You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This change completes the generic execution-authorization lineage and worker-isolation boundary required by the PQL asset-authoring and read-only trial flow.
Defines immutable, digest-bound receipts for profile approval claims, execution preauthorization claims, authenticated grants, execution claims, execution completion, and the final lineage index.
Requires a fresh point-of-use authorization decision and durable receipt consumption before every target CLI, HTTP, and browser effect.
Keeps machine asset admission non-authorizing and separate from Host execution policy.
Isolates worker HOME, workspace, Git configuration, SSH/askpass state, and credential helpers from trusted Host/publisher authority.
Adds durable, object-bound workspace/HOME ownership, supervised process launch, crash recovery, cleanup retention evidence, and fail-closed pathname/inode replacement handling.
Integrates the lineage through Generic Host, Workflow QA, Environment Factory, Testing Runner, and runtime projection paths.
Authorization Boundary
Machine-admitted test assets carry only audit facts:
Compatibility does not imply execution authorization. No receipt in the exported lineage is a reusable capability, and asset admission cannot grant execution or promotion authority.
Safety
Target repositories remain read-only.
Worker processes receive no GitHub, Git, SSH, askpass, or credential-helper authority.
Product-specific, secret, local-path, and conflict-marker added-line scans: clean
The repository-wide runner and a repeated Generic Host example run did not complete in the local validation environment: both became silent in unrelated long-running package/lifecycle stages and were terminated after bounded waits. Neither emitted a test failure before termination. The focused affected tests and independent review above completed at the final head; this Draft remains open for CI and human review rather than claiming a complete local full-suite pass.
Delivery Boundary
This Draft PR does not authorize a production run, mutate a target repository, approve a promotion, merge itself, or create product-specific runtime policy. It supplies the generic testing-package contracts and enforcement needed for a later Host-authorized trial.
本地通过公开的 dispatch('replay-guard')、dispatch('complete-replay') 和 dispatch('load-result') 复现:先用配置 A 完成运行并成功读取结果,再用不同密钥和 generation 的配置 B 在同一 FKST_DURABLE_ROOT 完成另一个运行;之后 A、B 各自读取自己的结果都会失败:
First result before second config: passed
First result after second config: structured execution replay state authentication failed
Second result after second config: structured execution replay state authentication failed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This change completes the generic execution-authorization lineage and worker-isolation boundary required by the PQL asset-authoring and read-only trial flow.
Authorization Boundary
Machine-admitted test assets carry only audit facts:
Execution still requires:
Compatibility does not imply execution authorization. No receipt in the exported lineage is a reusable capability, and asset admission cannot grant execution or promotion authority.
Safety
Validation
Validated at
3a779536eea1b82747b8353ec6d1a0d76d153947with the repository-pinned FKST engine:git diff --check: passedAPPROVEThe repository-wide runner and a repeated Generic Host example run did not complete in the local validation environment: both became silent in unrelated long-running package/lifecycle stages and were terminated after bounded waits. Neither emitted a test failure before termination. The focused affected tests and independent review above completed at the final head; this Draft remains open for CI and human review rather than claiming a complete local full-suite pass.
Delivery Boundary
This Draft PR does not authorize a production run, mutate a target repository, approve a promotion, merge itself, or create product-specific runtime policy. It supplies the generic testing-package contracts and enforcement needed for a later Host-authorized trial.