fix: bind complete P1 manual dist graph and snapshot identity

prepare records an immutable manifest of every regular backend/dist file
(path/size/sha256/dev/ino) in the owned root and binds its record identity
in ownership; serve revalidates record and every file before spawn, passes
the manifest to the child on fd 4, and the immutable preload hash-verifies
all files at startup and serves only cached verified bytes for any import
below backend/dist, so imported dependency replacement is refused before
RUNNING or never executes. The render command validates the commit
snapshot.json manifest, binds snapshot bytes to the manifest digest and the
installed Git blob, and passes the expected digest to the renderer, which
revalidates head/files digest with bounded no-follow reads and renders only
verified bytes with lease release on refusal.
This commit is contained in:
2026-08-10 17:36:24 +02:00
parent 1c11d61f78
commit c7338969d7
6 changed files with 323 additions and 73 deletions
+24 -14
View File
@@ -37,15 +37,20 @@ path/device/inode/size/SHA-256, creates no supervisor or readiness-status file,
`PENDING` and the server stopped, and refuses an existing root. Use guarded `stop` and `cleanup`
rather than deleting or reusing state manually.
`serve` revalidates the bound `backend/dist/server.js` identity and bytes, every owned
root/runtime/log ancestor, the absence of a legacy supervisor, and the original log identity before
spawning. The log and production entrypoint are opened with no-follow semantics and their descriptors
are passed directly to the child; an immutable preload makes Node load the already verified
entrypoint bytes rather than a later pathname replacement. The child remains the production Node
entrypoint itself: `node --import data:text/javascript;base64,<immutable-preload>
backend/dist/server.js` followed by six ownership, control, and entrypoint-identity arguments. The
preload owns the authenticated fixed `127.0.0.1:8792` control channel and bounded watchdog, and tracks
the HTTP server that this same process successfully binds to `127.0.0.1:8791`. Before publishing the
`serve` revalidates the bound `backend/dist/server.js` identity and bytes, the immutable
post-build manifest of every regular `backend/dist` file (path, size, SHA-256, device, inode),
every owned root/runtime/log ancestor, the absence of a legacy supervisor, and the original log
identity before spawning. The log, the production entrypoint, and the distribution manifest are
opened with no-follow semantics; the entrypoint and manifest descriptors are passed directly to the
child, and an immutable preload makes Node load the already verified entrypoint bytes and the
complete verified `backend/dist` module graph rather than a later pathname replacement. At startup
the preload hash-verifies every manifest file and serves only those cached verified bytes for any
import below `backend/dist`, so a same-path regular replacement is refused (before or during
serving) and can never execute. The child remains the production Node entrypoint itself:
`node --import data:text/javascript;base64,<immutable-preload> backend/dist/server.js` followed by
six ownership, control, and entrypoint-identity arguments (plus the manifest descriptor on fd 4).
The preload owns the authenticated fixed `127.0.0.1:8792` control channel and bounded watchdog, and
tracks the HTTP server that this same process successfully binds to `127.0.0.1:8791`. Before publishing the
`RUNNING` PID record, the parent requires exact nonce-bound control acknowledgements that identify
that owned listener, a 2xx `GET /health`, stable listener generation and entrypoint identity, and a
final authenticated status check. A foreign health listener cannot satisfy readiness. A startup or
@@ -61,11 +66,16 @@ no-follow directory identities to rename and remove only the exact stopped owned
siblings and automated integration artifacts are outside its cleanup boundary.
After `prepare`, follow the 14 ordered steps in the generated absolute-path `GUIDE.md`. Personally run each generated `http-01` through `http-14` curl script in numeric order; they save the exact status, three validation, three sequential publication, pull, three read responses, and three ZIP exports. Each publication derives its current base commit with a bounded parser from the preceding saved API response, with no placeholder base. Run the five numbered negative validation scripts separately at checklist step 10. The render commands validate the bounded saved read response,
its commit-addressed owned snapshot path, the saved publish commit, and the installed Git HEAD before
calling the acceptance-only production renderer. The renderer imports the built `ThtRunner`, resolves
bindings from environment paths, copies one lease with mode `0600` through an opened no-follow
`rendered` directory descriptor, rejects an output-parent identity swap, and releases the lease in
`finally`. For each exported ZIP, invoke the generated extractor with the exact expected workspace ID
its commit-addressed owned snapshot path, the saved publish commit, the installed Git HEAD, and the
bounded `snapshot.json` manifest of that commit: they bind the snapshot bytes to the manifest digest,
the saved revision blob to the manifest revision, and the manifest blob to the installed Git commit
(`git rev-parse <commit>:workspaces/<id>.yaml` plus `git hash-object` of the snapshot bytes) before
calling the acceptance-only production renderer with the expected `--snapshot-sha256`. The renderer
revalidates the bounded `snapshot.json` (`head`, `files[<id>.yaml]`) and reads the snapshot exactly
once with no-follow semantics, rendering only the digest-verified bytes. It imports the built
`ThtRunner`, resolves bindings from environment paths, copies one lease with mode `0600` through an
opened no-follow `rendered` directory descriptor, rejects an output-parent identity swap, and
releases the lease in `finally`. For each exported ZIP, invoke the generated extractor with the exact expected workspace ID
(`p1-filesystem`, `p1-http`, or `p1-s3`); its `python3` helper opens the source once, stages and
revalidates its SHA-256, anchors every extraction and cleanup operation to an opened no-follow
`exports/extracted` directory descriptor, and binds both the manifest and parsed descriptor identity