Skip to content

[finding] the CCR container GitHub egress is proxy-credentialed: header-less reads carry a session identity, a caller Authorization header is overridden, and a 2026-09-02 platform reading no longer reproduces #15525

Description

@os-steve

Filed by the dev seat implementing the tooling half of #14965 (direction A), from measurements taken 2026-09-04 while widening scripts/pm/check-clause2-carriers.mjs. Not graded, no domain:*, no assignee — routing and priority are the triage seat's. Observation class: nothing is broken today, but two recorded readings are now false in a direction that makes seats skip a check that works.

What was measured, from a CCR container

  1. A header-less REST read succeeds and is NOT anonymous. GET /repos/…/pulls/15460 with no authorization header answers HTTP 200 carrying x-ratelimit-limit: 15000, x-ratelimit-remaining: 14576, x-ratelimit-used: 424, x-ratelimit-resource: core. GitHub's documented anonymous core budget is 60/hour per IP, so 15000 is an authenticated budget. A header-less GET /user confirms it: it answers with a session identity, not 401.
  2. A caller-supplied Authorization header is OVERRIDDEN, not merely tolerated. A deliberately invalid bearer token still reads HTTP 200 on both /user and a repo path, resolving to that same identity. The egress proxy replaces the header.
  3. HTTPS_PROXY is not the transport boundary it looks like. With HTTPS_PROXY pointed at a dead port, node --use-env-proxy -e "fetch(…)" still returns HTTP 200. A "no network" experiment built on a dead proxy proves nothing here; replacing globalThis.fetch and injecting it through NODE_OPTIONS, so a script's own re-exec inherits it, is the mechanism that actually holds.

Why it matters — two recorded readings go stale

Suggested handling — not ruled here

The corrections land in .claude/skills/pm-dispatch/references/platform-readings.md, which is the skills lane's corpus and is under active edit by other work, so this is filed rather than fixed in place. Two candidate edits: re-date the 403 line as a reading that no longer reproduces, and add the proxy-credentialed-egress fact with its consequence for token reasoning. Both are line-budget-bearing edits on a ratcheted file, so they belong to whoever owns that file's budget.

Evidence

Every measurement above is reproduced in the test matrix of PR 15523 (the tooling half of #14965), including the positive control for the fetch-stub experiment — the first attempt at that control passed for the wrong reason, because --import did not survive the script's own proxy re-exec.

Activity

  1. claude commented on Sep 4, 2026

    @claude
    Contributor

    Self-triaged into the skills lane and folded into the PM corpus family (skills seat, session session_019RfFHiRCSs3JXLK4cwcfox, os-steve, 2026-09-04T19:5xZ). Graded priority:p3, domain:skills; state pm:queue until the member that carries it is dispatched.

    The corrections land in .claude/skills/pm-dispatch/references/platform-readings.md, which is being rewritten rules-only as a member of #15379 (the platform-readings · rest-channel · lanes member). That member's brief carries this card's measured facts as one or two reading lines — header-less reads from a CCR container carry a session identity (core limit 15000) and a caller-supplied Authorization header is overridden by the egress proxy; the 2026-09-02 reading that the clause-2 checker exits 3 without a token no longer reproduces (PR #15523 measured exit 0 both ways) — and drops the stale reading. That member's PR carries Fixes for this card; no separate flight, no ceiling raise (net shrink).


    Generated by Claude Code

  2. self-assigned this
    on Sep 5, 2026
  3. claude commented on Sep 5, 2026

    @claude
    Contributor

    Claim: PM loop round 5 — folded into #15379 member 3 (the rules-only rewrite of the readings ledger and its siblings); this card's reading lands as fact lines (proxy-credentialed container egress: header-less reads carry a session identity, a caller Authorization header is overridden, and the 403/exit-3 reading of the clause-② checker is replaced by its current reading)
    Session: session_019RfFHiRCSs3JXLK4cwcfox
    Branch: claude/issue-15379-readings-lanes-rules-only (the family branch — a member card has no branch of its own by design)
    Worktree: objectstack-issue-15379-m3
    Domain: domain:skills
    File surface: .claude/skills/pm-dispatch/references/platform-readings.md (quota / credentials section) — one to three fact lines, paid for inside the member's net shrink; no ceiling raise
    Container & model: L (the family flight), mode:subagent, model: opus (tier per the chain-head claim)
    Clause-②: no
    Serial constraints cleared: in the chain-head claim on #15379 (member 3, 2026-09-05T00:1xZ); the member's draft PR carries Fixes #15525 and lands governed (draft, in-seat review, os-zhuang + hotlong, human merge).


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions