Ref writers, server side: the pre-receive hook, run tokens, admission - #303
Open
nishu-builder wants to merge 1 commit into
Open
nishu-builder wants to merge 1 commit into
nishu-builder wants to merge 1 commit into
Conversation
nishu-builder
added this pull request to stack #307
October 5, 2026 10:11
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-2-server
branch
from
October 5, 2026 14:04
3e145e0 to
85c83cf
Compare
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-2-server
branch
2 times, most recently
from
October 6, 2026 02:13
0540044 to
f6e7e18
Compare
The server installs a pre-receive hook that re-execs its own binary (design/ref-writers.md). A ref in a refs/caos/w/<ns>/ namespace may be written only by a key in that namespace's `writers` list, proven by a signature over (ref, old, new) or by a run token; a namespace's id is the hash of its first writers commit, and only a writer's signature changes the list. Content-named refs must point at what they name. A ref outside every namespace is let through until conversations move into namespaces later in this stack. A top-level request's signed X-Caos-Write header names the writer it acts for. A job whose `writes` arg asks for namespaces (or `*`) its creator was handed gets a token at /secret/caos-write for the life of its container, and its children are handed only that. A worker's scratch GitStore pushes with the token; the shared formats and ed25519 signing live in conversation-protocol's `writers` module. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc
nishu-builder
force-pushed
the
claude/upbeat-cori-xk77fg-2-server
branch
from
October 6, 2026 02:18
f6e7e18 to
f278d6d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The server half of
design/ref-writers.md. Part 2 of 4, stacked on #298.Pre-receive hook. The server installs
hooks/pre-receive, which re-runs the server binary with--pre-receive, so it covers smart HTTP and iroh alike. For each ref a push moves:refs/caos/req/<h>,refs/heads/caos-test/<h>) must point at<h>, or be deleted;refs/caos/w/<ns>/needs one of that namespace's writers, proven by a signature or a run token.writersitself changes only by a current writer's signature, as a fast-forward;refs/caos/dev(caos.unguardedRef) is always accepted.git config caos.refWriters reporton the server's repository only logs what it would refuse.Run tokens. A job whose
writesarg names namespaces, or*, gets a token at/secret/caos-write, revoked when its container is done. A top-level request is granted what the writer of its signedX-Caos-Writeheader may write; a continuation or child only what its creator was granted. A token can found a namespace that lists only its own writer, and can never change a writers list.conversation_protocol::v3::writersholds what the client and workers share: the list format, genesis commits, the signed messages, andGitStorepush auth.Anything else is still let through. Conversations and actors live outside namespaces until #305 moves them in and refuses the rest, so nothing pushed today is refused.
Verified here
cargo fmt --check,clippy -D warningsandcargo testpass.server/tests/pre_receive.rsdoes realgit pushes through the hook binary. The one failing test,launcher::checkout_import_completes_partial_history_and_keeps_local_edits, fails the same way onmainin this container.conversation-protocol, build and pass their tests.nix buildpass.Not verified here
caos-testsuite:caosd upcan't fetch flake inputs from inside its containers in this sandbox.Stack
🤖 Generated with Claude Code
https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc