diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 15 |
1 files changed, 11 insertions, 4 deletions
@@ -127,10 +127,17 @@ serves only paths published in the verified run manifest (logs, the manifest itself, and stray files are never exposed), `steps` serves only checkpointed GLBs (manifest members for completed runs), and every served stream is hashed against its recorded SHA-256 and byte count at request -time. Filesystem links inside a run directory (file or intermediate -directory symlinks/junctions) are rejected with `400`; hash or byte-count -deviations return `409`, and manifest failures surface as `500`. The -server binds to the ASP.NET default (add +time. Filesystem links anywhere in the chain from the configured artifact +root through the project and run directories down to the requested file +are rejected with `400` — for manifest reads, checkpoint digest recording, +and every served stream — and a failed open disposes its stream +deterministically. Hash or byte-count deviations return `409`, and +manifest verification failures surface as `500`. Link checks are not +atomic with the open: a concurrent local writer could substitute a path +component between the check and the open (TOCTOU); served content remains +bound to the recorded SHA-256 digest, so a substituted file is served only +if byte-identical. Operators must treat the artifact root as trusted +against local writers. The server binds to the ASP.NET default (add `--urls http://127.0.0.1:8099` to match the legacy port). ## CLI |
