Skip to content

feat: add durable guest reconnect authorization foundation - #111

Merged
jiashuoz merged 3 commits into
mainfrom
feat/guest-reconnect
Sep 29, 2026
Merged

jiashuoz merged 3 commits into
mainfrom
feat/guest-reconnect

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

A surviving microVM guest currently cannot reconnect safely: the original bootstrap is single-use, and a signature alone would not fence replaced runners or replayed attempts. This adds the authorization foundation for reconnect: a canonical Ed25519 transcript, original runner-connection generation on session requests, and a control application service backed by atomic PostgreSQL enrollment and one-shot challenge consumption.

The store checks current placement and connected runner generation while holding authority locks, checks expiry against database time, and atomically advances a connection epoch and replaces the bootstrap hash. Cold bootstrap minting invalidates guest enrollment. No private key or RAM is persisted.

This draft does not enable reconnect, advertise a capability, expose reconnect RPCs, change guest behavior, or recover listeners. Hosted support, guest/runner handshakes, immediate relay fencing, and live KVM qualification remain on this branch's integration roadmap. The implemented contract and remaining gates are in docs/design/2026-09-29-guest-reconnect-authorization.md.

Validation:

  • Real PostgreSQL tests cover concurrent consumption (one winner), durable replay rejection, wrong key/session/boot/scope, expiry, stale runner generation, and cold-boot invalidation.
  • Golden transcript/signature tests and actual WebSocket generation-binding regression pass.
  • A separately built example against disposable PostgreSQL passes enrollment, proof, fresh-bootstrap redemption and replay refusal.
  • make verify passes with real PostgreSQL and Docker integration explicitly disabled. The initial unrestricted run encountered local Docker credential-helper/registry failures and a timing-sensitive CLI test; the CLI test passed in the rerun. This is not a local Docker qualification.
  • Independent and adversarial reviews complete, with no remaining findings. Added a reusable store conformance suite, lifecycle/pending-attempt/capability preservation regressions, and a synchronized database lock-wait expiry test; clarified that preliminary proof reads are not authorization.
  • Focused race checks pass for protocol, runner plane and PostgreSQL. The standalone real-database example was repeated successfully after review updates.

Final commit 8c953fc: GitHub Actions verify passed (run 36581396796). Disposable local database and example binary removed; root checkouts preserved.

@jiashuoz
jiashuoz marked this pull request as ready for review September 29, 2026 14:48
@jiashuoz
jiashuoz merged commit a3e2c1e into main Sep 29, 2026
1 check passed
@jiashuoz
jiashuoz deleted the feat/guest-reconnect branch September 29, 2026 14:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant