v0.20.0 — Launcher self-mount guard + tjor self-install (#67)
Breaking by design (pre-1.0 minor bump): the tree bin/tjor runs from is
refused as a writable mount unless --allow-self-mount; developing tjor
inside tjor now goes through tjor self-install.
Security
- BREAKING (by design): the running tjor tree is refused as a writable
mount (#67). The treebin/tjorruns from executes unsandboxed on the
host on every invocation and is the build context of every image — the
proxy (holding the session MITM CA key and brokered credentials) and the
root-running agent entrypoint included. Mounted writable into a cage (as the
workspace or a--dir, whether the mount is the tree, a parent, or a
directory inside it), one write persisted into every later session and onto
the host; the natural trigger was developing tjor inside a tjor session
launched by the checkout's ownbin/tjor. The launch is now refused after
every mount root is canonical and before any image is resolved or built,
naming both paths and the remedies.--allow-self-mountoverrides with a
loud warning; a read-only overlap (--dir-ro) is allowed with a notice.
Applies to every install kind. tjor self-install [--ref <commit-ish>](#67). Archives the committed
tree into~/.tjor/install/<sha>/(marked.tjor-source-sha,chmod -R a-w,currentsymlink), prints the launcher path and the commits since the
previous install, and is idempotent per sha. This is how to develop tjor
inside tjor: launch from the installed copy with the checkout as the
workspace.a-wguards against accidents only — the agent runs as the host
uid — the controls are the refusal above and the install root joining the
sensitive set:~/.tjor/install(orTJOR_INSTALL_ROOT) is refused as a
workspace or--dir/--dir-rounless--unsafe-dir.- A self-installed tree builds locally, like a checkout (ADR 0008
amended). The pull-vs-build decision keys on "source tree" (.gitor the
marker), so an archived tree never pulls a published image for its
VERSION. Only an installed release pulls. - Images record their source. Every local build (agent, proxy,
conformance) is labeledtjor.source-sha: the marker's sha, orHEAD
(-dirtywith uncommitted changes) for a checkout, orrelease-<VERSION>. tjor doctorreports launcher mutability. The root line says which kind
of tree is running (mutable git checkout / self-installed<sha>,
read-only / installed release), and from inside a checkout warns that a
launch from here would be refused, namingself-install. Scoping note: the
issue's "whether any configured profile mounts it writable" has no
equivalent — profiles declare no mounts — so the launch-from-here case is
what doctor checks.- Coverage:
tests/integration/self_mount_test.sh(daemon-free,unit
job; 45 checks) proves the refusals, the override, the read-only notice,
self-install's properties, the marker-driven local build, the label, the
install-root sensitivity and the doctor report; it is theself-mountsuite
of the boundary matrix with a newlauncher-integritycapability. Specs:
newlauncher-integrity;image-distributionandsession-launchamended.