Skip to content

Ref writers, server side: the pre-receive hook, run tokens, admission - #303

Open
nishu-builder wants to merge 1 commit into
claude/upbeat-cori-xk77fgfrom
claude/upbeat-cori-xk77fg-2-server
Open

nishu-builder wants to merge 1 commit into
claude/upbeat-cori-xk77fgfrom
claude/upbeat-cori-xk77fg-2-server

Conversation

@nishu-builder

@nishu-builder nishu-builder commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

The server half of design/ref-writers.md. Part 2 of 4, stacked on #298.

  • Pre-receive hook. The server installs hooks/pre-receive, which re-runs the server binary with --pre-receive, so it covers smart HTTP and iroh alike. For each ref a push moves:

    • a content-named ref (refs/caos/req/<h>, refs/heads/caos-test/<h>) must point at <h>, or be deleted;
    • a ref under refs/caos/w/<ns>/ needs one of that namespace's writers, proven by a signature or a run token. writers itself changes only by a current writer's signature, as a fast-forward;
    • refs/caos/dev (caos.unguardedRef) is always accepted.

    git config caos.refWriters report on the server's repository only logs what it would refuse.

  • Run tokens. A job whose writes arg names namespaces, or *, gets a token at /secret/caos-write, revoked when its container is done. A top-level request is granted what the writer of its signed X-Caos-Write header may write; a continuation or child only what its creator was granted. A token can found a namespace that lists only its own writer, and can never change a writers list.

  • conversation_protocol::v3::writers holds what the client and workers share: the list format, genesis commits, the signed messages, and GitStore push auth.

Anything else is still let through. Conversations and actors live outside namespaces until #305 moves them in and refuses the rest, so nothing pushed today is refused.

Verified here

  • cargo fmt --check, clippy -D warnings and cargo test pass. server/tests/pre_receive.rs does real git pushes through the hook binary. The one failing test, launcher::checkout_import_completes_partial_history_and_keeps_local_edits, fails the same way on main in this container.
  • llm-step, run-and-update-ref and llm-test-tool, which link conversation-protocol, build and pass their tests.
  • Both lint scripts and nix build pass.

Not verified here

  • The caos-test suite: caosd up can't fetch flake inputs from inside its containers in this sandbox.

Stack

  1. Propose ref writers: who may push a ref, and how jobs inherit it #298: design doc
  2. this PR: server
  3. Ref writers, client side: keys, namespaces and writers from caos-cli #304: caos-cli
  4. Ref writers for conversations and actors: namespaces, delegation, and closing the rest #305: conversations and actors

🤖 Generated with Claude Code

https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc

The server installs a pre-receive hook that re-execs its own binary
(design/ref-writers.md). A ref in a refs/caos/w/<ns>/ namespace may be written
only by a key in that namespace's `writers` list, proven by a signature over
(ref, old, new) or by a run token; a namespace's id is the hash of its first
writers commit, and only a writer's signature changes the list.
Content-named refs must point at what they name. A ref outside every namespace
is let through until conversations move into namespaces later in this stack.

A top-level request's signed X-Caos-Write header names the writer it acts
for. A job whose `writes` arg asks for namespaces (or `*`) its creator was
handed gets a token at /secret/caos-write for the life of its container, and
its children are handed only that. A worker's scratch GitStore pushes with
the token; the shared formats and ed25519 signing live in
conversation-protocol's `writers` module.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NzY2JJGk9nTMG6gu8dZXpc
@nishu-builder
nishu-builder force-pushed the claude/upbeat-cori-xk77fg-2-server branch from f6e7e18 to f278d6d Compare October 6, 2026 02:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants