Correct sealed OCI load, observe host check, and Ubuntu npm - #149
Merged
Merged
Conversation
zacharybalicki
marked this pull request as ready for review
September 30, 2026 23:12
Ubuntu 24.04's default containerd snapshotter rejects a gzip layer that the manifest labels as an uncompressed tar, and docker load can still exit 0. Apply writes a temporary archive with the media type corrected and treats an unpack error as a failed load. The sealed file and the CLI 0.3.24 / Python 3.1.0 pins stay in place.
Apply now accepts archive e0b19d55 and the identity fields inside that tar. The media-type rewrite stays, and the Optics CLI 0.3.24 and Agent SDK Python 3.1.0 pins stay.
…ics. docker run -d exits 0 when the process has already stopped and when the container is still starting. The host check waits for a running loader with the known pins and clsact, and it refuses a stopped process. On Ubuntu 24.04, plan installs the npm package when Node is present and the installer is root, and it blocks with that prerequisite otherwise.
Main still named the older customer-staging tar. Apply opens the pe-residuals archive, so the allowlist and its lock test use that basename, hash, source commit, and manifest digest. The temporary allow, checksum, and revoke steps stay. Stage-removal tests pass npm_action on LiveGrant.
zacharybalicki
force-pushed
the
cursor/oci-default-docker-load-e6f8
branch
from
October 1, 2026 00:38
8fe3cea to
424e4b7
Compare
Member
Author
|
FOUNDER_OVERRIDE_MERGE (not Kate/
|
6 of 7 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CANDIDATE_ONLY. Nothing here is published. Optics CLI stays 0.3.24 and Agent SDK Python stays 3.1.0. This pull request is not merged.
What changed
On Ubuntu 24.04, default Docker uses the containerd image store. That unpacker trusts the layer media type. The Run 3 sealed tar says each layer is an uncompressed tar, and the bytes are gzip.
docker loadprintsLoaded imageand then fails witharchive/tar: invalid tar header, and it can still exit 0.vantio-install applywrites a temporary archive in the stage directory with the media type set to match the bytes, and loads that file. The sealed file you hashed stays put. Docker keeps the storage driver Ubuntu installed. Preflight records this asPF-OCI-LOAD. An unpack error in thedocker loadoutput fails the install, even when docker exits 0.Apply still accepts that Run 3 archive. The frozen pin is
e0b19d557891b1ee8bbd20e702df11669d175e4083ef5bbe2f7077cf30093b5e, source commit06696d5020700693b0154c59d0e072a24f648378, sealed manifest digestsha256:8b40aec5c125043ec4278a14170677474c9ca31a7ae78e8496c40dffa69d0e19. The file name apply opens isvantio-phantom-engine-pe-residuals-06696d5-linux-amd64.oci.tar.Run 3 on
i-012a9e706d93285d0loaded that sealed tar and then stopped inFAILED_SAFE.docker run -dfor the observe container exited 0, the container later printed Phantom Engine active and AUDIT on ens5, and the installer host check did not verify it.docker run -dexits 0 when the daemon accepts the container, including when the process has already stopped. The host check now reads container status and pid. A stopped process is not verified, even when bpffs pins are still present. A detached container that is still starting is read again for up to 20 seconds, until the loader is running, the five known pins are present, and clsact is on the interface. A detached container that reaches that state is verified.Attempt 1 stopped before docker load because the Ubuntu
nodejspackage does not include npm.PF-NPMrecords that. When Node.js 18 or newer is present, npm is missing, and the installer is root, the plan stays ready andensure_noderunsapt-get install -y --no-install-recommends npm. That is the only allowlistedapt-get. When npm is missing and the installer is not root, plan stops andPLAN.jsonshows: Install the Ubuntu npm package. The nodejs package does not include the npm binary. Rollback does not remove that package.This branch is rebased onto main
a81df8b9dc3852326b8ce0b25f70fe8f70eae3f8. The network-transfer allowlist still describes the temporary copy, checksum, and revoke. Its basename, hash, source commit, and manifest digest now match the Run 3 sealed archive that apply opens. Stage removal still refuses to follow a symlink.Proof
Unit tests:
python3 -m unittest discover -s packages/vantio-install/tests -q— 165 tests, OK, on this rebased tip. The previous tip of this pull request reported 144. Those tests do not start Docker and do not call apt.A local Docker 29.1.3 inspect of a one-shot container printed
exited 0 false false .... A detached sleep printedrunning <pid> true false .... Those probe containers were removed. No EC2 lab was started. No npm, PyPI, or install.vantio.ai publish.Council notes:
PASS_WITH_NONBLOCKING_NOTES. The wait was not re-run against the sealed loader on a clean Ubuntu host, andapt-get install npmwas not executed in this session. Evidence is under/home/vantioai/scratch/installer-apply-remedi-2026-09-30/.Residual
PHANTOM-ARTIFACT-MANIFEST.jsonin the bundle still has to carry this commit, this archive hash, the sealed manifest digestsha256:8b40aec5…, the config digest, the loader hash, and the three layer digests. A sidecar that still describes the older seal72719cf4…does not pass.The operations guide branch
cursor/pe-ops-sealed-oci-e6f8(415e55f089b54b1f2a6da6695e755dd10c835da1) is pushed on vantio-phantom-engine. This run opens pull requests only on vantio-open-core.Current head:
424e4b787f6d8335894019a87f2788ece8faa37a.