settings 2026-04-23 16:11:46 -04:00
Bryan Helmkamp
8290d693ad
cache manifest defaults separately from server settings 2026-04-23 16:09:37 -04:00
Bryan Helmkamp
dc1640e738
drop exec raw cli mcp fallback 2026-04-23 16:00:06 -04:00
Bryan Helmkamp
dde726936d
cache dense workflow settings in prepared manifests 2026-04-23 15:57:51 -04:00
Bryan Helmkamp
84b79f9d69
derive local server cli config from lifecycle settings 2026-04-23 15:49:58 -04:00
Bryan Helmkamp
daf8c7fb10
split cli command context off sparse machine settings 2026-04-23 15:44:29 -04:00
Bryan Helmkamp
3f807f42a6
Merge pull request #169 from fabro-sh/fix/dependabot-openssl-astro
fix(deps): patch rust-openssl and astro security advisories
2026-04-23 15:35:41 -04:00
Bryan Helmkamp
b3b0b02b5d
move cli install storage parsing behind local_server 2026-04-23 15:31:17 -04:00
Bryan Helmkamp
b4a5dbe839
Merge remote-tracking branch 'origin/main' into fix/auto-pr-resolved-client 2026-04-23 15:30:07 -04:00
Bryan Helmkamp
f757bed5b2
use dense server settings in install metadata paths 2026-04-23 15:29:53 -04:00
Bryan Helmkamp
fce31708de
Merge remote-tracking branch 'origin/main' into fix/dependabot-openssl-astro 2026-04-23 15:29:00 -04:00
Bryan Helmkamp
dda6f44d1e
ci: drop check-env-mutation.sh, rely on clippy disallowed_methods
clippy.toml already bans std::env::{set_var,remove_var} via
disallowed_methods, and every existing call site carries a scoped
#[expect(clippy::disallowed_methods, reason = "...")]. The shell grep
is redundant and forced a second, less granular allowlist.

Also update server-secrets-strategy.md to describe clippy as the
enforcement mechanism.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 15:24:33 -04:00
Bryan Helmkamp
b5b67226f1
ci: restore install.rs server-symbol allowlist and worker-token scrub exemption
Both Boundary checks have been red on main for multiple commits:

- check-boundary.sh: install.rs reintroduced direct use of
  fabro_config::ServerSettings::from_layer in 93b6577cd but was dropped
  from server_symbol_allowlist in bb0d05be2. Re-add it.
- check-env-mutation.sh: the worker FABRO_WORKER_TOKEN scrub added in
  077469d0c is documented as the approved pattern in
  docs-internal/server-secrets-strategy.md but was missing from the
  allowlist. Add the exact line.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 15:20:58 -04:00
Bryan Helmkamp
ded4b3acac
route cli install metadata through dense server settings 2026-04-23 15:20:45 -04:00
Bryan Helmkamp
4c8f7fe164
use workflow builders in root and run fixtures 2026-04-23 15:20:42 -04:00
Bryan Helmkamp
662825ac65
use toml builders in config fixtures 2026-04-23 15:15:05 -04:00
Bryan Helmkamp
2a60b6c3dc
add workflow settings builder toml entrypoint 2026-04-23 15:12:48 -04:00
Bryan Helmkamp
077469d0c6
refactor(auth): scrub FABRO_WORKER_TOKEN from worker env at startup
The worker subprocess is spawned with env_clear+allowlist by the server, so
the only sensitive value in its env is FABRO_WORKER_TOKEN itself. Read the
token and remove_var it from the process env in main() before Tokio starts
worker threads, then thread it explicitly through runner::execute(&str).

Every descendant (hooks, local sandbox, devcontainer initializeCommand,
MCP stdio, etc.) now inherits a worker env with no bearer in it, so an
unscrubbed spawn site cannot leak the token. This makes the prior denylist
scrub in fabro-hooks and fabro-sandbox redundant — delete it and the shared
WORKER_SECRET_ENV_DENYLIST constant. The sandbox keeps its _api_key/_secret/
_token/_password/_credential suffix heuristic for user-supplied env_vars
hygiene.

Extend the server-dispatched-worker env-leak integration test to also
assert a Bash stage running in the worker does not observe FABRO_WORKER_TOKEN.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 15:10:58 -04:00
Bryan Helmkamp
68b9fc13a5
inline builtin defaults layer 2026-04-23 15:09:05 -04:00
Bryan Helmkamp
7456cb3252
fix(deps): bump astro from 5.9.3 to 6.1.6
Patches GHSA-j687-52p2-xcff (CVE-2026-41067): XSS in define:vars via
incomplete </script> tag sanitization. Requires Astro >= 6.1.6.

Also bumps @astrojs/react to ^5.0.4 for Astro 6 compatibility.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 15:08:28 -04:00
Bryan Helmkamp
9ed21bcf38
fix(deps): bump rust-openssl from 0.10.75 to 0.10.78
Patches multiple security advisories in rust-openssl (<0.10.78):
- GHSA: Deriver::derive and PkeyCtxRef::derive buffer overflow
- GHSA: Incorrect bounds assertion in AES key wrap
- GHSA: MdCtxRef::digest_final writes past caller buffer
- GHSA: Unchecked callback length in PSK/cookie trampolines
- GHSA: Out-of-bounds read in PEM password callback

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 15:07:10 -04:00
Bryan Helmkamp
dc6a92e696
drop public settings load wrappers 2026-04-23 14:59:48 -04:00
Bryan Helmkamp
2ee9850abb
drop server resolve wrapper 2026-04-23 14:57:10 -04:00
Bryan Helmkamp
916b97c0ad
drop cli and features resolve wrappers 2026-04-23 14:43:07 -04:00
Bryan Helmkamp
43d32464a2
drop project run workflow resolve wrappers 2026-04-23 14:40:09 -04:00
Bryan Helmkamp
e20d8d9435
route project namespace resolution through workflow builders 2026-04-23 14:38:54 -04:00
Bryan Helmkamp
fbb924b9c4
chore: fix nightly clippy lints on worker jwt branch
- fabro-client: collapse identical match arms for DevToken/Worker bearer
- fabro-hooks: rewrite filter_map(bool::then) as filter().map() chain
- fabro-sandbox: import WORKER_SECRET_ENV_DENYLIST rather than absolute path
- fabro-server: box large execute_run_in_process future; take path: &str in
  test-only bearer_request; use let-else in session-secret test; replace unit
  pattern _ with () in worker_token request_parts helper; import StatusCode
- fabro-cli run/mod.rs: box large runner::execute future
- fabro-cli worker_auth.rs: drop unused async on shutdown, allow
  clippy::unwrap_used at file level for subprocess test harness setup

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 12:08:55 -04:00
Bryan Helmkamp
30986207cb
trim config wrapper and storage override helpers 2026-04-23 12:01:49 -04:00
Bryan Helmkamp
a75e820064
refactor(auth): simplify worker jwt helpers and reuse existing utilities
- drop _pub wrapper parse helpers; make originals pub(crate)
- drop AppState::issue_worker_token thin wrapper
- delete 9 narrating comments the extractor types already encode
- add ActorRef::system_worker() alongside ::user()/::agent()
- share WORKER_SECRET_ENV_DENYLIST from fabro-util between hooks/sandbox
- reuse jwt_auth::bearer_token and session_secret_key_error helpers

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-23 12:01:22 -04:00
Bryan Helmkamp
9220af6e80
migrate remaining run settings consumers to dense snapshots 2026-04-23 11:55:12 -04:00
Bryan Helmkamp
0b36ed985b
test(auth): share cli test jwt helpers 2026-04-23 11:42:50 -04:00
Bryan Helmkamp
b2bcf0d5a8
refactor settings builders and dense run snapshots 2026-04-23 11:35:21 -04:00
Bryan Helmkamp
891b7f90ae
test(auth): backfill worker jwt regression coverage 2026-04-23 11:35:08 -04:00
Bryan Helmkamp
519f46038d
refactor(auth): use per-run worker JWTs for subprocesses 2026-04-23 11:04:45 -04:00