Repository navigation
Conversation
Keep the ownership-pipe writer in Runtime and forward its verified reader through Browser launchers. Reuse the update-controller pipe contract for VM, hosted, native and proof helpers, and flush the crosvm guest before VM termination. Verify parent loss for TERM, INT and KILL through the real helper spawn path, Runtime provider shutdown, and guest flush ordering. Targeted Rust, Node, product-data and formatting checks pass. Full control-socket and installed VM journeys require operator proof outside the sandbox.
…nux launches engines
…ocket length limit
Preserve the read-only seed while giving the owned VZ launch disk private write permissions before guest overlays. Recreate partial clone output before the copy fallback. Add a seed mode, inode and write isolation regression.
Retain Engine obligations when its owner is unavailable or its receipt is incomplete. Preserve partial native evidence across control-service reconciliation and restart. Add bound receipt, pending ownership, replacement/reset refusal and partial absence regressions. Validation: control-service settlement smoke, product-data/public-copy checks, Rust format checks and diff check pass. Compiled Rust and installed journey proof remain pending.
Acquire the existing profile sidecar lease before checking Runtime ownership. Retain trusted root/profile directory descriptors, reject linked or replaced profile paths, and keep the lease in the blocking unlink worker through cancellation. Preserve scoped Reset receipts and missing-disk idempotence. Validation: independent Mac/Linux source review, workspace formatting and diff check pass. Writer, link, replacement and cancellation regressions are prepared; compiled and installed proof remain pending.
Keep the single startup result inline and preserve all tested handle transfers. The scoped Clippy expectation documents its bounded use. Validation: independent usage and ownership review; executable source is byte-identical after removing the attribute.
Pass the validated Engine receipt into Runtime terminal retirement so first remote Close can persist exact cleanup proof and safely release its owner. Preserve native cleanup validation, authority checks and replay ordering. Verification: the cached prior signed Carrier case failed in 0.92 seconds; both exact signed Carrier and remote cleanup/replay/late-input tests pass after one targeted compile. Independent receipt and call-site review passed. Whitespace, workspace formatting and product-data checks pass.
Use an atomic sequence and exclusive directory creation so parallel tests cannot adopt or remove another fixture. Add a forced-collision regression that preserves the existing owner.
Verify the exact bytes consumed by tar for each payload before immutable publication. Keep source checks and ownership-aware publication cleanup. Verification: python3 -B scripts/package-browser-vm-image-test.py -v (7 passed); git diff --cached --check; independent producer review passed.
Validate every selected source before publishing helpers, retain owned output identity during cleanup, and require explicit handoff from native producers. Release wrappers use the managed Node component. Verification: python3 -B scripts/browser-host-release-test.py -v (20 passed); git diff --cached --check; independent admission and cleanup reviews passed. Complete role integration remains with #217 and #89.
…nto feat/217-browser-role-closure # Conflicts: # docs/BROWSER_CAPSULE.md
16 tasks
# Conflicts: # elastos/crates/elastos-server/src/setup.rs
…ole-closure # Conflicts: # elastos/CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Normal installation obtains one admitted ARM64 Browser guest and matching helpers for Mac Apple Virtualization and Jetson crosvm/KVM. Both hosts use the same Chromium + Selkies + network-wrapper VM. Runtime owns admission, grants and lifecycle; Engine executes websites; Exit owns authorized website streams; Carrier carries delivery below Runtime authority.
This integrates #295's ownership changes through a normal merge. Linux launches use the principal's persistent profile disk, keep a single-writer lock through the guest writer's lifetime, and require guest flush/unmount before crosvm stops. Setup checks KVM access and keeps Home usable when Browser preparation needs repair. Node and TURN use admitted helper paths. The installer owns the explained one-time privileged Linux network/KVM step and its removal.
The guest recipe freezes authenticated Debian/security snapshots, exact Chromium payload hashes and a compatible Python dependency closure. Bootstrap requires Debian archive keys and forces signature validation. Release packaging accepts the shared image by CID through the existing bounded Carrier stream, with exact length/SHA-256 checks and the common idle-data deadline. Mac and ARM Linux consume the same admitted image set. The host-native namespace Engine, its privileged CI smoke and obsolete product instructions are retired; Playwright stays test-only.
The normal pre-push gate passed all 34 workspace checks, Clippy with warnings denied, 4,049 Rust tests and 1,478 behaviour tests. Its 63 gate fixtures cover complete package removal while preserving strict proof for changed inputs. The exact release-source step passes under umask 022. A bounded independent review's bootstrap and gate integration findings are resolved.
Refs #217, #288 and #165. #217's current checkpoint owns candidate identity, verification and the image handoff. Native image production, signed admission, fresh Mac/Jetson journeys, crosvm lock retention after launcher death and profile survival through update remain acceptance work. Hardware, media, soak, manual UX and human approval gates remain open. OMP owns cross-family review, integration, signing and release publication; Irzhy reviews the integrated ownership part here.