Skip to content

Integrate the selected Local worker and crash-safe Setup lifecycle #268

Description

@Anuraj-dev

Parent

What to build: Integrate only the measured Bakeoff Winner into the atomic installer, daemon-owned worker lifecycle, mode transitions, and Setup maintenance protocol. Production admission remains closed throughout this ticket.

Blocked by: #267.

Status: blocked · P1 · L3 implementation

  • Catalog only immutable artifacts and explicitly catalogued HTTPS redirect hosts; preserve fail-closed behavior on host rotation.
  • Complete consent, download, digest/size/ABI validation, first-inference health, atomic receipt activation, retained receipt, repair, rollback, and interrupted-install recovery.
  • Acquire a daemon-owned maintenance reservation before mutation; wait for active Recording/Replay, drain and unload the idle worker, then release ownership explicitly.
  • Never use socket absence alone as proof the daemon is absent and never mutate artifacts leased by a live Recording.
  • Bind the selected executable and model to packaged/verified identities; reject caller-controlled paths and mismatched receipts.
  • Integrate bounded starts, prepare, inference, cancellation, crash/OOM recovery, mode switching, suspend/resume, and exact child-tree cleanup.
  • Exercise truncation, redirect escape, wrong hash/size/ABI, symlink/FIFO/path attacks, ENOSPC, concurrent Setup, and process kill at every install transaction boundary.
  • Prove prior valid and retained receipts survive every pre-commit failure.
  • Keep production Local admission unavailable before capture at ticket exit, as required by L3.
  • Run independent review and all exact-head repository checks.

Do not include: enabling Local capture, claiming Fedora support, weakening privacy restrictions, or adding a public experimental selector.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions