← Files Meetings (Beta)ARCHIVED FILE

scripts/companion_audio_activity.py

8.75 KB · Oct 8, 2026 · 12:02 UTC

↓ Download file

"""Metadata-only vetoes for automatic owner replacement, never kill authority."""

from __future__ import annotations

import os
import re
import stat
import time
from dataclasses import dataclass, field
from enum import Enum
from pathlib import Path

import control_client

RECENT_AUDIO_SECONDS = 300
_MAXIMUM_ENTRIES = 4_096
_MAXIMUM_GENERATIONS = 256
_MAXIMUM_DEPTH = 16
_MAXIMUM_SCAN_SECONDS = 0.5
_STORAGE_GENERATION = re.compile(r"storage-[0-9a-f]{32}\Z")
_AUDIO_DIRECTORIES = ("Recordings", "NativeCaptureScratch", "UploadOutbox")


class AudioActivityStatus(str, Enum):
    COMPLETE = "complete"
    UNKNOWN = "unknown"


@dataclass(frozen=True)
class _FileActivity:
    path: Path
    device: int
    inode: int
    size: int
    modified_ns: int
    changed_ns: int


@dataclass(frozen=True)
class AudioActivitySnapshot:
    control_root: Path
    status: AudioActivityStatus
    recent_audio: bool = False
    files: tuple[_FileActivity, ...] = ()
    directories: tuple[tuple[Path, tuple[int, int] | None], ...] = ()


class _Unavailable(Exception):
    pass


def _identity(metadata: os.stat_result) -> tuple[int, int]:
    return metadata.st_dev, metadata.st_ino


def _reject_links(metadata: os.stat_result) -> None:
    # st_file_attributes is available only on Windows, including Python 3.10.
    if stat.S_ISLNK(metadata.st_mode) or (
        getattr(metadata, "st_file_attributes", 0) & stat.FILE_ATTRIBUTE_REPARSE_POINT
    ):
        raise _Unavailable


@dataclass
class _Scan:
    now_ns: int
    deadline: float
    entries: int = 0
    files: list[_FileActivity] = field(default_factory=list[_FileActivity])
    directories: dict[Path, os.stat_result | None] = field(
        default_factory=dict[Path, os.stat_result | None]
    )

    def check(self) -> None:
        if self.entries > _MAXIMUM_ENTRIES or time.monotonic() >= self.deadline:
            raise _Unavailable

    def metadata(self, path: Path, *, directory: bool) -> os.stat_result:
        self.check()
        current = path.lstat()
        _reject_links(current)
        expected = stat.S_ISDIR if directory else stat.S_ISREG
        if not expected(current.st_mode):
            raise _Unavailable
        self.check()
        return current

    def directory(self, path: Path, *, optional: bool = False) -> bool:
        try:
            metadata = self.metadata(path, directory=True)
        except FileNotFoundError:
            if not optional:
                raise
            self.directories[path] = None
            return False
        self.directories[path] = metadata
        return True

    def audio(self, path: Path, depth: int = 0) -> None:
        if depth > _MAXIMUM_DEPTH:
            raise _Unavailable
        if not self.directory(path, optional=depth == 0):
            return
        with os.scandir(path) as entries:
            for entry in entries:
                self.entries += 1
                self.check()
                metadata = entry.stat(follow_symlinks=False)
                _reject_links(metadata)
                child = path / entry.name
                if stat.S_ISDIR(metadata.st_mode):
                    self.audio(child, depth + 1)
                elif stat.S_ISREG(metadata.st_mode):
                    metadata = self.metadata(child, directory=False)
                    # No payload reads or extension assumptions: encrypted frames,
                    # legacy WAVs and partially prepared uploads all preserve work.
                    if depth == 0 and entry.name == "audio-encryption-key.v1.dpapi":
                        continue
                    self.files.append(
                        _FileActivity(
                            child,
                            metadata.st_dev,
                            metadata.st_ino,
                            metadata.st_size,
                            metadata.st_mtime_ns,
                            metadata.st_ctime_ns,
                        )
                    )
                else:
                    raise _Unavailable

    def generations(self, rust: Path) -> None:
        if not self.directory(rust, optional=True):
            return
        with os.scandir(rust) as entries:
            for count, entry in enumerate(entries, 1):
                self.entries += 1
                self.check()
                if count > _MAXIMUM_GENERATIONS:
                    raise _Unavailable
                if _STORAGE_GENERATION.fullmatch(entry.name):
                    generation = rust / entry.name
                    self.directory(generation)
                    self.audio(generation / "Recordings")

    def revalidate(self, control_root: Path) -> None:
        for path, expected in self.directories.items():
            self.check()
            if expected is None:
                try:
                    path.lstat()
                except FileNotFoundError:
                    continue
                raise _Unavailable
            current = self.metadata(path, directory=True)
            if _identity(current) != _identity(expected):
                raise _Unavailable
            # Health/control files can change independently of audio. Other
            # directory mutations make enumeration incomplete for this attempt.
            if path != control_root and (
                current.st_mtime_ns != expected.st_mtime_ns
                or current.st_ctime_ns != expected.st_ctime_ns
            ):
                raise _Unavailable


def capture_audio_activity(control_root: Path) -> AudioActivitySnapshot:
    """Observe fixed native audio roots without interfering with listener repair.

    Missing optional roots are safe to observe only beneath verified parents.
    Limits and uncertain filesystem evidence return UNKNOWN, which later vetoes
    automatic termination but does not stop the ordinary health challenge.
    """
    try:
        if (
            not control_root.is_absolute()
            or control_root.name != "LocalMeetingsControl"
            or ".." in control_root.parts
            or control_root.drive.startswith("\\\\")
        ):
            raise _Unavailable
        scan = _Scan(time.time_ns(), time.monotonic() + _MAXIMUM_SCAN_SECONDS)
        # Do not enter redirected ancestors, including Windows junctions.
        for ancestor in reversed((control_root, *control_root.parents)):
            scan.check()
            _reject_links(ancestor.lstat())
        app = control_root.parent
        scan.directory(app)
        scan.directory(control_root)
        private_control = control_client.require_private(control_root, directory=True)
        observed_control = scan.directories[control_root]
        if observed_control is None or _identity(private_control) != _identity(observed_control):
            raise _Unavailable
        # Native audio directories can have ordinary inherited permissions.
        # They provide a conservative veto, not owner or replacement authority.
        for name in _AUDIO_DIRECTORIES:
            scan.audio(app / name)
        scan.generations(app / "Rust")
        scan.revalidate(control_root)
        files = tuple(sorted(scan.files, key=lambda item: item.path))
        recent = any(
            max(item.modified_ns, item.changed_ns)
            >= scan.now_ns - RECENT_AUDIO_SECONDS * 1_000_000_000
            for item in files
        )
        return AudioActivitySnapshot(
            control_root,
            AudioActivityStatus.COMPLETE,
            recent,
            files,
            tuple(
                sorted(
                    (path, _identity(value) if value is not None else None)
                    for path, value in scan.directories.items()
                )
            ),
        )
    except (OSError, ValueError, control_client.ControlUnavailable, _Unavailable):
        return AudioActivitySnapshot(control_root, AudioActivityStatus.UNKNOWN)


def require_audio_inactive(baseline: AudioActivitySnapshot) -> None:
    """Recheck an automatic attempt's baseline immediately before each signal."""
    current = capture_audio_activity(baseline.control_root)
    if (
        baseline.status != AudioActivityStatus.COMPLETE
        or current.status != AudioActivityStatus.COMPLETE
    ):
        raise control_client.CooperativeHandoffDeclined(
            "Automatic recovery could not verify local audio activity",
            recovery_blocker="audio-activity-unavailable",
        )
    if baseline.recent_audio or current.recent_audio or baseline.files != current.files:
        raise control_client.CooperativeHandoffDeclined(
            "Automatic recovery preserved recently changed local audio",
            recovery_blocker="recent-audio-activity",
        )
    if baseline.directories != current.directories:
        raise control_client.CooperativeHandoffDeclined(
            "Automatic recovery audio directories changed",
            recovery_blocker="audio-activity-unavailable",
        )

SHA-256: ce94227d29a796b06ce34d8925133bad179a5eff684dea8a3e518dac43168202