fix: render registry workspaces for harness

This commit is contained in:
2026-08-05 16:03:45 +02:00
parent ece9cfda50
commit bd798b1c96
21 changed files with 659 additions and 69 deletions
+12 -6
View File
@@ -1,6 +1,6 @@
# ThothII — Project State
> Starting-point snapshot for new sessions. Last updated: 2026-08-05 (portable deployment decoupled).
> Starting-point snapshot for new sessions. Last updated: 2026-08-05 (Task 13 fix round 3/5).
> Point a fresh session here ("read PROJECT_STATE.md") before substantial work.
## Unified deployment release gate — Task 13 (2026-08-05)
@@ -39,11 +39,17 @@
writable parent bind while protected/tracked sources remain separate read-only mounts. Clean
empty-root render/setup and wrong-service/value/mount mutations are green. The corrected server
one-shot built and started both healthy services from an empty Pi-state root, then stopped at an
incorrectly addressed authenticated frontend hop; the trusted-hop fixture correction is
deterministic-only. The corrected rollback one-shot passed runtime/Pi/registry/persistence and
stopped-candidate preflight, then stopped at active-session inventory before mutation. Exact
cleanup passed for both. Full server behavior, compensation/all-sentinel preservation, and
native Windows PowerShell/Docker execution remain explicit release gates.
incorrectly addressed authenticated frontend hop. Fix round 3 adds the exact fourth private
non-admin claim and proves its nginx/backend transformation in a focused auth test. It also
centralizes schema-v2 registry descriptor resolution and secret-safe runtime rendering in
`ThtRunner`, preserving canonical revision identity and durable session roots for inventory,
create/resume/show, SQL, and Pi calls. The fresh update-only one-shot now passes mutation,
automatic `rolled_back` compensation, exact prior-image restoration, unchanged registry head
and mount identities, all four persistence sentinels, post-rollback doctor/workspace checks,
and exact labeled-resource cleanup. The one authorized server invocation was blocked at its
first Docker readiness call by the execution sandbox's socket permission before any Compose
resource could be created, so authenticated workspace/fail-closed session behavior remains an
explicit release gate. Native Windows PowerShell/Docker execution also remains pending.
## Portable deployment decoupling — LIVE 2026-08-05