← Files Meetings (Beta)ARCHIVED FILE
scripts/native_runtime_windows_recovery.py
18.7 KB · Oct 8, 2026 · 12:02 UTC
"""Authenticate a private Windows source copy using the executing release's pins.
The installed cache is a byte transport. Only build-generated constants in the
already executing MCP authorize native bytes; mutable cache JSON never does.
"""
# native_runtime remains the shared, monkeypatchable facade for its split
# implementation modules; the private names below are those existing seams.
# pyright: reportPrivateUsage=false
from __future__ import annotations
import os
import re
import shutil
import stat
from collections.abc import Callable, Iterator
from contextlib import contextmanager
from dataclasses import dataclass
from pathlib import Path, PurePosixPath
import native_runtime
from native_runtime_types import (
NativeArtifactFingerprint,
NativeRuntimeStatus,
PlatformRuntimeSpec,
StableGenerationManifest,
WindowsRuntimeVerification,
)
from native_runtime_windows_pins import (
WINDOWS_RUNTIME_PINNED_FILES,
WINDOWS_RUNTIME_PLUGIN_VERSION,
WINDOWS_RUNTIME_WINDOWS_BINDING,
)
from windows_private_runtime import WindowsPrivateRuntimeError, fresh_private_directory
from helpers import is_json
MAXIMUM_SOURCE_CLEANUP_ROOTS = 8
MAXIMUM_SOURCE_CLEANUP_ENTRIES = 8192
MAXIMUM_SOURCE_CLEANUP_DEPTH = 32
MAXIMUM_SOURCE_CLEANUP_BYTES = 512 * 1024 * 1024
def _private_source_tree(root: Path) -> tuple[int, int]:
"""Validate an entire bounded scratch tree before deleting any of it."""
native_runtime._private_runtime_directory(root, create=False)
identity = root.lstat()
pending = [(root, 0)]
entries = 0
size = 0
while pending:
path, depth = pending.pop()
metadata = path.lstat()
entries += 1
if (
entries > MAXIMUM_SOURCE_CLEANUP_ENTRIES
or depth > MAXIMUM_SOURCE_CLEANUP_DEPTH
or stat.S_ISLNK(metadata.st_mode)
or getattr(metadata, "st_file_attributes", 0) & 0x400
or not (stat.S_ISDIR(metadata.st_mode) or stat.S_ISREG(metadata.st_mode))
or (stat.S_ISREG(metadata.st_mode) and metadata.st_nlink != 1)
):
raise native_runtime.NativeRuntimeError("private Windows source tree is unsafe")
native_runtime._require_windows_private_runtime_acl(path)
if stat.S_ISDIR(metadata.st_mode):
with os.scandir(path) as children:
for child in children:
if entries + len(pending) >= MAXIMUM_SOURCE_CLEANUP_ENTRIES:
raise native_runtime.NativeRuntimeError(
"private Windows source is too large"
)
pending.append((Path(child.path), depth + 1))
else:
size += metadata.st_size
if size > MAXIMUM_SOURCE_CLEANUP_BYTES:
raise native_runtime.NativeRuntimeError("private Windows source is too large")
return identity.st_dev, identity.st_ino
def cleanup_abandoned_sources(runtime_root: Path, revalidate_lock: Callable[[], None]) -> None:
"""Reclaim crash residue once, before a family-lock holder opens any snapshot.
Snapshot contexts can nest during activation, so neither snapshot entry nor
generation cleanup may perform this sweep. The family lock proves liveness;
current-user trust and private ancestry protect the inspected deletion graph.
"""
if not enabled():
return
def failed() -> None:
native_runtime.log_native_runtime_event("cleanup", "failed", error_kind="source")
try:
if native_runtime.stable_runtime_root(create=False) != runtime_root:
raise native_runtime.NativeRuntimeError("private Windows source root changed")
root_metadata = runtime_root.lstat()
root_identity = root_metadata.st_dev, root_metadata.st_ino
candidates: list[Path] = []
with os.scandir(runtime_root) as entries:
for index, entry in enumerate(entries):
if index >= 256 or len(candidates) >= MAXIMUM_SOURCE_CLEANUP_ROOTS:
break
if re.fullmatch(r"source--[a-f0-9]{32}", entry.name) is not None:
candidates.append(Path(entry.path))
except (OSError, RuntimeError):
failed()
return
for candidate in candidates:
try:
identity = _private_source_tree(candidate)
native_runtime._private_runtime_directory(runtime_root, create=False)
root_metadata = runtime_root.lstat()
native_runtime._private_runtime_directory(candidate, create=False)
current = candidate.lstat()
if (root_metadata.st_dev, root_metadata.st_ino) != root_identity or (
current.st_dev,
current.st_ino,
) != identity:
raise native_runtime.NativeRuntimeError("private Windows source changed")
except (OSError, RuntimeError):
failed()
