feat: add durable guest reconnect authorization foundation - #111
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A surviving microVM guest currently cannot reconnect safely: the original bootstrap is single-use, and a signature alone would not fence replaced runners or replayed attempts. This adds the authorization foundation for reconnect: a canonical Ed25519 transcript, original runner-connection generation on session requests, and a control application service backed by atomic PostgreSQL enrollment and one-shot challenge consumption.
The store checks current placement and connected runner generation while holding authority locks, checks expiry against database time, and atomically advances a connection epoch and replaces the bootstrap hash. Cold bootstrap minting invalidates guest enrollment. No private key or RAM is persisted.
This draft does not enable reconnect, advertise a capability, expose reconnect RPCs, change guest behavior, or recover listeners. Hosted support, guest/runner handshakes, immediate relay fencing, and live KVM qualification remain on this branch's integration roadmap. The implemented contract and remaining gates are in
docs/design/2026-09-29-guest-reconnect-authorization.md.Validation:
make verifypasses with real PostgreSQL and Docker integration explicitly disabled. The initial unrestricted run encountered local Docker credential-helper/registry failures and a timing-sensitive CLI test; the CLI test passed in the rerun. This is not a local Docker qualification.Final commit
8c953fc: GitHub Actionsverifypassed (run 36581396796). Disposable local database and example binary removed; root checkouts preserved.