Skip to content

Add signed bundle installer and recovery#40

Merged
dovvnloading merged 1 commit into
mainfrom
codex/signed-bundle-installer
Jul 21, 2026
Merged

Add signed bundle installer and recovery#40
dovvnloading merged 1 commit into
mainfrom
codex/signed-bundle-installer

Conversation

@dovvnloading

Copy link
Copy Markdown
Owner

Summary

  • add transport-independent signed recipe bundle staging and atomic activation
  • persist digest-named generations, the current/previous verified state, and a chained Ed25519 keyring update history
  • reject reparse points, hardlinks, path escapes, source mutation, incomplete state, and unverified startup recovery
  • require explicit trusted rollback authorization and keep provider/process execution disabled
  • add installer ADR/evidence and adversarial crash, tamper, key-rotation, and recovery tests

Scope boundary

This PR does not copy user-owned conversation artifacts, decode images, publish outputs, launch processes, provide a sandbox/provider, or enable execution. The next gate is trusted artifact copy-in/output validation and publication.

Verification

  • Python: 171 passed, 1 native-platform skip, 1 pre-existing pytest-asyncio warning
  • Frontend: 39 tests passed; lint, typecheck, and production build passed
  • compileall, contract generation, and git diff --check passed
  • prior native broker PR Add authenticated native broker adapter #39 is already merged into main

@dovvnloading
dovvnloading marked this pull request as ready for review July 21, 2026 21:21
@dovvnloading
dovvnloading merged commit e595106 into main Jul 21, 2026
1 check passed
@dovvnloading
dovvnloading deleted the codex/signed-bundle-installer branch July 21, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant