Repository navigation
Repair native installs whose executable bytes drifted - #13
Merged
Merged
Conversation
A valid managed receipt with mismatched executable bytes previously failed admission before any command dispatch, so `update` itself could not repair the installation and startup hard-failed every invocation. - `update` (explicit install) repairs: receipt-bound identity under the exclusive lock, drifted bytes preserved beside the install record, pinned installs restored to their recorded pin, recorded tag reinstalled when nothing newer is published. - `update status`/`update check` report `mismatch` instead of failing. - Automatic-policy startup repairs and re-enters the verified image before product work; non-auto policies and suppressing contexts fail closed as before. Attempts are daily-bounded via a dedicated last_repair_unix stamp so a routine check never delays self-healing. - Replacement invariants compare the stored receipt rather than the legitimately-drifted bytes; the recorded pin may no longer be changed by a replacement instead of pinning being impossible to publish. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
4 of 6 tasks
0thernet
added a commit
to hraness/gobstopper
that referenced
this pull request
Oct 6, 2026
## Summary A managed install whose receipt is valid but whose executable bytes drifted used to dead-end every command — including `gobstopper update`, the verb that would repair it. The launchd proxy crash-looped on the same gate. This release takes `hraness-cli-update` 0.1.2 ([hraness/cli-update#13](hraness/cli-update#13), tag `v0.1.2`): - `gobstopper update` repairs the drifted install explicitly under any policy: drifted bytes are preserved beside the install record, a pinned install restores its recorded pin, otherwise the recorded tag is reinstalled or a newer verified release applied. - `gobstopper update status` / `check` report a `mismatch` status instead of exiting before command dispatch. - Automatic-policy startup repairs and re-enters the verified image before product work — a supervised `proxy serve` self-heals via launchd relaunch. Disabled policies and suppressing contexts fail closed; repair attempts are bounded once per day on a dedicated `last_repair_unix` stamp. - `proxy doctor` now reports `drifted` when the service executable has a valid receipt whose bytes no longer match. Version bump to 0.8.10 (the tag was never published; the drifted local binary only claimed it) plus the `CHANGELOG.md` release section. #### Test plan - [x] `cargo build -p gobstopper` — clean - [x] `cargo test -p gobstopper --bin gobstopper self_update` — 31 passed - [x] `cargo fmt --all -- --check` — clean - [x] cli-update suite: 51 native tests incl. repair/pinned/startup-reentry/fail-closed cases (upstream repo) - [ ] CI Required + verify evidence minting, then assurance receipts for the final head - [ ] Merge, tag v0.8.10, release workflow, install on this machine, verify proxy + MCP + update status Generated with [Devin](https://devin.ai) --------- Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A valid managed receipt with mismatched executable bytes failed admission before command dispatch, so
updateitself could not repair the installation and every startup (including supervised services) hard-failed. This makes the updater self-healing while preserving every ownership and integrity boundary.update(explicit install) repairs: receipt-bound identity check under the exclusive lock, drifted bytes preserved beside the install record, pinned installs restored to their recorded pin, the recorded tag reinstalled when nothing newer is published.update status/update checkreport a newmismatchstatus instead of erroring before dispatch.Repaired→StartupOutcome::Reenter). Disabled policies and incidental-suppression contexts fail closed exactly as before.last_repair_unixstate field so a routine daily-check stamp can never postpone self-healing and a failing repair cannot storm the network.Test plan
cargo test --workspace --locked— 54 tests incl. 9 new drift/repair cases (status diagnosis, explicit repair, pinned repair, auto repair+reentry, disabled/suppressed contexts, failed-repair closedness + daily bound, foreign receipt rejection, installer-failure safety)cargo clippy --workspace --all-targets --locked -- -D warningscargo fmt --all -- --checkbun run check:ts— unchanged TS adapter still greenGenerated with Devin