Skip to content

Pin cross-instance --purge safety (G3h: Beta survives Alpha purge)

Summary

  • G3h closes the most operator-critical multi-instance regression vector: service uninstall --instance Alpha --purge MUST NOT destroy Beta's state. A regression in IsSafeInstanceDir / ResolveCertsPath / recursive-delete bounds could silently nuke the shared /etc/squid-tentacle/instances/ parent dir, taking ALL instances down with one purge.
  • The operator scenario this matters for: a host runs Alpha (decommissioned) + Beta (live production); Alpha's purge MUST leave Beta fully functional. If Beta's cert identity gets deleted, the server's trust list still has its thumbprint but the agent can't authenticate next poll → silent production outage hours later.
  • Test composes G1h's setup (register both) + service install Alpha only + service uninstall --instance Alpha --purge + 6 assertions: Alpha artefacts gone (happy path) + Beta config/cert-dir/registry-entry survive + log mentions Alpha specifically, never Beta.

Why this is the highest-value remaining multi-instance pin

G1h proved register isolation; G2h proved service-install isolation. The remaining attack surface is the cross-instance destruction path — operations on instance A that side-effect instance B. --purge recursing into a shared parent dir is the worst-case version. After G3h, the multi-instance happy-path + worst-case-destruction-path are both pinned.

Test plan

  • dotnet build green (0 errors)
  • CI tentacle-linux-e2e workflow passes G3h_PurgeAlpha_DoesNotDestroyBetaState
  • G3h asserts: Alpha config + cert dir gone (happy path) + Beta config + cert dir + registry entry STILL EXIST + log line "Removed '{Alpha}' from instance registry" present + log MUST NOT contain "Removed '{Beta}'"
  • Existing 42 Linux E2E tests still pass

🤖 Generated with Claude Code

Merge request reports

Loading