From bba99bea934fe397b6aed59d3f33a5315799fa28 Mon Sep 17 00:00:00 2001 From: "Somhairle H. Marisol" Date: Mon, 21 Sep 2026 07:54:39 +0800 Subject: Harden artifact serving: root-chain link validation, deterministic stream disposal --- README.md | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) (limited to 'README.md') diff --git a/README.md b/README.md index 0f126db..4c23116 100644 --- a/README.md +++ b/README.md @@ -127,10 +127,17 @@ serves only paths published in the verified run manifest (logs, the manifest itself, and stray files are never exposed), `steps` serves only checkpointed GLBs (manifest members for completed runs), and every served stream is hashed against its recorded SHA-256 and byte count at request -time. Filesystem links inside a run directory (file or intermediate -directory symlinks/junctions) are rejected with `400`; hash or byte-count -deviations return `409`, and manifest failures surface as `500`. The -server binds to the ASP.NET default (add +time. Filesystem links anywhere in the chain from the configured artifact +root through the project and run directories down to the requested file +are rejected with `400` — for manifest reads, checkpoint digest recording, +and every served stream — and a failed open disposes its stream +deterministically. Hash or byte-count deviations return `409`, and +manifest verification failures surface as `500`. Link checks are not +atomic with the open: a concurrent local writer could substitute a path +component between the check and the open (TOCTOU); served content remains +bound to the recorded SHA-256 digest, so a substituted file is served only +if byte-identical. Operators must treat the artifact root as trusted +against local writers. The server binds to the ASP.NET default (add `--urls http://127.0.0.1:8099` to match the legacy port). ## CLI -- cgit v1.2.3