Skip to content

refactor: remove the unreachable ExecGate; refresh docs and counts (#55) - #74

Merged
abienkowski merged 3 commits into
mainfrom
refactor/remove-execgate-55
Oct 11, 2026
Merged

abienkowski merged 3 commits into
mainfrom
refactor/remove-execgate-55

Conversation

@abienkowski

Copy link
Copy Markdown
Collaborator

Description

Part of #55 (Task 6, the last task of the plan: remove ExecGate, refresh docs and counts).

What changes

  • ExecGate is removed from Go, Rust and TS. The middleware chain only runs on the create route (POST /containers/create), and the router denies every exec path before that (segment-exact since Routing parity: TS path-wide exec deny; Go matchEndpoint accepts endpoint subpaths #49, for every method), so the gate could never fire. Its tests go too, including the two chain tests that called the chain directly with an exec path (Rust test_chain_execute_denies_exec_via_gate, TS "denies exec request"); exec denial is covered by the router tables, the spec (execNeverAllowed, emptySegmentsHideNoExec) and the integration suite.
  • Docs:
    • README: "5 validation gates + 1 config mutator", the ExecGate row dropped, per-language unit counts plus 45 integration + 15 socket, the formal-verification summary names each module's scope (9 request-handling invariants, 6 listener invariants, 7 router properties).
    • AGENTS.md and CONTRIBUTING: the gate list and per-module counts, recounted from the runners.
    • spec/docker_socket_policy.qnt: the exec rows are { method: "*", path: "/containers/:name/exec" } and { method: "*", path: "/exec/*" }, matching the router (any method).
    • spec/README.md: lists emptySegmentsHideNoExec, fixes a missing comma.
    • spec/listener-design.md: the numeric-gid wording matches the normative table (digits only, 0-4294967294; larger exits 2).
    • deploy/test.sh header: ExecGate dropped from the list.

Counts (before → after)

Before After
Go 108 (middleware 29, proxy 41) 108 (main 24, audit 4, middleware 27, policy 10, proxy 43)
Rust 147 143 (main 23, policy 15, middleware 46, proxy 45, handler 8, audit 4, transport 2)
TS 164 (1 skipped) 161, 1 skipped (flags 44, listen 13, middleware 38, proxy 32, policy 10, handler 10, shutdown 5, transport 5, audit 4)

The Go total is unchanged because #71 and #72 each added one proxy test and this PR removes two middleware tests. (The docs before this PR still said Go 108, Rust 145, TS 162; they had not been updated by #71–#73.)

Review notes

  • Release: merging cuts v0.3.7 (patch). Simulated squash: bump=patch tag=v0.3.7.
  • No behaviour change: the gate was unreachable.

Verification

  • make test-all: Go ok, Rust 143 passed, TS 161 tests, 160 pass, 1 skipped.
  • make lint-all, make typecheck, make test-release (51 passed, 9 passed) pass.
  • make test-spec: all 6 runs pass. make verify: [ok] No violation found (both modules).
  • Go integration: ALL 45 TESTS PASSED; CI runs all three.
  • grep -rni execgate over the tracked sources and docs (excluding plans) finds nothing.

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Refactor (dead code removal)

Implementation(s) changed

  • Go
  • Rust
  • TypeScript
  • Quint specification (endpoint table rows)
  • CI / infrastructure

Testing

  • Unit tests pass (make test-all)
  • Integration tests pass (Go 45 locally; CI runs all three)
  • Quint verification passes (make verify, make test-spec)
  • New tests added: none (removal)

Checklist

  • I have read CONTRIBUTING.md
  • My code follows the project's coding style
  • I have updated documentation as needed

@abienkowski abienkowski added the Type: Maintenance Added to issues and PRs when a change is for repository maintenance , such as CI or linter changes. label Oct 11, 2026
@abienkowski
abienkowski merged commit b6a845b into main Oct 11, 2026
7 checks passed
@abienkowski
abienkowski deleted the refactor/remove-execgate-55 branch October 11, 2026 07:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: Maintenance Added to issues and PRs when a change is for repository maintenance , such as CI or linter changes.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant