Skip to content

MUTATION A run: bearer key not required - #4

Closed
tonydzi wants to merge 2 commits into
MARM-mainfrom
mutation/auth-off
Closed

tonydzi wants to merge 2 commits into
MARM-mainfrom
mutation/auth-off

Conversation

@tonydzi

@tonydzi tonydzi commented Sep 3, 2026

Copy link
Copy Markdown
Owner

Mutation run to prove the new tests go red on an auth regression. Not for merge.

… uses the keyless fallback (Lyellr88#170 item 5)

Item 5's --expose-network bullet: the flag's only effect is the published
host binding (services/docker_commands.py:126), and everything that checks it
today checks argv or a 127.0.0.1-published container. Nothing reached a
running container over the interface that only exposed mode opens, so the
mode that accepts off-host clients was never shown to reject unauthenticated
ones.

The other half of the bullet, "loopback behaves as documented", turned out
not to hold in Docker at all. auth.py:16 documents a keyless mode that trusts
127.0.0.1 and 401s everyone else, but the run plan always sets
SERVER_HOST=0.0.0.0, and at that host api_key_bootstrap.py:53-54 generates and
persists a key when none was given. MARM_API_KEY is therefore always truthy
inside the image and the documented fallback is unreachable. That is the safe
direction, but it is unpinned: nothing would notice if it changed.

- exposed test: publishes on 0.0.0.0 and talks to the container over the
  host's own routable address, not 127.0.0.1, so it exercises the path the
  flag exists for. Unauthenticated 401, keyed 200, /health public.
- no-key test: a container given no key still challenges. The two 401s are
  told apart by WWW-Authenticate, which only the key branch sends (auth.py:47),
  and the generated key is read back out of the bind mount and used.

Assisted-by: Claude (Anthropic)
@tonydzi

tonydzi commented Sep 3, 2026

Copy link
Copy Markdown
Owner Author

Self-verification run complete; evidence linked from Lyellr88#192.

@tonydzi tonydzi closed this Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant