feat(capsule): integrate Station consumer lifecycle - #1659
Open
joshuajbouw wants to merge 8 commits into
Open
Conversation
Add authenticated Station install, update, show, and typed lock lifecycle support on the current mainline runtime and storage layout. AI-Disclosure: Codex | implemented the Capsule Station consumer and current-main regression integration; human reviewed and verified the independently tested lifecycle evidence Signed-off-by: Joshua J. Bouw <[email protected]>
Keep platform-neutral Station tests compiled everywhere while limiting shell-script fixtures and Unix permission APIs to supported targets. AI-Disclosure: Codex | implemented the Windows test compilation fix; human reviewed and verified formatting, test compilation, and strict clippy Signed-off-by: Joshua J. Bouw <[email protected]>
Describe Station as the v1 product while retaining internal wire and format identifiers such as station-lock-v2. AI-Disclosure: Codex | implemented the terminology correction; human reviewed and verified formatting, all-target compilation, and diff checks Signed-off-by: Joshua J. Bouw <[email protected]>
joshuajbouw
marked this pull request as ready for review
August 26, 2026 12:37
Add paired lock path and hidden raw-byte digest arguments. Validate untrusted sidecars before parsing, bind staged capsule bytes to typed Station commitments, persist owner-scoped provenance before daemon installation, and restore prior state on failure. Assisted development disclosure: implementation was prepared with an AI coding assistant and reviewed by the committing author. Signed-off-by: Joshua J. Bouw <[email protected]>
Validate archive bytes independently before owner-scoped lock writes and preserve lock ownership with conditional rollback when daemon installation fails. Assisted development disclosure: implementation was prepared with an AI coding assistant and reviewed by the committing author. Signed-off-by: Joshua J. Bouw <[email protected]>
Closes #1677 Same host session replaces the previous gateway attach. Silent readers idle-EOF after two minutes. At the 16-attach cap, idle LRU eviction admits a new slot and busy slots fail fast. mcp gc SIGTERMs orphaned astrid/aos mcp attach processes and never signals Python aos-mcp-frame. Replacement teardown is serialized and fail-closed before a new permit is acquired. Slot cancellation is passed into RMCP initialization. Signed-off-by: Joshua J. Bouw <[email protected]>
Stage and bind verified capsule bytes before persisting owner-scoped Station locks, then roll back with compare-and-swap so concurrent provenance survives. Closes #1682 Assisted development disclosure: implementation was prepared with an AI coding assistant and reviewed by the committing author. Signed-off-by: Joshua J. Bouw <[email protected]>
Bring the reviewed Station consumer lifecycle and atomic install transaction onto current main without changing the accepted feature blobs. Assisted development disclosure: integration was prepared with an AI coding assistant and reviewed by the committing author. Signed-off-by: Joshua J. Bouw <[email protected]>
Member
Author
|
Architecture hold: this PR remains useful, reviewed evidence for atomic package/provenance installation, but it is not the final landing vehicle. #1719 must first remove Station-specific types and state from the kernel boundary while preserving the proven exact-byte, CAS, ownership, and lifecycle invariants. The successor will require fresh review, CI, and the full production lifecycle test. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linked Issue
Tracking #1682
Depends on #1719
Refs #1563
Summary
Integrates authenticated Capsule Station v1 install, update, show, removal, and durable provenance into the current Astrid mainline. Station-bound installs now carry a typed artifact and lock binding into the daemon so verified bytes, package mutation, and owner-scoped Station lock state cannot diverge under concurrent installs.
Internal identifiers such as
station-lock-v2name wire or format revisions; they are not a Station product version.Changes
Verification
a32d25d1384ebd7207f664df9c1ea807c5deb8ff25a099d2384b9cf9ae8b1b0d73ccdfe70845c5613477e0195f67af572f5c8155cc22a0ef716bcdd2Claim boundary
This PR lands the Astrid consumer lifecycle. It does not host or activate a Station, move the public Station pin, publish production TUF metadata, or grant runtime capabilities from Station acceptance.
Residuals
AI / Tool Assistance
An AI coding assistant helped implement, test, integrate, and review the change. Joshua J. Bouw reviewed the resulting design, security invariants, and verification evidence and remains accountable for the submission.
Checklist
changes/{issue}.{kind}.md