状态:可独立合并的 enabling infrastructure;尚未形成 product-ready 的 release trust root,也未接入 Desktop/CLI managed-workspace 产品路径。
本切片只证明:
普通 caller 不能用自报的 executable path 或 SHA-256 获得 Gitoxide helper 调用资格;只有内部 release owner 签发、与 owner token 绑定的 artifact claim,在 exact platform、architecture、 protocol、size 与 SHA-256 校验通过后,才能转换为另一个指定 owner 可消费的 opaque invocation capability。artifact 在 admission 后变化时,调用前重验必须 fail closed。
它不证明平台签名、安装目录保护、helper spawn、repository observation、T1 admission、managed workspace 或 crash recovery。
未来的 packaged-release owner └─ issueGitoxideHelperReleaseArtifactClaimInternal(ownerToken, exact artifact identity) ↓ opaque release claim artifact authority └─ exact file/platform/protocol verification ↓ opaque invocation capability 未来的 invocation owner └─ verifyGitoxideHelperArtifactForInvocationInternal(ownerToken, capability)
WeakMap 中;对象表面不包含 path、digest 或 size。@maka/runtime-host/server 导出。{ executablePath, expectedSha256 } 不能成为这条链的 authority。当前没有 production release owner。issueGitoxideHelperReleaseArtifactClaimInternal() 只是未来受信 packaging owner 的接缝,不是签名信任根;这限制产品启用条件,但不阻止该窄 authority 作为后续切片的 可审查基础设施合并。
一次 artifact 校验包含:
admission 与每次 invocation resolve 都执行这套校验。它可以识别校验之前或校验期间的替换,不会把 相邻 manifest 当作自证信任根;但校验完成后必须关闭 handle,而 Node 只能按 path spawn,所以这里不把 “刚验证的 bytes”表述成“实际执行的 bytes”。
| 项目 | v1 合同 |
|---|---|
| owner | Runtime Host 内部 artifact authority |
| 原子性边界 | 单个打开 file handle 的一次 identity + streaming digest observation |
| durable state | 无;claim/capability 仅存在于进程内 |
| 非法/伪造 claim | gitoxide_helper_release_claim_invalid |
| 平台或架构不匹配 | gitoxide_helper_release_claim_unsupported |
| path/symlink/读取失败 | gitoxide_helper_artifact_invalid |
| size/digest/identity 漂移 | gitoxide_helper_artifact_identity_mismatch |
| 错误 owner/伪造 capability | gitoxide_helper_invocation_capability_invalid |
| rollback | 只读校验,无副作用,无需回滚 |
本切片没有声称抵抗拥有同一 OS 用户文件写权限的主动攻击者。特别是:
正式生产接入前,必须由 packaged-release owner 提供信任根,并明确三平台安装目录与签名能力。不能 通过给本 API 再传一个裸 expected digest 来绕过这一门槛。
| 平台 | 当前持续验证 | 尚未承诺 |
|---|---|---|
| Linux | regular-file identity、digest、symlink path rejection | package signature、protected install root、spawn identity |
| macOS | 同 Linux | code-sign verification、notarized artifact binding、spawn identity |
| Windows | regular-file identity、digest、junction path rejection | Authenticode binding、ACL-protected install root、spawn identity |
后续只能按下面顺序推进:
gitoxide-helper-invocation-owner-v1.zh-CN.md;在第 1 项完成以前,不接 Desktop/CLI,也不恢复旧 Git CLI adapter。