port: fix the credential mount, the /reborn pull, and cargo re-fetching
Three fixes from the port agent's first infrastructure report. **A. The credential file is written, so it cannot be a read-only mount.** `credential.helper=store` rewrites its file after a successful auth: temp file, then rename over the target. Renaming onto a bind-mount point gives EBUSY, which surfaces as `fatal: unable to write credential store: Device or resource busy`. The push succeeds anyway, and that is the real hazard -- a `fatal:` line that is routinely wrong teaches the reader to ignore the one that is real. It also fired intermittently, so it read as flakiness rather than as a mount. Fixed by mirroring the pattern already used for .claude.json: mount it as `.git-credentials.host:ro` and have the entrypoint copy it to a writable ~/.git-credentials at 600. Mounting rw would also silence it, but then the container can clobber the host's real credential file; copying cannot. **B. `git -C /reborn pull` can never work, and should not.** /reborn is a live read-only mount of the RE agent's working tree -- it updates itself, and pulling would move another agent's checkout. The prompt now says so, and adds the consequence the agent found the hard way: because the mount is live, HANDOFF can move mid-iteration, so anything copied out of it (BLOCKED.md especially) may already be stale and must be re-checked rather than trusted. **C.** CARGO_HOME moves to a named volume; it was on the container overlay, so the pinned decoder source was re-fetched from the network on every fresh start. Also adds SYLPH_PORT_REPO, so this launcher can be run from a worktree without repointing the agent's checkout -- which is how these edits were made, the agent being mid-iteration on auto/p0-exporter in the shared tree. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -16,8 +16,16 @@ believed later. If you need an answer the disc has not given you, write it in
|
||||
|
||||
1. `docs/MISSION.md` — milestones, gates, scope.
|
||||
2. `/reborn/docs/port/HANDOFF.md` — **the contract.** What is decoded, what was
|
||||
measured off the running game, and what is known undecodable. `git -C /reborn
|
||||
pull` first; the RE agent publishes continuously.
|
||||
measured off the running game, and what is known undecodable.
|
||||
|
||||
**It is a live read-only mount of the RE agent's working tree**, so it updates
|
||||
itself and there is nothing to pull — `git -C /reborn pull` cannot work (the
|
||||
mount is read-only) and should not: it would move another agent's checkout.
|
||||
`git -C /reborn log -1` shows where they are.
|
||||
|
||||
Because it is live, **it can move under you mid-iteration.** Anything you
|
||||
copied out of it earlier — `docs/BLOCKED.md` especially — may already be
|
||||
stale. Re-check it against HANDOFF before trusting it.
|
||||
3. `docs/FORMAT.md` — the open format. It is versioned and it is yours to
|
||||
revise, but a change is a deliberate act with a version bump.
|
||||
4. `docs/BLOCKED.md` — what you are waiting on, so you do not re-discover it.
|
||||
|
||||
Reference in New Issue
Block a user