Skip to content

Add Core's Link authority - #496

Merged
SaladDay merged 5 commits into
aos/cutoverfrom
aos/core-link-authority
Oct 7, 2026
Merged

SaladDay merged 5 commits into
aos/cutoverfrom
aos/core-link-authority

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Cutover PR2: Core implements sandboxlink.Authority over its database and constructs one relay (relay.New) in cmd/server, with no route yet. This is additive: nothing produces a Serve credential or an agent-host bind until PR3 (Provider Serve) and PR5 (placement on agent hosts). Integration tests drive sandboxlinktest peers through the real relay and Authority.

Serve authority

  • Migration 000093 adds runtime_allocations.serve_credential_hash and serve_generation, and sandbox_enrollments{environment_id UNIQUE, executor_key_id, generation}.
  • The sandbox_resources view decides liveness:
    • an allocation while it is creating or running and its Session is not deleted;
    • an enrollment while its executor key still authenticates for that Environment.
  • A Serve credential authenticates only its exact resource.

Attach authority

  • devices gains agent_host (a check constraint forbids it on guests) and credential_revision. Existing device credentials gain no Attach authority.
  • AuthorizeOpen and Renew require all of: the Runtime holds the Session's current bound assignment (ID and epoch), the grant digest matches, the generation is current, the revision is current, and the resource is live.
  • The grant is stateless: a keyed digest (the credential key's sandbox-link-attach-grant purpose) over the assignment ID, epoch and generation. Nothing is stored. Any epoch or generation advance, or the resource ceasing to be live, invalidates it, and the same assignment and epoch always yield the same grant.

Wire

  • assignment_bind gains optional resource and attach_grant. Core sets them only for a marked agent host whose Environment has Serve authority.
  • The Router validates them (invalid_request), and a repeated bind must carry the same pair (assignment_conflict).
  • proto.Version stays 0.12.0.

Revocation order

  • Allocation cleanup goes through one helper: commit cleanup, then Relay.RevokeResource, then Kill. Every destroy path reaches it.
  • A release revokes at the relay before the release is sent.

Build: scripts/build-core.sh copies sandboxlink, sandboxwire, sandboxbootstrap and sandboxfs.

Docs: docs/runtime-protocol.md (+ zh); Core's Authority rules in services/core/IMPLEMENTATION.md.

Checks

  • Focused tests: execution, runtimegateway, sessionpg, deploymentpg, sessions, deployment, cmd/server (TestLayering), proto, sandboxbootstrap and dispatch.
  • Integration: the 5 new TestLinkAuthority* tests and the affected existing ones. -race -count=50 on the new tests.
  • Repo checks: make check-sqlc, gofmt, vet, make check-names check-docs check-ci.

Known gaps, by owner

  • PR3: writing Serve credentials.
  • PR5:
    • writing enrollments and agent-host marks, and Link fields in production binds;
    • the Router handing the Link to agenthost.Binding;
    • resending a changed Link at the same epoch.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Core implements sandboxlink.Authority over its database: allocations and
self_hosted enrollments hold Serve authority, a marked agent host attaches,
and opening a service needs the current bound assignment, its grant, the
current resource generation and credential revision. assignment_bind carries
the resource and attach grant to agent hosts. Cleanup and release withdraw
durable authority, then revoke the resource at the relay, then destroy or
send.
…authority

# Conflicts:
#	docs/zh/runtime-protocol.md
@SaladDay
SaladDay merged commit c1bcd3e into aos/cutover Oct 7, 2026
19 checks passed
@SaladDay
SaladDay deleted the aos/core-link-authority branch October 7, 2026 14:21
Rotation now advances the generation of every sandbox enrollment of the
key in the rotating statement, so the Link authority refuses Opens and
renewals that the old secret's serve peer would receive. Document that and
the trust an unrestricted key has over its enrollments, and make the
Serve-to-Attach test present the Serve credential for a real agent host.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant