The ESO-mounted secret is root-owned mode 0400 (correct — init.sh runs as root before the gosu drop to the agent user). The original version of this context pointed CP_SERVICE_TOKEN_FILE directly at that raw mount, which the agent process (uid 1000) can never read. Confirmed live 2026-09-03: a real scope-decompose-sonnet@1 dispatch against concept 7666d278-ae58-4f12-990d-c4959a3e19a9 hit exactly this — the agent correctly diagnosed 'cp_cli invocation can't proceed... token is root-owned mode 0400 so it's not readable by the agent user', wrote its decompose plan, but could never actually call cp-cli to create the child tasks. The trigger engine's new side-effect verification (finalize.py, bug 9dffc5b8) correctly caught this and refused to advance flow_state — so this was a visible, retriable failure rather than another silent false-positive. Fix: init.sh restages the secret to /run/agent/cp-service-token/token, mode 0600, owned by the agent user — mirrors anthropic-cloud-paul-oauth/v1/init.sh's existing pattern. CP_SERVICE_TOKEN_FILE now points at the restaged copy.
31 lines
1.2 KiB
YAML
31 lines
1.2 KiB
YAML
kind: context
|
|
name: cp-service-token
|
|
version: 1
|
|
description: "CP-internal service bearer token — authenticates agent-container write calls back to the control plane (AU-51/AU-51b, bug b3a96acc)"
|
|
requires: []
|
|
provides: []
|
|
|
|
# AU-51b: the ESO-mounted secret is root-owned mode 0400 (init.sh runs as
|
|
# root, before the gosu drop to the agent user, uid 1000) — unreadable by
|
|
# the agent process directly. Confirmed live 2026-09-03: a real agent
|
|
# session hit exactly this ("cp-cli invocation can't proceed... token is
|
|
# root-owned mode 0400 so it's not readable by the agent user"). Mirrors
|
|
# anthropic-cloud-paul-oauth/v1's pattern: init.sh restages a 0600
|
|
# agent-owned copy outside the ESO mount. CP_SERVICE_TOKEN_FILE points at
|
|
# the restaged copy, not the raw mount.
|
|
#
|
|
# The value at this path MUST match the CP's CP_INTERNAL_BEARER_TOKEN
|
|
# (same account: cp-decompose-service-token, account_id
|
|
# 1d963673-6ac9-4f85-875a-2ce5323e76ad, owner (cp, cp)).
|
|
env:
|
|
CP_SERVICE_TOKEN_FILE: /run/agent/cp-service-token/token
|
|
|
|
scripts:
|
|
init: "./init.sh"
|
|
|
|
secrets_required:
|
|
- name: cp-service-token
|
|
account_ref: "1d963673-6ac9-4f85-875a-2ce5323e76ad"
|
|
mount_path: /run/agent/secrets/cp-service-token
|
|
mode: "0400"
|