summaryrefslogtreecommitdiff
path: root/README.md
diff options
context:
space:
mode:
authorSomhairle H. Marisol <[email protected]>2026-09-21 07:54:39 +0800
committerSomhairle H. Marisol <[email protected]>2026-09-21 07:54:39 +0800
commitbba99bea934fe397b6aed59d3f33a5315799fa28 (patch)
tree9a32e7a70c68476d6d6e8e78c7db1bede047e388 /README.md
parent56800fbbd4488db20abd4f44f0d39e48599be0ab (diff)
downloadsomhairles-dream-fsharp-bba99bea934fe397b6aed59d3f33a5315799fa28.tar.gz
Harden artifact serving: root-chain link validation, deterministic stream disposal
Diffstat (limited to 'README.md')
-rw-r--r--README.md15
1 files changed, 11 insertions, 4 deletions
diff --git a/README.md b/README.md
index 0f126db..4c23116 100644
--- a/README.md
+++ b/README.md
@@ -127,10 +127,17 @@ serves only paths published in the verified run manifest (logs, the
manifest itself, and stray files are never exposed), `steps` serves only
checkpointed GLBs (manifest members for completed runs), and every served
stream is hashed against its recorded SHA-256 and byte count at request
-time. Filesystem links inside a run directory (file or intermediate
-directory symlinks/junctions) are rejected with `400`; hash or byte-count
-deviations return `409`, and manifest failures surface as `500`. The
-server binds to the ASP.NET default (add
+time. Filesystem links anywhere in the chain from the configured artifact
+root through the project and run directories down to the requested file
+are rejected with `400` — for manifest reads, checkpoint digest recording,
+and every served stream — and a failed open disposes its stream
+deterministically. Hash or byte-count deviations return `409`, and
+manifest verification failures surface as `500`. Link checks are not
+atomic with the open: a concurrent local writer could substitute a path
+component between the check and the open (TOCTOU); served content remains
+bound to the recorded SHA-256 digest, so a substituted file is served only
+if byte-identical. Operators must treat the artifact root as trusted
+against local writers. The server binds to the ASP.NET default (add
`--urls http://127.0.0.1:8099` to match the legacy port).
## CLI