← Files Meetings (Beta)ARCHIVED FILE

scripts/meetings_app/manager.py

16.6 KB · Oct 8, 2026 · 12:02 UTC

↓ Download file

"""Typed app-control routing across supported native Meetings machines."""

from __future__ import annotations

from collections.abc import Callable, Mapping
from dataclasses import dataclass
from typing import Generic

from meetings_app.models import NativeAppRuntime, NativeCaptureObservation
from meetings_app.platforms import (
    CompatibleOwnerOperations,
    CompatibleOwnerPlatformHandler,
    OwnerT,
    ProofT,
    UnsupportedCompatibleOwnerPlatformHandler,
    is_windows_registration,
    registration_for,
)
from native_runtime_types import PlatformRuntimeSpec
from recording_control_action_contract import (
    RECORDING_CONTROL_SAFE_INTEGER_MAX,
    ControlAction,
    ControlPlatform,
    control_action_arguments_are_valid,
    parse_control_platform,
)
from recording_status_contract import (
    RecordingNativeStatus,
    RecordingStartupRecovery,
    RecordingUploadPhase,
    is_recording_startup,
    is_recording_state,
    is_recording_upload,
    parse_recording_schema_compatibility,
)

from helpers import is_json


def _runtime_platform(status: Mapping[str, object]) -> ControlPlatform:
    try:
        value = status["platform"]
    except (KeyError, TypeError):
        return ControlPlatform.UNKNOWN
    return parse_control_platform(value)


def supports_compatible_idle_windows_platform(value: object) -> bool:
    """Nonthrowing Windows-family hint for one generated platform value."""

    registration = registration_for(parse_control_platform(value))
    return registration is not None and is_windows_registration(registration)


def supports_compatible_idle_windows_owner(status: Mapping[str, object]) -> bool:
    """Nonthrowing Windows-family hint for explicit Meetings callsites."""

    return supports_compatible_idle_windows_platform(_runtime_platform(status))


def _has_finalized_streamed_recording(
    state: Mapping[str, object],
    capture: NativeCaptureObservation,
    *,
    audio_bytes: int,
    require_streaming_session: bool,
) -> bool:
    """Trust only the signed owner's exact generated hosted-stream completion."""

    recording = capture.contract
    if recording is None or "lastRecording" not in recording:
        return False
    receipt = recording["lastRecording"]
    if (
        receipt is None
        or audio_bytes <= 0
        or "streamingCompleted" not in receipt
        or receipt["streamingCompleted"] is not True
        or "savedLocally" not in receipt
        or receipt["savedLocally"] is not False
        or "audioBytes" not in receipt
        or receipt["audioBytes"] != audio_bytes
        or "recordingId" not in receipt
        or type(receipt["recordingId"]) is not str
    ):
        return False

    if "sessionId" in receipt:
        session_id = receipt["sessionId"]
        if type(session_id) is not str or not control_action_arguments_are_valid(
            ControlAction.STOP,
            {"expectedSessionId": session_id},
        ):
            return False
    elif require_streaming_session:
        return False

    if "lastAudioSavedLocally" not in recording or recording["lastAudioSavedLocally"] is not False:
        return False

    upload = state["upload"] if "upload" in state else None
    return (
        is_recording_upload(upload)
        and "phase" in upload
        and upload["phase"] == RecordingUploadPhase.UPLOADED.value
        and "hasDurableReceipt" in upload
        and upload["hasDurableReceipt"] is False
        and "completedRecordingId" in upload
        and upload["completedRecordingId"] == receipt["recordingId"]
    )


def _has_finalized_remote_recording(
    capture: NativeCaptureObservation,
    *,
    audio_bytes: int,
    mixed_bytes: int,
    require_streaming_session: bool,
) -> bool:
    """Recognize a stopped remote-only capture without inspecting its outbox."""

    recording = capture.contract
    if recording is None or "lastRecording" not in recording:
        return False
    receipt = recording["lastRecording"]
    rust = receipt["rust"] if receipt is not None and "rust" in receipt else None
    if (
        receipt is None
        or audio_bytes <= 0
        or mixed_bytes != audio_bytes
        or "recordingId" not in receipt
        or type(receipt["recordingId"]) is not str
        or "stoppedAt" not in receipt
        or not receipt["stoppedAt"].strip()
        or "savedLocally" not in receipt
        or receipt["savedLocally"] is not False
        or "streamingCompleted" in receipt
        or (
            rust is not None
            and ("terminal" not in rust or rust["terminal"] != "host-attested-finalized")
        )
        or "audioBytes" not in receipt
        or receipt["audioBytes"] != audio_bytes
        or "lastAudioSavedLocally" not in recording
        or recording["lastAudioSavedLocally"] is not False
    ):
        return False

    if "sessionId" in receipt:
        session_id = receipt["sessionId"]
        if type(session_id) is not str or not control_action_arguments_are_valid(
            ControlAction.STOP,
            {"expectedSessionId": session_id},
        ):
            return False
    elif require_streaming_session:
        return False

    return True


def can_automatically_replace_owner(
    state: Mapping[str, object],
    *,
    require_streaming_session: bool = False,
) -> bool:
    """Protect active capture without making durable uploads an update fence."""

    try:
        status = state["status"]
        can_stop = state["canStop"]
    except (KeyError, TypeError):
        return False

    if "lastCaptureFailed" in state and state["lastCaptureFailed"] is not False:
        return False

    schema_present = "schemaVersion" in state
    schema_version = state["schemaVersion"] if schema_present else None
    if schema_present:
        generated_authority = dict(state)
        generated_authority.pop("recording", None)
        if not is_recording_state(generated_authority):
            return False
    compatibility = parse_recording_schema_compatibility(
        schema_version,
        field_present=schema_present,
    )
    if "startup" in state:
        startup = state["startup"]
        if not is_recording_startup(startup) or "recovery" not in startup:
            return False
        recovery = startup["recovery"]
        if recovery not in (
            RecordingStartupRecovery.READY.value,
            RecordingStartupRecovery.BLOCKED.value,
        ):
            return False
        attention = startup["attention"] if "attention" in startup else None
        if recovery == RecordingStartupRecovery.BLOCKED.value and (
            "canStart" not in state
            or state["canStart"] is not True
            or attention
            != {
                "kind": "startup-recovery-failed",
                "stage": "outbox",
                "outcome": "returned-false",
            }
            or ("admissionFenced" in state and state["admissionFenced"] is not False)
            or ("handoffQuiescent" in state and state["handoffQuiescent"] is not False)
        ):
            return False
        if attention is not None:
            if (
                "kind" in attention and attention["kind"] == "retained-audio-needs-manual-recovery"
            ) or ("stage" in attention and attention["stage"] == "native-scratch"):
                return False
    if "recording" in state:
        capture = NativeCaptureObservation.from_value(state["recording"])
        if capture is None:
            return False
        recording = capture.wire
        mixed_bytes = 0
        if "mixedBytes" in recording:
            mixed_value = recording["mixedBytes"]
            if (
                type(mixed_value) is not int
                or not 0 <= mixed_value <= RECORDING_CONTROL_SAFE_INTEGER_MAX
            ):
                return False
            mixed_bytes = mixed_value
        if "startedAt" in recording and recording["startedAt"] not in (None, ""):
            return False
        saved_locally: bool | None = None
        if "lastAudioSavedLocally" in recording:
            saved_value = recording["lastAudioSavedLocally"]
            if type(saved_value) is not bool:
                return False
            saved_locally = saved_value
        audio_bytes = 0
        if "lastAudioBytes" in recording:
            audio_value = recording["lastAudioBytes"]
            if type(audio_value) is not int or audio_value < 0:
                return False
            audio_bytes = audio_value
        receipt: dict[str, object] | None = None
        if "lastRecording" in recording:
            receipt_value = recording["lastRecording"]
            if receipt_value is not None and not is_json(receipt_value):
                return False
            receipt = receipt_value
            if receipt is not None and (
                (
                    not receipt
                    and (
                        saved_locally is not False
                        or "lastAudioBytes" not in recording
                        or audio_bytes != 0
                    )
                )
                or ("savedLocally" in receipt and type(receipt["savedLocally"]) is not bool)
            ):
                return False

        streaming_completed = (
            receipt is not None
            and "streamingCompleted" in receipt
            and receipt["streamingCompleted"] is True
        )
        if streaming_completed and not _has_finalized_streamed_recording(
            state,
            capture,
            audio_bytes=audio_bytes,
            require_streaming_session=require_streaming_session,
        ):
            return False

        finalized_remote_recording = not streaming_completed and _has_finalized_remote_recording(
            capture,
            audio_bytes=audio_bytes,
            mixed_bytes=mixed_bytes,
            require_streaming_session=require_streaming_session,
        )
        if (saved_locally is True or audio_bytes > 0) and not (
            streaming_completed or finalized_remote_recording
        ):
            if (
                receipt is None
                or "savedLocally" not in receipt
                or receipt["savedLocally"] is not True
            ):
                return False
            if audio_bytes > 0 and (
                saved_locally is False
                or (
                    "audioBytes" in receipt
                    and (
                        type(receipt["audioBytes"]) is not int
                        or receipt["audioBytes"] != audio_bytes
                    )
                )
            ):
                return False
        if (
            mixed_bytes > 0
            and not finalized_remote_recording
            and (
                saved_locally is not True
                or audio_bytes != mixed_bytes
                or receipt is None
                or "savedLocally" not in receipt
                or receipt["savedLocally"] is not True
                or "audioBytes" not in receipt
                or type(receipt["audioBytes"]) is not int
                or receipt["audioBytes"] != mixed_bytes
            )
        ):
            return False
    if "meetingId" in state:
        meeting_id = state["meetingId"]
        if meeting_id is not None and (type(meeting_id) is not str or meeting_id != ""):
            return False
    if ("canPause" in state and state["canPause"] is not False) or (
        "canResume" in state and state["canResume"] is not False
    ):
        return False
    return (
        compatibility.supports_recording_authority
        and status == RecordingNativeStatus.IDLE.value
        and can_stop is False
        and ("sessionId" not in state or state["sessionId"] in (None, ""))
        and ("startedAt" not in state or state["startedAt"] in (None, ""))
    )


def can_force_replace_owner_without_native_ack(
    state: Mapping[str, object],
    *,
    finalized_recording_is_durable: bool = False,
    require_streaming_session: bool = False,
) -> bool:
    """Require independent finalization proof before bypassing native consent."""

    if not can_automatically_replace_owner(
        state,
        require_streaming_session=require_streaming_session,
    ):
        return False

    capture = NativeCaptureObservation.from_value(
        state["recording"] if "recording" in state else None
    )
    if capture is None:
        return False
    recording = capture.wire
    receipt = recording["lastRecording"] if "lastRecording" in recording else None
    if receipt:
        if finalized_recording_is_durable is True:
            return True
        if capture.contract is None or "lastRecording" not in capture.contract:
            return False
        generated_receipt = capture.contract["lastRecording"]
        if generated_receipt is None or "rust" not in generated_receipt:
            return False
        rust = generated_receipt["rust"]
        return (
            rust is not None
            and "terminal" in rust
            and rust["terminal"] == "host-attested-finalized"
        )
    return (
        "lastAudioSavedLocally" in recording
        and recording["lastAudioSavedLocally"] is False
        and "lastAudioBytes" in recording
        and type(recording["lastAudioBytes"]) is int
        and recording["lastAudioBytes"] == 0
    )


@dataclass(frozen=True)
class MeetingsAppManager(Generic[OwnerT, ProofT]):
    """Resolve typed machine handlers while concrete handoff policy stays injected."""

    host: str
    resolve_spec: Callable[[str], PlatformRuntimeSpec]
    operations: CompatibleOwnerOperations[OwnerT, ProofT]

    def can_automatically_replace_owner(self, state: Mapping[str, object]) -> bool:
        """Use one portable capture-only policy for automatic owner recovery."""

        return can_automatically_replace_owner(
            state,
            require_streaming_session=self.host == "win32",
        )

    def can_force_replace_owner_without_native_ack(
        self,
        state: Mapping[str, object],
        *,
        finalized_recording_is_durable: bool = False,
    ) -> bool:
        """Separate capture-idle observations from destructive finalization proof."""

        return can_force_replace_owner_without_native_ack(
            state,
            finalized_recording_is_durable=finalized_recording_is_durable,
            require_streaming_session=self.host == "win32",
        )

    def resolve_platform_spec(
        self,
        value: object,
    ) -> tuple[ControlPlatform, PlatformRuntimeSpec]:
        platform = parse_control_platform(value)
        registration = registration_for(platform)
        if registration is None:
            self.operations.reject("native update platform is unsupported")
        if self.host != registration.expected_host:
            self.operations.reject("native update platform does not match host")
        spec = self.resolve_spec(platform.value)
        if spec.platform_key != platform.value:
            self.operations.reject("native update platform does not match")
        return platform, spec

    def resolve_handler(
        self,
        status: Mapping[str, object],
    ) -> CompatibleOwnerPlatformHandler:
        platform = _runtime_platform(status)
        registration = registration_for(platform)
        if registration is None:
            return UnsupportedCompatibleOwnerPlatformHandler()
        resolved_platform, spec = self.resolve_platform_spec(platform.value)
        runtime = NativeAppRuntime(
            status=status,
            platform=resolved_platform,
            spec=spec,
        )
        return registration.factory(runtime)

    def authenticate_update_owner(
        self,
        status: Mapping[str, object],
        *,
        preverified_source: ProofT | None = None,
    ) -> tuple[CompatibleOwnerPlatformHandler, OwnerT]:
        """Route one explicit Update through its typed platform policy."""

        handler = self.resolve_handler(status)
        owner = handler.authenticate_compatible_owner(
            self.operations,
            allow_durable_handoff=handler.family == "windows",
            preverified_source=preverified_source,
        )
        return handler, owner

    def authenticate_compatible_idle_force_start_owner(
        self,
        status: Mapping[str, object],
    ) -> tuple[CompatibleOwnerPlatformHandler, OwnerT] | None:
        """Authenticate an idle Force Start owner on either supported platform."""

        handler = self.resolve_handler(status)
        if handler.runtime is None:
            return None
        owner = handler.authenticate_compatible_owner(self.operations)
        return handler, owner

    def preverify_staged_update_source(
        self,
        status: Mapping[str, object],
    ) -> ProofT | None:
        if not supports_compatible_idle_windows_owner(status):
            return None
        handler = self.resolve_handler(status)
        return handler.preverify_staged_update_source(self.operations)

SHA-256: 51b85f95bab9998e88bd5ab53511c3ff4bf715e55a83be1e3b576e7fde183c2a