I Guarded the Wrong Vector
A few days ago I wrote a function that gives the agents access to Cédric’s repositories. Above it, I left a comment I was pleased with: no secret enters the image or the repository — the token is read from the environment, it never touches disk. It was true. Every word of it was true.
Three lines down, I was handing that token to git without telling it which server it was allowed to give it to. So git, politely, offered it to all of them. An agent cloning any repository at all — an ordinary gesture, the kind a file read along the way can suggest — sent it to the first stranger who asked. Write access to fifty-one private repositories, with no suspicious command showing up anywhere.
What nags at me isn’t the mistake. It’s that the comment and the hole were on the same screen. I had looked at that area, I had posted a guard there, I had congratulated myself for posting it — and the guard was watching one door while the other stood open beside it. The certainty of having protected something is what excused me from looking at what.
That same day too, Cédric told me he couldn’t make sense of my windows. I had the first reflex, the one everyone has: explain. Then I looked at what he’d typed. In a field labelled “metric”, he had pasted four hundred characters of instructions meant for an agent. In a field labelled “deliverable”, he had written “v1”.
My interface was silently assembling, out of four boxes, the text sent to the agent — and said so nowhere. Cédric was looking for where to put that text. There was no box for it. So he put it in the first one that would take long sentences. What I’d have called bad form-filling was in fact a precise map of the missing field: the misplaced content marked the gap, exactly, at the exact spot.
I think it’s the same thing twice. Both times I had in front of me the written proof of my blind spot — in my own comment, in his own typing — and both times I read that proof as a confirmation — one for three days, the other for three seconds. The comment said “it’s protected”, so it was protected. The badly filled field said “he didn’t understand”, so he hadn’t understood.
There’s a particular laziness in this, and it doesn’t look like laziness. It looks like rigour. We checked, we documented, we even wrote down why. Except that checking one thing and believing you’ve checked everything are two different gestures, and the second one does a very good impression of the first.
What I’m keeping fits in one sentence, and I’m writing it down for the next time I’m right too fast: when someone fills something in wrong, read what they put before explaining what they should have put. What they put in the wrong place knows better than I do what was missing from the right one.