← Files Meetings (Beta)ARCHIVED FILE
scripts/control_client_retention.py
9.36 KB · Oct 8, 2026 · 12:02 UTC
"""Authenticated runtime provenance for stream-only companion handoffs."""
from __future__ import annotations
from collections.abc import Mapping
from pathlib import Path
import control_client
from native_runtime_types import PlatformRuntimeSpec
from runtime_config import RUNTIME_CONFIG
def _resolved_path(value: object, *, message: str) -> Path:
if not isinstance(value, str) or not value:
raise control_client.ControlUnavailable(message)
try:
return control_client.Path(value).resolve(strict=True)
except (OSError, ValueError) as exc:
raise control_client.ControlUnavailable(message) from exc
def _is_direct_versioned_plugin_app(
path: Path,
family_root: Path,
*,
artifact_name: str = RUNTIME_CONFIG.app_name,
) -> bool:
"""Allow only the exact family-root/version/artifact path.
The family root is derived by native_runtime from Codex's plugin cache;
accepting arbitrary descendants would let a descriptor point at an
unrelated signed app copied under a writable subtree.
"""
try:
relative = path.relative_to(family_root)
except ValueError:
return False
return (
len(relative.parts) == 2
and control_client._PLUGIN_VERSION_COMPONENT.fullmatch(relative.parts[0]) is not None
and relative.parts[-1] == artifact_name
)
def _is_stable_runtime_artifact(
path: Path,
spec: PlatformRuntimeSpec,
*,
require_active: bool,
) -> bool:
from native_runtime import stable_runtime_artifact_root
try:
stable_runtime_artifact_root(path)
control_client.stable_runtime_verification_manifest(
path, spec, require_active=require_active
)
except (OSError, control_client.NativeRuntimeError):
return False
return True
def _runtime_handoff_source(
runtime: Mapping[str, object],
expected: Path,
spec: PlatformRuntimeSpec,
) -> tuple[Path, Path]:
"""Authorize the source cache while an immutable generation owns execution."""
source_value = runtime.get("_sourcePluginRoot")
source_root = expected.parent
source_missing = False
if isinstance(source_value, str) and source_value:
try:
source_root = control_client._resolved_path(
source_value,
message="native update handoff requester is not canonical",
)
except control_client.ControlUnavailable:
source_root = control_client._exact_missing_handoff_path(
source_value,
message="native update handoff requester is not canonical",
)
source_missing = True
family_root = control_client.plugin_cache_family_root(source_root, allow_missing=source_missing)
if family_root is None:
raise control_client.ControlUnavailable("native update handoff requester is not canonical")
if not source_missing:
try:
control_client.require_canonical_plugin_registration(source_root, family_root)
if source_root != expected.parent:
control_client.plugin_artifact_path(source_root, spec)
except control_client.NativeRuntimeError as exc:
raise control_client.ControlUnavailable(
"native update handoff requester is not canonical"
) from exc
if source_root != expected.parent and not control_client._is_stable_runtime_artifact(
expected,
spec,
require_active=True,
):
raise control_client.ControlUnavailable("native update handoff app identity does not match")
return source_root, family_root
def _lexical_absolute_path(value: object, *, message: str) -> Path:
"""Read one absolute, normalized path without requiring it to exist.
A retained handoff receipt is needed precisely when Codex has already
pruned the old bundle path. We still reject relative paths, traversal,
and non-normalized spellings before considering that narrow recovery
lane; the receipt was minted only while the original path existed and
validated.
"""
if not isinstance(value, str) or not value:
raise control_client.ControlUnavailable(message)
candidate = control_client.Path(value).expanduser()
if not candidate.is_absolute():
raise control_client.ControlUnavailable(message)
normalized = control_client.Path(control_client.os.path.normpath(str(candidate)))
if normalized != candidate:
raise control_client.ControlUnavailable(message)
return normalized
def _future_path(value: object, *, message: str) -> Path:
"""Normalize an absolute cache path even when its last child is absent."""
candidate = control_client._lexical_absolute_path(value, message=message)
try:
return candidate.resolve(strict=False)
except (OSError, ValueError) as exc:
raise control_client.ControlUnavailable(message) from exc
def _exact_missing_handoff_path(value: object, *, message: str) -> Path:
"""Return one lexically canonical path only when it is truly absent."""
if not isinstance(value, str) or not value or not control_client.os.path.isabs(value):
raise control_client.ControlUnavailable(message)
candidate = control_client.Path(value)
if str(candidate) != value or control_client.os.path.normpath(value) != value:
raise control_client.ControlUnavailable(message)
if control_client._path_entry_may_exist(candidate):
raise control_client.ControlUnavailable(message)
try:
resolved = candidate.resolve(strict=False)
except (OSError, ValueError) as exc:
raise control_client.ControlUnavailable(message) from exc
if resolved != candidate:
raise control_client.ControlUnavailable(message)
return candidate
def _resolved_handoff_paths(
expected_app_path: Path,
plugin_family_root: Path,
spec: PlatformRuntimeSpec,
) -> tuple[Path, Path]:
expected = control_client._resolved_path(
str(expected_app_path),
message="native update handoff app identity is unavailable",
)
try:
family = control_client._resolved_path(
str(plugin_family_root),
message="native update handoff plugin cache is unavailable",
)
except control_client.ControlUnavailable:
# An immutable active generation can outlive a completely pruned
# official cache family. Its validated manifest is the replacement
# authority; the absent family is used only as a narrowly checked
# lexical namespace for the old descriptor, never as executable
# provenance.
if not control_client._is_stable_runtime_artifact(expected, spec, require_active=True):
raise
family = control_client._future_path(
str(plugin_family_root),
message="native update handoff plugin cache is unavailable",
)
configured_home = control_client.os.environ.get("CODEX_HOME", "")
if configured_home != configured_home.strip():
raise control_client.ControlUnavailable(
"native update handoff plugin cache is unavailable"
) from None
codex_home = (
control_client.Path(configured_home).expanduser()
if configured_home
else control_client.Path.home() / ".codex"
)
try:
relative = family.relative_to((codex_home / "plugins" / "cache").resolve(strict=False))
except (OSError, ValueError) as exc:
raise control_client.ControlUnavailable(
"native update handoff plugin cache is unavailable"
) from exc
if (
len(relative.parts) != 2
or relative.parts[0] not in control_client.OFFICIAL_CACHE_PUBLISHERS
or relative.parts[1] != control_client.RUNTIME_CONFIG.server_name
):
raise control_client.ControlUnavailable(
"native update handoff plugin cache is unavailable"
) from None
return family, expected
def _expected_executable_path(
app_path: Path,
spec: PlatformRuntimeSpec,
) -> Path:
if spec.artifact_kind == "windows-executable":
return control_client._resolved_path(
str(app_path),
message="native update handoff app identity is unavailable",
)
try:
with (app_path / "Contents" / "Info.plist").open("rb") as handle:
info = control_client.plistlib.load(handle)
except (OSError, control_client.plistlib.InvalidFileException) as exc:
raise control_client.ControlUnavailable(
"native update handoff app identity is unavailable"
) from exc
executable = info.get("CFBundleExecutable") if isinstance(info, dict) else None
if not isinstance(executable, str) or not executable:
raise control_client.ControlUnavailable("native update handoff app identity is unavailable")
return control_client._resolved_path(
str(app_path / "Contents" / "MacOS" / executable),
message="native update handoff app identity is unavailable",
)
resolved_path = _resolved_path
is_direct_versioned_plugin_app = _is_direct_versioned_plugin_app
is_stable_runtime_artifact = _is_stable_runtime_artifact
runtime_handoff_source = _runtime_handoff_source
lexical_absolute_path = _lexical_absolute_path
future_path = _future_path
exact_missing_handoff_path = _exact_missing_handoff_path
resolved_handoff_paths = _resolved_handoff_paths
expected_executable_path = _expected_executable_path
SHA-256: 5588ea5974f3f5c19cc8f5bfde990edd183df39d1c5a1e2b14627923abcbb491