Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
262 changes: 238 additions & 24 deletions .github/workflows/client-v1-conformance.yml

Large diffs are not rendered by default.

54 changes: 47 additions & 7 deletions docs/phase1-conformance.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,12 +15,15 @@ the final bytes.

## Frozen GLib source adoption

The Phase 1 lock binds the reviewed GLib iterator backport in both source roots:
The production binding and prior diagnostic harness below retain the reviewed
GLib iterator backport. The current executable harness commit and tree are
recorded in `phase1-conformance.lock.json` under `harnessAuthority`; the isolated
quota-reader repair advances that binding through the two-commit process below.

| Source | Revision | Tree |
| --- | --- | --- |
| Production Chat | `0da8c4749f57e63601b29d66032f80c9bbac1cb5` | `7be1737c4aae02493660d39a2d6f6fdf4dd9e696` |
| Executable harness | `2a594dc5e6643a318fd9f1f660845646899a413d` | `e21006a194ad73dda94c7f248dca32e91733f392` |
| Prior diagnostic harness | `e8fe64b4d2b9bd38a03d8c23a28432518b41c187` | `b8934b32dc6a1352df55bab36af6e261d0aa9e86` |

The production snapshot changes only two Cargo files and 123 reviewed
vendor/provenance files from its prior frozen revision. The executable harness
Expand Down Expand Up @@ -1340,7 +1343,7 @@ The later SDK validator repin must use these exact committed file bytes:

| File | Bytes | SHA-256 |
| --- | ---: | --- |
| `.github/workflows/client-v1-conformance.yml` | 488,849 | `73707057e4a8bcf5055301245d49a23cba2d5b7730e01a0cf1f5e7fd4df727f0` |
| `.github/workflows/client-v1-conformance.yml` | 500,326 | `ec2eda9cf170a3588de5bc2a710c6fe9214e72e7032a9f1e6af1ebf4a6215525` |
| `scripts/contract-canary.mjs` | 40,116 | `1683e2484a228b89ee241b9b434f277895bb6113fa1c2f7051267563b2582380` |
| `scripts/executable-resolution.mjs` | 9,154 | `31e3c412ff8c835f14522f36a59e91f4a4ba82913210ae8e3b4455217503f430` |
| `scripts/owned-temp-directory.mjs` | 6,965 | `a9c55c85cf2b7d70310d278bafd2c8e7695d66f4ae38b9c3f1f12fce0b442095` |
Expand All @@ -1365,11 +1368,13 @@ The later SDK validator repin must use these exact committed file bytes:
| `scripts/unix-producer-supervisor.test.sh` | 13,348 | `a8c6f48915b0c86a704a7ddc28eaa7f808ae0a3ddfcdb38c0c23ac0d83738f6d` |
| `scripts/phase1-windows-supervisor-build.sh` | 4,646 | `713a9e0282887ade3e243b5ba175794d74cdb02c28c38dcd41491c9505812770` |
| `scripts/phase1-windows-supervisor-install.ps1` | 1,743 | `2baab275f0bb6789884cded5f6185d00bfa5348b9e7c3ad1e5575353639101d5` |
| `scripts/windows-job-supervisor.cs` | 310,437 | `802afa50fdfc5c989c837c653e724588124c44dc1ade18b6924789347542e23c` |
| `scripts/windows-job-supervisor.test.ps1` | 177,859 | `c8805aad43f691175f299b96fd196d8bca23acf26ad5f7d750d908b618cb8975` |
| `scripts/windows-job-supervisor.cs` | 319,914 | `62b243a47e7646b1dafcc1583101332d9c7004d98ac200bb91bc828867928526` |
| `scripts/windows-job-supervisor.test.ps1` | 178,124 | `b22a424e2cf90ea6c06c184cf7bf0ca737f6e0a55e656ecc2ff614b5969b4b64` |
| `scripts/windows-quota-diagnostics.test.ps1` | 13,409 | `2594ddf573f7642eea7e050382dcc523daa5b477852d3db774b570328502a2e8` |
| `scripts/windows-owner-directory-quota.test.ps1` | 11,176 | `23b0b5106c5d50676622bf74238e465a80c5a6a9d017275d067263673d9ceecb` |
| `scripts/windows-identity-cleanup-diagnostics.test.ps1` | 5,343 | `cb642a675e39d6052827edc01658466b41b3f590e6e52931f257eaf5fd64ba3e` |
| `scripts/windows-quota-isolated-reader.test.ps1` | 17,205 | `8125f8a2166c4cc65e461b3019d2497656aa51e11fdea80eceb7b336aad299c1` |
| `scripts/windows-quota-lifetime.test.ps1` | 2,513 | `dd10741c19cd97cc1b9ee29ebe18b8381503d589680acd0eddaabda08b5e7aec` |
| `scripts/windows-identity-cleanup-diagnostics.test.ps1` | 5,596 | `fa738d8e93a8132a26e34fbbb58e89f7ac12c13e7298cf923f8db6b31e7097c5` |
| `scripts/windows-cleanup-delete-diagnostics.test.ps1` | 7,433 | `e9d30285a1fe0ad035637621c6a3840eb8a6194b2f23e1a4aa188c5884cd0c64` |
| `scripts/windows-process-sid-diagnostics.cs` | 4,054 | `cd4b1c16a759ce4e63b87c82c4be0dbee9c0b48e9bfd3851eb966c303918e1a2` |
| `scripts/windows-process-sid-diagnostics.test.ps1` | 7,316 | `c83e2d63355fb95c8220045115a3b8106b7507b7132d235ad74eb0283f6c481f` |
Expand Down Expand Up @@ -1523,6 +1528,26 @@ they do not establish the cause of run `34422000259` retroactively.

## Windows quota monitor diagnostics

Native run `34627213499` isolated the reader failure above the isolated root:
ancestor index 3 denied attributes, while direct target reads returned one
1,024-byte file. The isolated root was at index 6. This distinguishes ancestor
metadata access from owner-directory enumeration and actual byte overflow.

Production accounting validates each fixed prefix through the isolated root as
the supervisor, preserving directory and reparse checks. It then expands and
measures only patterns constrained to that root under the validated isolated
user token. Outside-root and ambiguous path components fail closed; denied
subtree reads are never retried as the supervisor. Token duplicates remain
noninheritable and valid across account disablement, and admitted reads retain
their handle through disposal. These attribute checks preserve the existing
check/use behavior; they do not establish immunity to ancestor replacement.
Native run `34632027669` subsequently confirmed that only the implicitly
created `profile\AppData` directory denied enumeration; its parent and both
explicitly initialized children were readable. That intermediate directory is
now included in the existing security initialization and validation loop, using
the same trustees and access contract as its parent and children. Native reader
success and refreshed protected acceptance remain required.

Protected run `34580621067` passed Linux and Darwin, while Windows reported a
quota-monitor error followed by identity-cleanup failure. That does not prove
a byte quota was exceeded. The supervisor now retains only fixed categories:
Expand Down Expand Up @@ -1571,7 +1596,7 @@ The cleanup diagnostic was introduced at `85bc89b1b6d8ef5c099566b827146e0e75608b
status staging harness and is retained in the diagnostic branch ancestry.


The combined quota-context harness is pinned at `e8fe64b4d2b9bd38a03d8c23a28432518b41c187`, tree
The combined quota-context harness was introduced at `e8fe64b4d2b9bd38a03d8c23a28432518b41c187`, tree
`b8934b32dc6a1352df55bab36af6e261d0aa9e86`. It retains the merged staging and cleanup diagnostics.
Only the supervisor and its embedded workflow authority bytes change from
the cleanup harness; all production inputs, native deltas and limits remain
Expand All @@ -1587,6 +1612,21 @@ skip; workflow/specification tests passed 128 cases with 19 platform skips.
Independent specification, quality and final binding reviews passed. These
local results do not replace native Windows CI or protected execution.


## Isolated-user quota accounting

The scoped reader retains the validated standard-user token and duplicates a
noninheritable handle for each synchronous quota scan. It covers background,
final process and post-quarantine terminal accounting without extending the
account lifetime or changing directory ACLs. Active reads own their handles
across identity disposal; surviving monitors retain their state until the task
finishes. See [the native regression contract](windows-quota-reproduction.md).

The earlier owner-directory reproduction landed in #220 with full native CI.
This accounting implementation requires its own native Windows run, reviewed
SDK rebinding and fresh protected validation. The denied protected descendant
and separate cleanup `win32-3` remain open under #219.

## Windows cleanup delete diagnostics

Protected run `34611963297` disclosed the first cleanup categories:
Expand Down
2 changes: 1 addition & 1 deletion docs/roadmap.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ exhaustion nor the identity of the denied descendant.
| --- | --- | --- |
| Frozen Linux backport adoption | Chat #210 and the prepared #207–#209 follow-ups landed. The production backport remains frozen at `0da8c4749f57e63601b29d66032f80c9bbac1cb5`; subsequent harness bindings retain the reviewed source ancestry. | [#188](https://github.com/OpenCoven/chat/issues/188) remains open for complete protected acceptance and advisory reconciliation. |
| Windows staging and diagnostics | Coven #988 and Chat #211 landed. Chat #216 adds bounded cleanup categories; #218 adds quota-root/operation context. All ten final #218 CI jobs passed, including native Windows tests. | Protected status-staging success remains unproven. [#219](https://github.com/OpenCoven/chat/issues/219) owns the quota enumeration repair and separate cleanup investigation. #211 review-thread disposition remains unverified. |
| Native quota reproduction | [Draft #220](https://github.com/OpenCoven/chat/pull/220) adds an isolated-owner directory fixture with readable and byte-overflow controls. See [the reproduction contract](windows-quota-reproduction.md). | Inspect native execution before selecting a repair. A matching fixture signature does not identify the protected run's denied descendant. |
| Native quota reproduction | [#220](https://github.com/OpenCoven/chat/pull/220) landed as `e0d543217b50d47d1c2b3d552adf9bb3df068dd0`. All ten CI checks passed; the native fixture reproduced terminal/background denial, passed readable/overflow controls and restored/removed its fixture. See [the reproduction contract](windows-quota-reproduction.md). | #219’s isolated-token accounting repair requires its own native execution, frozen-source/SDK rebinding and fresh protected acceptance. The exact protected descendant and separate cleanup failure remain unresolved. |
| SDK binding | [SDK #204](https://github.com/OpenCoven/sdk/pull/204) landed at `7f53b74c1c2be2719c87a1c0592d1c13a6a641cf`, binding the exact #218 producer/workflow/bootstrap bytes. Both scopes were rotated and read back before the protected attempt. | Rebind any subsequent governed source change. [SDK #38](https://github.com/OpenCoven/sdk/issues/38) and the final release gate remain open. |
| Process-identity investigation | Chat #207's bounded test-only diagnostics landed. | [#206](https://github.com/OpenCoven/chat/issues/206) still requires causal evidence; later successful jobs do not classify its original failure. |

Expand Down
26 changes: 26 additions & 0 deletions docs/windows-quota-reproduction.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,3 +53,29 @@ that the owned root is actually removed.
The reproduction changes no production quota limits, private ACL rules, frozen
source bindings or validator scopes. A repair still requires native regression
proof, reviewed source and SDK binding updates, and fresh protected acceptance.

## Isolated quota reader

The accounting repair retains the standard-user token after its existing SID,
account, group, integrity and privilege validation. Each synchronous filesystem
scan duplicates that private token into a noninheritable handle, impersonates
only for the scan, then disposes the duplicate. Background, final process and
post-quarantine terminal scans use the same bounded directory walker.

