Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
An opted-in sessiond now enrolls a process-memory signing key at fresh boot, including secret-free boots, and requires a signed reconnect before accepting current configuration. Reconnect remains unavailable after proof, credential redemption or configuration failure. A successful empty-secret refresh also removes obsolete configuration values.
The guest handshake uses strict 4 KiB stream frames and one five-second deadline. It checks the retained session/boot and increasing accepted epoch, preserves the running agent/PTY, and updates sessiond plus the atomic environment snapshot for future
rainier execchildren; existing child environments are unchanged. Legacy boot behavior remains the default.Depends on #114 (and its #113 prerequisite); this draft is stacked on
feat/guest-reconnect-hostand must be rebased/retargeted after the prerequisites merge. No shipping host sets the new boot opt-in. Host listener ownership, current configuration reconstruction, relay takeover, cold enrollment ordering, capability negotiation and real guest/agent qualification remain required before enabling it. This does not implement snapshots or claim Phase B completion.Validation:
make verifywith disposable PostgreSQL failed on Docker credential-helper/registry access and the pre-existing latency cleanup timing case. That latency case passed in isolation. Final-head Linux CI passed: fullmake verify, non-root jail ownership, CLI/client race checks and fleet script syntax. The built guest process probe passed again after CI.The executable fixture substitutes for the not-yet-enabled shipping host path; AF_VSOCK/KVM and hosted relay takeover remain unqualified. Contract and limitations are documented in
docs/design/2026-09-30-guest-reconnect-session.md. Independent and adversarial reviews passed. Resolved findings: stale cached environment for future execs, and readiness returning after expiry during configuration application. Both have failing-before/passing-after regressions; the original adversarial deadline probe now passes. A documentation nit now distinguishes proof refusal from expiry after settings were applied.Commits:
7407a4eimplementation,bbda76areview fixes,289059fdocumentation clarification.