Skip to content

Correct sealed OCI load, observe host check, and Ubuntu npm - #149

Merged
zacharybalicki merged 4 commits into
mainfrom
cursor/oci-default-docker-load-e6f8
Oct 1, 2026
Merged

zacharybalicki merged 4 commits into
mainfrom
cursor/oci-default-docker-load-e6f8

Conversation

@zacharybalicki

@zacharybalicki zacharybalicki commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

CANDIDATE_ONLY. Nothing here is published. Optics CLI stays 0.3.24 and Agent SDK Python stays 3.1.0. This pull request is not merged.

What changed

On Ubuntu 24.04, default Docker uses the containerd image store. That unpacker trusts the layer media type. The Run 3 sealed tar says each layer is an uncompressed tar, and the bytes are gzip. docker load prints Loaded image and then fails with archive/tar: invalid tar header, and it can still exit 0.

vantio-install apply writes a temporary archive in the stage directory with the media type set to match the bytes, and loads that file. The sealed file you hashed stays put. Docker keeps the storage driver Ubuntu installed. Preflight records this as PF-OCI-LOAD. An unpack error in the docker load output fails the install, even when docker exits 0.

Apply still accepts that Run 3 archive. The frozen pin is e0b19d557891b1ee8bbd20e702df11669d175e4083ef5bbe2f7077cf30093b5e, source commit 06696d5020700693b0154c59d0e072a24f648378, sealed manifest digest sha256:8b40aec5c125043ec4278a14170677474c9ca31a7ae78e8496c40dffa69d0e19. The file name apply opens is vantio-phantom-engine-pe-residuals-06696d5-linux-amd64.oci.tar.

Run 3 on i-012a9e706d93285d0 loaded that sealed tar and then stopped in FAILED_SAFE. docker run -d for the observe container exited 0, the container later printed Phantom Engine active and AUDIT on ens5, and the installer host check did not verify it. docker run -d exits 0 when the daemon accepts the container, including when the process has already stopped. The host check now reads container status and pid. A stopped process is not verified, even when bpffs pins are still present. A detached container that is still starting is read again for up to 20 seconds, until the loader is running, the five known pins are present, and clsact is on the interface. A detached container that reaches that state is verified.

Attempt 1 stopped before docker load because the Ubuntu nodejs package does not include npm. PF-NPM records that. When Node.js 18 or newer is present, npm is missing, and the installer is root, the plan stays ready and ensure_node runs apt-get install -y --no-install-recommends npm. That is the only allowlisted apt-get. When npm is missing and the installer is not root, plan stops and PLAN.json shows: Install the Ubuntu npm package. The nodejs package does not include the npm binary. Rollback does not remove that package.

This branch is rebased onto main a81df8b9dc3852326b8ce0b25f70fe8f70eae3f8. The network-transfer allowlist still describes the temporary copy, checksum, and revoke. Its basename, hash, source commit, and manifest digest now match the Run 3 sealed archive that apply opens. Stage removal still refuses to follow a symlink.

Proof

Unit tests: python3 -m unittest discover -s packages/vantio-install/tests -q — 165 tests, OK, on this rebased tip. The previous tip of this pull request reported 144. Those tests do not start Docker and do not call apt.

A local Docker 29.1.3 inspect of a one-shot container printed exited 0 false false .... A detached sleep printed running <pid> true false .... Those probe containers were removed. No EC2 lab was started. No npm, PyPI, or install.vantio.ai publish.

Council notes: PASS_WITH_NONBLOCKING_NOTES. The wait was not re-run against the sealed loader on a clean Ubuntu host, and apt-get install npm was not executed in this session. Evidence is under /home/vantioai/scratch/installer-apply-remedi-2026-09-30/.

Residual

PHANTOM-ARTIFACT-MANIFEST.json in the bundle still has to carry this commit, this archive hash, the sealed manifest digest sha256:8b40aec5…, the config digest, the loader hash, and the three layer digests. A sidecar that still describes the older seal 72719cf4… does not pass.

The operations guide branch cursor/pe-ops-sealed-oci-e6f8 (415e55f089b54b1f2a6da6695e755dd10c835da1) is pushed on vantio-phantom-engine. This run opens pull requests only on vantio-open-core.

Current head: 424e4b787f6d8335894019a87f2788ece8faa37a.

Open in Web Open in Cursor 

@zacharybalicki
zacharybalicki marked this pull request as ready for review September 30, 2026 23:12
@cursor cursor Bot changed the title Correct sealed OCI layer media types before docker load Correct sealed OCI load, observe host check, and Ubuntu npm Oct 1, 2026
Ubuntu 24.04's default containerd snapshotter rejects a gzip layer that the manifest labels as an uncompressed tar, and docker load can still exit 0. Apply writes a temporary archive with the media type corrected and treats an unpack error as a failed load. The sealed file and the CLI 0.3.24 / Python 3.1.0 pins stay in place.
Apply now accepts archive e0b19d55 and the identity fields inside that tar. The media-type rewrite stays, and the Optics CLI 0.3.24 and Agent SDK Python 3.1.0 pins stay.
…ics.

docker run -d exits 0 when the process has already stopped and when the container is still starting. The host check waits for a running loader with the known pins and clsact, and it refuses a stopped process. On Ubuntu 24.04, plan installs the npm package when Node is present and the installer is root, and it blocks with that prerequisite otherwise.
Main still named the older customer-staging tar. Apply opens the pe-residuals archive, so the allowlist and its lock test use that basename, hash, source commit, and manifest digest. The temporary allow, checksum, and revoke steps stay. Stage-removal tests pass npm_action on LiveGrant.
@zacharybalicki
zacharybalicki force-pushed the cursor/oci-default-docker-load-e6f8 branch from 8fe3cea to 424e4b7 Compare October 1, 2026 00:38
@zacharybalicki
zacharybalicki merged commit 2e93017 into main Oct 1, 2026
8 checks passed

Copy link
Copy Markdown
Member Author

FOUNDER_OVERRIDE_MERGE (not Kate/kvantio)

  • Exact head: 424e4b787f6d8335894019a87f2788ece8faa37a
  • Squash: 2e93017dd7816bbba8dbfeb1627a2dae4dd1b4ab
  • Council: PASS_WITH_NONBLOCKING_NOTES
  • Next: Run 3 docs-only healthy-apply. CANDIDATE_ONLY; no publish. Merge ≠ proof.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant