fix: serialize P1 manual server ownership
This commit is contained in:
@@ -28,18 +28,26 @@ secret files, concrete request/inspection commands, and `GUIDE.md`. It leaves st
|
||||
the server stopped. It refuses an existing root; use the guarded `stop` and `cleanup` actions rather
|
||||
than deleting or reusing state manually.
|
||||
|
||||
`serve` starts only `node backend/dist/server.js`, bound to `127.0.0.1:8791`, and saves logs and a
|
||||
guarded PID identity inside the owned root. `stop` sends TERM only after validating the ownership
|
||||
nonce, executable, command token, repository cwd/root, and recorded process start identity. It never
|
||||
uses `pkill`. `cleanup` refuses a live or ambiguous process and removes only the exact owned fixed
|
||||
`serve` exclusively reserves the lifecycle and PID records before checking the fixed port, then
|
||||
starts an owned Node supervisor that imports the production backend configuration and app in the same
|
||||
process and binds it to `127.0.0.1:8791`. Readiness and `backend.pid` bind that exact process to a
|
||||
random nonce and an ephemeral loopback control endpoint. `stop` revalidates the exact executable,
|
||||
arguments, repository cwd/root, and process start identity, then requests shutdown over the
|
||||
nonce-authenticated cooperative channel and requires the exact acknowledgement. It never sends a
|
||||
numeric terminating signal. `serve`, `stop`, and `cleanup` are serialized; ambiguous, stale, or
|
||||
starting records remain for operator inspection. `cleanup` removes only the exact stopped owned fixed
|
||||
root. Foreign siblings and automated integration artifacts are outside its cleanup boundary.
|
||||
|
||||
After `prepare`, follow the 14 ordered steps in the generated absolute-path `GUIDE.md`. Personally run each generated `http-01` through `http-14` curl script in numeric order; they save the exact status, three validation, three sequential publication, pull, three read responses, and three ZIP exports. Each publication derives its current base commit with a bounded parser from the preceding saved API response, with no placeholder base. Run the five numbered negative validation scripts separately at checklist step 10. The render commands validate the bounded saved read response,
|
||||
its commit-addressed owned snapshot path, the saved publish commit, and the installed Git HEAD before
|
||||
calling the acceptance-only production renderer. The renderer imports the built `ThtRunner`, resolves
|
||||
bindings from environment paths, copies one lease atomically with mode `0600`, and releases it in
|
||||
`finally`. Do not inspect or print raw secret-file contents; only inspect ownership/mode/path metadata
|
||||
and canary absence outside `fixture-secrets`.
|
||||
`finally`. For each exported ZIP, invoke the generated extractor with the exact expected workspace ID
|
||||
(`p1-filesystem`, `p1-http`, or `p1-s3`); it stages one immutable owned copy, confines extraction,
|
||||
and binds both the manifest and parsed descriptor identity to that expected ID. The generated secret
|
||||
scan checks bounded bytes from every Git object, including unreachable blobs and dangling commits.
|
||||
Do not inspect or print raw secret-file contents; only inspect ownership/mode/path metadata and canary
|
||||
absence outside `fixture-secrets`.
|
||||
|
||||
## Failures and verdict
|
||||
|
||||
|
||||
Reference in New Issue
Block a user