Skip to content

Repair native installs whose executable bytes drifted - #13

Merged
0thernet merged 1 commit into
mainfrom
devin/repair-drifted-install
Oct 6, 2026
Merged

0thernet merged 1 commit into
mainfrom
devin/repair-drifted-install

Conversation

@0thernet

@0thernet 0thernet commented Oct 6, 2026

Copy link
Copy Markdown
Member

Summary

A valid managed receipt with mismatched executable bytes failed admission before command dispatch, so update itself could not repair the installation and every startup (including supervised services) hard-failed. This makes the updater self-healing while preserving every ownership and integrity boundary.

  • update (explicit install) repairs: receipt-bound identity check under the exclusive lock, drifted bytes preserved beside the install record, pinned installs restored to their recorded pin, the recorded tag reinstalled when nothing newer is published.
  • update status/update check report a new mismatch status instead of erroring before dispatch.
  • Automatic-policy startup repairs and re-enters the verified image before product work (Repaired → StartupOutcome::Reenter). Disabled policies and incidental-suppression contexts fail closed exactly as before.
  • Repair attempts are daily-bounded by a dedicated last_repair_unix state field so a routine daily-check stamp can never postpone self-healing and a failing repair cannot storm the network.
  • Transaction invariants now compare the stored receipt (not the legitimately-drifted bytes); the recorded pin may no longer be changed by a replacement — it is preserved, which also lets pinned installs repair to their pin.

Test plan

  • cargo test --workspace --locked — 54 tests incl. 9 new drift/repair cases (status diagnosis, explicit repair, pinned repair, auto repair+reentry, disabled/suppressed contexts, failed-repair closedness + daily bound, foreign receipt rejection, installer-failure safety)
  • cargo clippy --workspace --all-targets --locked -- -D warnings
  • cargo fmt --all -- --check
  • bun run check:ts — unchanged TS adapter still green
  • Required CI on this PR

Generated with Devin

A valid managed receipt with mismatched executable bytes previously
failed admission before any command dispatch, so `update` itself could
not repair the installation and startup hard-failed every invocation.

- `update` (explicit install) repairs: receipt-bound identity under the
  exclusive lock, drifted bytes preserved beside the install record,
  pinned installs restored to their recorded pin, recorded tag
  reinstalled when nothing newer is published.
- `update status`/`update check` report `mismatch` instead of failing.
- Automatic-policy startup repairs and re-enters the verified image
  before product work; non-auto policies and suppressing contexts fail
  closed as before. Attempts are daily-bounded via a dedicated
  last_repair_unix stamp so a routine check never delays self-healing.
- Replacement invariants compare the stored receipt rather than the
  legitimately-drifted bytes; the recorded pin may no longer be changed
  by a replacement instead of pinning being impossible to publish.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@0thernet
0thernet merged commit ef4c380 into main Oct 6, 2026
9 checks passed
@0thernet
0thernet deleted the devin/repair-drifted-install branch October 6, 2026 05:26
0thernet added a commit to hraness/gobstopper that referenced this pull request Oct 6, 2026
## Summary

A managed install whose receipt is valid but whose executable bytes
drifted used to dead-end every command — including `gobstopper update`,
the verb that would repair it. The launchd proxy crash-looped on the
same gate.

This release takes `hraness-cli-update` 0.1.2
([hraness/cli-update#13](hraness/cli-update#13),
tag `v0.1.2`):

- `gobstopper update` repairs the drifted install explicitly under any
policy: drifted bytes are preserved beside the install record, a pinned
install restores its recorded pin, otherwise the recorded tag is
reinstalled or a newer verified release applied.
- `gobstopper update status` / `check` report a `mismatch` status
instead of exiting before command dispatch.
- Automatic-policy startup repairs and re-enters the verified image
before product work — a supervised `proxy serve` self-heals via launchd
relaunch. Disabled policies and suppressing contexts fail closed; repair
attempts are bounded once per day on a dedicated `last_repair_unix`
stamp.
- `proxy doctor` now reports `drifted` when the service executable has a
valid receipt whose bytes no longer match.

Version bump to 0.8.10 (the tag was never published; the drifted local
binary only claimed it) plus the `CHANGELOG.md` release section.

#### Test plan

- [x] `cargo build -p gobstopper` — clean
- [x] `cargo test -p gobstopper --bin gobstopper self_update` — 31
passed
- [x] `cargo fmt --all -- --check` — clean
- [x] cli-update suite: 51 native tests incl.
repair/pinned/startup-reentry/fail-closed cases (upstream repo)
- [ ] CI Required + verify evidence minting, then assurance receipts for
the final head
- [ ] Merge, tag v0.8.10, release workflow, install on this machine,
verify proxy + MCP + update status

Generated with [Devin](https://devin.ai)

---------

Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant