Watch
2
An argN or any-arg guard on a kubectl grant would silently not bind, because umbra's valueFlags table is AWS-shaped #1351
Closed
opened 2026-08-28 18:47:06 +00:00 by coilyco-ops
·
2 comments
No Branch/Tag specified
main
release
aos/claude/ee98-wardfreeze
chore/full-name-attribution
aos/claude/mt75-bundle-tag
aos/claude/ad84-revert-voice
aos/claude/ad84-voice
aos/claude/tc69-abspath
aos/claude/mt75-quiet-plan
voice-no-rarity-statements
aos/claude/mt75-netlify-remove
aos/claude/ad84-titles
aos/claude/ad84
aos/claude/mt75-aterm-fullscreen
aos/claude/mt75-netlify-wrap
aos/claude/mt75-kubectl-context
aos/claude/mt75
aos/claude/mt75-ward-cut
aos/claude/eb77
aos/claude/fp87-ward-schema
aos/claude/fp87-ward-posture
aos/claude/fp87
aos/claude/vt77
aos/1105-require-issue-labels
aos/claude/kb87-native-arch
aos/claude/kb87-window-identity
aos/claude/kb87
aos/claude/tg69
aos/claude/ff54-retire-issue-refs
aos/claude/ff54
aos/claude/rc44-bundle-version
aos/claude/mu55-contract-tests
aos/claude/mu55-sound-mark
aos/claude/rc44
aos/claude/mu55-identity-card
aos/claude/mu55-doctor
aos/claude/mu55-shadow-reap
aos/claude/mu55-drop-windows
aos/claude/mu55-dryrun-exits
aos/claude/mu55-list-json
aos/claude/mu55-title-order
aos/claude/mu55-overlay-contract
aos/claude/qu74
aos/claude/ue86
aos/claude/yq86
aos/claude/vk48-harness-set
aos/claude/vk48-default-agent
aos/claude/vk48-completion
aos/claude/vk48-release-fix
aos/claude/vk48
aos/claude/yb89
aos/claude/sb46
fix/agent-compose-pin-v3-roster
aos/claude/ve67-defer
aos/claude/ve67
aos/claude/ur54
aos/claude/tj49
feat/acompose-v3-roster
ops/393-retire-doc-size-alias
ops/393-drop-em-dash-check
feat/vendored-tree-exclude
aos/claude/xlarge-band
aos/claude/ue65
aos/claude/identity-color-wins
aos/claude/ap47
aos/claude/zr44
aos/claude/xk58
aos/claude/aw85-skill-size-owner
aos/claude/ym96-docs-bands
aos/claude/wt57-pin-aos-bundle
aos/claude/wt57-image-inputs-filter
aos/claude/ym96-label-taxonomy
ops/dev-base-pin-rust-1.90.0
aos/claude/mg96-clean
aos/claude/mg96
backup/fix/bake-precommit-hooks
rescue/aos-test-timeout
aos/claude/issues-977-979-agents-base
aos/claude/sx87
refactor/remove-context-budget-json
issue-946
aos/codex/20260806t050901z-50407-6291ab0a
aos/codex/standalone-shadow-workspace
backup/aos/codex/20260806t061240z-10127-754d7de2
aos/codex/standalone-local-service-route
aos/codex/aosterm-aoscompose-wrapper
aos/codex/agents-launch-profile-source
aos/codex/launch-profiles-yaml
aos/codex/20260806t031603z-7731-c76c17f2
backup/aos/codex/20260805t183628z-5916-617bb239
backup/aos/codex/20260805t025242z-30811-fbb135ff
aos/codex/aos-v2-roster-852
aos/codex/20260801t164712z-64119-69ee8bb6
backup/aos/codex/20260801t164900z-67616-2ad2d0e3
issue-834
aos/codex/pr-829-1130
issue-824-agent-proxy-model-routing
task-merge-pr818
fix/aos-ci-20260730
issue-671
issue-734
issue-484
issue-498
issue-622
issue-512
issue-679
issue-454
backup/issue-785-first-person
issue-785-first-person
director-pr784
restore-language-images
recovery/2026-07-28-triaged-branch-archive
recovery/2026-07-27-local-work
recovery/aos-local-build-20260727
codex/land-pr-733
codex/aos-ci-watch
issue-642
issue-682-goose-yaml
issue-656-goose-context
safety/aos-local-main-09347d0
issue-611-specialist-images
fix-action-run-list-page
issue-454-v2
experiment/no-ops-forgejo
feat/dev-base-image
aos-v0.275.0
v0.283.0
aos-v0.274.0
aos-precommit-v0.63.0
aos-v0.273.0
aos-v0.272.0
aos-precommit-v0.62.0
aos-v0.271.0
aos-v0.270.0
aos-precommit-v0.61.0
aos-precommit-v0.60.0
aos-v0.269.0
aos-v0.268.0
aos-precommit-v0.59.0
aos-precommit-v0.58.0
aos-v0.267.0
aos-precommit-v0.57.0
aos-precommit-v0.56.0
aos-eval-v0.12.0
aos-v0.266.0
aos-eval-v0.11.0
aos-eval-v0.10.0
aos-precommit-v0.55.0
aos-v0.265.0
aos-v0.264.0
aos-v0.263.0
aos-v0.262.0
aos-eval-v0.9.0
aos-v0.261.0
aos-v0.260.0
aos-v0.259.0
aos-v0.258.0
aos-v0.257.0
aos-precommit-v0.54.0
aos-precommit-v0.53.0
aos-precommit-v0.52.0
aos-precommit-v0.51.0
aos-precommit-v0.50.0
v0.282.0
v0.281.0
aos-v0.256.0
aos-v0.255.0
aos-v0.254.0
aos-v0.253.0
aos-v0.252.0
aos-v0.251.0
aos-v0.250.0
aos-v0.249.0
aos-v0.248.0
aos-v0.247.0
aos-v0.246.0
aos-v0.245.0
aos-v0.244.0
aos-v0.243.0
aos-v0.242.0
aos-v0.241.0
v0.280.0
aos-v0.240.0
aos-v0.239.0
aos-v0.238.0
aos-v0.237.0
aos-v0.236.0
aos-v0.235.0
aos-v0.234.0
aos-v0.233.0
aos-v0.232.0
aos-v0.231.0
aos-v0.230.0
aos-v0.229.0
aos-v0.228.0
aos-v0.227.0
v0.279.0
aos-v0.226.0
v0.278.0
aos-v0.224.0
aos-v0.223.0
v0.277.0
aos-precommit-v0.49.0
aos-v0.222.0
aos-precommit-v0.48.0
aos-eval-v0.8.0
aos-eval-v0.7.0
v0.276.0
aos-precommit-v0.47.0
aos-precommit-v0.46.0
aos-v0.221.0
aos-precommit-v0.45.0
aos-v0.220.0
aos-eval-v0.6.0
aos-precommit-v0.44.0
aos-v0.219.0
aos-v0.218.0
v0.275.0
aos-precommit-v0.43.0
aos-v0.217.0
aos-precommit-v0.42.0
aos-precommit-v0.41.0
aos-eval-v0.5.0
aos-precommit-v0.40.0
aos-precommit-v0.39.0
aos-v0.216.0
aos-precommit-v0.38.0
aos-precommit-v0.37.0
aos-precommit-v0.36.0
aos-v0.215.0
aos-precommit-v0.35.0
aos-v0.214.0
aos-precommit-v0.34.0
aos-precommit-v0.33.0
aos-precommit-v0.32.0
aos-precommit-v0.31.0
v0.274.0
aos-eval-v0.4.0
aos-eval-v0.3.0
aos-precommit-v0.30.0
aos-precommit-v0.29.0
aos-precommit-v0.28.0
aos-precommit-v0.27.0
aos-eval-v0.2.0
aos-precommit-v0.26.0
aos-eval-v0.1.0
aos-precommit-v0.25.0
aos-precommit-v0.24.0
aos-v0.213.0
aos-v0.212.0
aos-v0.211.0
aos-v0.210.0
aos-v0.209.0
aos-v0.208.0
aos-v0.207.0
aos-v0.206.0
aos-v0.205.0
aos-v0.204.0
aos-v0.203.0
aos-precommit-v0.23.0
v0.273.0
v0.272.0
aos-v0.202.0
aos-precommit-v0.22.0
v0.271.0
aos-v0.201.0
aos-v0.200.0
aos-precommit-v0.21.0
aos-v0.199.0
aos-v0.198.0
aos-precommit-v0.20.0
v0.270.0
aos-precommit-v0.19.0
aos-v0.197.0
aos-v0.196.0
v0.269.0
aos-v0.195.0
aos-v0.194.0
aos-v0.193.0
aos-precommit-v0.18.0
v0.268.0
v0.267.0
aos-precommit-v0.17.0
v0.266.0
aos-v0.192.0
aos-v0.191.0
aos-precommit-v0.16.0
aos-v0.190.0
aos-v0.189.0
aos-v0.188.0
aos-v0.187.0
aos-v0.186.0
aos-precommit-v0.15.0
aos-v0.185.0
aos-v0.184.0
aos-precommit-v0.14.0
aos-v0.183.0
v0.265.0
aos-v0.182.0
aos-v0.181.0
aos-v0.180.0
aos-v0.179.0
aos-precommit-v0.13.0
aos-v0.178.0
aos-precommit-v0.12.0
aos-v0.177.0
aos-precommit-v0.11.0
aos-v0.176.0
aos-v0.175.0
aos-v0.174.0
aos-precommit-v0.10.0
aos-v0.173.0
aos-v0.172.0
aos-v0.171.0
aos-v0.170.0
aos-v0.169.0
aos-v0.168.0
aos-v0.167.0
aos-precommit-v0.9.0
v0.264.0
aos-v0.166.0
aos-v0.165.0
aos-v0.164.0
aos-v0.163.0
aos-v0.162.0
aos-v0.161.0
v0.263.0
aos-v0.160.0
aos-v0.159.0
aos-precommit-v0.8.0
aos-v0.158.0
aos-v0.157.0
aos-precommit-v0.7.0
aos-v0.156.0
aos-v0.155.0
aos-v0.154.0
aos-v0.153.0
v0.262.0
aos-precommit-v0.6.0
aos-precommit-v0.5.0
aos-precommit-v0.4.0
aos-v0.152.0
aos-precommit-v0.3.0
aos-v0.151.0
aos-v0.150.0
aos-v0.149.0
aos-precommit-v0.2.0
aos-v0.148.0
aos-v0.147.0
aos-v0.146.0
aos-v0.145.0
aos-v0.144.0
aos-v0.143.0
aos-precommit-v0.1.0
aos-v0.142.0
aos-v0.141.0
aos-v0.140.0
aos-v0.139.0
aos-v0.138.0
aos-v0.137.0
aos-v0.136.0
aos-v0.135.0
aos-v0.134.0
aos-v0.133.0
aos-v0.132.0
aos-v0.131.0
aos-v0.130.0
aos-v0.129.0
aos-v0.128.0
aos-v0.127.0
aos-v0.126.0
aos-v0.125.0
v0.261.0
aos-v0.124.0
v0.260.0
aos-v0.123.0
aos-v0.122.0
aos-v0.121.0
aos-v0.120.0
aos-v0.119.0
aos-v0.118.0
aos-v0.117.0
aos-v0.116.0
aos-v0.115.0
aos-v0.114.0
aos-v0.113.0
aos-v0.112.0
aos-v0.111.0
aos-v0.110.0
aos-v0.109.0
aos-v0.108.0
aos-v0.107.0
aos-v0.106.0
aos-v0.105.0
aos-v0.104.0
v0.259.0
aos-v0.103.0
v0.258.0
aos-v0.102.0
aos-v0.101.0
aos-v0.100.0
aos-v0.99.0
aos-v0.98.0
aos-v0.97.0
aos-v0.96.0
aos-v0.95.0
aos-v0.94.0
aos-v0.93.0
aos-v0.92.0
aos-v0.91.0
aos-v0.90.0
aos-v0.89.0
v0.257.0
aos-v0.88.0
aos-v0.87.0
aos-v0.86.0
v0.256.0
aos-v0.85.0
aos-v0.84.0
aos-v0.83.0
aos-v0.82.0
aos-v0.81.0
aos-v0.80.0
aos-v0.79.0
aos-v0.78.0
aos-v0.77.0
aos-v0.76.0
aos-v0.75.0
aos-v0.74.0
aos-v0.73.0
aos-v0.72.0
aos-v0.71.0
aos-v0.70.0
aos-v0.69.0
aos-v0.68.0
aos-v0.67.0
aos-v0.66.0
aos-v0.65.0
aos-v0.64.0
aos-v0.63.0
aos-v0.62.0
aos-v0.61.0
aos-v0.60.0
aos-v0.59.0
aos-v0.58.0
aos-v0.57.0
aos-v0.56.0
aos-v0.55.0
aos-v0.54.0
aos-v0.53.0
aos-v0.52.0
aos-v0.51.0
aos-v0.50.0
aos-v0.49.0
aos-v0.48.0
aos-v0.47.0
aos-v0.46.0
aos-v0.45.0
aos-v0.44.0
aos-v0.43.0
aos-v0.42.0
aos-v0.41.0
aos-v0.40.0
aos-v0.39.0
aos-v0.38.0
aos-v0.37.0
aos-v0.36.0
aos-v0.35.0
aos-v0.34.0
aos-v0.33.0
aos-v0.32.0
aos-v0.31.0
aos-v0.30.0
aos-v0.29.0
aos-v0.28.0
aos-v0.27.0
aos-v0.26.0
aos-v0.25.0
aos-v0.24.0
aos-v0.23.0
aos-v0.22.0
aos-v0.21.0
aos-v0.20.0
aos-v0.19.0
aos-v0.18.0
aos-v0.17.0
aos-v0.16.0
aos-v0.15.0
aos-v0.14.0
aos-v0.13.0
aos-v0.12.0
aos-v0.11.0
aos-v0.10.0
aos-v0.9.0
aos-v0.8.0
aos-v0.7.0
aos-v0.6.0
aos-v0.5.0
aos-v0.4.0
aos-v0.3.0
aos-v0.2.0
aos-v0.1.0
v0.255.0
v0.254.0
v0.253.0
v0.252.0
v0.251.0
v0.250.0
v0.249.0
v0.248.0
v0.247.0
v0.246.0
v0.245.0
v0.244.0
v0.243.0
v0.242.0
v0.241.0
v0.240.0
v0.239.0
v0.238.0
v0.237.0
v0.236.0
v0.235.0
v0.234.0
v0.233.0
v0.232.0
v0.231.0
v0.230.0
v0.229.0
v0.228.0
v0.227.0
v0.226.0
v0.225.0
v0.224.0
v0.223.0
v0.222.0
v0.221.0
v0.220.0
v0.219.0
v0.218.0
v0.217.0
v0.216.0
v0.215.0
v0.214.0
v0.213.0
v0.212.0
v0.211.0
v0.210.0
v0.209.0
v0.208.0
v0.207.0
v0.206.0
v0.205.0
v0.204.0
v0.203.0
v0.202.0
v0.201.0
v0.200.0
v0.199.0
v0.198.0
v0.197.0
v0.196.0
v0.195.0
v0.194.0
v0.193.0
v0.192.0
v0.191.0
v0.190.0
v0.189.0
v0.188.0
v0.187.0
v0.186.0
v0.185.0
v0.184.0
v0.183.0
v0.182.0
v0.181.0
v0.180.0
v0.179.0
v0.178.0
v0.177.0
v0.176.0
v0.175.0
v0.174.0
v0.173.0
v0.172.0
v0.171.0
v0.170.0
v0.169.0
v0.168.0
v0.167.0
v0.166.0
v0.165.0
v0.164.0
v0.163.0
v0.162.0
v0.161.0
v0.160.0
v0.159.0
v0.158.0
v0.157.0
v0.156.0
v0.155.0
v0.154.0
v0.153.0
v0.152.0
v0.151.0
v0.150.0
v0.149.0
v0.148.0
v0.147.0
v0.146.0
v0.145.0
v0.144.0
v0.143.0
v0.142.0
v0.141.0
v0.140.0
v0.139.0
v0.138.0
v0.137.0
v0.136.0
v0.135.0
v0.134.0
v0.133.0
v0.132.0
v0.131.0
v0.130.0
v0.129.0
v0.128.0
v0.127.0
v0.126.0
v0.125.0
v0.124.0
v0.123.0
v0.122.0
v0.121.0
v0.120.0
v0.119.0
v0.118.0
v0.117.0
v0.116.0
v0.115.0
v0.114.0
v0.113.0
v0.112.0
v0.111.0
v0.110.0
v0.109.0
v0.108.0
v0.107.0
v0.106.0
v0.105.0
v0.104.0
v0.103.0
v0.102.0
v0.101.0
v0.100.0
v0.99.0
v0.98.0
v0.97.0
v0.96.0
v0.95.0
v0.94.0
v0.93.0
v0.92.0
v0.91.0
v0.90.0
v0.89.0
v0.88.0
v0.87.0
v0.86.0
v0.85.0
v0.84.0
v0.83.0
v0.82.0
v0.81.0
v0.80.0
v0.79.0
v0.78.0
v0.77.0
v0.76.0
v0.75.0
v0.74.0
v0.73.0
v0.72.0
v0.71.0
v0.70.0
v0.69.0
v0.68.0
v0.67.0
v0.66.0
v0.65.0
v0.64.0
v0.63.0
v0.62.0
v0.61.0
v0.60.0
v0.59.0
v0.58.0
v0.57.0
v0.56.0
v0.55.0
v0.54.0
v0.53.0
v0.52.0
v0.51.0
v0.50.0
v0.49.0
v0.48.0
v0.47.0
v0.46.0
v0.45.0
v0.44.0
v0.43.0
v0.42.0
v0.41.0
v0.40.0
v0.39.0
v0.38.0
v0.37.0
v0.36.0
v0.35.0
v0.34.0
v0.33.0
v0.32.0
v0.31.0
v0.30.0
v0.29.0
v0.28.0
v0.27.0
v0.26.0
v0.25.0
v0.24.0
v0.23.0
v0.22.0
v0.21.0
v0.20.0
v0.19.0
v0.18.0
v0.17.0
v0.16.0
v0.15.0
v0.14.0
v0.13.1
v0.13.0
v0.12.0
v0.11.1
v0.11.0
v0.10.0
v0.9.0
v0.8.0
v0.7.0
v0.6.0
v0.5.0
v0.4.0
v0.3.0
v0.2.12
v0.2.11
v0.2.10
v0.2.9
v0.2.8
v0.2.7
v0.2.6
v0.2.5
v0.2.4
v0.2.3
v0.2.2
v0.2.1
v0.2.0
v0.1.0
Labels
Clear labels
burndown-2026-06
Backlog burndown June 2026
burndown-2026-08
Closed in the 2026-08-26 backlog burn-down. Reopen freely: state:closed label:burndown-2026-08 recovers the whole set.
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
coherence-core
Core review set for the warded control plane coherence milestone. These issues form the release spine; adjacent milestone issues are stretch or supporting work.
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
qa-fixture
Disposable issue admitted to the bounded Ward QA verification lane.
role/advocate
requires work from the Developer Advocate seat
role/director
requires work from the Portfolio Director seat
role/exec
requires work from the exec role
role/frontend
requires work from the Frontend Engineer seat
role/gamedev
requires work from the Game Developer seat
role/human
requires a person, and specifically not an agent seat
role/platform
requires work from the Platform Engineer seat
role/qa
requires work from the QA role
role/science
requires work from the Applied Scientist seat
role/sysadmin
requires work from the Systems Administrator seat
state
ambient
ambient and ephemeral work, held as a maintained document rather than a queue
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
Milestone
Clear milestone
No items
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/agentic-os#1351
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found while closing #1348 in #1349. Nothing is broken today. This is a trap laid for whoever writes the next guard, and it fails in the direction that does not announce itself.
The mechanic
umbra's
positionals()strips flags before anargNorany-argselector reads argv. To know that--context ser8is two tokens rather than a flag followed by a positional, it consults a hardcoded table incli/execverb/argv.go:Every entry is an AWS CLI global. No kubectl flag is in it - not
--context,--namespace,-n,-f,-o.So for
aosguard ops kubectl get pods --context ser8,positionals()returns["pods", "ser8"]. The flag's value is indistinguishable from a resource name.Why it is quiet
when/deny-whenon a flag selector are unaffected, becauseflagValue()scans argv for--flag valueand--flag=valuedirectly and never consults the table. That is why the guard in #1349 binds correctly, and I verified it against the built binary rather than assuming.The table only governs
argNandany-arg. There are no such guards on kubectl grants today, so there is no live defect. But the failure mode for the first person who adds one is:deny-when arg0 matches kube-systemintending to protect a namespace--context--context something, because the argv slots shiftA guard that passes its own tests and then quietly stops binding is the exact shape of the #1348 defect this came out of, and of
resolve_release_refin #1346. Three in one incident.umbra's own docs already name the hazard: "Dropping an entry weakens any
argNguard on a binary taking that flag, and does it silently. umbra#282." So the engine knows, and the table is still one vendor's shape.What to do
Upstream fix is umbra#282: the table belongs in the guardfile, declared per wrap, not hardcoded to one vendor.
Locally, until that lands, the cheap protection is a line in
kubectl.kdlsaying thatargNandany-argselectors are not safe on this wrap while kubectl's value flags are absent from umbra's table. A reader reaching for one deserves to be told before they write it, not after it stops binding.Prefer a flag selector over
argNon this wrap regardless. It reads what it names.Related
Read the code to fix this and stopped, because the fix has a fork that belongs to whoever owns umbra's grammar rather than to an unattended run. Re-labelling
autonomy/async-consult. Everything below is measured atumbramain.Confirmed, and it is worse than the issue says
cli/execverb/argv.gois 65 lines and the table is exactly as quoted. Two things to add:The short-flag branch has the same defect and no table at all.
So
-n kube-systemdrops-nand leaveskube-systemin positionals.-nis the flag an author is most likely to reach for on kubectl, and it cannot be taught to the table because the table is long-flags-only.The error path already exists.
selectorValuesreturns([]string, error)andevalWhenalready fails closed on it, so a refusal needs no new plumbing aboveresolveSelector.Grantis already threaded to that point, so a declared flag set reaches it in two signature changes rather than four.Why I did not just fix it
The obvious repair, teaching the table kubectl's flags, is the same trap re-armed for the next tool. The structural repair needs a declaration, and there the fork is real.
Truncating positionals at the first unknown flag fails open. I worked this through and discarded it:
deny-when any-arg matches Xwould stop scanning before reachingXand allow the call. For a deny guard, reading fewer values is the dangerous direction.So refusal is the only safe treatment of an ambiguous flag, which forces the question:
argNguards refuse ordinary calls like--all-namespaces. If unknown means boolean, the trap survives for exactly the flags nobody thought to declare.argNguards that already exist inaws.kdl,actions.kdl, andnetlify.kdl, and aws only works today because the builtin table happens to be AWS-shaped.allow-flag/deny-flag.What I would build once that is settled
Wrap-level
value-flagcovering long and short forms,positionalsconsulting builtin plus declared, andresolveSelectorreturning an error so an unclassifiable flag refuses instead of guessing. Roughly: two signature changes, one grammar node, avalidate()rule, tests for the kubectl and-ncases, anddocs/execverb.md. It also needs an umbra release and a pin bump here, which is the loop#1385just proved.Not established
Whether the nine existing
argNguards ever receive argv containing a flag. If they never do, a build-time refusal costs nothing and is clearly right. I did not check their call sites, and that check is most of the evidence the fork needs.Fixed at the source. umbra PR #335 (
coilyco-flight-deck/umbra), branchumbra/claude/ee98-valueflag.Confirmed the mechanic first rather than trusting the write-up, and it is exactly as described:
ser8sits in the positional list, soarg2would read a flag value as a resource name.What landed, in two halves
Either half alone still permits a silent bind, so both are needed.
value-flag <name>on a grant, merged over the built-in table. A guardfile now states its own tool's shape instead of inheriting AWS's. With it declared:positionals([...], "--context") -> [get pods].argN/any-argwhile allowing a long flag that neither the table nor its own list names is rejected when the guardfile parses, with a message naming the flag and both ways to satisfy it. The arity is not inferable from the flag alone, and guessing is what produced the silence in the first place.Runtime behavior is unchanged for every guardfile that parses today, so this is not a migration.
A third test asserts a flag selector still needs no declaration, since
flagValue()reads argv directly and was never affected. That keeps the fix from taxing the guards this issue correctly identified as fine.docs/execverb.mdhad already called this: the table "is one vendor's shape and belongs in the guardfile" (umbra#282).Not closable yet
This reaches aosguard only through the pin chain: umbra release, then
ARG SPECGEN_VERSIONindocker/dev-base/full/Dockerfile, then an aosguard release. That is the same chain that made #1366 look landed twice while the shipped binary was unchanged, so I am leaving this open until the built binary refuses a real undeclared grant. Nothing to do meanwhile - the trap is closed the moment the pin moves.