continue
# A replaced lock is an authorization failure, not a cleanup warning.
revalidate_lock()
try:
shutil.rmtree(candidate)
except OSError:
failed()
def enabled() -> bool:
return (
native_runtime._is_windows_host()
and native_runtime.RUNTIME_CONFIG.flavor == "production"
and WINDOWS_RUNTIME_PLUGIN_VERSION is not None
and bool(WINDOWS_RUNTIME_PINNED_FILES)
)
def uses_pinned_source(plugin_root: Path) -> bool:
"""Use executing-code pins only for that code's own source directory.
Snapshot still requires the sealed version and exact bytes. A failed own-
source proof must not fall back to ordinary metadata verification. Distinct
successors retain the ordinary private-ACL and provenance verifier instead.
"""
return enabled() and plugin_root.resolve(strict=False) == native_runtime.PLUGIN_ROOT.resolve(
strict=False
)
def allows_running_source(plugin_root: Path, family_root: Path) -> bool:
"""Admit the host-launched sealed release when old caches lack a pointer.
Directory age is only a conservative stale-process fence. It never supplies
an expected native digest or admits bytes from another version.
"""
if (
not enabled()
or plugin_root.name != WINDOWS_RUNTIME_PLUGIN_VERSION
or plugin_root != native_runtime.PLUGIN_ROOT.resolve(strict=True)
or family_root.name != native_runtime.RUNTIME_CONFIG.server_name
or family_root.parent.name not in native_runtime.OFFICIAL_CACHE_PUBLISHERS
or native_runtime.plugin_cache_family_root(plugin_root) != family_root
):
return False
from native_runtime_stable import _official_cache_directory_creation_ns
selected = plugin_root.lstat()
if plugin_root.is_symlink() or getattr(selected, "st_file_attributes", 0) & 0x400:
return False
if (plugin_root / ".installing").exists():
return False
selected_created = _official_cache_directory_creation_ns(selected)
for candidate in family_root.iterdir():
if candidate == plugin_root:
continue
if native_runtime.GITHUB_RELEASE_COMPONENT.fullmatch(candidate.name) is None:
continue
metadata = candidate.lstat()
if (
candidate.is_symlink()
or not stat.S_ISDIR(metadata.st_mode)
or getattr(metadata, "st_file_attributes", 0) & 0x400
or candidate.resolve(strict=True).parent != family_root
or _official_cache_directory_creation_ns(metadata) >= selected_created
):
return False
return True
@dataclass(frozen=True)
class WindowsSourceSnapshot:
artifact: Path
status: NativeRuntimeStatus
verification: WindowsRuntimeVerification
def source_fingerprint(plugin_root: Path, spec: PlatformRuntimeSpec) -> NativeArtifactFingerprint:
files = WINDOWS_RUNTIME_PINNED_FILES.get(spec.platform_key, {})
return tuple(
native_runtime._path_identity(plugin_root / relative) for relative in sorted(files)
)
def _pinned_files(plugin_root: Path, spec: PlatformRuntimeSpec) -> dict[str, tuple[int, str]]:
if not uses_pinned_source(plugin_root) or plugin_root.name != WINDOWS_RUNTIME_PLUGIN_VERSION:
raise native_runtime.NativeRuntimeError("Windows recovery release identity is unavailable")
pins = WINDOWS_RUNTIME_PINNED_FILES.get(spec.platform_key)
if not pins or len(pins) > 8192:
raise native_runtime.NativeRuntimeError("Windows recovery inventory is unavailable")
for relative, (size, digest) in pins.items():
parts = PurePosixPath(relative).parts
if (
not parts
or parts[0] != "native"
or ".." in parts
or "\\" in relative
or ":" in relative
or relative != PurePosixPath(relative).as_posix()
or not 0 < size <= native_runtime.MAXIMUM_ARCHIVE_BYTES
or native_runtime.SHA256_HEX_PATTERN.fullmatch(digest) is None
or any(parent.as_posix() in pins for parent in PurePosixPath(relative).parents)
):
raise native_runtime.NativeRuntimeError("Windows recovery inventory is malformed")
if not all(
relative in pins
for relative in (
native_runtime.WINDOWS_PRODUCTION_BUNDLE_RELATIVE_PATH.as_posix(),
native_runtime.WINDOWS_PRODUCTION_LOCK_RELATIVE_PATH.as_posix(),
f"native/{spec.platform_key}/{spec.artifact_name}",
)
):
raise native_runtime.NativeRuntimeError("Windows recovery inventory is incomplete")
return pins
def pinned_generation(plugin_root: Path, spec: PlatformRuntimeSpec) -> str:
"""Compare desired code identity without re-verifying an unused cache copy.
The executing release's pins define the generation, including license files.
This is only an update hint: reusing a current generation still requires its
independent artifact and owner proofs. Every launch or changed generation
retains snapshot's complete byte verification, even if the cache is damaged.
"""
pins = _pinned_files(plugin_root, spec)
executable_digest = pins[f"native/{spec.platform_key}/{spec.artifact_name}"][1]
license_prefix = f"native/{spec.platform_key}/THIRD_PARTY_LICENSES/"
entries: set[tuple[str, str, str]] = set()
for relative, (_, digest) in pins.items():
if relative.startswith(license_prefix):
license_path = PurePosixPath(relative[len(license_prefix) :])
entries.add((license_path.as_posix(), "file", digest))
for parent in license_path.parents:
if parent != PurePosixPath("."):
entries.add((parent.as_posix(), "directory", ""))
licenses_digest = (
native_runtime.hashlib.sha256(
native_runtime.json.dumps(
sorted(entries), ensure_ascii=True, separators=(",", ":")
).encode("utf-8")
).hexdigest()
if entries
else None
)
return native_runtime._stable_generation_name(
spec, native_runtime._windows_generation_sha256(executable_digest, licenses_digest)
)
def require_matching_manifest(
source: WindowsSourceSnapshot, expected: StableGenerationManifest, spec: PlatformRuntimeSpec
) -> None:
digest = source.status.get("_executableSHA256")
if not isinstance(digest, str):
raise native_runtime.NativeRuntimeError("Windows source identity is unavailable")
generation_digest = native_runtime._windows_generation_sha256(
digest, source.verification.get("thirdPartyLicensesSha256")
)
if (
expected["generation"] != native_runtime._stable_generation_name(spec, generation_digest)
or expected["executableSha256"] != digest
or expected["version"] != source.status.get("version")
or expected["buildTimestamp"] != source.status.get("buildTimestamp")
or expected["verification"] != source.verification
):
raise native_runtime.NativeRuntimeError("Windows source changed before activation")
def _copy_file(source: Path, destination: Path, size: int, digest: str | None) -> None:
"""Bound the read and authenticate the new file, never the source's ACL."""
before = source.lstat()
if (
not stat.S_ISREG(before.st_mode)
or before.st_size != size
or before.st_size <= 0
or source.is_symlink()
or getattr(before, "st_file_attributes", 0) & 0x400
):
raise native_runtime.NativeRuntimeError("pinned Windows source file is unsafe")
destination.parent.mkdir(parents=True, exist_ok=True)
with source.open("rb") as incoming, destination.open("xb") as outgoing:
opened = os.fstat(incoming.fileno())
if not stat.S_ISREG(opened.st_mode):
raise native_runtime.NativeRuntimeError("pinned Windows source is not a regular file")
remaining = size
while remaining:
chunk = incoming.read(min(remaining, 1024 * 1024))
if not chunk:
raise native_runtime.NativeRuntimeError("pinned Windows source is incomplete")
outgoing.write(chunk)
remaining -= len(chunk)
if incoming.read(1):
raise native_runtime.NativeRuntimeError("pinned Windows source changed size")
outgoing.flush()
os.fsync(outgoing.fileno())
if digest is not None and native_runtime.sha256_regular_file(destination) != digest:
raise native_runtime.NativeRuntimeError(
"Windows source does not match the executing release"
)
@contextmanager
def snapshot(
plugin_root: Path, runtime_root: Path, spec: PlatformRuntimeSpec
) -> Iterator[WindowsSourceSnapshot]:
"""Copy sealed native inputs while the caller holds the runtime family lock."""
pins = _pinned_files(plugin_root, spec)
family = native_runtime.plugin_cache_family_root(plugin_root)
if (
family is None
or family.name != native_runtime.RUNTIME_CONFIG.server_name
or family.parent.name not in native_runtime.OFFICIAL_CACHE_PUBLISHERS
):
raise native_runtime.NativeRuntimeError(
"Windows recovery requires the official plugin cache"
)
native_runtime.require_canonical_plugin_registration(plugin_root, family)
owned_root: Path | None = None
try:
with fresh_private_directory(runtime_root, "source-") as private_root:
owned_root = private_root
for relative, (size, digest) in pins.items():
_copy_file(plugin_root / relative, private_root / relative, size, digest)
# This composite also binds the MCP archive, so its complete hash
# cannot be embedded in that archive. Its Windows subtree must equal
# the independently pinned build value before it is used as evidence.
composite = native_runtime.VERIFIED_CAM_DISTRIBUTION_RELATIVE_PATH
composite_size = (plugin_root / composite).stat().st_size
if not 0 < composite_size <= native_runtime.MAXIMUM_MANIFEST_BYTES:
raise native_runtime.NativeRuntimeError("Windows distribution is too large")
_copy_file(plugin_root / composite, private_root / composite, composite_size, None)
decoded = native_runtime._read_strict_local_json(
private_root / composite,
maximum_bytes=native_runtime.MAXIMUM_MANIFEST_BYTES,
label="private Windows distribution",
)
sources = decoded.get("sources")
if (
decoded.get("schemaVersion") != 2
or decoded.get("kind") != "chatgpt-meetings-verified-composite-distribution"
or not is_json(sources)
or sources.get("windows") != WINDOWS_RUNTIME_WINDOWS_BINDING
):
raise native_runtime.NativeRuntimeError(
"Windows distribution does not match release"
)
relative_executable = f"native/{spec.platform_key}/{spec.artifact_name}"
executable_pin = pins.get(relative_executable)
if executable_pin is None:
raise native_runtime.NativeRuntimeError("Windows executable pin is unavailable")
artifact = private_root / spec.artifact_name
_copy_file(private_root / relative_executable, artifact, *executable_pin)
license_prefix = f"native/{spec.platform_key}/THIRD_PARTY_LICENSES/"
for relative, pin in pins.items():
if relative.startswith(license_prefix):
_copy_file(
private_root / relative,
private_root / "THIRD_PARTY_LICENSES" / relative[len(license_prefix) :],
*pin,
)
# Explicit internal call: a private authenticated snapshot is not a
# second official plugin registration and must not enter that lookup.
verification = native_runtime._windows_production_verification_manifest(artifact, spec)
licenses = native_runtime._windows_source_licenses_sha256(artifact, spec)
if licenses is not None:
verification["thirdPartyLicensesSha256"] = licenses
# Generation metadata must agree with ordinary source verification.
# Policy releaseVersion is projected separately from the verified distribution.
fingerprint, version, timestamp = native_runtime._plugin_bundle_fingerprint(
artifact, spec
)
distribution = verification.get("windowsDistribution")
if distribution is None:
raise native_runtime.NativeRuntimeError("Windows release binding is unavailable")
status: NativeRuntimeStatus = {
"installed": True,
"version": version,
"buildTimestamp": timestamp,
"appPath": str(artifact),
"artifactPath": str(artifact),
"platform": spec.platform_key,
"artifactKind": spec.artifact_kind,
"artifactPathKind": spec.artifact_path_kind,
"capabilities": [],
"source": "plugin-bundled",
"_artifactFingerprint": fingerprint,
"_executableSHA256": executable_pin[1],
}
yield WindowsSourceSnapshot(artifact, status, verification)
except (OSError, WindowsPrivateRuntimeError) as exc:
raise native_runtime.NativeRuntimeError("private Windows source is unavailable") from exc
finally:
# Close directory pins before removing this operation's private scratch
# copy. Installed cache, stable generations and user data are untouched.
if owned_root is not None:
try:
shutil.rmtree(owned_root)
except OSError as exc:
raise native_runtime.NativeRuntimeError(
"private Windows source cleanup is incomplete"
) from exc
SHA-256: e46a596634139b1663a18a1cfeec728d943398f3b9a820f7d67b8fb1c01d7f80