Pin cross-instance --purge safety (G3h: Beta survives Alpha purge)
Summary
-
G3h closes the most operator-critical multi-instance regression vector:
service uninstall --instance Alpha --purgeMUST NOT destroy Beta's state. A regression inIsSafeInstanceDir/ResolveCertsPath/ recursive-delete bounds could silently nuke the shared/etc/squid-tentacle/instances/parent dir, taking ALL instances down with one purge. - The operator scenario this matters for: a host runs Alpha (decommissioned) + Beta (live production); Alpha's purge MUST leave Beta fully functional. If Beta's cert identity gets deleted, the server's trust list still has its thumbprint but the agent can't authenticate next poll → silent production outage hours later.
- Test composes G1h's setup (register both) + service install Alpha only +
service uninstall --instance Alpha --purge+ 6 assertions: Alpha artefacts gone (happy path) + Beta config/cert-dir/registry-entry survive + log mentions Alpha specifically, never Beta.
Why this is the highest-value remaining multi-instance pin
G1h proved register isolation; G2h proved service-install isolation. The remaining attack surface is the cross-instance destruction path — operations on instance A that side-effect instance B. --purge recursing into a shared parent dir is the worst-case version. After G3h, the multi-instance happy-path + worst-case-destruction-path are both pinned.
Test plan
-
dotnet buildgreen (0 errors) -
CI tentacle-linux-e2e workflow passes G3h_PurgeAlpha_DoesNotDestroyBetaState -
G3h asserts: Alpha config + cert dir gone (happy path) + Beta config + cert dir + registry entry STILL EXIST + log line "Removed '{Alpha}' from instance registry" present + log MUST NOT contain "Removed '{Beta}'" -
Existing 42 Linux E2E tests still pass