Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
45 changes: 45 additions & 0 deletions continuityos/trusted_human_approval_production.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,9 @@

from .durable_approval_replay import SQLiteApprovalReplayGuard
from .multi_host_approval_replay import MULTI_HOST, PostgresApprovalReplayAuthority
from .witnessed_approval_replay import (
ROLLBACK_PROTECTION, PostgresWitnessedApprovalReplayAuthority,
)
from .persistent_governance_store import resolve_persistent_governance_store_path
from .trusted_human_approval import HumanApprovalResult, verify_and_consume_human_approval

Expand Down Expand Up @@ -53,6 +56,20 @@ def build_multi_host_production_replay_authority(
return authority


def build_witnessed_multi_host_production_replay_authority(
*, replay_dsn: str, replay_witness: Any, replay_namespace: str = "human-approval",
) -> PostgresWitnessedApprovalReplayAuthority:
"""Build the R24 rollback/tamper-aware MULTI_HOST replay authority."""
authority = PostgresWitnessedApprovalReplayAuthority(
replay_dsn, witness=replay_witness, namespace=replay_namespace
)
if authority.replay_scope != MULTI_HOST:
raise RuntimeError("production human approval: multi-host replay scope drift")
if authority.rollback_protection != ROLLBACK_PROTECTION:
raise RuntimeError("production human approval: rollback protection drift")
return authority


def verify_and_consume_human_approval_production(
*,
replay_db_path: str | Path,
Expand Down Expand Up @@ -127,9 +144,37 @@ def verify_and_consume_human_approval_production_multi_host(
)


def verify_and_consume_human_approval_production_multi_host_witnessed(
*, replay_dsn: str, replay_witness: Any, replay_namespace: str,
execution_host_count: int, request_receipt: Any, approval_envelope: Any,
trusted_key_registry: Any, pinned_registry_sha256: str, repository: str,
current_base_sha: str, current_head_sha: str, current_tree_sha: str,
now_unix: int,
) -> HumanApprovalResult:
"""Verify one approval with R24 external-witness rollback protection."""
if _execution_host_count(execution_host_count) < 2:
raise ValueError(
"production human approval: witnessed multi-host binding requires topology > 1"
)
authority = build_witnessed_multi_host_production_replay_authority(
replay_dsn=replay_dsn, replay_witness=replay_witness,
replay_namespace=replay_namespace,
)
return verify_and_consume_human_approval(
request_receipt=request_receipt, approval_envelope=approval_envelope,
trusted_key_registry=trusted_key_registry,
pinned_registry_sha256=pinned_registry_sha256, repository=repository,
current_base_sha=current_base_sha, current_head_sha=current_head_sha,
current_tree_sha=current_tree_sha, now_unix=now_unix,
replay_guard=authority,
)


__all__ = [
"DEFAULT_BUSY_TIMEOUT_MS", "SINGLE_HOST", "MULTI_HOST",
"build_production_replay_guard", "build_multi_host_production_replay_authority",
"build_witnessed_multi_host_production_replay_authority",
"verify_and_consume_human_approval_production",
"verify_and_consume_human_approval_production_multi_host",
"verify_and_consume_human_approval_production_multi_host_witnessed",
]
Loading
Loading