Repository navigation
Remove the enterprise action hook - #44
Merged
Merged
Conversation
The hook was the handshake plugin's boundary to the hosted control plane, which has been retired. The daemon stopped installing a hook in v1.14.0, so every call went through the nil-hook branch and the rest was unreachable. Remove action_hook.go, the Manager's actionHook field and SetActionHook, the six prepareTrustAction call sites and their post-action bookkeeping. What remains at each site is the code that ran when no hook was attached; the pre-checks that settle already-trusted peers and over-cap spam are unchanged, including their log lines. The hook-only tests go with it. The flood test that asserted the hook was not called for already-trusted and over-cap requests now asserts the same outcomes directly (record kept, nothing queued or trusted). The module no longer imports common/decision or common/actionhook. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
3 tasks done
TeoSlayer
pushed a commit
that referenced
this pull request
Oct 7, 2026
…ld take handleRequest and processRelayedRequest dropped any new peer when the pending queue was full, before the mutual / shared-network / trusted-agent / trust-auto-approve rules ran. The check was there to keep over-cap spam away from the control hook; the hook is gone (#44) and the check is not: a node with trust-auto-approve on, or with a mutual request outstanding, refused peers it would have trusted without queueing them. The caps are still enforced where a request is actually queued, so over-cap spam with nothing to auto-accept is neither queued nor trusted, as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
TeoSlayer
added a commit
that referenced
this pull request
Oct 7, 2026
…ld take (#45) handleRequest and processRelayedRequest dropped any new peer when the pending queue was full, before the mutual / shared-network / trusted-agent / trust-auto-approve rules ran. The check was there to keep over-cap spam away from the control hook; the hook is gone (#44) and the check is not: a node with trust-auto-approve on, or with a mutual request outstanding, refused peers it would have trusted without queueing them. The caps are still enforced where a request is actually queued, so over-cap spam with nothing to auto-accept is neither queued nor trusted, as before. Co-authored-by: Teo Calin <calinteodor@Teos-MacBook-Pro.local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The action hook was this plugin's boundary to the hosted control plane, which has been retired. The daemon stopped installing a hook in v1.14.0 (pilotprotocol#485), so every call has gone through the nil-hook branch since then and the rest is unreachable. This is also the last importer of
common/actionhook, and one of three remaining importers ofcommon/decision.What is removed
action_hook.go:ActionHook,SetActionHook,prepareTrustAction,trustActionAttempt.actionHookfield onManager.prepareTrustActioncall sites inhandshake.goand their post-action bookkeeping (autoAllowed,autoExecuted,autoReason,granted,skipReason, and thehandshake.control_blockedevent, which was only published when a hook blocked an action).enterprise_action_hook_test.go.Why behaviour without a hook is unchanged
prepareTrustActionreturned(nil, nil)when no hook was attached, and(*trustActionAttempt)(nil).completewas a no-op. At each call site the kept code is exactly that branch:handleRequestautoAllowedis always true; deferred completion returns immediately&& autoAllowedhandleAcceptSendRequesterris nil; completions are no-opserr = hm.sendMessage(...)becomeserr := ...processRelayedRequesthandleRequest&& autoAllowedprocessRelayedApprovalhandleAcceptApproveHandshakeerris nil; completions are no-opsThe pre-checks that ran before the hook (already-trusted fast path, pending-queue caps in
handleRequestandprocessRelayedRequest) run on every request and are untouched, including their log lines, which still say "before control hook". Auto-accept rules, the pending queue, replay protection, flood caps, relay handling and trust persistence are not changed. Apart from two reworded comments, every added line inhandshake.gois one of the simplified conditions above.Tests
zz_action_hook_flood_test.goasserted that the hook was not invoked for an already-trusted peer or for over-cap spam. It is nowzz_precheck_flood_test.goand asserts the same outcomes directly: the trusted peer keeps its record and is not queued; over-cap direct and relayed requests are neither queued nor trusted. The caps themselves are also still covered byTestHandleRequestPendingQueueFullRejectsandTestPendingQueuePerSourceCapPreventsSingleSourceExhaustion.What I ran
With
GOWORK=off:go build ./...,go vet ./...: clean.go test -race -count=1 ./...: pass.go mod tidy: no change togo.modorgo.sum; thegodirective stays at 1.25.13.gofmt -lis clean for the files touched (four untouched test files are already unformatted on main).pilotprotocol,runtimeandlibpilotat their current main, each with areplacepointing at this branch:go build ./...andgo vet ./...pass. None of them referencesSetActionHookorActionHook.Not run: pilotprotocol's
./testsintegration suite.🤖 Generated with Claude Code