The retained token supports terminal accounting after account disablement; no
new logon or delayed quarantine is needed. Identity disposal closes admission to
new reads, while an already admitted read owns its handle through completion.
If a monitor survives its existing bounded teardown wait, its cancellation and
failure state are disposed only when that task finishes.

`scripts/windows-quota-isolated-reader.test.ps1` checks owner-only directories
below and above quota, the actual terminal producer path, post-disable reads,
exception restoration, an unreadable supervisor-private directory, and a read
held across identity disposal. `scripts/windows-quota-lifetime.test.ps1` checks
state lifetime with an incomplete monitor and an already completed monitor.
The unimpersonated characterization still requires supervisor access denial;
private directory permissions are not expanded.

Native Windows results and a fresh protected run are required before treating
this repair as accepted. The separate protected cleanup `win32-3` failure and
the exact denied descendant remain unresolved by this change.
14 changes: 7 additions & 7 deletions phase1-conformance.lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,11 @@
},
"harness": {
"repository": "OpenCoven/chat",
"revision": "2a594dc5e6643a318fd9f1f660845646899a413d"
"revision": "eda879fa0da04e76289fa977e3e853d9d8696df7"
},
"harnessAuthority": {
"revision": "2a594dc5e6643a318fd9f1f660845646899a413d",
"tree": "e21006a194ad73dda94c7f248dca32e91733f392",
"revision": "eda879fa0da04e76289fa977e3e853d9d8696df7",
"tree": "4f0386723bc7742f4ee69beba3b38a454987a018",
"files": [
{
"path": "scripts/phase1-conformance.mjs",
Expand Down Expand Up @@ -116,8 +116,8 @@
},
{
"path": "scripts/windows-job-supervisor.cs",
"blob": "b26b4415b1973a82f2efc90253211546b1adb332",
"sha256": "802afa50fdfc5c989c837c653e724588124c44dc1ade18b6924789347542e23c"
"blob": "386c2469d01268670d8dd83a164f9a5ae6ee0ebc",
"sha256": "62b243a47e7646b1dafcc1583101332d9c7004d98ac200bb91bc828867928526"
},
{
"path": "scripts/contract-canary.mjs",
Expand Down Expand Up @@ -146,8 +146,8 @@
},
{
"path": ".github/workflows/client-v1-conformance.yml",
"blob": "83eef716c752dfe45d5dccf54300445dbee4e216",
"sha256": "73707057e4a8bcf5055301245d49a23cba2d5b7730e01a0cf1f5e7fd4df727f0"
"blob": "fe798fefd769385190fcf4b5c7773bf24b8bafa9",
"sha256": "ec2eda9cf170a3588de5bc2a710c6fe9214e72e7032a9f1e6af1ebf4a6215525"
}
],
"productionDeltas": [
Expand Down
3 changes: 3 additions & 0 deletions scripts/windows-identity-cleanup-diagnostics.test.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,9 @@ Write-Host 'Bounded identity cleanup classification passed.'
# categories; each must still pair with exactly one retained inner exception.
$instanceFlags = [Reflection.BindingFlags]'NonPublic,Instance'
$identity = [Runtime.Serialization.FormatterServices]::GetUninitializedObject($identityType)
# Constructor bypass also skips field initializers. Keep the lifetime gate real
# while leaving the absent account/token unprovisioned for this cleanup probe.
$identityType.GetField('quotaTokenSync', $instanceFlags).SetValue($identity, [object]::new())
$secret = 'ocv-secret-' + [Guid]::NewGuid().ToString('N')
$missingRoot = Join-Path ([IO.Path]::GetTempPath()) ('opencoven-missing-' + [Guid]::NewGuid().ToString('N'))
foreach ($assignment in @(
Expand Down
Loading
Loading