Skip to content

Scheduled digests omit requester identity and cannot acquire production host leases #394

Description

@Calmingstorm

Confirmed production wiring defect

Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P2.

Scheduled digests call the tool executor for each host's disk/memory checks without user_id. Production wiring installs HostAccessManager, whose host acquisition correctly rejects an absent requester identity. The digest therefore cannot acquire any host and posts denial text as a normally completed report.

Sources: digest calls and formatting, host guard, production injection.

Isolated evidence

Real executor/digest code with fake host registry/access collaborators, fake Discord channel and no LLM summary:

Disk (isolated-digest-host): Unknown or disallowed host
Memory (isolated-digest-host): Unknown or disallowed host
host registry acquisitions: 0
posted digest: denial sections

Two independent confirmations exercised the actual identity-less acquisition guard and checked the production call chain. No managed host or real Discord channel was contacted.

Acceptance criteria

  • Pass explicit persisted requester authority for user-created digests; system-owned digests need an explicit auditable system execution context consistent with other scheduled work.
  • Never default arbitrary identity-less calls to elevated authority or bypass host policy.
  • Treat failed ToolResult probes as collection failures/degraded evidence, not just non-exception strings.
  • Cover the real executor/access-manager composition, allowed/denied hosts, system-owned schedules and partial failure reporting.

Behavior change: digests become functional under the intended authority and report collection failure honestly. No source changes were made.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions