portable

package
v1.45.13 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: GPL-2.0 Imports: 17 Imported by: 0

README

PR7 portable locator and entrypoint slice

The projected package invokes its notification binary with exactly portable-launch --locator agent-notify-<64 lowercase SHA256 hex>.json. Only PLUGIN_DATA is used to select identity; PLUGIN_ROOT is passed through but never interpreted as a client identifier. HOME, PATH, cwd and MCP clientInfo cannot select the integration. The launcher starts the ledger-authorized regular primary with portable-primary and the same bounded selector. That primary revalidates the locator, installation, its own executable path and the parent-pinned ledger SHA256 (a fixed internal argument) before entering the existing MCP composition. No setup, repair, network or permission action exists in this route. Unsupported platforms fail closed.

Plan and consumer contract

This is the first implementation slice of LAUNCHER-PROMPT.md, the PR7 plan, and PORTABLE-CONTRACT.md (the successful UAP spike at /tmp/pr7-portable-spike-ww36typd). Next comes the setup-owned UAP stager/activator decorator, discovery handoff and consumer removal integration. Those are not implemented here.

Binding.Registration is a pure API returning an exact existing-kernel consumer key/record and locator bytes. Binding.Filename derives the immutable selector from the complete canonical JSON, including explicit integration, UAP install, binding and scope IDs, component ID, owner and all physical root identities. Shared data therefore contains independent per-binding files. The next writer must independently validate the committed UAP binding/data receipt, snapshot the existing installation, then use the existing component transaction/CAS API to register that exact consumer and publish the 0600 locator. This API alone does not authorize a writer. Never write an arbitrary installation marker as authority.

Registration uses Consumer.Registration for the canonical binding document and Consumer.Commands for the one primary path; it adds no duplicate ledger and no kernel schema extension. The primary filename must select a fingerprinted, regular executable in Ledger.RuntimeRoot. Setup must select the installed platform binary, not the existing installer’s symlink alias. Locator bytes are delivery metadata, not a second authoritative managed file: do not add their removable PLUGIN_DATA path to Ledger.Files, since cache loss must not invalidate the permanent installation.

Every launch checks the current installed snapshot and acquires the existing setup lease (disabled notification policy still permits MCP status). Current owner, installation, runtime, consumer record, recovery, generation/policy floor and fingerprints are checked. Per-request policy reads check the binding again; native delivery retains the existing installed lease. Binding does not freeze the component generation, so unrelated consumer updates do not stale survivors. Consumer removal/replacement revokes the binding; an old snapshot cannot acquire a lease after a concurrent managed change. Managed primary refresh may retain the same path; an immutable binding change requires new projected argv/locator. The next writer must revoke through the component kernel before deleting the locator or forwarding UAP removal.

Security and runtime boundaries

The reader walks absolute clean physical directories with no-follow openat, then opens one exact file nonblocking/no-follow. It checks owner, mode, type, link count and a 16 KiB size/read bound. JSON rejects duplicate keys, aliases, unknown fields, trailing values and invalid identifiers. The data directory is private; permanent roots reject group/other writes. Parent symlinks are rejected, including common macOS aliases: setup must provide physical paths.

A five-second context bounds lock acquisition; regular filesystem syscalls, including the existing kernel's fingerprint reads, have no hard wall-time bound. The launch lease covers Start and is released before the primary acquires its own lease, avoiding a child-start deadlock. Cancellation kills/reaps the owned primary; no shell or daemon is added. Security assumes the existing kernel's trusted same-user setup boundary: this does not sandbox a malicious process already able to rewrite private owner state outside the component lock.

MCP uses explicit permanent ControlRoot/GlobalConfig and the same service, journal and spool defaults. Package removal after start does not relocate state. No new Linux native capability is introduced: the Linux subprocess bridge uses an injected fixed boot clock and a native factory that panics if invoked, with actual runtime/MCP composition and read-only status calls. Production retains its existing unsupported-platform behavior where the native clock is absent.

Qualification

Focused tests cover both integrations in shared data, exact argv, minimal two-variable child environments, spaces, removal of package/data, revocation, lease exclusion, canceled acquisition, strict JSON and unsafe filesystem objects, owner/floor/recovery/primary failures, MCP stdout purity and signal cancellation. The production composition bridge copies the test executable into fresh package and permanent-runtime roots; it never invokes a client or native backend. No installed activation, UAP decorator, discovery collision/handoff, real native retention or full E2E qualification is claimed. Darwin execution and unsupported-platform behavior beyond the existing contract remain separate platform gates.

Documentation

Overview

Package portable selects an explicitly registered installed runtime. Setup publishes locators after the kernel consumer commit; launch never writes.

Index

Constants

View Source
const MaxBytes = 16384

Variables

View Source
var ErrInvalid = errors.New("portable_binding_invalid")

Functions

func ExactCommittedBinding added in v1.45.3

func ExactCommittedBinding(ledger installruntime.Ledger, b Binding) bool

ExactCommittedBinding validates one consumer without checking the executable.

func ExactLocator added in v1.45.3

func ExactLocator(b Binding) (bool, error)

ExactLocator returns true only for the private, byte-identical locator. A missing locator is allowed during a resumed revoke.

func InstalledGlobalConfig added in v1.45.3

func InstalledGlobalConfig(ledger installruntime.Ledger, installationID, controlRoot string) (string, bool, error)

InstalledGlobalConfig preserves the config path in a published locator. Changing it changes the consumer key, so existing bindings must keep it until an explicit migration replaces their locator and consumer together.

func InstalledPrimary added in v1.45.2

func InstalledPrimary(ledger installruntime.Ledger, installationID, controlRoot string) (string, bool, error)

InstalledPrimary preserves the identity of an already committed installation. In particular, old locators used "primary" even though bootstrap never wrote that file. A later add/update/remove must not silently change their identity.

func ParseArgs

func ParseArgs(args []string) (string, error)

func PlatformPrimary added in v1.45.2

func PlatformPrimary() string

PlatformPrimary is the regular writer installed by the release bootstrap. Keep the slash-separated locator value independent of the host path separator.

func Publish

func Publish(b Binding) (string, error)

Publish writes the exact locator after the kernel consumer already exists. Identical bytes are a no-op; a conflicting file fails closed.

func ResolvePrimaryExecutable added in v1.45.2

func ResolvePrimaryExecutable(ledger installruntime.Ledger, primary string) (string, error)

ResolvePrimaryExecutable selects a live, ledger-owned writer for setup. Old bindings retain the logical "primary" identity even when that filename was never installed; their helper must use the same owned fallback as launch.

func RevokeLocator

func RevokeLocator(b Binding) error

func SameInstalledFile

func SameInstalledFile(current, installed string) bool

SameInstalledFile is true when current and installed name the same regular file. Darwin /var vs /private/var aliases compare equal; a copy does not.

func ValidateGlobalConfigParent added in v1.45.3

func ValidateGlobalConfigParent(path string) error

ValidateGlobalConfigParent applies launch's read-only parent check during setup, before a binding can be published.

Types

type Binding

type Binding struct {
	Version        int         `json:"version"`
	Integration    Integration `json:"integration"`
	InstallationID string      `json:"installationID"`
	BindingID      string      `json:"bindingID"`
	ScopeID        string      `json:"scopeID"`
	ComponentID    string      `json:"componentID"`
	Owner          string      `json:"owner"`
	ScopeRoot      string      `json:"scopeRoot"`
	DataRoot       string      `json:"dataRoot"`
	ControlRoot    string      `json:"controlRoot"`
	GlobalConfig   string      `json:"globalConfig"`
	RuntimeRoot    string      `json:"runtimeRoot"`
	Primary        string      `json:"primary"`
}

Binding is immutable consumer identity. Generation is deliberately excluded: independent consumer updates must not invalidate surviving bindings. The installed snapshot and lease fence current generation at each launch.

func CommittedBindingVariants added in v1.45.3

func CommittedBindingVariants(ledger installruntime.Ledger, expected Binding) ([]Binding, error)

CommittedBindingVariants is for a controlled transition that temporarily holds the old and replacement consumer for the same UAP binding.

func ResolveCommittedBinding added in v1.45.3

func ResolveCommittedBinding(ledger installruntime.Ledger, expected Binding) (Binding, bool, error)

ResolveCommittedBinding selects the exact historical consumer for a UAP binding. GlobalConfig and Primary may differ from the current defaults: both are part of the registered bytes and must come from the ledger on removal. All other fields are fixed by the UAP receipt and the managed installation.

func (Binding) CheckPrimaryFile added in v1.45.2

func (b Binding) CheckPrimaryFile(snapshot installruntime.InstalledSnapshot) error

CheckPrimaryFile is used before a new binding is committed. It does not require its consumer record yet, but it requires a live, ledger-owned writer.

func (Binding) CheckSnapshot

func (b Binding) CheckSnapshot(snapshot installruntime.InstalledSnapshot) error

CheckSnapshot keeps an already-running portable service bound to the current consumer on every policy read. Revocation does not require deleting shared data.

func (Binding) Filename

func (b Binding) Filename() (string, error)

func (Binding) Registration

func (b Binding) Registration() (string, installruntime.Consumer, []byte, error)

Registration returns the exact consumer record the next setup slice must commit under the component lock/CAS before publishing locator bytes. Calling this pure function does not establish UAP receipt ownership or authorize setup.

type Integration

type Integration string
const (
	Codex  Integration = "codex"
	Claude Integration = "claude"
)

type Lease

type Lease struct {
	Binding    Binding
	Executable string
	SHA256     string
	Release    func()
}

func Acquire

func Acquire(ctx context.Context, data, name string) (*Lease, error)

Acquire rejects missing/revoked/foreign bindings before any runtime work. The consumer record, not a data marker, authorizes the complete identity.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL