fix: reject broken runtime launchers and preserve failed proof evidence
Some checks failed
Governed runtime contract / contract (push) Failing after 16s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
This commit is contained in:
tegwick 2026-09-27 23:19:50 +02:00
parent 4e666d6fa3
commit 43e621439a
26 changed files with 1367 additions and 3 deletions

View file

@ -25,7 +25,7 @@ class BootstrapRefused(RuntimeError):
def prepare(path: Path, config: OpsRunConfig) -> tuple[MessagesPolicy, Path, str]:
"""Validate value-free, owner-controlled pins without a key or queue claim."""
from glas_harness.profiles import ProfileCatalog
from sandboxer.extensions.runtime import verified_runtime
from sandboxer.extensions.runtime import RUNTIME_MOUNT, verified_runtime
try:
_private_file(path)
if not path.is_absolute() or path.resolve() != path or path.stat().st_size > 65536:
@ -64,6 +64,15 @@ def prepare(path: Path, config: OpsRunConfig) -> tuple[MessagesPolicy, Path, str
runtime = verified_runtime({"runtime": data["runtime"]})
if runtime is None or not runtime.is_absolute() or runtime.resolve() != runtime:
raise ValueError
# A matching artifact digest does not prove its generated launchers
# survived relocation. Refuse build-host interpreters before claiming.
for name in ("rein-aharness", "glas-harness"):
executable = runtime / "bin" / name
if executable.is_symlink() or not executable.is_file() or not os.access(executable, os.X_OK):
raise ValueError
with executable.open("rb") as stream:
if stream.readline(4096) != f"#!{RUNTIME_MOUNT}/bin/python3\n".encode():
raise ValueError
for private in (path.parent, spend.path.parent, Path(spend.policy.target_repo)):
a, b = runtime.resolve(), private.resolve()
if a.is_relative_to(b) or b.is_relative_to(a):