Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
96379d6
feat: preview basic Compose builds in native config import
Oct 8, 2026
5934593
chore: reconcile basic-build preview with native readiness
Oct 8, 2026
4e5b031
chore: align build preview with completed compiler cleanup
Oct 8, 2026
d7b2901
feat: preview file-backed config and secret grants
Oct 8, 2026
0a7331d
feat: preview file-backed config and secret grants
Oct 8, 2026
dbafdb9
chore: reconcile build preview with current job conversion
Oct 8, 2026
71f3bb4
chore: align build preview with current fixture diagnostics
Oct 8, 2026
461989c
chore: reconcile file preview with current import purposes
Oct 8, 2026
fad11ca
chore: align retained file foundation with current preview
Oct 8, 2026
ef27492
feat: adopt verified retained file config bindings
Oct 8, 2026
b13d6a9
chore: reconcile retained file ownership with bridge adoption
Oct 8, 2026
562e8c0
feat: preserve protected native file permissions
Oct 8, 2026
a76653b
Merge commit '562e8c0de20e5758c5cb99fa25838b877bdb6dc7' into feat/nat…
Oct 8, 2026
6d6ccb2
feat: preserve protected secrets during retained adoption
Oct 8, 2026
ea3d702
feat(native): integrate protected retained files with current topolog…
Oct 8, 2026
3c4bdce
chore: reconcile retained secret proofs with current fixtures
Oct 8, 2026
c0241b6
chore(native): reconcile protected files with current next
Oct 8, 2026
8a57ac1
test(native): budget protected snapshot lifecycle
Oct 8, 2026
228b964
feat(native): reconcile retained file proofs with completed jobs
Oct 9, 2026
1aa67ac
fix(native): observe unnamed retained file binds safely
Oct 9, 2026
9881207
Merge branch 'next' into feat/native-retained-secret-permissions
Oct 9, 2026
7be8ad2
test: align dependency forwarding with owned mount inspection
Oct 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions docs/reference/native-compose-adoption.md
Original file line number Diff line number Diff line change
Expand Up @@ -294,6 +294,63 @@ it does not independently terminate a caller-owned engine callback.

## Rollback and interruption recovery

### Original file grants: private version 8

The distinct retained-file preparation owner supports a closed subset:
static image services, the original default bridge, already-bound local named
volumes and explicit file-backed config grants with a verified read-only `0444`
target, plus protected original secret grants with verified `0400` or `0600`
source and guest permissions. The ordinary adoption baseline remains closed; pure import preview
alone never authorizes retained files. Builds, jobs, profiles, routes, custom
networks, readiness/dependency intersections, managed/generated inputs and typed
locals remain refused by this file family before material or engine acquisition.
Unused declarations do not grant access or authorize material reads.

Preparation checks every original bind's exact source path, target and read-only
flag alongside the existing original resource identities. Docker may omit a
bind's `Name` field; its observation projects that absence as the exact empty
name. Named volumes still require their literal verified name. Descriptor-held reads
require canonical owned directories and regular, single-link source files; no
symlink, hardlink, path escape, source replacement or unsafe writable material is
adopted. It never rewrites or chmods the original. Private source facts retain
device/inode, owner, mode, size, timestamps and a content digest. Fixed original-ID
guest `stat`/`sha256sum` queries must agree with the host content and selected
permission policy; effective guest UID/GID and file identity are observed, not inferred as
root. Repeated observations fence drift, but do not atomically freeze the guest,
host filesystem or Docker.

Private manifest and receipt version 8 retain that proof. Material bytes, paths,
identities and digests never enter public plans, reports or diagnostics. Current
material and guest proof are reacquired before retained start/restart or exec,
after effects and immediately before successful journal publication. The file
owner requires one finite mutation deadline. Failure, uncertainty, permission or
content drift leaves pending ownership for explicit stop recovery.

Saved ps/logs, stop/recovery and rollback validate the saved closed proof and exact
original bind/resource identities without acquiring current material. They can
settle stopped originals even after a material source disappears; missing or
changed material still refuses a new start or exec. Rollback restores only the
exact held authored pair and never edits a material file or deletes retained data.

Private file proof version 1 preserves the config-only `0444` contract. Version 2
adds protected original secret binds with exact `0400` or `0600` source and guest
permissions. The strict retained-purpose mapper preserves whether a permission
was omitted or explicitly declared. An omitted secret permission can normalize
only to the verified original effective permission; an explicit permission must
agree with that same source and guest. Explicit `0444` over a protected source
refuses. Config grants remain `0444`, and pure import preview keeps its existing
declarative defaults. The private candidate is normalized only after the original
proof, then compiled. Saved reads derive the same candidate from the immutable
proof and raw authored intent without material reads. Unknown proof versions,
policy-presence swaps, changed source mode and changed guest UID/GID refuse.

This source contract is not complete file/secret or NC04 parity. No original
permission is changed, no guest owner is inferred, and UID/GID overrides remain
refused. Original mount and material ownership, granted and ungranted reads,
read-only write refusal, linked-checkout isolation, retained lifecycle, recovery
and rollback remain required live gates. Mixed build, job, custom-network,
routing, generated, managed and typed-local families stay outside this owner.

After the original containers are stopped, `hack config adopt --rollback`
journals `rolling-back`, holds the installed candidate and restores both exact
legacy originals. Link-before-unlink restoration cannot overwrite another file;
Expand Down
16 changes: 12 additions & 4 deletions docs/reference/native-config-files.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,8 +60,8 @@ managed owner and exact material projection. The native graph adapter continues
refuse raw file namespace presence, including empty definitions and inactive
grants, before private value copies. Neither path falls back to another backend.

The first private owner subset is read-only mode `0444` with no UID/GID override;
custom permissions, writable access, one-off `run`, and projects combining builds
The private owner supports read-only modes `0444`, `0400` and `0600` with no UID/GID
override. Other permissions, writable access, one-off `run`, and projects combining builds
with file inputs remain outside that subset. File-backed Compose config/secret
mounts do not implement portable ownership remapping, so emitting ignored attributes
would not satisfy this contract. See the [Compose long-syntax contract](https://docs.docker.com/reference/compose-file/services/#secrets).
Expand All @@ -84,9 +84,17 @@ managed owner before reading file bytes. Hooks may create the selected source fi
changing selection or unsupported permission intent refuses delivery. All authored
build/file combinations, including inactive workloads, refuse before private reads.

Snapshots use owned 0700 directories outside the checkout, exclusive 0444 files,
0600 metadata and exact read-only binds with `create_host_path: false`. A private
Snapshots use owned 0700 directories outside the checkout, exclusive files with
the exact selected `0444`, `0400` or `0600` mode, and 0600 metadata and exact read-only binds with `create_host_path: false`. A private
generated extension anchors the root receipt, snapshot, manifest and file identities.
Snapshot reference/manifest/journal version 1 remains the exact `0444` contract.
Version 2 records protected `0400`/`0600` members, with the requested mode bound by
the selected compiler grant and each immutable file anchor. Older clients refuse
version 2. Host source permissions are observed and never changed to satisfy a
grant; the selected mode applies only to Hack's exclusive private copy. Effective
guest ownership is not remapped or inferred from an image user. This source
contract does not establish application access or retained Compose bind parity;
those need separate live ownership and permission acceptance.
The bind projection encodes literal dollar signs once for Compose interpolation;
filesystem paths and the stored reference remain raw. Saved document checks require
those exact encoded binds and reject interpolation in additional mounts, including
Expand Down
7 changes: 5 additions & 2 deletions docs/reference/native-config-import.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,8 +138,11 @@ grant does not authorize retained adoption of any of those feature families.

These are Linux declaration defaults. Compose's file-backed binds can ignore
permission options, so this preview does not establish original file modes or
runtime binding equivalence. Retained adoption still refuses these declarations
and grants before private values, keys or engine probes. See Docker's
runtime binding equivalence. The ordinary retained-adoption baseline still refuses
file declarations and grants before private values, keys or engine probes. The
separate [retained-file owner](native-compose-adoption.md) requires original bind
and material proof for its closed config-0444 subset; preview completeness does
not provide that authority or qualify ordinary secret permissions. See Docker's
[config grants](https://docs.docker.com/reference/compose-file/services/#configs)
and [secret grants](https://docs.docker.com/reference/compose-file/services/#secrets).

Expand Down
Loading
Loading