Skip to content

test(native): add protected file lifecycle acceptance - #227

Draft
roodboi wants to merge 32 commits into
nextfrom
feat/native-protected-files-acceptance
Draft

roodboi wants to merge 32 commits into
nextfrom
feat/native-protected-files-acceptance

Conversation

@roodboi

@roodboi roodboi commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Adds a maintained protected-file acceptance selector for ordinary native snapshots and retained Compose file adoption. Synthetic config/secret sources exercise 0444/0400/0600 guest modes, observed UID/GID, granted and ungranted reads, read-only write refusal, linked-worktree isolation, restart, interrupted saved recovery, rollback and exact owned cleanup. No user secret or source permission is changed.

The selector uses bounded captures, exact resource identities, saved stop and nonforced removal. It preserves unsupported-family refusals, source and material freshness checks, redacted output, pending intent and sibling isolation. The current fixture removes unsupported worktree/pull-policy declarations from its closed retained source. Its Docker forwarding guard accepts the exact shipping ownership, alias and runtime config-hash formats while refusing foreign IDs and unknown formatters.

Current head: d0a9381930d32013de8371b362746a5b6b6665fc. Source review covers the selector and its normal production carry from #226. Verification includes 42 formatter/guard controls, one runtime query control, both affected preparation/lifecycle positives, scoped TypeScript, changed lint, privacy and diff checks. Earlier local and hosted failures remain retained; checks on predecessor heads are historical evidence.

The unexecuted successor recipe records explicit reuse of the qualified 04658513 CLI (73a5102d…) and compiler (4621a943…). Every production and build input is unchanged; exactly six test/doc paths differ. New immutable copies and a versioned provenance receipt bind this head. No new build or current runtime pass is claimed.

Actual protected guest access, lifecycle, recovery, rollback and complete original-engine restoration remain required. Prior real attempts stopped at prerequisites or source refusal and do not prove those behaviors. ROOT controls the next one-shot M3 grant; current exact-head CI is separate. This PR does not establish broad file-backed migration support, performance gains or release readiness.

hack-cli-tests added 19 commits October 8, 2026 13:11
Map closed file declarations and explicit read-only service grants without
acquiring file material. Preserve authored provenance and compiler validation,
and keep retained adoption refused until its runtime ownership proof is qualified.
Map closed file declarations and explicit read-only service grants without
acquiring file material. Preserve authored provenance and compiler validation,
and keep retained adoption refused until its runtime ownership proof is qualified.
Preserve preview-only build and job adoption fences while retaining current
completed-job conversion. Bind converted job build provenance to native job
targets and preserve the original Compose source pointers.
Preserve the closed config0444 file proof family and canonical bridge
receipt semantics. Ordinary file adoption, mixed families and broader
secret permissions remain refused until their separate proof gates.
Support exact 0444, 0400 and 0600 modes on exclusive private file snapshots.
Keep version 1 limited to 0444 and require protected members for version 2.
Original source permissions remain unchanged; guest and retained-bind
acceptance are separate gates.
Bind omitted and explicit secret permission intent to the observed original
source and guest in closed private file proof2. Normalize the candidate only
after that proof and reproduce it from saved intent for read-only recovery.
Keep config proof1 and original material ownership unchanged.

Actual guest access, readonly writes, linked isolation and lifecycle acceptance
remain separate gates; this checkpoint carries source and focused controls.
@blacksmith-sh

This comment has been minimized.

@blacksmith-sh

This comment has been minimized.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant