Ref writers, client side: keys, namespaces and writers from caos-cli - #304
Open
nishu-builder wants to merge 1 commit into
Open
nishu-builder wants to merge 1 commit into
nishu-builder wants to merge 1 commit into
Conversation
nishu-builder
added this pull request to stack #307
October 5, 2026 10:11
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-3-cli
branch
from
October 5, 2026 14:04
716e130 to
379142e
Compare
caos-cli gains a ref writer key (`caos.ref-writer-key`) and the commands that use it (design/ref-writers.md): - ref-writer-key new|show - namespace new [<label>] - writers list|add|remove <namespace> [<key> [<label>]] - ref-push <rev> <ref> With a key set, caos-cli signs its pushes to the caos remote and its compute requests (`X-Caos-Write`, through a signer the caos library takes), so the jobs it starts may write what they ask for. Client tests sign as a writer of their own, and tests/ref-writers checks the hook, signatures and run tokens end to end. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-3-cli
branch
from
October 5, 2026 19:03
379142e to
7a60eef
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The client half of
design/ref-writers.md: caos-cli can hold a ref writer key and use it. Part 3 of 4, stacked on #303.caos-cli ref-writer-key new|showmakes a key. It lives in the checkout's git config ascaos.ref-writer-key.caos-cli namespace new [<label>],writers list|add|remove <namespace> [<key> [<label>]]andref-push <rev> <ref>.X-Caos-Write(caos::set_request_signer), so the jobs it starts can be granted its namespaces.dev/cli-test/workergives each client test a fresh key. The newtests/ref-writerscovers the hook end to end: content-named refs, founding a namespace, adding and removing a writer, and which jobs a run token lets write.Conversations don't use any of this yet; #305 moves them in.
Verified here
cargo fmt --check,clippy -D warningsandcargo testpass, exceptlauncher::checkout_import_completes_partial_history_and_keeps_local_edits, which fails the same way onmainin this container.nix buildpass.tests/ref-writers' client steps by hand against the builtserverandcaos-cli: founding a namespace, the refusals, andwriters add/remove.Not verified here
caos-testsuite, includingtests/ref-writers' job steps:caosd upcan't fetch flake inputs from inside its containers in this sandbox.Stack
🤖 Generated with Claude Code
https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc