Skip to content

feat(poker): bake and supervise the forum poker table's house seat - #14

Merged
jjohare merged 7 commits into
mainfrom
feat/poker-citizen-house-seat
Oct 3, 2026
Merged

jjohare merged 7 commits into
mainfrom
feat/poker-citizen-house-seat

Conversation

@jjohare

@jjohare jjohare commented Oct 3, 2026

Copy link
Copy Markdown

Self-contained commit found on the shared checkout (another session, 09:41Z). Pins verified by the repin pass: NAR hash reproduces, vendored lockfile byte-identical to the kit Cargo.lock. Separate from custody PR #12 so each bakes on its own merit.

🤖 Generated by Claude Code

claude and others added 3 commits October 3, 2026 11:52
…poker_citizen], forum ADR-2020)

nostr-bbs-poker-citizen from the kit at the website's KIT_REF (d673708),
lib/poker-citizen.nix with the commit's lockfile vendored; [program:poker-citizen]
runs config/poker/run-citizen.sh (waits for the sidestr:dreamlab producer) with
the key, ledger, relay and daily cap from [poker_citizen]. REBUILD-class: until
the image is rebuilt the service runs from a release build in tmux `poker-citizen`.

Co-Authored-By: jjohare <github@thedreamlab.uk>
bea1338 added [poker_citizen] to agentbox.toml and the flake, but not to
the manifest schema (validator E016 UnknownManifestKey) or the ADR-039
catalogue (check-manifest-catalogue: poker_citizen.enabled uncatalogued).

- schema/agentbox.toml.schema.json: poker_citizen object, additionalProperties
  false, with the five keys the flake reads (enabled, key_file, state, relay,
  daily_cap).
- system-manifest.js: CATALOGUE entry 'poker-citizen', shaped like
  payments-sidestr, gate poker_citizen.enabled. apply_class is 'rebuild', not
  payments-sidestr's 'boot': the flake bakes the program and package, so a
  flip needs an image rebuild.

Co-Authored-By: jjohare <github@thedreamlab.uk>
The governed-path changes since each stamp are PR #14's two commits only: [poker_citizen] in
agentbox.toml, its schema object and catalogue entry, and the flake's poker-citizen package and
program (outbound only, no listener). One dated note per record; earlier notes kept.

ADR-2122's note records an open gap instead of closing it here: poker-citizen holds a signing key
but is not in secret_bearing_programs, so under [security].role_isolation it would still run as
devuser. The flag ships off; a role for it is the owner's follow-up.

Co-Authored-By: jjohare <github@thedreamlab.uk>
@jjohare
jjohare force-pushed the feat/poker-citizen-house-seat branch from bea1338 to 2de360f Compare October 3, 2026 11:55
claude and others added 4 commits October 3, 2026 12:00
The house seat holds a signing key that pays out up to daily_cap DREAM a day, but was not in
secret_bearing_programs, so under [security].role_isolation it would have stayed devuser.

- config/role-accounts.json: role ab-poker-citizen at 970 (next free after 969; 965 stays
  reserved), its own group; poker-citizen added to secret_bearing_programs; house.key from the
  at-rest copy /var/lib/agentbox/secrets/poker-citizen.key, migrated once from the workspace key
  (legacy), delivered 0400 to /run/secrets/ab-poker-citizen; ledger dir
  /var/lib/agentbox/events/sidestr/poker-citizen (970:devuser 2750), seeded once.
- config/poker/run-citizen.sh: the faucet's custody rule. Under the flag the ledger defaults to
  the events volume (umask 027); flag off with that ledger ahead of the workspace one, refuse
  (CUSTODY-STATE-AHEAD) rather than settle hands twice.
- agentbox.toml: [poker_citizen].state is no longer pinned (it would point the role at a
  workspace path it cannot write); the runner's default is the same path flag-off.
- tests: role-custody-migrate checks the runner's ledger path and rollback guard (33 cases).
  isolate on the real program shape gives user=ab-poker-citizen and
  POKER_CITIZEN_KEY_FILE=/run/secrets/ab-poker-citizen/house.key.
- docs: the role tables in SECURITY-profiles and ADR-2122.

Co-Authored-By: jjohare <github@thedreamlab.uk>
ADR-2122's note closes the gap its previous note recorded; the other eight see only the
[poker_citizen].state line becoming a comment. Earlier notes kept.

Co-Authored-By: jjohare <github@thedreamlab.uk>
…iable without a role

secret_bearing_programs is an opt-in list, and the poker house seat showed its weakness: the first
program added after role isolation landed held a key and was not on it, so the build said nothing.

role-accounts isolate now also fails the build when a user=devuser program that is not in
secret_bearing_programs has an environment naming
- a ROLE-class variable from config/custody/env-classes.json, or its file_var twin
  (--env-classes; the flake now passes it), or
- a variable ending _PRIVKEY_HEX, _SK or _KEY_FILE.
Root programs and role programs are exempt; the error names the program and the variable.

Red first: against PR #14 before its role (2de360f), isolate over every [program:] block in that
flake fails with exactly one error, poker-citizen / POKER_CITIZEN_KEY_FILE. With the role, all 43
programs pass. tests/config/lib/flake-programs.sh renders the flake's programs (user and variable
names, no Nix eval); role-isolation-supervisor runs it both ways on every CI run (25 cases), and
four Rust unit tests cover each branch (cargo 172).

Co-Authored-By: jjohare <github@thedreamlab.uk>
…ds (e3b06d6)

Co-Authored-By: jjohare <github@thedreamlab.uk>
@jjohare
jjohare merged commit 8f55d9a into main Oct 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants