Skip to content

feat(sessiond): retain guest identity and authenticate reconnect - #115

Draft
jiashuoz wants to merge 3 commits into
feat/guest-reconnect-hostfrom
feat/guest-reconnect-session
Draft

jiashuoz wants to merge 3 commits into
feat/guest-reconnect-hostfrom
feat/guest-reconnect-session

Conversation

@jiashuoz

@jiashuoz jiashuoz commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

An opted-in sessiond now enrolls a process-memory signing key at fresh boot, including secret-free boots, and requires a signed reconnect before accepting current configuration. Reconnect remains unavailable after proof, credential redemption or configuration failure. A successful empty-secret refresh also removes obsolete configuration values.

The guest handshake uses strict 4 KiB stream frames and one five-second deadline. It checks the retained session/boot and increasing accepted epoch, preserves the running agent/PTY, and updates sessiond plus the atomic environment snapshot for future rainier exec children; existing child environments are unchanged. Legacy boot behavior remains the default.

Depends on #114 (and its #113 prerequisite); this draft is stacked on feat/guest-reconnect-host and must be rebased/retargeted after the prerequisites merge. No shipping host sets the new boot opt-in. Host listener ownership, current configuration reconstruction, relay takeover, cold enrollment ordering, capability negotiation and real guest/agent qualification remain required before enabling it. This does not implement snapshots or claim Phase B completion.

Validation:

  • Full sessiond, relay and sandboxexec race suites passed; focused negative/cancellation/large-environment/concurrent-snapshot checks passed.
  • Built guest test artifact exercised real TCP streams and the production PTY implementation in a separate process: enrollment, refused reconnect, verified proof against the enrolled key, fresh token redemption, unchanged shell PID/PTY, refreshed parent configuration and real exec children with removed secrets absent and boot-chain exports retained.
  • Public contract checks, image security policy checks, build and vet passed.
  • Local full make verify with disposable PostgreSQL failed on Docker credential-helper/registry access and the pre-existing latency cleanup timing case. That latency case passed in isolation. Final-head Linux CI passed: full make verify, non-root jail ownership, CLI/client race checks and fleet script syntax. The built guest process probe passed again after CI.

The executable fixture substitutes for the not-yet-enabled shipping host path; AF_VSOCK/KVM and hosted relay takeover remain unqualified. Contract and limitations are documented in docs/design/2026-09-30-guest-reconnect-session.md. Independent and adversarial reviews passed. Resolved findings: stale cached environment for future execs, and readiness returning after expiry during configuration application. Both have failing-before/passing-after regressions; the original adversarial deadline probe now passes. A documentation nit now distinguishes proof refusal from expiry after settings were applied.

Commits: 7407a4e implementation, bbda76a review fixes, 289059f documentation clarification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant