Skip to content

feat(protected): Isolate owned daemon roles from runtime observers - #1416

Merged
leumor merged 15 commits into
developfrom
feature/pr-314-controller-owned-workload-role-isolation
Sep 22, 2026
Merged

leumor merged 15 commits into
developfrom
feature/pr-314-controller-owned-workload-role-isolation

Conversation

@leumor

@leumor leumor commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

The current cross-version supervisor launches candidate code as the observer, so its private state and sibling management interfaces do not have a workload boundary. This adds a prospective controller-owned four-role adapter for debian13-systemd257-workload-v1, with distinct role accounts, fixed systemd services, isolated storage and network namespaces, constrained management connections, and scoped process observation and termination.

Draft: PR-314 implementation and installed acceptance remain incomplete. Protected authorize/start/checkpoint remain closed.

Changes

  • Retain controller launch intent, generation, boot/manager/cgroup identity, finite deadlines and operation budgets. Reconcile lost start responses and require whole-role quiescence before terminal success.
  • Keep observer authority private, stage exact immutable role inputs through bounded copies, separate expected configuration from daemon-writable state, and expose only fixed in-role paths.
  • Preserve the four-role topology with a closed FNP relay network and controller-bound FCP/HTTP connections. Require controller-verified Mail bootstrap on every session refresh, including after restart.
  • Integrate source-built daemon startup, signed AppHost installation, content retrieval and restart through the new observer adapter without a same-UID launch fallback. Reject unsupported selections before preparation.
  • Add installation assets, a separate administrator positive-path driver, a 45-case workload acceptance contract, regression tests, and a runbook recording evidence and remaining work.
  • Include review fixes for restrictive administrator umasks and both early and pidfd-confirmed process-exit races; required app bindings and final invocation checks still fail closed.

Validation

Latest focused checks executed during implementation/review:

Check Result
Workload tests under root 95 passed, no skips
Observer adapter tests 24 tests, 8 skipped, passed
Acceptance-contract tests 12 passed
Python syntax and final diff whitespace Passed

Earlier broader checks and exact counts are recorded in docs/pr-314-controller-owned-workload-role-isolation.md. They include the four certification self-tests and a successful ./gradlew :platform-devtools:installDist assembleCryptadDist. No Java source changed; the full Java test suite was not run. The distribution build reported 329 Error Prone warnings in 117 untouched Java files. Two overlapping local scheduler runs passed their harness tests but produced different numeric verdicts, including dispersion/regression findings in one run; neither established performance acceptance.

Local root fixtures exercise filesystem permissions, socket transfer and real process-exit timing. Service-manager and many fault observations are simulated. Unit-file verification is static only. The installed driver prerequisite probe returned exit 78: not executed.

Outstanding implementation and acceptance

  • Complete installed hostile/lifecycle drivers: active sibling/admin canaries, candidate/app-UID attacks, namespace/resource escapes, late descendants, revocation, controller/observer loss, output races and stale invocation reuse.
  • Complete workload fixture preparation and copied-reference orchestration, then execute the exact Debian 13/systemd/network/AppHost profile and fix findings.
  • Catalog, scheduler, composed-budget, recovery-clone, migration, historical-product and higher-level Mail consumer adapters remain unsupported; these are implementation gaps, not credential-only operational debt.
  • No installed workload case passed in this session. No PR-313 finite-native case was run. Its fixed 65-case contract remains incomplete; the historical 17 positive cases retain their original source/product/profile identity and do not satisfy this boundary.
  • Original protected authority, independent review, duration/resource comparison and Phase 12 completion remain separate. The 49 mandatory assertions and historical 47 unresolved assertions are unchanged.

Base is 45eb43d6654074df884f59415fa598c1cda93e36, the squash integration of #1415 (PR-313). Historical observations and failed/interrupted evidence are preserved. No VM was allocated or deleted, and no existing-host workload deployment or protected enablement was performed.

Add a fixed four-role source-build adapter with controller-owned launch intent, isolated storage and network namespaces, scoped process observation, and exact-invocation cleanup.

Require controller-verified app sessions, set role access independently of administrator umask, and handle process-exit sampling races without weakening required bindings.

Include an installed positive-path driver, acceptance contract, regression tests, and the remaining implementation and installed-validation gaps. Keep protected execution closed pending workload, finite-native, and original-authority prerequisites.
@leumor
leumor marked this pull request as ready for review September 22, 2026 05:53
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-22T13:28:28.334280Z ad07c8e New commits
🔒 Security Review ✅ Completed 2026-09-22T06:12:20.945316Z 204134e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Use controller-owned role constants throughout preparation after validating the selected roster. This removes private selection data from generated configuration paths and resolves the CodeQL clear-text data flow without suppressing the check. Cover substituted and reordered role selections before mutation.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 204134e8f1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/protected/restricted_workload_controller.py Outdated
Comment thread tools/release-certification/restricted/pr314_acceptance.py
Keep malformed candidate HTTP responses inside the request error boundary so they cannot terminate the controller and healthy sibling roles. Require distinct measured principal context in workload acceptance v2 and bind denial UIDs to the fixed actor account. Add live HTTP parser and hostile principal regressions.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4a36b7048e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9592b50f38

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/protected/restricted_workload_controller.py Outdated
Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated
Comment thread tools/release-certification/restricted/pr314_acceptance.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c092ab8e2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated
Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 15492c2bc6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated
Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated
Provide the Linux peer-option name only within fake-connection tests, preserving protocol and malformed-response coverage on macOS. Guard the real descriptor-transfer test on its Linux proc, setns, and close-on-exec prerequisites. Keep production credential handling unchanged.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5a9b36565a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f50583f507

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py
Comment thread tools/release-certification/restricted/pr314_acceptance.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: daf5757aee

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py
Comment thread tools/release-certification/restricted/pr314_acceptance.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5aa876606f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 145ec11990

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_workload_driver.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c5811959f1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/protected/restricted_workload_app.py Outdated
Comment thread tools/release-certification/restricted/systemd/cryptad-workload@.service Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3ef78579d8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread tools/release-certification/restricted/pr314_acceptance.py
@sonarqubecloud

Copy link
Copy Markdown

@leumor
leumor merged commit 64a1708 into develop Sep 22, 2026
22 checks passed
@leumor
leumor deleted the feature/pr-314-controller-owned-workload-role-isolation branch September 22, 2026 13:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant